Skip to main content
Windows 10 ESU, India

Extended Security Updates are designed so that staying costs more than leaving. Use them that way.

ESU is a legitimate bridge for Windows 10 devices that genuinely cannot move to Windows 11 by the current period end. It provides critical and important security patches only, per device, in annual periods running to October 2026, 2027 and 2028. The price steps up each year and enrolment is cumulative, so a device joining late pays for the years it skipped. That pricing model is not an accident: Microsoft built it to make ESU a temporary answer. The organisations that use it well enrol a named list, set an exit date at enrolment, and shrink the list every quarter.

Microsoft
Windows 10
Cloud Solution Partner
  • 3 periodsTo October 2026, 2027, 2028
  • Per deviceNot per organisation
  • CumulativeLate joiners pay for skipped years
  • Security onlyNo features, no support
What you are actually buying

Eight things to understand before enrolling a single device.

ESU is frequently bought as a blanket renewal by organisations who have not read what it covers. It covers less than people assume, it costs more each year by design, and it works well only when it is scoped narrowly. These are the facts that should shape the decision.

Critical and important security updates, nothing else

ESU delivers security fixes rated critical or important. It does not deliver feature updates, non-security bug fixes, new capabilities, or Microsoft technical support. A Windows 10 device on ESU is patched against the vulnerabilities Microsoft considers serious enough and is otherwise frozen. For most business use that is sufficient as a bridge; it is not equivalent to being on a supported operating system.

Three annual periods with hard boundaries

Year 1 runs from 15 October 2025 to 13 October 2026. Year 2 from 14 October 2026 to 12 October 2027. Year 3 to October 2028, and then the programme ends. Each boundary is a price step and a decision point. A device still on ESU in Year 3 is running an operating system three years past end of support on hardware that is almost certainly past its own refresh date.

The price escalates every year, by design

Microsoft publishes the per-device figures directly and we do not repeat them here, partly because they change and partly because the number is not the point. The structure is the point: each year costs more than the last, deliberately, so that ESU becomes progressively less attractive than migration. An organisation renewing fleet-wide into Year 2 is paying a premium for having not decided in Year 1.

Enrolment is cumulative

A device enrolled for the first time in Year 2 pays for Year 1 as well, and one enrolled in Year 3 pays for all three. There is no discount for joining late. This has a practical consequence: if a device is going to need ESU at any point, enrolling it at the start of the current period is cheaper than waiting, and the decision about which devices those are needs making now rather than at the boundary.

Licensed per device, so scope is everything

ESU is bought per device, not per organisation, which means the cost scales directly with how many machines you enrol. Enrolling the whole fleet because it is simpler multiplies the cost by the fleet size. Enrolling only the devices that genuinely cannot move by the period end, after a scan has sorted the fleet, is what makes ESU affordable as a bridge and unaffordable as a strategy.

Enrolment through volume licensing or Intune

Organisations enrol through their volume licensing agreement or, for Intune-managed fleets, through the device management console, which is the practical path for most Indian businesses already on Microsoft 365. The enrolment has to be applied and verified per device; a licence purchased and not activated on the device provides nothing. We check enrolment status from the device side, not from the purchase record.

Cloud PC and virtual desktop scenarios differ

Windows 10 running in Windows 365 Cloud PC or Azure Virtual Desktop carries its own ESU entitlement under those services, which changes the calculation for organisations considering a Cloud PC route for their hard cases. For some roles it is cheaper to stream a supported Windows 11 desktop to an old device than to enrol that device in ESU, and the comparison is worth doing explicitly.

What ESU does not fix

Third-party vendors dropping Windows 10 support on their own schedules, browsers and endpoint protection included. Hardware ageing throughout the bridge period. Customer security questionnaires that ask about supported operating systems, where ESU is a mitigation to explain rather than a clean yes. And the underlying decision, which ESU defers rather than makes.

Using it well

Eight rules for ESU as a bridge rather than a destination.

The difference between an organisation that uses ESU sensibly and one that renews it fleet-wide for three years is a handful of disciplines, all of which are cheaper than the alternative.

Scan before you enrol

A compatibility scan sorts the fleet into devices that can upgrade, devices that need a firmware fix, and devices that must be replaced. Only the last group, and only the part of it that cannot be replaced by the period end, is an ESU candidate.

  • Most fleets have fewer genuine ESU candidates than expected
  • Firmware-fixable devices should be fixed, not enrolled
  • Retired and unused devices should not be enrolled at all

Enrol a named list, not the fleet

Per-device pricing means every unnecessary enrolment is pure cost. The list should be short, specific, and justified device by device.

  • Each device on the list has a reason it cannot move yet
  • The list is reviewed by the department that owns the devices
  • If the list is most of the fleet, the programme has not started

Set the exit date at enrolment

Every enrolled device gets a replacement or upgrade date the moment it is enrolled, and that date is inside the current period. ESU without an exit date becomes permanent by neglect.

