Extended Security Updates are designed so that staying costs more than leaving. Use them that way.
ESU is a legitimate bridge for Windows 10 devices that genuinely cannot move to Windows 11 by the current period end. It provides critical and important security patches only, per device, in annual periods running to October 2026, 2027 and 2028. The price steps up each year and enrolment is cumulative, so a device joining late pays for the years it skipped. That pricing model is not an accident: Microsoft built it to make ESU a temporary answer. The organisations that use it well enrol a named list, set an exit date at enrolment, and shrink the list every quarter.
- 3 periodsTo October 2026, 2027, 2028
- Per deviceNot per organisation
- CumulativeLate joiners pay for skipped years
- Security onlyNo features, no support
Eight things to understand before enrolling a single device.
Critical and important security updates, nothing else
ESU delivers security fixes rated critical or important. It does not deliver feature updates, non-security bug fixes, new capabilities, or Microsoft technical support. A Windows 10 device on ESU is patched against the vulnerabilities Microsoft considers serious enough and is otherwise frozen. For most business use that is sufficient as a bridge; it is not equivalent to being on a supported operating system.
Three annual periods with hard boundaries
Year 1 runs from 15 October 2025 to 13 October 2026. Year 2 from 14 October 2026 to 12 October 2027. Year 3 to October 2028, and then the programme ends. Each boundary is a price step and a decision point. A device still on ESU in Year 3 is running an operating system three years past end of support on hardware that is almost certainly past its own refresh date.
The price escalates every year, by design
Microsoft publishes the per-device figures directly and we do not repeat them here, partly because they change and partly because the number is not the point. The structure is the point: each year costs more than the last, deliberately, so that ESU becomes progressively less attractive than migration. An organisation renewing fleet-wide into Year 2 is paying a premium for having not decided in Year 1.
Enrolment is cumulative
A device enrolled for the first time in Year 2 pays for Year 1 as well, and one enrolled in Year 3 pays for all three. There is no discount for joining late. This has a practical consequence: if a device is going to need ESU at any point, enrolling it at the start of the current period is cheaper than waiting, and the decision about which devices those are needs making now rather than at the boundary.
Licensed per device, so scope is everything
ESU is bought per device, not per organisation, which means the cost scales directly with how many machines you enrol. Enrolling the whole fleet because it is simpler multiplies the cost by the fleet size. Enrolling only the devices that genuinely cannot move by the period end, after a scan has sorted the fleet, is what makes ESU affordable as a bridge and unaffordable as a strategy.
Enrolment through volume licensing or Intune
Organisations enrol through their volume licensing agreement or, for Intune-managed fleets, through the device management console, which is the practical path for most Indian businesses already on Microsoft 365. The enrolment has to be applied and verified per device; a licence purchased and not activated on the device provides nothing. We check enrolment status from the device side, not from the purchase record.
Cloud PC and virtual desktop scenarios differ
Windows 10 running in Windows 365 Cloud PC or Azure Virtual Desktop carries its own ESU entitlement under those services, which changes the calculation for organisations considering a Cloud PC route for their hard cases. For some roles it is cheaper to stream a supported Windows 11 desktop to an old device than to enrol that device in ESU, and the comparison is worth doing explicitly.
What ESU does not fix
Third-party vendors dropping Windows 10 support on their own schedules, browsers and endpoint protection included. Hardware ageing throughout the bridge period. Customer security questionnaires that ask about supported operating systems, where ESU is a mitigation to explain rather than a clean yes. And the underlying decision, which ESU defers rather than makes.
Eight rules for ESU as a bridge rather than a destination.
Scan before you enrol
A compatibility scan sorts the fleet into devices that can upgrade, devices that need a firmware fix, and devices that must be replaced. Only the last group, and only the part of it that cannot be replaced by the period end, is an ESU candidate.
- Most fleets have fewer genuine ESU candidates than expected
- Firmware-fixable devices should be fixed, not enrolled
- Retired and unused devices should not be enrolled at all
Enrol a named list, not the fleet
Per-device pricing means every unnecessary enrolment is pure cost. The list should be short, specific, and justified device by device.
- Each device on the list has a reason it cannot move yet
- The list is reviewed by the department that owns the devices
- If the list is most of the fleet, the programme has not started
Set the exit date at enrolment
Every enrolled device gets a replacement or upgrade date the moment it is enrolled, and that date is inside the current period. ESU without an exit date becomes permanent by neglect.
- The exit date drives the procurement schedule
- Devices past their exit date are escalated, not renewed
- Year 2 renewal for a device is a failure of the plan, not a decision
Enrol early in the period
Cumulative pricing means a device that will need ESU at all is cheapest enrolled at the start of the current period. Waiting to see does not save money, it costs the skipped months for nothing.
