Managed IT
Guide

Windows 10 End of Support: An SMB Action Guide

Windows 10 reached end of support over a year ago, and the PCs still running it haven't noticed because nothing visibly broke. This guide covers what ESU actually costs and excludes, whether your hardware qualifies for Windows 11, the separate 2028 deadline hiding inside Microsoft 365 Apps, and how to actually plan a mixed fleet.

Oct 9, 2026
9 min read
Windows 10 End of Support: An SMB Action Guide

Windows 10 reached end of support on October 14, 2025. If that sentence reads like news to you, it isn't — it's a year old. What's actually news is where that leaves a business that didn't move in time: still running, still getting work done, and quietly losing the one thing that made it safe to run in the first place. Nothing broke on that date. That's exactly the problem. A PC that stops receiving security updates doesn't announce it; it just becomes a slightly better target every month that passes.

This guide is for the SME that's past the point of "we should look into this eventually" and needs the actual numbers: what the paid extension costs and what it doesn't cover, whether your hardware can even run Windows 11, the separate deadline hiding inside Microsoft 365, and what to actually do with a fleet that's a mix of all three.

What changed on October 14, 2025 — and what didn't

Windows 10, version 22H2 — the final release, across Home, Pro, Pro Education and Pro for Workstations — stopped receiving technical support, feature updates, and quality updates, including security and reliability fixes, on that date. Existing Long-Term Servicing Channel (LTSC) builds are the one exception; they keep running on their own separate lifecycle, unaffected by this.

What didn't change: the PCs themselves. They still boot, still run Office, still print to the shared printer. That continuity is exactly why this is easy to put off — there's no outage forcing the decision, just a growing gap between what's running and what's being checked for new vulnerabilities. Every month that gap is open, it's open to everyone, not just to whoever eventually exploits it.

The ESU bridge: what it actually buys, and what it doesn't

Microsoft's answer for businesses that need more time is Extended Security Updates (ESU) — a paid, annual subscription that keeps flowing critical and important security patches to enrolled devices. It is explicitly not a substitute for being on a supported version. Three things it does not include, by Microsoft's own description: new features, nonsecurity updates customers request, and design-change requests. Technical support isn't bundled in either — ESU only covers problems with the ESU program itself (licensing, installation, activation, or a regression it caused), and even that needs an active support plan on top. You are paying to keep the roof from leaking, not for a renovation, and general troubleshooting for Windows 10 itself isn't part of what you're buying.

To enroll, a device has to be running version 22H2 — the last Windows 10 release, so there's no ESU path for anything older without updating to 22H2 first. Pricing runs through the Microsoft Volume Licensing Program at $61 USD per device for Year One, and Microsoft's own program terms state the price doubles every consecutive year, for a maximum of three years — so a device enrolled for the full stretch is looking at roughly $61, then about $122, then about $244 per year, before whatever your reseller or licensing agreement adds on top. It's sold in full-year increments only — no six-month option — and the years are cumulative: skip Year One and try to join in Year Two, and you still have to pay for Year One. The program's first year started in November 2025, a few weeks after the end-of-support date itself. Commercial and educational organizations can hold ESU coverage for a maximum of three years total.

There's a genuine exception worth knowing about if any part of your environment is already cloud-based: Windows 10 virtual machines running in Windows 365, Azure Virtual Desktop, Azure VMs, Azure Dedicated Host, Azure VMware Solution, and several other Azure-hosted scenarios get ESU at no additional cost. Physical endpoints that connect into a Windows 365 Cloud PC get the same deal — up to three years of ESU, free, as long as the Windows 365 subscription is active. In practice, that means the actual desktop a user works in can already be a fully supported Windows 11 Cloud PC, even while the physical machine in front of them is still technically running Windows 10. That's a real way to buy time without paying the per-device ESU fee twice over — once for the subscription you're already paying for anyway.

