Blog
Windows 10: one hundred days from end of support
On 14 October 2025, Windows 10 stops receiving security updates. That is roughly one hundred days from now. It is not enough time to migrate a large estate from a standing start, but it is enough to make sure nothing preventable is still unsupported when the date arrives. Here is what a realistic plan still achieves.
The arithmetic nobody wants to do
One hundred calendar days is about seventy working days, and fewer once you subtract August leave and September change freezes. A full estate migration in that window is not credible for most organisations, and any plan that pretends otherwise will fail in a way that surprises nobody. What the window does allow is a disciplined split: know exactly what you have, move everything that can move, and put a deliberate, costed bridge under everything that cannot. The organisations in trouble this autumn will not be the ones with devices left on Windows 10. They will be the ones who cannot say which devices, why, or for how long.
Weeks 1 to 3: triage by evidence, not by meeting
Start with discovery, not workshops. You need three facts per device: is the hardware eligible for Windows 11, which applications does it actually run, and who depends on it. Configuration Manager and Intune will give you the hardware readiness picture in days. Application usage takes purpose-built tooling; our Scout capture tool exists precisely because asset registers and reality rarely agree.
The output is three honest buckets. Ready now: eligible hardware, compatible applications, upgrade in place. Ready with work: eligible hardware blocked by one or two applications or a pending refresh. Genuinely stuck: ineligible hardware awaiting procurement, or devices anchored to legacy applications, lab instruments and line-of-business systems with no near-term path. Most estates we assess put 60 to 80 per cent of devices in the first bucket. That is the opportunity the next ninety days must not waste.
The organisations in trouble this autumn will not be the ones with devices left on Windows 10. They will be the ones who cannot say which devices, why, or for how long.
Weeks 3 to 6: pilot fast, then trust the pilot
Windows 11 24H2 has been generally available since October 2024; this is not early-adopter territory. Run a two-week pilot across a representative slice of hardware models, application profiles and user roles, not a hand-picked group of IT staff with clean laptops. Instrument it properly: upgrade success rate, application failures, driver issues, helpdesk contacts. Fix what the pilot finds, then stop piloting. A pilot that runs for months is a decision being avoided.
Weeks 6 to 14: migrate the willing at pace
For the ready-now bucket, the in-place upgrade through Windows Update for Business or Configuration Manager is quick, keeps user data intact, and rolls back cleanly. Ring-based deployment lets you move hundreds of devices a week with a small team, holding each ring until the previous one is quiet. Communicate relentlessly and give people a self-service window before enforcement. The ready-with-work bucket runs in parallel: remediate the blocking applications, then feed those devices into the rings. This is also the moment to be ruthless about application debt. We have seen a rationalisation exercise take an estate from 26,000 application titles to about 1,000; you will not achieve that by October, but every application you retire now is one you never have to test, package or support on Windows 11.
ESU is a bridge, priced to make sure you cross it
For the genuinely stuck, Microsoft's Extended Security Updates programme is the right answer, and it should be planned now, not discovered in September. The commercial pricing has been public since April 2024: 61 US dollars per device for Year 1, covering security updates to 13 October 2026. The price doubles each year for up to three years, and it is cumulative, so joining late means paying for the years you skipped. ESU delivers security fixes only: no new features, no non-security fixes, no general support. Buy it for a named, finite list of devices, each with an owner and an exit date. An ESU purchase without an exit plan is not a bridge; it is a subscription to the problem.
What pretending has already cost
The end-of-support date was announced years ago, and estates that treated it as negotiable are now paying for the delay in ways that were entirely avoidable. Hardware refreshes that could have been spread across three budget cycles are being compressed into one, at whatever lead times suppliers can offer. Application estates that could have been rationalised calmly are being migrated wholesale, sprawl and all, because there is no time left to do it properly. And ESU spend is being committed for devices that were upgrade-eligible all along, which is the most expensive way there is to buy nothing. One hundred days will not undo that. It will, spent well, stop it getting worse.
One hundred days is enough, if you start now
We can put evidence behind your triage in the first fortnight: hardware readiness, real application usage and a costed plan for every device, including the stuck ones.