Extended Security Updates: 6 Critical Windows 10 Choices

Windows 10 lifecycle timeline from end of support on 14 October 2025 through to Microsoft 365 Apps and Edge updates ending in October 2028
Every date here is Microsoft’s own. The last one is the reassuring-looking trap: Office and Edge keep updating long after the operating system stops.

Windows 10 stopped being supported on 14 October 2025, and almost three in ten Windows desktops worldwide were still running it in July 2026. Extended Security Updates are the paid stay of execution Microsoft sells for exactly that situation, and in June 2026 the company quietly handed one group of users another free year of them. If you are a business, that group is almost certainly not you.

That share figure is Statcounter’s July 2026 desktop measurement: Windows 11 on 68.93% and Windows 10 still on 29.83%. Everything else below comes from Microsoft’s own lifecycle and licensing documentation, linked at each claim.

Two things are worth establishing before the detail. Extended Security Updates exist in two separate programmes that share a name, and the post is organised by where you sit on the timeline rather than around the next deadline — because the right answer changes as the dates pass, and a piece written the other way stops being true the morning after.

What Extended Security Updates actually buy you

Microsoft’s ESU programme page is blunt about the scope. Enrolled PCs receive “critical and important security updates” as rated by the Microsoft Security Response Center. That is the whole product.

The same page lists what is excluded: new features, customer-requested non-security updates, design change requests, and general support. Microsoft goes further — the programme “only includes support for the license activation, installation, and possible regressions of the ESU itself”, and anything beyond that needs a separate paid support plan.

There is a version floor. Devices must be running Windows 10 version 22H2, which is the final Windows 10 release. Long-term servicing releases are a different animal: Microsoft states plainly that “Windows 10 Long Term Servicing releases (LTSB/LTSC) have their own lifecycles and are NOT covered via the Windows 10 ESU program”.

So Extended Security Updates are a patch feed, not a support contract. Nothing gets fixed. Nothing gets better. The machine simply stops accumulating known, unpatched holes at the rate it otherwise would.

Comparison of the consumer and commercial Windows 10 Extended Security Updates programmes, showing the free consumer route excludes domain-joined, Entra-joined and MDM-enrolled devices
Two programmes with the same name. Only one of them is available to a managed business estate.

The free extra year is not yours

In late June 2026, Microsoft extended the consumer programme by a year without an announcement. BleepingComputer noticed it on 25 June, in a documentation edit and an editor’s note appended to an old blog post. Microsoft’s end of support page now states that enrolled devices “will continue to receive critical and important security updates through October 12, 2027”.

Consumer enrolment costs nothing if you sync your PC settings to a Microsoft account. The alternatives are 1,000 Microsoft Rewards points or a one-off $30. Microsoft also warns that enrolment options and timing “may vary by region, such as in the European Economic Area”.

Then comes the sentence that decides this for every business reading. The same Microsoft page says the consumer programme “excludes devices managed by an organization or enrolled in enterprise licensing programs”. In practice Windows refuses the consumer enrolment on machines joined to an Active Directory domain, joined to Microsoft Entra, enrolled in mobile device management, or running in kiosk mode.

That is not a loophole to be worked around. It is the boundary between two differently-priced products, and the moment you domain-join or MDM-enrol a device you have chosen the paid side of it. An estate that is properly managed — which is the estate we would argue for in any case, and the one our note on remote systems hardening assumes — is by definition ineligible for the free route.

If a supplier has told you your office PCs got a free extra year, they have read the consumer headline and not the eligibility line underneath it. Ask which of your devices they enrolled, and how.

What commercial Extended Security Updates cost

Microsoft publishes one price and one rule. Volume licensing sells Windows 10 ESU at “$61 USD per device for Year One”, and “the price doubles every consecutive year, for a maximum of three years”. Run the arithmetic Microsoft’s rule dictates and Year Two is $122, Year Three $244, and a device carried the whole distance costs $427 before tax and before anybody’s margin.

Two structural details cost more organisations money than the headline price does.

It is sold by the year, and it is cumulative. Microsoft: “Customers can’t buy partial periods, for instance, only six months.” And: “If you decide to purchase the program in Year Two, you have to pay for Year One too, as ESUs are cumulative.” Waiting does not save you the first year. It defers the first year and adds the second.

Year One started in November 2025. Anyone joining now is buying a period that has largely elapsed. The minimum purchase is one licence, which at least means you can cover a handful of stragglers rather than the whole estate.

We are not going to publish a rand price, because it depends on your agreement, your partner and the exchange rate on the day — and quoting one would be marketing rather than information. Take Microsoft’s dollar figure, multiply by your device count, and compare it against a replacement PC amortised over four years. That comparison is the entire decision for most organisations, and it is arithmetic you can do yourself in ten minutes.

One exemption is worth knowing because it is free money. Microsoft grants ESU at no additional cost for Windows 10 virtual machines in Windows 365, Azure Virtual Desktop, Azure VMs, Azure Local and several related services. Windows 10 endpoints connecting to a Windows 365 Cloud PC are entitled for up to three years with an active subscription. If you already pay for any of that, check what it covers before you buy a licence you already own.

Six routes off Windows 10

Buying Extended Security Updates is one of six things you can do with a Windows 10 device, and it is rarely the right one for more than a minority of them. Work through the estate a machine at a time.

Six routes off Windows 10: upgrade in place, replace the device, buy commercial ESU, move it to the cloud, isolate and retire, or do nothing
Every device in the estate takes one of these. The sixth is a decision too, whether or not anyone made it deliberately.

