The server under the desk
Every estate has one. Finding the unracked, unpatched, load-bearing hardware before its retirement finds you.

It is not always literally under a desk. Sometimes it is in a branch office closet, or a VM on a host nobody owns, or a NAS labeled DO NOT TURNOFF in marker. But every estate has at least one: hardware outside the racks, outside the patch cycle, outside the inventory, inside the critical path.
We find them the same three ways every time.
- Follow the power and the network, not the CMDB. Switch port maps and DHCP leases do not lie. Anything drawing power and holding a lease that the inventory cannot name goes on the list.
- Follow the printouts. Reports that arrive on paper or by email on a schedule come from somewhere. Twice we have traced a daily P&L email to a desktop in a closed branch office.
- Ask the question sideways. Not "are there unofficial servers" (answer: no). Ask "when the power went out last year, what did you have to go restart by hand?" Watch the room.
Once found, resist the instinct to condemn it. The server under the desk exists because somebody needed something and the official channel said no or said eighteen weeks. It is evidence of unmet demand, usually built by the most resourceful person on the floor. Treat the builder as a source, not a suspect, or the next one gets hidden better.
Then price it like any other standing stock. What runs on it, who breathes on it, what dies with it. The usual answer is worse than expected: these boxes skew old, and old means out of support. Windows Server 2016 hits end of support in January 2027, and Microsoft's own guidance is already pointing at the exits. The under-desk fleet is disproportionately built on exactly this stratum: whatever was current when the workaround was born.
The remediation menu is short. Promote it: rack it, patch it, inventory it, give it an owner. Replace it: the workload was real, so build the sanctioned version before you unplug the unsanctioned one, not after. Or retire it: sometimes the report it produces stopped being read in 2021, and the kindest thing is a dated decommission with a month of "scream test" silence first.
What you may not do is nothing. Unowned hardware in the critical path is an incident with a lead time, and the inventory is only finished when it is on it. The mainframe is not your problem. The mini-tower behind the filing cabinet, running the label printer for the entire warehouse, on an OS that stops patching next year: that is your problem. Go find it.