  • The exit date drives the procurement schedule
  • Devices past their exit date are escalated, not renewed
  • Year 2 renewal for a device is a failure of the plan, not a decision

Enrol early in the period

Cumulative pricing means a device that will need ESU at all is cheapest enrolled at the start of the current period. Waiting to see does not save money, it costs the skipped months for nothing.

  • Decide the list before the period boundary, not after
  • Late enrolment pays for coverage you did not receive
  • The October boundaries are the planning dates

Review the list quarterly and expect it to shrink

The list should get shorter every quarter as devices are replaced or upgraded. A list that grows or stays flat is a signal that the migration has stalled and ESU has become the plan.

  • Track enrolled devices against their exit dates
  • Report the count to whoever owns the budget
  • A shrinking list is the only healthy trajectory

Verify enrolment on the device, not the invoice

A licence bought is not a device patched. Enrolment has to be applied and confirmed per device, and a fleet that believes it is covered because the purchase went through is worse off than one that knows it is not.

  • Check the update status on the device itself
  • Intune reporting shows enrolment state per machine
  • Audit this after every period boundary

Compare against Cloud PC for the hard cases

For roles where the device cannot move and the application cannot change, a Windows 365 Cloud PC streaming a supported desktop to the old hardware is sometimes cheaper than ESU and is a supported position rather than a bridge.

  • Cloud PC carries its own ESU entitlement for Windows 10 sessions
  • Turns an unsupported device into a thin client
  • A licensing decision, and worth costing explicitly

Document the risk acceptance

ESU is a mitigation, not a resolution, and under DPDP and sector rules the decision to keep devices on a bridged operating system is a risk acceptance somebody should sign.

  • Record which devices, why, and until when
  • Name the owner who accepted the residual risk
  • This is what an auditor or a customer will ask to see
Why bring us in

We scope the list before anybody buys anything.

The scan comes first, always

Enrolling before scanning is how fleets end up paying ESU on devices that could have been upgraded with a firmware setting. We sort the fleet from evidence first, and the ESU list is what is left after the upgrade, fix and retire buckets are removed. It is consistently shorter than the client expected.

We will tell you which devices should not be enrolled

That reduces the size of any ESU purchase and it is the right advice. A partner who benefits from your licensing spend has a reason to recommend the fleet. We manage estates for clients on an ongoing basis, so a bloated ESU list is our problem next year as well as yours.

Microsoft Partner, so enrolment and verification are routine

Enrolment through Intune, verification per device, and the reporting that shows which machines are actually covered are things we do in client tenants regularly. A licence bought and not applied is a gap we specifically check for.

We attach ESU to the migration it is bridging

ESU only makes sense inside a Windows 11 programme with a replace list and a procurement schedule. We scope it as one workstream of that programme, with exit dates that drive procurement, rather than as a standalone purchase that quietly becomes the plan.

Where ESU is genuinely the right call

The legitimate bridge cases, by sector.

Clinical and diagnostic workstations

Vendor-certified software with no Windows 11 release yet, on devices that cannot be replaced until the vendor moves. A genuine bridge case, with the exit date set by the vendor roadmap.

Shop-floor and quality systems

Machines controlling or monitoring equipment, where the software vendor and the equipment lifecycle decide the date. Usually paired with network isolation rather than ESU alone.

Regulated organisations mid-refresh

A funded replacement programme with procurement lead times that cross the period boundary. ESU covers the gap, with exit dates matching delivery dates, and the risk acceptance documented for the auditor.

Education with budget cycles

Large fleets where the replace share is high and capital arrives on an academic calendar. ESU bridges to the next budget, on a list that shrinks as each tranche of devices arrives.

GCCs awaiting a parent decision

Device standards set by a global parent on their own timeline. ESU covers the Indian fleet until the group refresh reaches it, with the exit date set by the group programme rather than locally.

Distributed sites with disposal logistics

Many small locations where replacing and collecting devices is a logistics exercise. ESU covers sites until their wave, with the schedule driven by the rollout plan rather than the boundary.

Per device, honestly

Which devices belong on ESU, and which do not.

The question is never whether to buy ESU. It is which specific devices need it, for how long, and what happens to them at the exit date. This is how we sort them.
Device situationESU decisionWhat happens instead or next
Meets the Windows 11 hardware barNo. Upgrade in place.A managed upgrade through Intune, with the Windows 11 security configuration applied afterwards. No ESU cost at all.
Capable hardware, TPM or Secure Boot disabledNo. Enable firmware, then upgrade.The cheapest category in the programme and the most often missed. Test the firmware procedure per model, then upgrade.
Below the bar, replacement already orderedOnly if delivery is after the period boundary.Short bridge with the exit date set to the delivery date. If the device arrives inside the period, do not enrol.
Below the bar, replacement not yet budgetedYes, with an exit date inside the current period.The exit date forces the budget conversation. This is the legitimate core of an ESU list.
Runs an application with no Windows 11 pathMaybe. Compare against Cloud PC and isolation first.A Cloud PC running the application in a supported desktop may be cheaper and is a supported position. If the device must stay, isolate it on the network.
No assigned user, no recent sign-inNo. Retire it.Wipe to an evidenced standard, close the asset record, dispose with a certificate. Enrolling an unused device in ESU is the purest form of waste in the programme.
Two ways to use it

ESU as a bridge against ESU as a strategy.

