Your Windows 10 security updates stop on a date the device will never mention.
Windows 10 Extended Security Updates are sold by the year, and Year 1 runs out on October 13, 2026. Microsoft classifies them as perpetual software, so nothing renews on its own and there is no subscription lapse to set off the usual alerts. The PC keeps booting. Word and Outlook keep updating. The operating system quietly stops getting patched.
- Year 2 is a separate purchase at double the price, with a new key on every device.
- Skipping a year does not save money. Microsoft charges for Year 1 anyway.
- Windows 11 Pro devices on version 24H2 reach end of servicing the same day.
In this short, our team walks through a Windows kernel vulnerability. Kernel flaws are the class of problem an operating system patch closes, and the class an unenrolled Windows 10 machine stops receiving fixes for.
What happens to Windows 10 on October 14, 2026?
If the device is enrolled in Extended Security Updates Year 2, nothing happens. If it is not, the operating system stops receiving security updates that day and the machine itself gives no sign of it.
Windows 10 reached end of support on October 14, 2025. Microsoft's Extended Security Updates program was the bridge across that date, and it is sold in one year blocks. Microsoft's Partner Center documentation publishes the coverage dates plainly: Year 1 covers October 15, 2025 through October 13, 2026. Year 2 picks up the next day and runs to October 12, 2027. Year 3 runs to October 10, 2028, and there is no Year 4.
So the program itself has not ended. What ends on October 13, 2026 is the coverage that a Year 1 purchase paid for. Buying the next year is a fresh decision, a fresh purchase order, and a fresh key deployment across every machine. It is not a renewal, because there is nothing to renew.
One scoping note before going further, because the two programs are routinely confused. Everything on this page describes the commercial program, the one organizations buy for managed devices. Microsoft runs a separate Extended Security Updates program for individuals and Windows 10 Home customers, with its own enrolment path, its own terms, and its own duration. If you are reading this for a home machine rather than a managed fleet, the consumer documentation is the one that governs you and the dates here do not apply.
That distinction is the whole reason this page exists. Almost everything else an institution buys from Microsoft is a subscription. A subscription lapses loudly. It sends a renewal notice, it charges a card, it puts a banner in the admin center, and somebody in accounting sees the line item. Extended Security Updates for Windows 10 do none of that.
Does Windows 10 ESU renew automatically?
No. Microsoft classifies Windows 10 Extended Security Updates as perpetual software, and perpetual purchases do not renew. Two sentences from the same Microsoft page settle it.
"Windows 10 ESUs are only perpetual, different than other ESUs that are either software or perpetual. Windows 10 ESUs are all simply perpetual by year."
"Perpetual software purchases have no end dates, they don't renew, they're perpetually available."
Microsoft Learn, Purchasing Extended Security Update Licenses as a Cloud Solution ProviderRead those together and the shape of the risk becomes clear. A Year 1 purchase is not a subscription that expires with a warning. It is a perpetual licence for one named coverage year. When that year's coverage end date passes, the licence has done everything it was ever going to do. It does not fail. It does not alert. It simply has nothing left to cover. That reading is ours rather than Microsoft's wording, and we would rather say so than dress an inference up as a quotation.
The practical consequence is that the safety nets a subscription provides are simply not there. There is no auto renewal charge to appear on a statement, and no subscription expiry to trigger the notices that normally accompany one. The device itself stays quiet too: it does not display a nag screen the way an unactivated copy of Windows does. Whether anyone tells you therefore depends on whether a person put the date on a calendar, which is a very different kind of control from a system that reminds you by default. Your reseller or managed provider may well raise it, and a good one will. The point is that the reminder has to come from somebody, because the licence will not generate one.
That leaves the absence of a patch as the first mechanical signal that coverage has lapsed, and absences are the hardest thing in technology operations for anyone to notice. To be clear about where it does show up: patch compliance reporting, vulnerability scanning and endpoint management tooling will all register an operating system that has stopped taking updates, and an institution running those well has a good chance of catching it. The gap is between organizations that watch that data deliberately and organizations that assume a device is fine because nobody has complained about it.
