Skip to content
Pro IT NW

Field notes · 11 min read ·

Share

Windows 10 ESU extended to 2027 — but not for your fleet

Windows 10 reached end of support on October 14, 2025. The free consumer ESU extension to October 12, 2027 does not cover a single domain-joined, Entra-joined, or MDM-managed device.

A headline went around in late June: "Microsoft extends free Windows 10 security updates to 2027." It is true. On June 25, 2026, Microsoft moved the free consumer Extended Security Updates (ESU) deadline out a full year, from October 12, 2026 to October 12, 2027. If a leadership team reads that and concludes the Windows 11 migration can slide another year, they have misread it — and the misread is expensive.

Here is the sentence that matters, and it comes straight from Microsoft: the consumer ESU program is "only for personal devices and is not available for systems joined to Active Directory domains, Microsoft Entra, or managed through Mobile Device Management (MDM)." That single line excludes almost every endpoint a regulated mid-market organization owns. The free year is real for a personal laptop at home. It does not touch your 400 managed corporate machines.

The one-line version: "Windows 10 got another free year" is true for grandma's laptop and false for your fleet. Domain-joined, Entra-joined, and Intune-managed devices are explicitly ineligible for the free consumer extension. For a managed estate, the deadline math has not changed.

The three dates that actually govern this

Strip away the headline and the timeline for a business is straightforward:

  • October 14, 2025 — Windows 10 reached end of support. No more free security updates for anyone outside an ESU program. That date is in the past.
  • June 25, 2026 — Microsoft extended the free consumer ESU program to October 12, 2027 (one year beyond the original October 12, 2026 end date). Consumer only.
  • October 12, 2027 — the new end date for the free consumer path. Still does not apply to managed fleets.

The commercial program — the one that governs managed business devices — was not touched by the June announcement. Its terms are unchanged, and they were never generous.

Does the Windows 10 ESU extension apply to a managed business fleet?

The confusion in the headline comes from treating "Windows 10 ESU" as one thing. It is two programs with different audiences, different prices, and — critically — different eligibility rules.

The consumer program (the one that got extended)

The consumer ESU program is aimed at individuals running Windows 10 on personal devices. Enrollment is done through the Windows Update settings on the device itself, and you have three ways in:

  • Pay a one-time $30, or
  • Back up your Windows settings to a Microsoft account (free), or
  • Redeem 1,000 Microsoft Rewards points.

In the European Economic Area, Microsoft made the consumer path free without conditions. One consumer ESU license covers up to 10 devices tied to the same Microsoft account. This is the program that now runs to October 12, 2027.

And this is the program that does not work on a managed device. The enrollment path checks the device's join state. If the machine is joined to an Active Directory domain, joined to Microsoft Entra, or enrolled in any MDM (Intune included), the consumer path is off the table. There is no toggle, no exception request, no volume version of the $30 offer. It is architecturally excluded.

The registered-vs-joined nuance: Microsoft Entra-registered devices ARE eligible for the consumer path. Entra-registered is the BYOD case — a personal machine with a work account added, not a corporate-joined device. If you have users on personal laptops with only a work account attached, those specific machines may qualify. Your corporate-owned, Entra-joined, Intune-managed standard build does not. Do not let "some Entra devices are eligible" get rounded up to "our Entra fleet is covered" — the word in the middle changes the answer.

The commercial program (the one that applies to you)

Commercial ESU for Windows 10 is a separate, paid, per-device program purchased through Volume Licensing. It was designed for exactly the managed-fleet scenario the consumer program excludes. Its terms:

  • $61 per device for Year 1.
  • The price doubles each year: roughly $122 in Year 2 and $244 in Year 3.
  • Cumulative cost of about $427 per device if you ride all three years.
  • Maximum run of three years — there is no year four.
  • Devices must be on Windows 10 version 22H2 to be eligible.
  • Enrollment is via a Volume Licensing MAK key or through Azure Arc.
  • Coverage is Critical and Important security updates only — no new features, no non-security fixes, no general technical support.

There is one place commercial ESU is free: Windows 10 VMs running in Windows 365, Azure Virtual Desktop, and Azure VMs get ESU at no additional cost. If part of your estate is cloud-hosted desktops, those are covered. The physical laptops and desktops on employee desks are not — those are the ones that hit the $61-doubling-annually schedule.

What this costs a real fleet

Put numbers on it. A mid-market organization with 400 managed Windows 10 endpoints that cannot move to Windows 11 in time is looking at:

YearPer-device price400-device cost
Year 1$61$24,400
Year 2$122$48,800
Year 3$244$97,600
3-year total~$427~$170,800

That is roughly $171,000 spent to keep 400 machines receiving security-only patches for three years — with no features, no fixes, no support, and a hard stop at the end. Spread real hardware refresh across that same window and the calculus almost always favors finishing the Windows 11 migration over renting time on Windows 10. The doubling schedule is deliberate: Microsoft priced commercial ESU to be a bridge you want off, not a destination you settle into.

The decision framework

The June news changes the headline, not the work. For any device in your estate, the sequence is the same.

Step 1: Eligibility check — is the free path even on the table?