Taken together, ESU is priced the way a deliberate bridge is priced: cheap enough to consider for one year, expensive enough by year three that migrating looks like the better deal. Treating it as a standing arrangement rather than a countdown is the mistake that costs the most.

Does your hardware even qualify for Windows 11?

Before budgeting for ESU at all, it's worth checking whether you need it. Windows 11's minimum hardware requirements are a 1 GHz or faster processor with two or more cores on a compatible 64-bit CPU or SoC, 4 GB of RAM, 64 GB of available storage, a graphics card compatible with DirectX 12 and a WDDM 2.0 driver, UEFI firmware with Secure Boot capability, and — the one that trips up the most business hardware — a Trusted Platform Module, TPM, version 2.0.

RAM and storage are rarely the blocker on a machine bought in the last several years. TPM 2.0 and Secure Boot support are where older business laptops and desktops actually fail the check, since plenty of mid-2010s hardware either lacks a TPM chip entirely or ships with an older version that doesn't qualify. For an in-place upgrade specifically, rather than a clean install, the device also needs to already be running Windows 10 version 2004 or later, with the security update from September 14, 2021 or later installed — an older build needs that sorted out before an upgrade is even on the table.

The practical first step, before any purchasing decision, is a straight inventory: which machines, which Windows 10 version, how old. Most SMEs discover the split isn't where they assumed — some older machines pass the TPM check fine, while a surprising number of "recent enough" ones don't.

The clock almost nobody mentions: Microsoft 365 Apps

Here's the part that trips people up: Microsoft 365 Apps — Word, Excel, Outlook and the rest — get their own, separate extension on Windows 10. Security updates for Microsoft 365 Apps running on Windows 10 continue for three years past the OS's own end-of-support date, through October 10, 2028, delivered via the normal update channels. On the surface, that sounds like three more years of breathing room.

It isn't quite that. Feature updates and Copilot support for Microsoft 365 Apps on Windows 10 continue only until a specific build, Version 2608, ships — after that, the app is frozen on that version and receives security updates only, all the way to October 2028. The OneDrive desktop app follows the same pattern: it keeps updating on Windows 10 22H2 through that date, but on any older Windows 10 build it has already stopped updating entirely. Support narrows too — if a problem only shows up with Microsoft 365 Apps on Windows 10 and doesn't reproduce on Windows 11, Microsoft directs the customer to upgrade; if that's genuinely not possible, support is limited to troubleshooting only, with no guaranteed workaround and no option to log a bug report or feature request for that configuration.

The one-sentence version for a business owner: your Office apps staying patched until 2028 says nothing about the operating system underneath them. It buys time for the application layer, not for the far bigger attack surface sitting below it.

What this means for a fleet that's a mix of everything

Once the inventory is done, most SME fleets split into three groups, each with a different, genuinely different answer — not one blanket decision for "the IT":

Machines that already meet Windows 11's requirements just need the upgrade scheduled and tested against the line-of-business software running on them — the lowest-cost path, and usually the right default. Machines that don't qualify but are otherwise fine for their job are a real choice between hardware replacement and shifting that user's desktop into a Windows 365 Cloud PC, turning the physical device into little more than a terminal while the operating system — and its support clock — moves into the cloud. Then there's the genuinely awkward case: a machine pinned to an old build because of one legacy application never tested anywhere else. That one needs its own plan, sometimes network isolation while a longer-term fix is found, rarely an indefinite ESU subscription, since ESU was never priced to be affordable past year one.

What doesn't belong in this picture is enrolling the whole fleet in ESU by default because it's the path of least resistance this quarter. It's the most expensive option in year three by design, and it buys time without resolving anything.

The mistakes that show up every time

Assuming "it still works" means "it's fine." An unpatched, unsupported endpoint is an open door to anything that touches the network from it — not just a risk to the one machine sitting on the desk.