There is a second trap sitting behind the first one, and it catches the organizations that decide to wait and see. Extended Security Updates are cumulative. Microsoft states it directly: "If you decide to purchase the program in Year Two, you have to pay for Year One too, as ESUs are cumulative." Sitting out a year does not bank the money. It defers the same cost and adds the next one on top. Microsoft's own guidance to partners says the same thing from the other side, instructing them that once Year 2 coverage dates are current, they should purchase both Year 1 and Year 2.
Nor can the bill be trimmed by covering only part of a year. Microsoft is explicit that the program must be purchased by year and that customers cannot buy partial periods. The minimum purchase, on the other hand, is a single licence, so there is no volume floor forcing an institution to buy coverage for machines it plans to retire.
Most institutions do not know how many Windows 10 machines they still have.
That number is the first thing this decision turns on, and it is usually smaller than people fear or larger than the asset register says. Our engineers read it from your tenant and tell you what each option would actually cost.
Request a free licensing assessmentWindows 10 ESU coverage years, and what each one costs
These coverage dates are published by Microsoft for the commercial program. The price column reflects Microsoft's published Volume Licensing figure for Year One and Microsoft's published statement that the price doubles every consecutive year.
| ESU year | Coverage starts | Coverage ends | Per device price |
|---|---|---|---|
| Year 1 Current coverage |
October 15, 2025 | October 13, 2026 | $61 Microsoft published list, Volume Licensing Program |
| Year 2 | October 14, 2026 | October 12, 2027 | $122 Arithmetic: double the published Year 1 figure |
| Year 3 Final year |
October 13, 2027 | October 10, 2028 | $244 Arithmetic: double again. There is no Year 4. |
A note on those prices, because precision matters when a number is going into a budget. The $61 figure is what Microsoft publishes for Year One through the Volume Licensing Program. The $122 and $244 figures are arithmetic from that number and Microsoft's published doubling statement, not separately published prices, and the three year total of $427 per device is the same arithmetic carried through. What a specific institution pays depends on its purchasing channel and its agreement, so treat these as the shape of the curve rather than as a quote. The shape is the point: the cheapest year of this program is the one that is ending.
Why nothing on the machine will look broken
Microsoft made a separate commitment about Microsoft 365 Apps, and it runs on a different clock from the operating system. That mismatch is what makes this date so easy to miss.
Microsoft committed to keep shipping security updates for Microsoft 365 Apps on Windows 10 for three years past the operating system's end of support, ending on October 10, 2028. Devices carry on receiving feature updates and Copilot support where eligible until Version 2608 ships, then hold on that version and keep taking security updates until 2028. The OneDrive desktop app on Windows 10 22H2 keeps updating on the same schedule.
None of that depends on Extended Security Updates. It is a Microsoft 365 commitment, not a Windows one. So on the morning of October 14, 2026, an unenrolled Windows 10 machine will look exactly like it did the day before. Outlook opens. Excel opens. Files sync. Copilot answers. There is no error, no red banner, and no help desk ticket, because from the user's chair nothing has changed at all.
Underneath, the thing that stopped is the layer that matters most. Operating system patches are what close kernel flaws, driver flaws, and remote code execution paths. Those are the vulnerabilities a supported Windows install receives a fix for on the second Tuesday of each month, and the ones an unenrolled machine now simply keeps.
Keeps working normally
- Microsoft 365 Apps security updates, through October 10, 2028
- Word, Excel, Outlook and PowerPoint, opening and running as usual
- OneDrive desktop sync on Windows 10 22H2, through October 10, 2028
- Microsoft 365 Copilot where eligible, on the frozen app version
- The machine itself. It boots, signs in, and behaves.
Stops, with no announcement
- Windows 10 operating system security updates
- Kernel and driver patches, including remote code execution fixes
- Any automatic renewal, because a perpetual licence does not renew
- The subscription lapse that would normally set off an alert
- Your ability to say the endpoint is still receiving security updates
Paying for ESU does not buy back Microsoft 365 support on Windows 10
This surprises people, so it is worth stating precisely. Microsoft's support limitations for Microsoft 365 Apps on Windows 10 apply, in Microsoft's own wording, "with or without Windows 10 Extended Security Updates." If an issue happens only on Windows 10 and not on Windows 11, support will ask you to move to Windows 11. If you cannot, support provides troubleshooting assistance only, and technical workarounds may be limited or unavailable.