Ask one question per device: is it domain-joined, Entra-joined, or MDM-managed? If the answer is yes to any of those, the consumer path is off the table. For a standard corporate build, the answer is yes. That means the only free option — the one in the headline — does not apply, and you are choosing between Windows 11 migration and paid commercial ESU. For the small number of BYOD/Entra-registered personal machines, the consumer path may apply to the individual, not to your fleet management.

Step 2: Windows 11 hardware eligibility

For each managed device, can it run Windows 11? The bar is TPM 2.0, a supported CPU generation, Secure Boot, and the minimum RAM/storage floor. Machines that pass should be scheduled into migration waves. Machines that fail are the candidate pool for commercial ESU — but only as a bridge while they are refreshed, not as a way to avoid the refresh.

Step 3: Application compatibility

Hardware eligibility is the easy filter. The harder one is the application catalog — line-of-business apps, vendor clients, licensing dongles, and anything with an OS-version dependency. A device can be hardware-eligible for Windows 11 and still blocked by one certified-on-Windows-10-only application. This is where migrations stall, and it is the reason a real assessment counts applications, not just endpoints.

Build the application matrix early: every packaged app, every browser-dependent internal tool, every vendor client with a stated OS requirement, mapped against a Windows 11 support statement. The devices that end up on the commercial-ESU list are usually not there because of hardware — they are there because one application behind them has not been certified yet, and that certification is a vendor timeline you do not control.

Step 4: Wave plan

Sequence the migration by risk and by department. Pilot on IT-bounded and low-risk users first, validate the application catalog against each wave, then roll production waves with rollback plans. Devices that must stay on Windows 10 for a defined reason — a pinned application, a hardware refresh in flight — get commercial ESU for that specific, documented, time-boxed reason, and a date they come off it.

The framing that keeps this honest: commercial ESU is a line item for the exceptions, not the plan for the fleet. If the "ESU device" list is more than a small, named, dated subset of the estate, the migration hasn't been scoped — the deadline has just been deferred at $61-and-doubling per device.

Why the "another free year" reading is dangerous

The risk is not that anyone lies. The risk is that a true consumer headline gets applied to a managed fleet in a budget conversation, the Windows 11 project loses its urgency, and the organization arrives at a worse version of the same deadline twelve months later — now with less runway and, if they reached for ESU late, a Year 2 or Year 3 price instead of Year 1.

Two things are simultaneously true, and both need to be said in the same breath: Microsoft did extend free Windows 10 security updates to October 2027, and that extension covers none of your managed devices. Urgency without panic: the machines still get patched today, and the sky is not falling — but the clock on the managed fleet did not move, and the cheapest version of the fix is the one you start now.

Where this connects to the rest of the estate

Windows 10 end-of-support rarely arrives alone. The same mid-market shops carrying a Windows 10 fleet in 2026 are often carrying a Windows Server 2019 estate on the same refresh clock and, frequently, a VMware renewal in the same fiscal year. Those decisions share hardware, discovery, and cutover windows — the desktop migration and the server modernization are cheaper run as one program than as three.

And the Windows 11 migration is not only a compliance exercise. It is the prerequisite for the Copilot and modern-management roadmap most of these organizations also want — which brings its own, separate readiness problem worth understanding before you turn it on.

The 30-second version

Windows 10 reached end of support on October 14, 2025. On June 25, 2026, Microsoft extended the free consumer ESU program to October 12, 2027 — but that program is "only for personal devices and is not available for systems joined to Active Directory domains, Microsoft Entra, or managed through Mobile Device Management (MDM)." Your managed fleet does not get the free year. (One nuance: Entra-registered BYOD devices are eligible; Entra-joined corporate devices are not.)

For managed devices, the real choices are unchanged: finish the Windows 11 migration, or buy the separate, paid, per-device commercial ESU — $61 in Year 1, doubling to ~$122 and ~$244, about $427 cumulative over a three-year maximum, on 22H2, security-only. Windows 10 ESU is free for Windows 10 VMs in Windows 365, Azure Virtual Desktop, and Azure VMs — not for physical endpoints. Treat commercial ESU as a bridge for named, dated exceptions, not a fleet strategy.

If the Windows 11 migration has stalled — hardware eligibility unknown, application compatibility unmapped, no wave plan — the fix is a fleet assessment that produces exactly those three answers. Start a project and we'll scope it: eligibility check, app-compat matrix, and a wave plan. Vendor-neutral, labor-only. We don't resell licenses.

Related reading

Sources and further reading


Pro IT NW is a senior-led, vendor-neutral, labor-only Microsoft project consultancy in Seattle, working USA-wide. We do not resell Windows, Microsoft 365, Azure, or ESU licenses. The recommendation in any specific engagement is what fits your fleet, your applications, and your operating model — finish the migration, or bridge the exceptions. Senior-led, labor-only, fixed fee.

Related service

Start a project

Written by the team at Pro IT NW · Senior-led Microsoft project consultancy · Seattle / USA-wide.

Have a project on the runway?

Tell us the workload, the seat count, and the deadline. We'll come back inside two business days with scope and a fixed-fee range.