Windows 10 support ended on 14 October 2025. The machines still work. That is exactly what makes this dangerous.
End of support does not break anything, which is why so many Indian organisations are still running it. What it does is stop the security updates, so every vulnerability discovered since October 2025 remains open on every unenrolled device, permanently. That turns a fleet of working laptops into a fleet of documented, unpatched exposures, and under the DPDP Rules and the CERT-In Directions that is a compliance position rather than an IT preference. This page is what end of support actually changes, and what the realistic options are.
- 14 Oct 2025Support ended
- No patchesFor unenrolled devices, permanently
- Rule 6DPDP safeguards are not met by an unpatched OS
- 3 optionsUpgrade, replace, or bridge with ESU
Eight things that changed in October 2025, and what each one costs you.
Security updates stopped
The central fact. Microsoft no longer issues security patches for Windows 10 to unenrolled devices. Every vulnerability disclosed since 14 October 2025 is unaddressed on those machines and will remain so. Attackers know this, and unsupported operating systems are targeted precisely because the fixes are published for the supported version and the exploit works unchanged on the unsupported one.
Microsoft support ended
No technical support, no bug fixes, no feature updates. If a Windows 10 device develops a problem, the answer from Microsoft is to upgrade. For an organisation with an internal team this matters less; for one relying on a support contract it means the platform is outside the vendor relationship entirely.
Third-party vendors are dropping support on their own schedules
Browser vendors, security software, line-of-business applications and device drivers all set their own Windows 10 end dates, and those are arriving now. A device can be running perfectly and lose a supported browser or a working endpoint protection agent because the vendor moved on. This is the failure mode that surprises people, because it is not on Microsoft calendar.
Your DPDP safeguards position changed
Rule 6 of the DPDP Rules requires reasonable security safeguards proportionate to the data you process. An operating system that has not received a security patch in months is difficult to describe as a reasonable safeguard, and if a breach occurs on such a device the question of whether you took reasonable measures will be asked. This is the piece most Indian organisations have not connected to their Windows fleet.
Your CERT-In and sectoral position changed too
Regulated sectors carry expectations about supported software, and customer security questionnaires increasingly ask directly whether every endpoint runs a supported operating system. An honest answer of no is a finding. A dishonest answer of yes is a representation you cannot defend. For BFSI, healthcare and anyone selling to enterprise, this is the exposure that arrives first.
Extended Security Updates became the only supported path
ESU provides critical and important security fixes only, per device, in annual periods running to October 2026, 2027 and 2028. The price escalates each year and is cumulative, so joining late means paying for the years skipped. It is a real option and a deliberately temporary one, designed so that staying on it costs more than leaving it.
The hardware question became unavoidable
Windows 11 requires TPM 2.0 and a supported processor, and Microsoft has confirmed the requirements will not be lowered. A share of every Windows 10 fleet cannot be upgraded and must be replaced. End of support turned that from a future budget line into a present one, and the longer the decision waits the older the hardware being bridged becomes.
Cyber insurance and customer contracts are noticing
Insurers ask about supported operating systems at renewal and some exclude incidents originating on unsupported systems. Enterprise contracts increasingly carry a clause about maintaining supported software. Neither is hypothetical in 2026, and both convert a technical decision into a commercial one with a date attached.
Three realistic paths, and one that is not.
Upgrade in place to Windows 11
For devices that meet the hardware bar. A managed upgrade through Intune or existing tooling, no hardware spend, and a device that returns to supported status.
- Requires TPM 2.0, Secure Boot and a supported processor
- A share of capable devices only need firmware settings enabled first
- The security configuration needs applying afterwards, not just the OS
Replace the device
For hardware below the bar. Microsoft will not relax the requirements, so these devices have a defined end date whatever else happens. A phased refresh with standardised models beats reactive replacement.
- This share of the fleet is the budget conversation
- Autopilot provisioning is what keeps a refresh from consuming IT
- Outgoing devices need evidenced wiping under DPDP
Bridge with ESU, on a named list with exit dates
For devices that genuinely cannot move by the current period end. Critical and important patches only, per device, at an escalating cumulative price. A bridge, not a destination.
- Enrol only what needs it, not the fleet
- Set the replacement date at the moment of enrolment
- Review quarterly and expect the list to shrink
Do nothing, which is what most fleets are doing
Unenrolled, unpatched, and working fine. No supportable position under DPDP Rule 6, no honest answer to a security questionnaire, and a growing exposure every month.
- Not a decision, but it has all the consequences of one
- Every disclosed vulnerability since October 2025 is open
- The path most organisations are on without having chosen it
Windows 365 Cloud PC for the hard cases
For roles where a physical device cannot be upgraded or replaced practically, a Cloud PC gives a supported Windows 11 desktop streamed to almost any endpoint, including old hardware used as a terminal.