Microsoft is equally direct that support incidents for Microsoft 365 Apps on Windows 10, again with or without Extended Security Updates, do not include the option to log a bug or request a product fix. Extended Security Updates buy security patches for the operating system. They do not buy back your position in the support queue, and they were never meant to.
Windows 11 Pro on 24H2 reaches end of servicing the same day
October 13, 2026 is not only the Windows 10 date. Microsoft's release information for Windows 11 lists version 24H2 with two different end of updates dates depending on edition, and the earlier one lands on exactly the same day.
Windows 11 version 24H2 stops receiving updates on October 13, 2026 for Home, Pro, Pro Education and Pro for Workstations. For Enterprise, Education, IoT Enterprise and Enterprise multi-session, 24H2 runs a further year, to October 12, 2027.
The edition split is the part that decides whether this matters to you, so it is worth being careful rather than dramatic about it. Windows 11 Business, the edition that comes with Microsoft 365 Business Premium, is the Pro edition. A great many credit unions, banks, and mortgage companies are licensed exactly that way. For those institutions, a fleet that is part Windows 10 on Extended Security Updates and part Windows 11 Pro on 24H2 has both halves stop on one October Tuesday. An institution standardized on Enterprise editions has the easier version of this problem, with a full extra year on the Windows 11 side.
The fix for the Windows 11 half is ordinary servicing rather than a purchase: move those devices to version 25H2, which carries Home and Pro editions to October 12, 2027 and Enterprise editions to October 10, 2028. One thing not to wait for is version 26H1. Microsoft scoped it to new devices arriving in early 2026 and states that it is not designed as a feature update for existing devices and is not offered as an in place update from 24H2 or 25H2. If the plan was to let the fleet roll forward onto 26H1 on its own, that plan does not exist.
There is a small mercy in the collision. Both halves are discovered by the same inventory pass, and for many institutions the same hardware refresh answers both questions at once. The machines still running Windows 10 in late 2026 are usually the oldest machines in the building, and the ones running Windows 11 Pro on an aging feature update are usually managed by the same team with the same tooling. One project, not two.
What Extended Security Updates do not cover
Four limits that change the shape of the decision, and one of them excludes an entire category of device that financial institutions tend to own.
Long-Term Servicing Channel devices are outside the program entirely
Microsoft states that Windows 10 Long Term Servicing releases have their own lifecycles and are not covered by the Windows 10 Extended Security Updates program. This matters more in financial services than in most industries. Teller terminals, ATM controllers, kiosks, and other specialized endpoints are frequently built on Long-Term Servicing Channel images precisely because they are meant to sit still for years. If any of those exist in your estate, they are on their own separate lifecycle dates, they will not be fixed by an ESU purchase, and they need to be looked up individually rather than assumed into the fleet number.
Only limited ESU-specific support is included
Microsoft answers the question directly with a single word: no. The program covers license activation, installation, and possible regressions caused by the Extended Security Updates themselves, and nothing else. General support is not provided for a Windows version past its end of support date. New features, customer requested nonsecurity updates, and design change requests are all explicitly out of scope. An institution treating ESU as a way to keep a supported estate is misreading what it buys.
The device has to be prepared before a key will take
Enrollment is not simply a purchase. Devices must be running Windows 10 version 22H2 with update KB5066791 or later installed, and then the Extended Security Updates Licensing Preparation Package, KB5072653, installed after it. Order matters there. Each coverage year then has its own Multiple Activation Key and its own distinct activation identifier, so moving from Year 1 to Year 2 means installing a new key and running a fresh activation across every enrolled machine. It is a deployment task on a deadline, not a line item on a purchase order.
Only whole years, and only three of them
Coverage cannot be bought for part of a year. Enrolled devices in a commercial or educational organization can receive security updates for a maximum of three years past end of support, which puts the hard floor under all of this at October 10, 2028. Whatever an institution decides about Year 2, the calendar ends in the same place. Every path that involves keeping Windows 10 is a path to the same date, and the only variable is how much gets spent getting there.
Four ways through October 13, and what each one really costs
Most institutions end up using more than one of these at the same time, sorted by which machines are in which situation.
Buy Year 2 and keep the machines
The straightforward path, and the right one when hardware genuinely cannot move yet. Budget for double the Year 1 figure per device, plan the key deployment as real work rather than a formality, and be honest that Year 3 doubles again. This buys time. It does not buy a solution, and the meter runs faster every year. For a small number of devices it can still be the cheapest option overall, which is why the count in step one decides this rather than instinct.
