Provided you have an Enterprise Agreement / Volume License Agreement or you have purchased Software Assurance - you can purchase Extended Security Updates from Microsoft for up to 3 years on a per server basis where you will be able to register / enroll a fixed number of systems into this program. See the FAQ for more details and eligibility.
If you NEED to stay on-premises with these systems, and you have all the prerequisites in place, you can generate a special "Multiple Activation Key" from the Azure portal and deploy it to your on-prem update service: Windows Update, Configuration Manager (current branch) and even 3rd party solutions.
Want to learn more? I've got you covered. I asked Ned Pyle - Principal Program Manager on the Windows Server Team to talk about your options and show us how to generate MAK keys.
For more details and documentation about this process - check out this article which has all the info on how to request and provision an Extended Security Update MAK key from the Azure portal, once you have purchased Extended Security Updates. For details on HOW to deploy this key to your Windows Server 2008/R2 systems - check out this detailed blog by Poornima Priyadarshini.
Did we miss anything? Let us know in the comments and we'll do our best to get you the info you need!