Windows 10 End of Support: ESU or Windows 11?
Windows 10 end of support: what Extended Security Updates cover, when they make sense, how a migration in waves works and which alternatives exist.
Microsoft stopped regular security updates for Windows 10 on 14 October 2025. Even so, many companies still run Windows 10 because of specialist applications, old hardware or a project pushed aside by daily business. The decision between Extended Security Updates (ESU), migration and new devices should be made now.
What ESU does and does not deliver
Extended Security Updates are a paid Microsoft programme that keeps supplying Windows 10 with security updates after end of support. For businesses it runs in yearly steps for up to three years, each year licensed separately at a rising price. The prerequisite is Windows 10 version 22H2 with all previous updates.
ESU includes no new features, no non-security bug fixes, no support for new hardware and drivers and no general technical support. Applications that themselves require Windows 11 remain unsupported. ESU therefore buys time rather than replacing migration. It makes sense in three situations:
- Specialist applications without Windows 11 approval. The vendor has announced but not yet delivered approval.
- Medical and laboratory equipment. Certification is tied to an operating system version; a change requires recertification.
- Machine controls and test rigs. Industrial PCs coupled to long-life plant whose software only runs on Windows 10.
In all three cases the computer is also isolated from the network. For office workstations with compatible hardware, ESU only postpones a project that is due anyway. Running Windows 10 without ESU is not advisable for computers with internet or company data access: every new vulnerability stays open permanently.
Evidence matters too. Article 32 GDPR requires technical and organisational measures in line with the state of the art, which is hard to reconcile with an unpatched system processing personal data. Cyber insurers ask about unsupported systems in the application and in a claim. ESU or migration is therefore also a question of documentation.
Hardware inventory: TPM 2.0 and Secure Boot
Windows 11 requires a Trusted Platform Module version 2.0, Secure Boot enabled in UEFI and a processor from Microsoft’s compatibility list. Before deciding, you need an inventory with three details per device: age and model, compatibility check result, user and applications. A central management tool such as Microsoft Intune delivers it instantly.
Many devices are reported incompatible although TPM and Secure Boot are merely disabled in UEFI. Switching the boot mode and enabling the module makes many recent computers compatible. If the module is genuinely missing, a new device or thin client is the more reliable option; Microsoft does not support Windows 11 without TPM. Hardware due for replacement fails regardless of the operating system, so ESU rarely pays off there.
In most companies the inventory produces a mix: most devices migrate, some are replaced, and a small remainder stays on Windows 10 with ESU.
Migration in waves
A migration in waves has proven effective:
- Pilot group. Five to ten users from different departments, including at least one user of each important specialist application. Two to four weeks of testing under real conditions including printing, scanning and interfaces.
- First wave. Departments with standard software, such as administration and sales, where problems with printers, shares and sign-in show up.
- Further waves. Sites and departments with specialist applications, each after vendor approval.
- Remainder list. Devices that cannot be migrated receive ESU, network separation and a replacement date.
Each wave ends at a fixed point where open issues are collected and resolved before the next. With a service provider, waves and remainder list belong in the contract. The migration process itself is described in the article Windows 11 migration for businesses.
Special case: terminal servers and thin clients
Companies that deliver applications via terminal servers or Citrix have an additional option: the applications run on the server, the client only displays the screen. An old Windows 10 computer can be replaced by a thin client, a small device without local data, with a lean operating system and central management. Existing PCs can also run a thin client operating system if the hardware is not enough for Windows 11.
For many identical workstations, for example in administration, practices or production, this is often the more economical route. How such an environment is structured is described on the page Thin clients.
Key points
- ESU buys time for specialist applications, medical equipment and machine controls; it does not replace migrating office workstations.
- An inventory with a compatibility check determines the mix of migration, new devices and ESU; many devices become compatible once TPM and Secure Boot are enabled.
- Migration runs in waves with a pilot group and a remainder list; in terminal server environments, thin clients are often the more economical option.
How DEVACON handles migration, client management and the remainder list is described on the page Managed IT Services.
This article comes from the DEVACON blog and was editorially revised for the new website.