- Decide the list before the period boundary, not after
- Late enrolment pays for coverage you did not receive
- The October boundaries are the planning dates
Review the list quarterly and expect it to shrink
The list should get shorter every quarter as devices are replaced or upgraded. A list that grows or stays flat is a signal that the migration has stalled and ESU has become the plan.
- Track enrolled devices against their exit dates
- Report the count to whoever owns the budget
- A shrinking list is the only healthy trajectory
Verify enrolment on the device, not the invoice
A licence bought is not a device patched. Enrolment has to be applied and confirmed per device, and a fleet that believes it is covered because the purchase went through is worse off than one that knows it is not.
- Check the update status on the device itself
- Intune reporting shows enrolment state per machine
- Audit this after every period boundary
Compare against Cloud PC for the hard cases
For roles where the device cannot move and the application cannot change, a Windows 365 Cloud PC streaming a supported desktop to the old hardware is sometimes cheaper than ESU and is a supported position rather than a bridge.
- Cloud PC carries its own ESU entitlement for Windows 10 sessions
- Turns an unsupported device into a thin client
- A licensing decision, and worth costing explicitly
Document the risk acceptance
ESU is a mitigation, not a resolution, and under DPDP and sector rules the decision to keep devices on a bridged operating system is a risk acceptance somebody should sign.
- Record which devices, why, and until when
- Name the owner who accepted the residual risk
- This is what an auditor or a customer will ask to see
We scope the list before anybody buys anything.
The scan comes first, always
Enrolling before scanning is how fleets end up paying ESU on devices that could have been upgraded with a firmware setting. We sort the fleet from evidence first, and the ESU list is what is left after the upgrade, fix and retire buckets are removed. It is consistently shorter than the client expected.
We will tell you which devices should not be enrolled
That reduces the size of any ESU purchase and it is the right advice. A partner who benefits from your licensing spend has a reason to recommend the fleet. We manage estates for clients on an ongoing basis, so a bloated ESU list is our problem next year as well as yours.
Microsoft Partner, so enrolment and verification are routine
Enrolment through Intune, verification per device, and the reporting that shows which machines are actually covered are things we do in client tenants regularly. A licence bought and not applied is a gap we specifically check for.
We attach ESU to the migration it is bridging
ESU only makes sense inside a Windows 11 programme with a replace list and a procurement schedule. We scope it as one workstream of that programme, with exit dates that drive procurement, rather than as a standalone purchase that quietly becomes the plan.
The legitimate bridge cases, by sector.
Clinical and diagnostic workstations
Vendor-certified software with no Windows 11 release yet, on devices that cannot be replaced until the vendor moves. A genuine bridge case, with the exit date set by the vendor roadmap.
Shop-floor and quality systems
Machines controlling or monitoring equipment, where the software vendor and the equipment lifecycle decide the date. Usually paired with network isolation rather than ESU alone.
Regulated organisations mid-refresh
A funded replacement programme with procurement lead times that cross the period boundary. ESU covers the gap, with exit dates matching delivery dates, and the risk acceptance documented for the auditor.
Education with budget cycles
Large fleets where the replace share is high and capital arrives on an academic calendar. ESU bridges to the next budget, on a list that shrinks as each tranche of devices arrives.
GCCs awaiting a parent decision
Device standards set by a global parent on their own timeline. ESU covers the Indian fleet until the group refresh reaches it, with the exit date set by the group programme rather than locally.
Distributed sites with disposal logistics
Many small locations where replacing and collecting devices is a logistics exercise. ESU covers sites until their wave, with the schedule driven by the rollout plan rather than the boundary.
Which devices belong on ESU, and which do not.
| Device situation | ESU decision | What happens instead or next | |
|---|---|---|---|
| Meets the Windows 11 hardware bar | No. Upgrade in place. | A managed upgrade through Intune, with the Windows 11 security configuration applied afterwards. No ESU cost at all. | |
| Capable hardware, TPM or Secure Boot disabled | No. Enable firmware, then upgrade. | The cheapest category in the programme and the most often missed. Test the firmware procedure per model, then upgrade. | |
| Below the bar, replacement already ordered | Only if delivery is after the period boundary. | Short bridge with the exit date set to the delivery date. If the device arrives inside the period, do not enrol. | |
| Below the bar, replacement not yet budgeted | Yes, with an exit date inside the current period. | The exit date forces the budget conversation. This is the legitimate core of an ESU list. | |
| Runs an application with no Windows 11 path | Maybe. Compare against Cloud PC and isolation first. | A Cloud PC running the application in a supported desktop may be cheaper and is a supported position. If the device must stay, isolate it on the network. | |
| No assigned user, no recent sign-in | No. Retire it. | Wipe to an evidenced standard, close the asset record, dispose with a certificate. Enrolling an unused device in ESU is the purest form of waste in the programme. |
ESU as a bridge against ESU as a strategy.
