
Windows or Linux: what the choice is really about
This question is almost never settled by the operating system. It is settled by which applications have to run, what you already pay in licences, and who keeps it up at three in the morning. This is what sits underneath those three.
There is no general answer. Anyone who tells you Linux is always cheaper, or that Windows is always easier to manage, has skipped the question that matters: which application has to run on it, and what happens when it falls over at night.
The cost is rarely where people look for it. Windows Server charges per physical core with a minimum per server, plus access licences per user or per device. With Linux you pay no licence but you do pay for support, and without that support you pay in hours from your own people.
Security is not a property of the operating system but of the maintenance around it. Both fall over the same way: a service exposed to the internet that has not been patched, and a login that should never have existed.
The question underneath
In practice, an operating system choice is rarely made on the operating system. It is made on three things that are already true before anyone asks.
- Which application has to run on it. If your ERP only runs on Windows, the question is answered. If your supplier ships their software as a container, it is answered too, just the other way round. This is by far the most decisive factor and usually the only one that counts.
- What you already pay for. If your organisation lives in Microsoft 365 with identities in Entra ID, a Windows server is not a new world but an extension of one you already manage. That is worth money, even though it appears on no quote.
- Who keeps it up at night. A team fluent in one is slow in the other, and at three in the morning slow is the same as broken.
Only when those three fail to decide it does the comparison below come into play. That happens less often than you would think.
Where the cost actually sits
Amounts do not appear on this site. The structure does, because that is where the surprises live.
Windows Server charges per physical core of the machine, with a minimum per server and per processor. That minimum is exactly where the sum goes wrong: a machine with few cores costs the minimum, and a dense host with many cores costs a multiple of what was budgeted. On top of that come access licences, counted per user or per device that reaches the server — not per concurrent session. Three hundred people on fifty workstations across shifts is therefore not fifty.
Linux has no such structure. With Red Hat and SUSE you pay a subscription per machine or per socket, and that subscription is support rather than a right to run: it runs without it. With Debian and Ubuntu you pay nothing, and can buy support separately if you want it.
That is where the free side sets its trap. An operating system without a licence is not the same as an operating system without cost. What you do not pay a vendor, you pay in hours from someone who plans the updates, tracks kernel versions and wakes up at two in the morning. For one server that disappears into the noise. For thirty it does not.
The security comparison, honestly
This is the part most nonsense gets written about, usually with a count of published vulnerabilities attached. That count says nothing. It measures how much has been found and reported, not how much exists, and the two do not count the same way: a Linux distribution includes thousands of packages that ship separately on Windows.
What does differ in practice is this:
- The default surface. A bare Linux server runs little and listens on little. A Windows server arrives with more on board. That is fixable — you switch off roles you do not use — but it takes an action, and actions get skipped.
- Where the crown jewels sit. In a Windows estate that is the directory. Whoever becomes domain admin has everything. In a Linux estate the equivalent is key management and sudo. Both can be protected, and in both cases that is where the effort belongs.
- The patching rhythm. Windows has a fixed monthly cycle, which makes planning easy and the time to a patch occasionally long. On Linux it comes per package and per distribution, which can be faster and asks for more attention.
What knocks both over is the same thing, and it belongs to neither: a service exposed to the internet that is behind on patches, and a login that should never have existed. We have never seen an incident that came down to the choice between these two. We have seen plenty that came down to the attention paid afterwards.
On performance, briefly
A lot of searching goes into speed comparisons between the two. For the kind of work we deal with — file services, databases for an organisation of tens to hundreds of people, application servers — the operating system is almost never the brake.
The brake is the storage, the memory, or a query nobody has ever looked at. A server that is too slow will, nine times out of ten, not get faster from a different operating system, and will get faster from replacing a disk that can no longer keep up.
We attach no figures here. A benchmark without its method is an opinion with a decimal point, and the measurement that counts is the one on your workload.
When each one wins
If the three questions at the start do not settle it, it comes down to this.
Windows Server wins when your identities already live in the Microsoft world, when group policy and the familiar management tooling take work off your hands that you would otherwise write yourself, or when a supplier only supports it there. That last one is not a technical argument, but it is a real one: support you do not get, you pay for yourself.
Linux wins for anything internet-facing that runs in numbers, for workloads that live in containers, and anywhere licence cost scales with growth you do not control. For web services, processing tiers and anything with Docker or Kubernetes around it, it is usually not a choice but a default.
And often the answer is both. Most estates we take over already run a mixture, usually without anyone ever having decided on it. That is not a problem as long as one thing holds: that for each of them you know who patches it, who restores it and where that is written down. How we set that up sits under managed IT.
Questions we get about this
The ones that come up most often when this choice is on the table.
Is Linux more secure than Windows?
Not as a property. A bare Linux server runs less by default and therefore offers less attack surface, and that is a real difference. But what knocks estates over is almost always the same: a service exposed to the internet that is behind on patches, or a login that should not have existed. Both are independent of the operating system. A well-maintained Windows server is safer than a forgotten Linux one, and the other way round.
What does Windows Server actually cost?
The structure matters more than the amount. You pay per physical core of the machine, with a minimum per server and per processor, plus access licences per user or per device. That last part is not counted per concurrent session, so shift work costs more than the number of workstations suggests. We run that sum with your numbers and show it, rather than reading a conclusion out of it.
Can we run both side by side?
Yes, and most estates we take over already do. The price of it is not technical but human: you need someone who knows what they are doing on each of them when something breaks. For a small team that is the real consideration, not the virtualisation layer — that stopped minding a long time ago.
Our Windows Server 2016 is running out. Is that a reason to switch?
It is a reason to do something, not a reason to do this. Extended support for Windows Server 2016 ends in January 2027, and after that there are no more security updates. A move to Linux should follow from the application running on it; if that does not point there, a newer Windows version is the calmer path. The worst answer is another year of delay: a server without updates is not a server with a risk, it is an open door.
Where this lands with us
The services this subject falls under.
Not sure which way to go?
Tell us which applications have to run on it and who does the managing. That is usually enough to settle this within half an hour.
Practical IT knowledge in your inbox
New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.