Cost rises every yearUpgrade eligible machines to Windows 11
Free for hardware that meets the requirements, and it ends the problem rather than deferring it. The work is real: compatibility checking, driver validation, line of business application testing, and a rollout with a rollback plan. Every machine that moves is one you never pay ESU for again and never revisit in 2027.
Ends the recurring costMove the workload to a Cloud PC
Microsoft includes Extended Security Updates at no additional cost for Windows 10 virtual machines in Windows 365, Azure Virtual Desktop and Azure virtual machines. Windows 10 endpoints connecting to a Windows 365 Cloud PC are also entitled to Extended Security Updates for up to three years while the Windows 365 subscription is active. For an institution with a genuinely stuck application, this is often the cleanest answer nobody considered.
ESU included, no separate purchaseReplace the hardware
The machines still running Windows 10 in late 2026 are usually the oldest machines you own. Once three years of escalating ESU fees are put next to the price of a device that is faster, under warranty, and Windows 11 capable on day one, the arithmetic frequently favors replacement. Run that comparison honestly rather than assuming the cheap option is the one that avoids capital spend.
Often cheaper than three ESU yearsWhat to do between now and October 13
In this order, because each step changes the answer to the next one.
Count the machines, from the tenant rather than the asset register
Every decision here scales with a number almost nobody has to hand. Pull the real count of Windows 10 devices from device management rather than from a spreadsheet, split it by edition, and separate out anything on a Long-Term Servicing Channel build because that category is outside the program and needs its own lookup. Institutions are regularly surprised in both directions.
Confirm which of them are enrolled today
Purchasing a licence and successfully activating it on a device are two different events, and the gap between them is where quiet failures live. Verify activation status on the machines themselves rather than assuming the purchase order covered the fleet. A device that was bought coverage but never had the key applied has been unprotected since last October.
Sort the count into the four paths
Windows 11 capable machines go to the upgrade pile. Machines held back by one stubborn application go to the Cloud PC pile. Machines old enough that ESU exceeds their residual value go to the replacement pile. Only what is left genuinely needs Year 2, and that pile is usually far smaller than the opening estimate.
Handle the Windows 11 24H2 half in the same pass
While the inventory is open, check which Windows 11 devices are on version 24H2 and which edition they run. Pro edition devices need to reach version 25H2 before October 13, 2026. Enterprise edition devices have until October 12, 2027. Do not plan around version 26H1, which Microsoft states is not offered as an in place update for existing devices.
Put the purchase and the key deployment on the calendar separately
These are different tasks with different owners and different failure modes. The purchase has to clear procurement. The key deployment has to reach every device and be verified device by device, because a key that did not apply looks identical to a key that did until the patch that was missed is the one that mattered. Give the deployment its own deadline, comfortably ahead of October 13.
Write down what you decided and why
In our experience across credit unions, banks, and mortgage companies, the difficulty at examination is rarely the mere presence of an older operating system. It is being unable to show the count, the reasoning, and the plan when someone asks. A short documented decision covering the device count, the four piles, the spend, and the target dates turns an awkward question into a two minute answer, and it is worth writing while the work is fresh rather than reconstructing it later.
We read the tenant and tell you what this actually costs you, per path.
ABT is a Tier 1 Microsoft Cloud Solution Provider. We manage Microsoft 365 tenants for more than 750 credit unions, banks, and mortgage companies, and we host the Azure environments behind the applications many of them run every day. Windows lifecycle transitions are ordinary work here rather than a research project we would have to start, and the licensing arithmetic behind them is a conversation we have several times a week.
- The device count as your tenant actually sees it. Windows 10 machines by edition and build, which ones are enrolled in Extended Security Updates today, which ones are Windows 11 capable, and which are on a Long-Term Servicing Channel build and therefore outside the program. This is read from device management rather than from a questionnaire, and the limit of that view is worth stating before you rely on it rather than after: anything unmanaged or off the tenant will not appear in it. We name that gap explicitly rather than letting a clean report imply it does not exist.
- The four paths costed against your actual numbers. What Year 2 would cost your fleet, what the upgrade eligible portion removes from that bill, where a Cloud PC is genuinely cheaper than a hardware refresh, and where it is not. Including the cases where the honest answer is that buying Year 2 is the right call.
