Icon chevron up
Here's a dismissible notice for cookies notices etc.
Dismiss
Staff at a community organization working across multiple branch offices

Modernizing Windows Server 2003 for Youth Employment Services

Youth Employment Services, a multi-branch Ontario charity, was running its core systems on Windows Server 2003, years after Microsoft stopped issuing security updates for it. Two custom internal applications were tied to those servers, and every branch firewall had reached end of lifecycle.

We rebuilt the server estate on Windows Server 2022, connected identity and email to Microsoft 365, published the custom applications as RemoteApps, replaced every branch firewall across a single weekend, and built LeaveTracker to handle union and non-union leave rules properly.

The situation

Youth Employment Services delivers employment programs from branches across Ontario. Its domain controllers and application servers were still running Windows Server 2003 — no security updates, no vendor fixes for anything disclosed since support ended, and no supported route to running current software on top. An unpatchable server is not a static risk. It worsens every month, because the list of known ways in keeps growing while the list of available fixes stays at zero.

Two custom line-of-business applications the branches depended on were bound to those servers, both written against the assumptions of that era: local paths, local execution, no provision for anyone working from another branch or from home. Email sat outside the organization's identity system, so creating an account or removing a departing employee meant doing the same job twice and hoping both halves were done. At the edge, the branch firewalls had reached end of lifecycle, no longer receiving firmware or signature updates and unable to run inspection features that current appliances treat as baseline.

The constraint that shaped the project was operational rather than technical. Branches serve the public on a schedule, so any work that took a branch offline during the working week meant turning people away at the door.

What we did

Six pieces of work, sequenced so the risky parts happened when nobody was trying to use the systems.

1
Rebuilt the server estate on Windows Server 2022

We built new rather than upgrading in place. There is no supported upgrade path from Server 2003 to a current release, and forcing one carries forward two decades of registry state, orphaned services and permissions nobody can explain. Building clean forced us to establish what the applications genuinely required, document it, and leave the rest behind.

2
Connected identity and email to Microsoft 365 with directory sync

Directory synchronization made the on-premises directory authoritative for identity while mail moved to Microsoft 365. One account, one password, one place to disable someone on their last day. Joiner and leaver handling stops being a checklist spread across systems and becomes a single action with a predictable result.

3
Published the custom applications as RemoteApps

Rather than rewrite two working applications, we published them through Remote Desktop Services. Staff launch them the way they launch anything else, but the code runs on the server and the casework data never leaves it. That delivered access from any branch or from home without touching application source, and without scattering copies across branch workstations.

4
Built LeaveTracker

Vacation and leave were tracked by hand. Union and non-union staff accrue entitlements under genuinely different rules — exactly the thing generic tools handle by approximating and asking a human to correct the answer. LeaveTracker implements both sets of logic as the collective agreement and the HR policy actually describe them, so the balance on screen is the balance.

5
Replaced every branch firewall in a single weekend

Firewall replacement goes wrong quietly: a rule that did not carry over, a tunnel that comes up but will not pass traffic, a printer that stops working on Tuesday for reasons nobody connects to Saturday. We staged and pre-configured every unit in advance, then cut them all over across one weekend, so no branch lost a business day and none was left running an old appliance alongside new ones.

6
Linked the branches and deployed next-generation security

With current appliances in place we established site-to-site VPN tunnels so every branch reached head-office resources over an encrypted link, and enabled intrusion prevention and detection alongside next-generation inspection the end-of-life units could not run at all.

The outcome

What this means for a similar organization

If you are running anything past end of life, the useful mental model is that you are accumulating unpatched vulnerabilities rather than holding a fixed level of risk. The machine is not getting weaker because it is ageing. It is getting weaker because the world keeps finding new ways in and the vendor has stopped closing them.

Custom applications are usually the reason charities stay put, and usually not a good enough reason. Delivery through Remote Desktop Services lets an old application live on a current, patched operating system and be reached from anywhere, with no rewrite. The application does not need to become modern. The platform underneath it does. The scheduling matters as much as the engineering: for branches that must be open to the public during the week, staging a multi-site firewall swap and cutting over in one window is the only option that respects what the organization is for.

Related: non-profit IT services and application development.

Running something you cannot patch?

Call 647-476-5259 for an honest read on how much risk an end-of-life server is carrying, and what a staged replacement would involve. Better to have that conversation before something forces it.

Close search

Search