Upgrade in place. The cheapest outcome when it works. Microsoft’s Windows 11 requirements are a 1 GHz dual-core compatible 64-bit processor, 4 GB of memory, 64 GB of storage, DirectX 12 graphics with a WDDM 2.0 driver, UEFI firmware that is Secure Boot capable, and TPM 2.0. The processor compatibility list is the one that fails machines people assume are fine.

Replace the device. For anything that misses the processor list or has no TPM 2.0, this is the honest answer. A four-year-old business laptop that cannot take Windows 11 is not a candidate for three years of paid patches.

Buy commercial Extended Security Updates. Correct for a defined, shrinking set of machines with a date attached to each one. Wrong as an estate-wide strategy, for reasons below.

Move the workload to the cloud. Windows 365 and Azure Virtual Desktop carry the entitlement already. This is worth modelling properly rather than dismissing — it changes the shape of the estate, not just its patch status.

Isolate and retire. The machine driving a lathe, a till or a lab instrument that the vendor never certified past Windows 10. Segment it, take it off general network access, and put a replacement date in the capital plan.

Do nothing. Also a route, and the one most estates are on by default. It is the most expensive of the six and nobody ever signs off on it explicitly.

Where you are on the timeline right now

Before October 2026. Commercial Extended Security Updates are in Year One and enrolment is retrospective, so the price does not change by acting today rather than next month — but the exposure does. Every unpatched month is a month of accumulated public vulnerabilities on a device your staff read email on.

From October 2026 to October 2027. Year Two, at double the Year One rate, and cumulative — an organisation enrolling here pays for both years. This is the window where the arithmetic tips decisively toward replacement for most fleets, because $183 per device buys a meaningful fraction of a new machine and leaves you exactly where you started.

After 12 October 2027. The consumer programme is finished. Commercial Year Three runs to the end of the three-year maximum at $244 for that year alone. At this point you are paying enterprise money to keep consumer-grade hardware breathing, and the case has to be a specific technical dependency, not inertia.

Through 10 October 2028. Two things outlive the operating system. Microsoft will provide security updates for Microsoft 365 Apps on Windows 10 until that date, with the apps frozen at Version 2608 and receiving security fixes only. And Microsoft Edge and the WebView2 Runtime “will continue to receive updates on Windows 10 22H2 until at least October 2028” — and Microsoft is explicit that ESU is not required for those.

Read that last pair carefully, because it is the trap. Office keeps updating. The browser keeps updating. The machine looks maintained from the desk it sits on, while the kernel, the drivers and the firmware underneath quietly stop receiving anything at all.

Microsoft also narrowed what support you can expect. If a Microsoft 365 Apps problem happens on Windows 10 and not on Windows 11, “support will ask the customer to move to Windows 11”, and those incidents carry no option to log a bug or request a product change.

When Extended Security Updates are the wrong answer

This is the part a reseller has no incentive to write, so here it is.

Extended Security Updates are the wrong purchase when they are bought for the whole estate. Three years of paid patches on a hundred machines is a hundred devices you will still have to replace, having spent $42,700 on not replacing them. The programme exists to cover the tail of a migration, not to substitute for one.

They are the wrong purchase when nobody has counted the eligible devices. The enrolment path is not trivial: Microsoft’s enablement guide requires version 22H2 with update KB5066791 or later, then the licensing preparation package KB5072653 installed after it, then a Multiple Activation Key applied and activated per device with slmgr.vbs, against a specific list of Microsoft activation endpoints. Devices that cannot reach those endpoints need phone activation. Buy first and inventory later and you will pay for licences you cannot apply.

They are the wrong purchase when the real problem is a line-of-business application nobody has tested on Windows 11. That is an application problem wearing an operating system costume, and paying Microsoft postpones the conversation with the software vendor rather than starting it.

And they are the wrong purchase when the money would fix something more dangerous. An estate with no tested restore, or with standing global admin rights, is not made safer by patching Windows 10 — it is made marginally less bad in one dimension while the actual route in stays open. Our pieces on backup testing and on identity attacks both argue that case at length.

The argument that has no expiry date

Every date in this post will pass. The pattern behind it will not.

Windows 10 shipped in July 2015 and its retirement date was published years in advance. Nothing about October 2025 was a surprise; the same is true of the Exchange Web Services retirement we wrote about in our Microsoft 365 migration piece, and of the licensing changes in our Business Premium and E3 comparison. Vendors publish these dates. Almost nobody maintains a list of them.

An organisation that keeps a lifecycle register — every operating system, database, firewall and line-of-business application, with its published end-of-support date and the budget year the replacement lands in — never has this conversation under time pressure. One that does not will have it again in 2028 about something else. That register is unglamorous, takes an afternoon to build, and is the single highest-return artefact in small-business IT governance. It is core to what we do under virtual CIO services, and it is the reason this decision costs some organisations a weekend and others a quarter.

What to do in the next fortnight

Count. You need three numbers before any purchase makes sense: how many Windows 10 devices you have, how many of them pass the Windows 11 hardware bar, and how many are blocked by an application rather than by hardware.

Check what you already own. Windows 365 and Azure Virtual Desktop entitlements are commonly forgotten, and so are devices that were quietly replaced and never decommissioned in the asset list.

Then decide per device, not per estate, and write the decision down with a date against it. Extended Security Updates are a reasonable line item for a shrinking, named list of machines. They are an expensive way to avoid a decision when they are applied to everything.

If you would rather have someone else do the counting and hand you the arithmetic, that is a conversation worth having — and the numbers in it will be Microsoft’s, not ours.