- Turns an unsupported device into a thin client for a supported desktop
- Useful for kiosks, contractors and seasonal staff
- A licensing decision rather than a hardware one
Isolate what genuinely cannot move
Some devices run software with no Windows 11 path and no replacement. If they must stay, they belong on a segmented network with no internet access and no email, treated as operational technology.
- Network isolation is the only defensible control for an unpatched device
- Document the risk acceptance and who signed it
- Set a review date so it does not become permanent by neglect
Retire what nobody uses
Every fleet contains devices with no assigned user and no recent sign-in. They need neither upgrade nor ESU, only wiping and a disposal record, and removing them shrinks every other number.
- Usually a larger share than expected
- Removes them from the ESU count and the refresh budget
- Wipe to a standard you can evidence before disposal
Move the remote and home workers first
Devices used outside the office are on networks you do not control, browsing the web and opening email, with no perimeter in front of them. They are the highest-exposure subset of an unpatched fleet and the easiest to reach with Autopilot.
- Ship a registered device direct, the old one comes back in the same box
- No office visit, no engineer, no waiting for a wave
- The exposure argument is strongest exactly where the fix is simplest
Work back from October 2026, not forward from today
The Year 2 boundary is when the ESU price steps up and late enrolment becomes cumulative. Procurement lead times for replacement hardware are what set the schedule behind that date.
- Replace list agreed and ordered well before the boundary
- Anything still on ESU at the boundary should already have an order behind it
- The scan takes days, which is why it should start this week
How to decide, device by device
A compatibility scan sorts the fleet from evidence, department heads review their own lists, and the result is a plan with a budget rather than a fleet-wide ESU renewal.
- Scan, do not guess from purchase dates
- The replace list is the capital request
- Agree exit dates for anything bridged
We tell you the size of the problem before proposing the answer.
We scan the fleet rather than reading the asset register
Asset registers say what was bought. A scan says what is running, whether TPM is enabled, and which devices are actually on ESU. The gap between the two is usually the most useful finding in the first week, and it is what makes the plan credible.
We connect it to your compliance position
Most Windows 10 conversations stay inside IT. We bring the DPDP, CERT-In and customer questionnaire angle, because that is what turns a deferred project into a funded one, and because it is genuinely where the exposure sits for an Indian organisation in 2026.
Microsoft Partner, so every path is one we deliver
Upgrade through Intune, refresh with Autopilot, bridge on ESU, or Cloud PC for the hard cases. We are not steering toward the option we happen to sell, because we deliver all of them, and the recommendation follows the scan rather than the other way round.
We give you a plan with a budget, not a renewal
The easy answer is fleet-wide ESU for another year. It is also the most expensive way to not decide. We produce a sorted fleet, a replace list your department heads have agreed, and a bridge list with exit dates, which is a plan the finance function can act on.
Who is most affected, and why.
BFSI and regulated
Unsupported operating systems are an audit finding with a regulator behind it. The migration is a compliance deadline, and the ESU bridge needs documenting as a risk acceptance rather than quietly renewing.
Healthcare
Sensitive data on shared clinical workstations, some running vendor-certified software with no Windows 11 path yet. The DPDP exposure is high and the vendor conversation sets the schedule.
Companies selling to enterprise
The security questionnaire arrives before the regulator does. An honest answer about unsupported endpoints is a finding that can stall a deal, which is frequently what funds the migration.
Manufacturing
Shop-floor and quality systems on old hardware that cannot move. The defensible answer is network isolation and a documented risk acceptance, not an unpatched device on the corporate network.
Education
Large fleets of older devices bought in bulk, so the replace share is high and the budget is the whole conversation. Often the fleets with the least visibility into what is actually running.
Small and mid-sized businesses
No dedicated IT, no scan, and no idea how many devices are exposed. Frequently the most surprised by the DPDP angle, and frequently the easiest to fix because the fleet is small.
How an unsupported operating system reads under each regime.
| Regime | What it asks | How Windows 10 without ESU answers | |
|---|---|---|---|
| DPDP Rules, Rule 6 | Reasonable security safeguards proportionate to the data processed | An operating system with months of unaddressed vulnerabilities is hard to describe as reasonable, and the question will be asked after a breach. | |
| DPDP breach reporting | Notify the Board and affected individuals, detailed report inside seventy two hours | A breach originating on an unpatched device carries a causation finding that points at a known, unremediated gap. | |
| CERT-In Directions | Six hour incident reporting, logs retained, systems maintained | Unsupported endpoints are the most likely origin of a reportable incident and the hardest to investigate afterwards. | |
| Customer security questionnaires | Do all endpoints run a supported operating system | An honest no is a finding. A yes you cannot evidence is a representation that fails at the first audit request. | |
| ISO 27001 and SOC 2 | Vulnerability management and patching operate effectively | A fleet that cannot be patched is a control that cannot operate, and it appears in the report or as a nonconformity. | |
| Cyber insurance | Supported software maintained, patches applied within a defined window | Some policies exclude incidents originating on unsupported systems. Check yours before assuming cover. |
Windows 10 before and after 14 October 2025.