- The Windows 11 24H2 exposure in the same pass. Which devices are on 24H2, which edition they carry, and therefore which of them share the October 13, 2026 date rather than having until 2027.
- A dated plan you can hand to a board or an examiner. The count, the decision, the spend, and the target dates, written to be read by the person who has to approve it rather than only by an engineer.
- Yours to keep. The assessment is yours whether or not you ever engage us, and whether or not you buy a single licence through us.
To be plain about what this is. The assessment is a free technical review of your Microsoft 365 tenant and device estate against the Windows lifecycle dates on this page. It is not a quote, and no price on this page is an offer: the figures above are Microsoft's published Volume Licensing list and arithmetic from it, and what any institution pays depends on its channel and agreement. We are not going to tell you that everything must move to Windows 11 by October, because for most institutions that is neither true nor achievable. Where the right answer is to buy Year 2 for part of the fleet and move the rest, we will say so. Where you are already in good shape, we will say that too and the conversation can be short. Credit unions, banks, and mortgage companies are our core practice, and the same review runs for organizations outside financial services.
ABT also operates M365 Guardian, its managed security service for credit unions, banks, and mortgage companies.
Where the facts on this page come from
Every date, price and quotation above is taken from Microsoft's own documentation, and each source is linked below so you can read the sentence in its original context rather than take our summary of it. All were read on 26 August 2026. Where the page moves from quoting to interpreting, on what perpetual licensing means in practice and on how the four paths compare, that is our reading and is written as such. ABT's own claims, our Tier 1 CSP status and the terms of the assessment, come from ABT and are marked as such.
- Purchasing Extended Security Update Licenses as a Cloud Solution Provider is the source for the coverage date table, for the statement that Windows 10 ESUs are only perpetual, for the statement that perpetual purchases do not renew, and for the guidance that once Year 2 coverage dates are current a partner should purchase both Year 1 and Year 2.
- Extended Security Updates (ESU) program for Windows 10 is the source for the $61 per device Year One figure through the Volume Licensing Program, for the statement that the price doubles every consecutive year for a maximum of three years, for the cumulative purchase rule, for the one licence minimum and the ban on partial periods, for the absence of technical support, and for the list of cloud and virtualization services where Extended Security Updates are included at no additional cost.
- Enable Windows 10 Extended Security Updates is the source for the October 14, 2025 end of support date, for the device prerequisites including the required update and the Licensing Preparation Package and the order they install in, for the separate activation identifier per coverage year, and for the exclusion of Long Term Servicing releases from the program.
- Windows 10 end of support and Microsoft 365 Apps is the source for the October 10, 2028 end of Microsoft 365 Apps security updates on Windows 10, for the Version 2608 freeze, for OneDrive desktop app updates continuing on Windows 10 22H2, and for the support limitations that apply with or without Extended Security Updates.
- Windows 11 release information is the source for the Windows 11 version 24H2 end of updates dates by edition, for the version 25H2 dates, and for the statement that version 26H1 is not designed as a feature update for existing devices and is not offered as an in place update from 24H2 or 25H2.
- Windows Lifecycle FAQ corroborates that Windows 10 version 22H2 was serviced with monthly updates through October 14, 2025, after which it is no longer supported.
Related reading
July 2026 Patch Tuesday: Three Exploited Flaws and What Financial Institutions Patch First
A month of exactly the updates an unenrolled Windows 10 machine would have missed. Useful for picturing what the gap actually contains.
FFIEC IT Examination Readiness for Financial Institutions
How institutions prepare for an IT examination, and why a documented decision about aging endpoints is worth having ready.
Lock It Down: Risk-Based Device Compliance with Microsoft Intune
How the device count on this page gets produced, and how compliance policy can keep an unpatched endpoint away from your data.
Windows 10 ESU questions, answered from Microsoft documentation
Windows 10 Extended Security Updates Year 1 coverage for organizations runs from October 15, 2025 to October 13, 2026. Microsoft publishes the full table in its Partner Center documentation: Year 2 runs October 14, 2026 to October 12, 2027, and Year 3 runs October 13, 2027 to October 10, 2028. There is no Year 4, so October 10, 2028 is the end of the program regardless of what an organization buys.