| Feature | Dimension | As a strategy | As a bridge |
|---|---|---|---|
Which devices | The whole fleet, because it is simpler | A named list that cannot move by the period end | |
Exit date | None, or the end of the programme | Set per device at enrolment, inside the period | |
Year 2 | Renewed fleet-wide at the higher rate | A shorter list, or none | |
Cumulative pricing | Paid on devices that could have been upgraded | Avoided by enrolling early and only what is needed | |
Hardware during the bridge | Ageing across the fleet for three years | Replaced on schedule as exit dates arrive | |
Security questionnaire answer | A mitigation to explain, fleet-wide | A small, documented exception list | |
Budget conversation | Deferred, then larger | Forced early by the exit dates | |
End state at October 2028 | Unsupported fleet, no bridge left | Windows 11 fleet, ESU long finished |
We do not publish the ESU price, and here is why that matters more than usual.
Every other page on this topic leads with the per-device figures, and they are the least useful number in the decision. Microsoft publishes them directly, they change at each period boundary by design, and quoting them tends to produce one of two bad reactions: sticker shock that delays the decision, or a fleet-wide renewal because the Year 1 figure looked manageable. What determines whether ESU is money well spent is not the rate. It is how many devices you enrol, for how long, and whether each one has a real exit date. A short list for one period is a bridge. The whole fleet for three years is the most expensive migration you will ever not do.
- The structure is the point: escalating, cumulative, per device, temporary by design
- Scope decides the cost far more than the rate does
- Compare ESU per device against the replacement it is deferring, not against zero
- If the Year 2 fleet-wide renewal looks affordable, the plan has quietly stalled
Four stages, and enrolment is the last one.
- 1
Scan and sort the fleet
A compatibility scan across the estate sorting every device into upgrade, firmware fix then upgrade, replace, or retire. The ESU candidates are the subset of the replace bucket that cannot be replaced by the current period end, and that subset is what the rest of the engagement is about.
- 2
Build the list with exit dates
Each candidate device reviewed with the department that owns it, given a reason it cannot move yet, and given an exit date inside the current period. Hard cases compared against Windows 365 Cloud PC and against network isolation, because ESU is not always the cheapest supported answer.
- 3
Document the risk acceptance and align procurement
The list, the reasons, the exit dates and the accepting owner recorded in a form an auditor or a customer can be shown. Replacement procurement aligned to the exit dates, because an exit date without an order behind it is an intention rather than a plan.
- 4
Enrol, verify, and review quarterly
Enrolment applied through Intune or volume licensing, verified on each device rather than on the invoice, and a quarterly review with the budget owner where the list is expected to shrink. Devices past their exit date are escalated, not silently renewed.
Twelve things to have settled before October.
The list
- Fleet scanned and sorted into upgrade, fix, replace, retireFrom evidence, not from the asset register
- ESU list limited to devices that genuinely cannot moveIf it is most of the fleet, stop and re-plan
- Every enrolled device has an exit date inside the periodSet at enrolment, not later
- Department owners have reviewed and agreed their devicesSo the list is owned, not imposed
The enrolment
- Enrolment route chosen: volume licensing or IntuneIntune is the practical path for most
- Enrolment verified on each device, not on the invoiceA licence bought is not a device patched
- Cloud PC compared for the hard casesSometimes cheaper, and a supported position
- Third-party vendor support dates checkedBrowsers and endpoint protection especially
The governance
- Risk acceptance documented and signedWhich devices, why, until when, by whom
- Quarterly review scheduled with the budget ownerThe list should shrink each quarter
- Replacement procurement aligned to exit datesThe exit date is only real if the order exists
- A plan for what happens if a device misses its exit dateEscalation, not silent renewal
Windows 10 ESU, answered plainly.
What ESU is bridging to.
Windows 11 migration
The programme ESU should sit inside: fleet sorting, the refresh, Autopilot provisioning and the security posture.
Learn moreWindows 11 vs Windows 10 for business
The honest comparison after end of support: what Windows 11 changes, what staying on ESU really costs, and how to decide device by device.
Learn moreWindows 10 end of support
What actually changed in October 2025, and why it is a compliance matter rather than an IT preference.
Learn moreFind out how short your ESU list should actually be.
The scan sorts the fleet from evidence, and the ESU candidates are what remains after the upgrade, fix and retire buckets come out. It is consistently a shorter list than clients expect, and every device not on it is money available for a replacement. Remote-first from Hyderabad, serving all of India.
Related Services
Explore more solutions that work great with this service
Windows 11 Migration
Sort the fleet, bridge the exceptions, provision without hands
Learn moreWindows 10 End of Support
What changed in October 2025 and why it is a compliance matter
Learn moreDevice Refresh Planning
Standardise, phase, register at purchase, dispose with a certificate
Learn moreWindows 365 Cloud PC
Cloud-based virtual desktop solutions
Learn more