Windows 10 editions do not all share one support date. Microsoft's release information records the October 14, 2025 end of support for affected releases and separate servicing information for long-term editions.
Inventory the edition, version and update status of every device before deciding whether to upgrade, replace or use an extended-update program. Include kiosks and specialist systems that may be outside normal desktop management.
What commercial ESU provides
Microsoft's commercial Windows 10 Extended Security Updates guidance describes annual coverage for critical and important security updates, with a maximum of three years for eligible organizations.
It is not general product support or a feature-development program. There is limited support for ESU activation, installation and possible ESU regressions under the stated support conditions.
The published commercial program is annual and cumulative, with price increases in successive years. Confirm the current quote, edition and eligibility; do not apply consumer terms or one release's program to a different product.
Upgrade, replace or bridge
Upgrade eligible devices. Check Microsoft's Windows 11 requirements, including the exact supported processor, TPM 2.0 and UEFI Secure Boot capability. Confirm license eligibility, application compatibility, drivers and peripherals.
Use a pilot group before a broad rollout. Test business applications, printers, authentication and recovery, and give users a support route during the change.
Replace unsuitable hardware. Base the sequence on support status, application importance and replacement constraints. A processor-generation shorthand is not a substitute for the current supported-device assessment.
Use an approved bridge where needed. ESU may provide time for a difficult application or hardware dependency. Record an owner, exit date and migration action for each exception. Microsoft also documents specific Windows 365 and cloud scenarios with ESU eligibility; verify those conditions rather than assuming that any cloud connection qualifies.
Check Secure Boot certificate renewal
Microsoft's Secure Boot certificate guidance explains the expiry of certificates issued in 2011, beginning in June 2026. Expiration does not simply make the device stop booting, but renewal matters for future boot-security protections.
Check update deployment and any required OEM firmware work on the actual device estate. A healthy general patch report is not sufficient evidence that every device has received the required certificates.
Include servers and less frequently connected devices in the inventory. Do not disable Secure Boot as a workaround.
Track the rollout
Maintain a per-device record of:
- Current edition, release and support arrangement.
- Hardware and application readiness.
- Upgrade, replacement or exception decision.
- Backup and recovery readiness.
- Planned completion and acceptance result.
- Certificate-update status where applicable.
An end-of-support date is a maintenance boundary, not a prediction that every device will fail or be exploited that day. The practical aim is to remove unsupported dependencies in a controlled sequence.
If the same refresh includes an older on-premises email system, review the Exchange Server migration options and coordinate client compatibility testing.
BustanTech provides software and migration services and business hardware. Contact us to discuss an inventory-led refresh plan.