Budgeting for ESU before checking Windows 11 eligibility. Paying a rising, three-year-capped fee to delay a decision you might be able to make for similar money, sooner, is the expensive way to arrive at the same place.

Treating the Microsoft 365 Apps extension as if it covers the operating system. It covers Office. Windows 10 itself still stopped getting security updates in October 2025, extension or not.

No fleet inventory. Past a handful of machines, this decision cannot be made device-by-device from memory — and the split between "qualifies easily" and "needs real work" is rarely where people assume it is until they actually check.

FAQ

Is it actually unsafe to keep using Windows 10 right now? It's not unsafe the way a car with no brakes is unsafe — it keeps running. But every security vulnerability discovered in Windows 10 from October 14, 2025 onward goes unpatched unless the device is enrolled in ESU, and that gap only grows with time. Treat "still works" and "still safe" as two separate questions.

What does ESU actually cost for a small business? Through the Microsoft Volume Licensing Program, $61 USD per device for Year One, doubling in price every consecutive year for a maximum of three years, sold in full-year blocks only, and cumulative — enrolling in Year Two without having paid for Year One still means paying for both.

Is upgrading eligible hardware to Windows 11 cheaper than paying for ESU? Usually, especially past year one, since ESU's price is designed to climb. The actual rollout cost depends on your existing licensing and who does the migration work, so get that number for your specific fleet before defaulting to the subscription.

Does the 2028 Microsoft 365 Apps update extension mean I can put off upgrading the OS? No. It covers security updates for the Office apps only, with a frozen feature-update version and narrower support once you're past the Windows 10 end-of-support date — it doesn't touch the underlying Windows 10 security gap at all.

What if some of our hardware simply can't run Windows 11? Replace it, or move that user's desktop into a Windows 365 Cloud PC, where the physical device just needs to connect and the operating system — current, supported, and on its own lifecycle — runs in the cloud instead. Either resolves the problem; an indefinite ESU subscription on hardware you were never going to upgrade generally doesn't make financial sense past year one.

Can we buy just one year of ESU to cover this quarter? Yes, that's how Year One is sold, but be aware the years are cumulative going forward — if you skip enrolling and come back in Year Two, Microsoft's terms require paying for Year One as well at that point.

Getting a fleet that's actually current

The hard part of this isn't any single fact above — it's that most SMEs are managing this decision per-machine, from memory, without a current inventory of what's running where. Our Managed IT & Support team builds that inventory, runs the Windows 11 eligibility check across the fleet, and handles the rollout — upgrade, replacement, or a shift to Windows 365 Cloud PC — as one planned project instead of a scramble per device as issues surface. And because an unpatched, unsupported endpoint is a security problem well before it's anything else, our Cybersecurity & Identity team can fold this into a broader review of what's actually exposed across your network, rather than treating Windows 10 end of support as a problem separate from the rest of your security posture. If another end-of-life product is also on your radar, our guide to SQL Server 2016's own end of support covers that specific deadline and its own ESU terms.

Windows 10
Windows 11
Managed IT
Endpoint Management
MKB

Related Articles

Managed IT

What Does Managed IT Cost for SMBs? Prices Per User (2026)

How much does managed IT support really cost for an SMB in the Netherlands? This guide breaks down price-per-user tiers, what each package includes, one-off and per-server costs, and how to compare quotes without surprises in 2026.

Read More
Managed IT

How to Choose the Right IT Partner for Your SMB (Checklist)

Choosing an IT partner is a multi-year decision that touches every part of your business. This practical checklist covers the questions to ask, the red flags to avoid, how to read an SLA, and how to compare managed service providers fairly.

Read More
Managed IT

What Does IT Workplace Management Cost in 2026?

How much should IT management per workplace actually cost? This guide breaks down 2026 price bands per tier, what a workplace really includes, and how to build the true monthly cost, not just the management fee.

Read More

Need Help with Your IT Infrastructure?

Let's discuss how we can help transform your IT operations with modern solutions.