| Feature | Dimension | Before end of support | After, without ESU |
|---|---|---|---|
Security patches | Monthly, from Microsoft | None, permanently | |
Known vulnerabilities | Fixed within the patch cycle | Accumulating, and public | |
Microsoft support | Available | Ended | |
Third-party software | Supported | Being dropped on vendor schedules | |
DPDP Rule 6 position | Defensible | Difficult to describe as reasonable | |
Security questionnaire answer | Yes, all endpoints supported | No, or a representation you cannot evidence | |
Cyber insurance | Within policy expectations | Possibly excluded, check the wording | |
What the user sees | A working laptop | A working laptop |
Working fine is not the same as supported, and the difference is the whole problem.
Nothing about end of support makes a device stop working, which is why so many fleets are still on Windows 10 and why the risk is so easy to underestimate. The machines boot, the applications open, and nothing looks different. What has changed is invisible: every vulnerability disclosed since October 2025 is open on those devices and will stay open. The organisations that get caught out are not the ones who decided to accept that risk. They are the ones who never noticed they were carrying it, because nothing broke.
- The absence of a visible problem is not evidence of a safe position
- Unsupported operating systems are targeted because the exploits are published
- A breach on an unpatched device carries a causation finding you cannot argue with
- The cost of deciding now is lower than the cost of deciding after an incident
Four stages, and the first one takes days.
- 1
Scan and size the exposure
A compatibility and inventory scan across the estate: how many devices are on Windows 10, which are enrolled in ESU and until when, which handle personal data, and which meet the Windows 11 hardware bar. Reported as a sorted fleet rather than a count, because the sort is what the decision needs.
- 2
Establish the obligations
What your contracts, your insurance and your sector expect about supported software, and what your DPDP position looks like with unpatched devices handling personal data. This is what turns the conversation from an IT preference into a dated obligation with an owner.
- 3
Decide device by device
Upgrade, enable firmware then upgrade, replace, bridge with an exit date, isolate, or retire. Reviewed with department heads so the replace list is agreed and budgeted, and the ESU list is a named set of exceptions rather than a fleet-wide renewal.
- 4
Hand into the migration programme
The sorted fleet, the agreed replace list and the bridge list with exit dates become the inputs to the Windows 11 migration: readiness assessment for the exceptions, Autopilot for the refresh, Intune for the upgrades, and evidenced disposal for the outgoing devices.
Twelve things to establish before deciding anything.
Exposure
- How many devices are still on Windows 10From a scan, not from an asset register
- How many of those are enrolled in ESUAnd when the current period ends
- Which unenrolled devices handle personal or sensitive dataThe DPDP question, and the priority list
- Which are internet-facing or used for email and browsingThe highest-risk subset
Options
- How many devices meet the Windows 11 hardware barTPM 2.0, Secure Boot, supported processor
- How many only need firmware settings enabledThe cheapest category, and often missed
- How many must be replacedThis is the budget
- Which applications have no Windows 11 path yetUsually a short list, a long vendor tail
Obligations
- What your customer contracts say about supported softwareIncreasingly a clause with a date
- What your cyber insurance excludesUnsupported systems are a common exclusion
- Whether any regulator or auditor has asked yetIf not yet, then soon
- Who owns this decision internallyIt stalls when nobody does
Windows 10 end of support, answered plainly.
The paths out.
Windows 11 migration
The programme end to end: fleet sorting, the refresh, Autopilot provisioning, the security posture and evidenced disposal.
Learn moreWindows 10 ESU
How Extended Security Updates work as a bridge, what they do and do not cover, and how the cumulative escalating pricing changes the decision.
Learn moreDPDP Act compliance
The Rule 6 safeguards obligation that an unpatched fleet fails, and the wider statutory position it sits inside.
Learn moreFind out how many devices are exposed, this week.
The scan takes days, commits you to nothing, and replaces a vague worry with a sorted fleet and a number. Tell us roughly how many devices you have and whether any are on ESU. Remote-first from Hyderabad, serving all of India.
Related Services
Explore more solutions that work great with this service
Windows 11 Migration
Sort the fleet, bridge the exceptions, provision without hands
Learn moreWindows 10 ESU
A bridge priced to become a destination nobody wants
Learn moreWindows 11 Readiness
Device-side scan, every machine sorted, report as the plan
Learn moreDPDP Act Compliance
The engineering half of DPDP, not the legal one
Learn more