Windows 10 Extended Security Updates (ESU) is a paid subscription that provides security patches now that mainstream support of Windows 10 has ended. Free security updates and technical support are no longer available.
ESU only provides security patches. It is a paid service that extends “critical” and “important” security updates for Windows 10 for a maximum of three years, but does not include technical support, non-security fixes or new features. Additionally, customers experiencing technical issues with Windows 10 that are unrelated to the ESU updates will be advised to upgrade to Windows 11. ESU does not provide complete patching, as vulnerabilities rated as “moderate” or “low” will not be addressed.
Given these limitations, Gartner recommends that regulated organisations assess whether Windows 10 ESU is compliant with regulatory definitions and requirements regarding end-of-life software.
For organisations that were unable to migrate by 14 October 2025, Microsoft offers the Windows 10 ESU programme. ESU is a paid annual subscription that delivers only “critical” and “important” security patches until 14 October 2028. Microsoft provides Windows 10 ESU for consumers and commercial customers.
The Windows 10 ESU programme is strictly limited to delivering “critical” and “important” security patches for vulnerabilities discovered after the end-of-support date. Vulnerabilities rated as “moderate” or “low” may not be addressed, meaning only partial coverage is provided. No additional updates, such as new feature releases, enhancements or non-security bug fixes, are provided, and the operating system remains functionally unchanged apart from these specified security patches.
ESU does not maintain a business-as-usual state, as general technical support is excluded. Microsoft will assist only with licence activation, ESU installation and troubleshooting issues directly caused by those updates. All other IT support, ranging from usability questions and hardware or software compatibility to performance issues, must be handled internally or by third-party providers.
Regulated organisations must assess whether Windows 10 ESU is compliant with their governing regulations. Many regulatory frameworks have explicit requirements and definitions around end-of-life (EOL) software, and non-compliance might have an additional financial impact.
On 24 April, 2025, Microsoft confirmed that Microsoft 365 applications on Windows 10 will continue to receive “critical” and “important” security updates until 10 October 2028 and feature updates through to October 2026. Support for these apps will be limited, and any issue affecting only Windows 10 may prompt a recommendation to migrate to Windows 11 for full compatibility and ongoing assistance.
Support for third-party applications on Windows 10 ESU will vary by provider, but plan for support ending on 14 October 2025. Organisations planning to run business-critical applications on Windows 10 ESU must confirm with the supplier that they will be supported before committing to purchasing.
Microsoft’s Windows 10 ESU licensing is structured to encourage migration to Windows 11 or Azure virtual environments by doubling prices each year for all customer segments. ESU licences are cumulative, so year two subscribers must purchase both year one and year two licences, and year three subscribers must cover all three years.
Educational institutions benefit from a significant discount compared to commercial organisations. Commercial customers that manage Windows 10 devices through Microsoft Intune receive a 25% reduction, lowering the first-year ESU fee to $45 per device. This escalating cost model reinforces Microsoft’s position that ESU is a short-term bridge and underscores the need to prioritise Windows 11 deployment.
ESU is available at no charge for Azure Virtual Machines and Windows 365 Cloud PCs. ESU is also provided for up to three years at no additional charge for Windows 10 virtual machines running in multiple Azure services, such as:
Physical Windows 10 endpoints connecting to Windows 365 Cloud PCs – for instance, a Windows 10 laptop used to access Windows 365 – are also entitled to ESU for up to three years with an active Windows 365 subscription. Running Windows 10 in Azure does not change the lack of technical support.
Gartner recommends upgrading to Windows 11 as soon as possible. Gartner clients have reported that migrating to Windows 11 has been substantially easier and less effort than previous Windows upgrades.
The Windows 10 ESU programme provides only “critical” and “important” security updates, leaving “moderate” and “low” vulnerabilities unpatched. Costs double annually, and support is limited to security fixes, making ESU unsuitable for long-term use. Non-security issues require internal or third-party support, increasing the total cost of ownership. Gartner urges organisations using Windows 10 ESU to recognise that it is a temporary, incomplete approach to supporting an estate of Windows-based PCs long-term.
However, for devices that cannot immediately meet Windows 11 hardware requirements, ESU may serve as a temporary bridge. Gartner urges IT leaders to regard the 14 October 2025 end-of-support date as a catalyst for broader IT strategy discussions, prioritising migration to ensure a secure and supported environment.
Zac Bowden
"*" indicates required fields
Software Asset Management is a business practice that involves managing and optimising the life cycle of software within an organisation.
Software asset management is relevant to many facets of a business - take a look at some of the roles that it can form part of the focus of.
Software vendors come in all shape and sizes - all with their own set of licensing models and rules. We take a look at just a few of them.
As a constantly evolving subject, SAM is not without its challenges. We take a look at some of the most common ones.
Wondering what an investment in SAM could do for your business? Fill out a few details and find out what return you could get!
Answer a few questions about your SAM infrastructure & experience, and we'll put together a personalised recommendation for the future.
A simple health check of what's being used across your Office 365 estate in this FREE, Microsoft backed and easy to setup review.
Just like you would with your vehicle each year, get an annual check up of your software asset management programme.
Overwhelmed by the task of documenting the steps for a successful SAM programme? Get the experts in to help!
Concerned your SAM tools aren't covering your whole estate? Or on the look out for an entirely new tool? Get us in to assist.
Not content with covering all things SAM related, we've teamed up with Capital to provide a comprehensive hardware asset management review.
A simple, one-time reconciliation of the software you have deployed versus the licence entitlement you own.
A regularly scheduled analysis of your organisation's estate, specifically adapted to your needs and budget.
A full appraisal of your Microsoft 365 setup and how best to optimise it through automated recommendations.
An add-on to our SAMplicity One, MOT and Plus offerings, quickly diagnose your ability to migrate your resources to the cloud.
In collaboration with law firm Addleshaw Goddard, ensure the legality of your SAM programme and get assistance with any contract disputes.
Available as standard with SAMplicity Plus, ensure you're compliant if you're unexpectedly audited by a vendor.
We've teamed up with some of the forefront experts in licensing knowledge so you can teach yourself to be an expert too.
Stumped by the continually evolving complexities of SAM? Join us for one of our comprehensive courses, either in-person or online.
It’s chock full of useful advice, exclusive events and interesting articles. Don’t miss out!