No. Microsoft states that "Windows 10 ESUs are only perpetual" and that "Perpetual software purchases have no end dates, they don't renew, they're perpetually available." A Year 1 purchase is a perpetual licence covering one named coverage year rather than a subscription, so there is no automatic renewal and no subscription expiry to trigger the notices that normally accompany one. Buying Year 2 is a separate purchase with its own activation key. When Year 1 coverage ends on October 13, 2026, an unenrolled device stops receiving operating system security updates, and nothing on the device itself announces it. A reseller or managed provider may raise it with you, but the licence will not generate a reminder on its own.
Microsoft publishes $61 USD per device for Year One through the Volume Licensing Program and states that "The price doubles every consecutive year, for a maximum of three years." That puts Year 2 at $122 per device and Year 3 at $244 per device by arithmetic, for a three year total of $427 per device. Those doubled figures are arithmetic from Microsoft's published Year One price rather than separately published prices, and what a specific organization pays depends on its purchasing channel and agreement.
You can buy later, but it does not save money. Microsoft states that "If you decide to purchase the program in Year Two, you have to pay for Year One too, as ESUs are cumulative." Microsoft's guidance to partners says the same from the other direction: once Year 2 coverage dates are current, partners should purchase both Year 1 and Year 2. Coverage also cannot be bought for part of a year, because Microsoft requires the program to be purchased by year and states that customers cannot buy partial periods.
No, and this is why the date is so easy to miss. Microsoft committed to providing security updates for Microsoft 365 Apps on Windows 10 for three years after Windows 10 end of support, "ending on October 10, 2028." Devices receive feature updates and Copilot support where eligible until Version 2608 is released, then remain on that version receiving security updates until 2028. The OneDrive desktop app on Windows 10 22H2 also continues updating through October 10, 2028. That commitment is independent of Extended Security Updates, so Word, Excel and Outlook keep updating on a machine whose operating system has stopped being patched.
No. Microsoft applies its Microsoft 365 Apps support limitations on Windows 10 "with or without Windows 10 Extended Security Updates." If an issue occurs only on Windows 10 and not on Windows 11, support will ask the customer to move to Windows 11, and if that is not possible, support provides troubleshooting assistance only with workarounds that may be limited or unavailable. Microsoft also states that these support incidents do not include the option to log a bug or request other product updates. Extended Security Updates buy operating system security patches and nothing beyond that; the program itself includes no technical support other than for the activation and installation of the updates.
No. Microsoft states that Windows 10 Long Term Servicing releases have their own lifecycles and are not covered by the Windows 10 Extended Security Updates program. This matters in financial services in particular, because teller terminals, ATM controllers and similar specialized endpoints are frequently built on Long-Term Servicing Channel images. Those devices sit on separate lifecycle dates that have to be looked up individually, and an Extended Security Updates purchase will not address them.
Yes, for virtual machines. Microsoft states that Extended Security Updates are available at no additional cost for Windows 10 virtual machines in Windows 365, Azure Virtual Desktop, Azure virtual machines, Azure Dedicated Host, Azure VMware Solution, Nutanix Cloud Clusters on Azure, Azure Local, Azure Stack Hub and Azure Stack Edge. Microsoft also states that Windows 10 endpoints connecting to Windows 365 Cloud PCs are entitled to Extended Security Updates for up to three years while the Windows 365 subscription licence is active. For an organization held back by a single application that will not run on Windows 11, moving that workload to a Cloud PC is often a cleaner answer than paying escalating per device fees.
For some editions, yes. Microsoft's release information lists Windows 11 version 24H2 as reaching end of updates on October 13, 2026 for Home, Pro, Pro Education and Pro for Workstations, and on October 12, 2027 for Enterprise, Education, IoT Enterprise and Enterprise multi-session. Windows 11 Business, the edition included with Microsoft 365 Business Premium, is a Pro edition, so organizations licensed that way share the same October 13, 2026 date on both halves of the fleet. The fix on the Windows 11 side is moving those devices to version 25H2. Version 26H1 is not an option for existing devices, because Microsoft states it is scoped to new devices and is not offered as an in place update from 24H2 or 25H2.
Find out what October 13
actually costs you.
Tell us roughly how many people are in the institution. Our engineers will read the tenant and come back with the real Windows 10 count, which devices are enrolled today, and what each of the four paths would cost against your own numbers.

