Blog

Windows 10 support has ended. Now what?

Windows 10 reached end of support on 14 October 2025. Nothing stopped working overnight, and that is exactly the trap. Here is what has actually changed, and how to run the exit if your estate was not ready in time.

What changed last Tuesday week, and what did not

Every Windows 10 device in your estate still boots, signs in and runs its applications exactly as it did on 13 October. End of support is not a kill switch. What ended is the supply line: no more security updates, no more quality fixes, no more technical support from Microsoft. The 14 October Patch Tuesday was the last one Windows 10 will ever receive without an Extended Security Updates licence, which means the first update those devices silently miss lands on 11 November.

The risk is therefore cumulative, not immediate. Each month adds newly disclosed vulnerabilities that will be patched on Windows 11 and documented in public, but never fixed on unlicensed Windows 10. Attackers read those release notes too. And the exposure is not only technical: an unsupported operating system is a direct problem for Cyber Essentials certification, a difficult conversation with cyber insurers, and an audit finding waiting to happen in any regulated sector.

The triage if you missed the date

Plenty of estates crossed 14 October with Windows 10 still in production. If that is you, resist the urge to either panic or shrug. Run a triage. Every remaining Windows 10 device falls into one of three buckets: hardware that is eligible for Windows 11 and simply has not been upgraded yet; hardware that fails the requirements (TPM 2.0, a supported processor) and needs replacing; and the genuinely stuck, such as devices tied to instruments, production lines or a line-of-business application with a hard dependency.

Count each bucket honestly, because they get three different treatments. The first bucket is a deployment exercise you can start this month. The second is a procurement plan with lead times. Only the third is a real candidate for extended support, and it is nearly always a far smaller number than the estate-wide figure people reach for first.

ESU: enrol narrowly, and price in the exit

Extended Security Updates buy time for that third bucket. Commercial pricing is public: 61 US dollars per device for Year 1, doubling each year to a maximum of three years, ending October 2028. It is also cumulative, so joining in Year 2 means paying for Year 1 as well. Waiting does not save money. Note the carve-outs: Windows 10 running in Windows 365 Cloud PCs or Azure virtual machines gets ESU at no additional cost, and consumers have a separate one-year route to 13 October 2026.

“We bought ESU” is a line item, not a plan. It buys security patches only: no new features, no fixes for anything that is not a security issue, no support.

The danger with ESU is organisational, not financial. Once the invoice is paid, the urgency drains out of the programme and the estate quietly settles in for another year. Treat ESU as a bridge with a named far end: enrol the devices that genuinely need it, attach an exit date to every one of them, and put the replacement or remediation work in the plan now, while the pressure is real.

The upgrade itself is easier than you may remember

If your hesitation is scar tissue from Windows 7 to 10, the picture has improved. Windows 11 version 25H2 shipped on 30 September 2025 as an enablement package: it shares a servicing branch with 24H2, so a device already on 24H2 moves to 25H2 with a small update and a restart. There is no reason for a migration landing now to target anything other than 25H2, and Enterprise and Education editions of it carry 36 months of support, a runway that comfortably outlasts any sensible exit plan.

For the Windows 10 to 11 step itself, application compatibility is rarely the blocker it once was; the same Windows platform sits underneath. The real gates are hardware eligibility and the state of the estate around the operating system: the application sprawl, the legacy configuration, the exceptions nobody documented. That is where migrations actually slow down.

Sequence the exit

The estates that move fastest from here follow the same sequence we use on every migration: discover, rationalise, then migrate in waves. Use proper discovery tooling to establish hardware eligibility, application usage and user groupings from evidence rather than spreadsheets. Rationalise before you migrate, because every application you retire is one you never have to package, test or troubleshoot; we have seen enterprise portfolios shrink from tens of thousands of titles to around a thousand once usage data replaces assumption. Then schedule waves by risk and readiness, with rollback, starting with the eligible-but-not-upgraded bucket where progress is cheapest.

Windows 10 ran for a decade. The end of support was announced years in advance, and the estates still carrying it are not lazy, they are busy. But the clock that mattered has now actually run out, and every month of drift is a month of unpatched exposure. Triage this week, enrol ESU only where the evidence says you must, and put a date on the far side of the bridge.

Still running Windows 10?

We plan and deliver Windows 11 migrations at enterprise scale: evidence-led discovery, honest ESU scoping and wave-by-wave execution with rollback.