Same product, same pricing, opposite outcomes. The difference is entirely in scope and in whether anybody set an exit date.
Feature
Dimension
As a strategy
As a bridge
Which devices
The whole fleet, because it is simplerA named list that cannot move by the period end
Exit date
None, or the end of the programmeSet per device at enrolment, inside the period
Year 2
Renewed fleet-wide at the higher rateA shorter list, or none
Cumulative pricing
Paid on devices that could have been upgradedAvoided by enrolling early and only what is needed
Hardware during the bridge
Ageing across the fleet for three yearsReplaced on schedule as exit dates arrive
Security questionnaire answer
A mitigation to explain, fleet-wideA small, documented exception list
Budget conversation
Deferred, then largerForced early by the exit dates
End state at October 2028
Unsupported fleet, no bridge leftWindows 11 fleet, ESU long finished

We do not publish the ESU price, and here is why that matters more than usual.

Every other page on this topic leads with the per-device figures, and they are the least useful number in the decision. Microsoft publishes them directly, they change at each period boundary by design, and quoting them tends to produce one of two bad reactions: sticker shock that delays the decision, or a fleet-wide renewal because the Year 1 figure looked manageable. What determines whether ESU is money well spent is not the rate. It is how many devices you enrol, for how long, and whether each one has a real exit date. A short list for one period is a bridge. The whole fleet for three years is the most expensive migration you will ever not do.

  • The structure is the point: escalating, cumulative, per device, temporary by design
  • Scope decides the cost far more than the rate does
  • Compare ESU per device against the replacement it is deferring, not against zero
  • If the Year 2 fleet-wide renewal looks affordable, the plan has quietly stalled
The engagement

Four stages, and enrolment is the last one.

  1. 1

    Scan and sort the fleet

    A compatibility scan across the estate sorting every device into upgrade, firmware fix then upgrade, replace, or retire. The ESU candidates are the subset of the replace bucket that cannot be replaced by the current period end, and that subset is what the rest of the engagement is about.

  2. 2

    Build the list with exit dates

    Each candidate device reviewed with the department that owns it, given a reason it cannot move yet, and given an exit date inside the current period. Hard cases compared against Windows 365 Cloud PC and against network isolation, because ESU is not always the cheapest supported answer.

  3. 3

    Document the risk acceptance and align procurement

    The list, the reasons, the exit dates and the accepting owner recorded in a form an auditor or a customer can be shown. Replacement procurement aligned to the exit dates, because an exit date without an order behind it is an intention rather than a plan.

  4. 4

    Enrol, verify, and review quarterly

    Enrolment applied through Intune or volume licensing, verified on each device rather than on the invoice, and a quarterly review with the budget owner where the list is expected to shrink. Devices past their exit date are escalated, not silently renewed.

Before the period boundary

Twelve things to have settled before October.

The October boundaries are when the price steps up and late enrolment becomes cumulative. This is what should be true before each one arrives.

The list

  • Fleet scanned and sorted into upgrade, fix, replace, retire
    From evidence, not from the asset register
  • ESU list limited to devices that genuinely cannot move
    If it is most of the fleet, stop and re-plan
  • Every enrolled device has an exit date inside the period
    Set at enrolment, not later
  • Department owners have reviewed and agreed their devices
    So the list is owned, not imposed

The enrolment

  • Enrolment route chosen: volume licensing or Intune
    Intune is the practical path for most
  • Enrolment verified on each device, not on the invoice
    A licence bought is not a device patched
  • Cloud PC compared for the hard cases
    Sometimes cheaper, and a supported position
  • Third-party vendor support dates checked
    Browsers and endpoint protection especially

The governance

  • Risk acceptance documented and signed
    Which devices, why, until when, by whom
  • Quarterly review scheduled with the budget owner
    The list should shrink each quarter
  • Replacement procurement aligned to exit dates
    The exit date is only real if the order exists
  • A plan for what happens if a device misses its exit date
    Escalation, not silent renewal
Questions we get asked

Windows 10 ESU, answered plainly.

Next step

Find out how short your ESU list should actually be.

The scan sorts the fleet from evidence, and the ESU candidates are what remains after the upgrade, fix and retire buckets come out. It is consistently a shorter list than clients expect, and every device not on it is money available for a replacement. Remote-first from Hyderabad, serving all of India.