Windows 10 end of life hits on October 14, 2025. For MSPs managing Intune fleets, that date doesn’t mean devices stop working — it means every unpatched Windows 10 device becomes a liability. This guide covers what Extended Security Updates (ESU) are, how to license and deploy them through Intune, and how to manage the rollout across multiple clients without doing it manually per tenant.
What Is Windows 10 End of Life?
Windows 10 end of life means Microsoft stops releasing security patches on October 14, 2025. Devices still run — but any vulnerability discovered after that date goes unpatched permanently, unless you’re enrolled in Extended Security Updates.
- Affected editions: Windows 10 Home, Pro, Enterprise, Education — all reach end of life simultaneously. No grace period by SKU.
- What stops: Security updates, bug fixes, and technical support from Microsoft. Defender definitions continue, but OS-level CVEs go unaddressed.
- Who it hits hardest: MSPs with mixed fleets — clients who haven’t completed Windows 11 migration by October 2025 are exposed. In practice, that’s most mid-market environments.
What Are Windows 10 Extended Security Updates (ESU)?
Windows 10 Extended Security Updates give organizations up to three additional years of critical and important security patches beyond the end-of-life date — the same model Microsoft used for Windows 7 and Windows Server 2008.
- ESU Year 1 (Oct 2025–Oct 2026): $61 per device for commercial customers
- ESU Year 2 (Oct 2026–Oct 2027): $122 per device (doubles each year by design)
- ESU Year 3 (Oct 2027–Oct 2028): $244 per device
- Windows 365 and Azure Virtual Desktop: ESU included at no extra cost
- Education: $1 per device per year
ESU is a bridge, not a destination. The price escalation is deliberate — Microsoft wants migrations completed, not fleets parked on Windows 10 indefinitely.
How to Deploy Windows 10 ESU with Intune
For Intune-managed devices, ESU activation is policy-driven — no per-device product key entry required. Here’s the full flow:
Step 1: Purchase ESU Licenses
Purchase through Microsoft Volume Licensing or your CSP. Licenses are assigned at the tenant level. CSP partners can purchase on behalf of clients and manage centrally across tenants — important for MSPs running multi-tenant environments.
Step 2: Activate ESU via Intune Settings Catalog
Once licensed, navigate to the Intune Admin Center → Devices > Configuration > Create > Settings Catalog.
- Search for “Extended Security Updates” in the Settings Catalog
- Enable the setting: Enable Extended Security Updates for Windows 10
- Assign to a device group scoped to your Windows 10 devices
- Devices check in and activate ESU automatically — no reboot required
Step 3: Verify Activation
Confirm ESU is active on enrolled devices via Devices > Monitor > Feature update failures, or run a custom report filtering on Windows 10 OS version with ESU compliance state. Devices showing ESU active will continue receiving patches through Windows Update — no separate WSUS configuration needed when managed through Intune.
How MSPs Manage Windows 10 ESU Across Multiple Clients
The per-device, per-year cost model makes Windows 10 ESU a fleet management problem at scale. For an MSP with 10 clients averaging 50 Windows 10 devices each, Year 1 alone is $30,500 — and that doubles in Year 2.
The operational challenge isn’t just cost — it’s tracking which devices across which tenants are covered, which need migration prioritized, and ensuring no device falls through without a patch.
- Inventory first: Run a device compliance report in Intune filtered by OS version. Every Windows 10 device needs a decision: ESU or migration timeline.
- Segment by client: Create a dynamic Entra ID group per tenant scoped to Windows 10 —
deviceOSVersion -startsWith "10.0". Assign ESU policy to this group. When a device migrates to Windows 11, it drops out automatically. - Track migration progress: ESU should shrink monthly as devices migrate. Build a dashboard or weekly report showing Windows 10 device count per client — stagnant numbers mean migration is stalled and ESU costs are compounding.
- Third-party patching doesn’t stop: ESU covers OS-level patches only. Applications — Chrome, Adobe, 7-Zip, and 1,000+ others — still need patching regardless of ESU status. That’s a separate workstream entirely.
Windows 10 ESU vs. Migrating to Windows 11
ESU buys time. It doesn’t buy compatibility. If hardware doesn’t meet Windows 11 requirements (TPM 2.0, CPU compatibility), ESU is the only option short of hardware refresh. The decision framework:
- Device is Windows 11 compatible: Migrate. ESU cost over 1-3 years exceeds the admin time of a managed Autopilot migration.
- Device is incompatible, under 2 years old: Consider hardware refresh — ESU Year 2+ costs approach the cost of a new device.
- Device is incompatible, mission-critical: ESU Year 1, plan hardware replacement in the budget cycle.
- Device is incompatible, low-use: Decommission rather than pay ESU on a device that barely gets used.
For a step-by-step on deploying Windows 11 via Autopilot after a hardware refresh, the Intune device enrollment guide covers the provisioning flow.
Frequently Asked Questions
Do Windows 10 devices stop working after October 14, 2025?
No. Devices continue to function normally. What stops is Microsoft issuing new security patches. Unpatched vulnerabilities discovered after that date remain unaddressed on devices without ESU.
Is Windows 10 ESU included in Microsoft 365?
No. ESU is a separate purchase. Microsoft 365 Business Premium and Enterprise E3/E5 licenses do not include Windows 10 ESU. The exception is Windows 365 (Cloud PC) and Azure Virtual Desktop — those include ESU at no additional cost.
Can Intune deploy ESU to devices not enrolled in Azure AD?
No. ESU activation via Intune Settings Catalog requires devices to be enrolled in Microsoft Intune with an Azure AD (Entra ID) join. Workgroup or on-premises only devices require a MAK (Multiple Activation Key) approach instead.
How do I check which Windows 10 devices are in my Intune tenant?
In the Intune Admin Center go to Devices > All Devices and filter by OS = Windows, then sort by OS version. Export to CSV for a full inventory across the tenant.
