Skip to main content
Windows 11 migration, India

Windows 10 stopped receiving security updates in October 2025. Every month on it since has been a choice, and the bridge gets more expensive each year.

Organisations still on Windows 10 in 2026 are either paying for Extended Security Updates or running without patches. ESU is deliberately priced to escalate and it is cumulative, so it is a bridge rather than a destination. A Windows 11 migration is three decisions dressed as one: which devices can upgrade in place, which have to be replaced because Microsoft will not relax the hardware requirements, and how you provision the result so the rollout does not consume your IT team for a year.

Microsoft
Windows 11
Cloud Solution Partner
  • October 2025Windows 10 support ended
  • TPM 2.0Non-negotiable, per Microsoft
  • ESUA bridge, priced to escalate
  • AutopilotProvisioning without touching devices
What the programme involves

Eight workstreams, and the first one decides the budget.

A Windows 11 migration is not a software upgrade with a hardware problem attached. It is a fleet decision, and the inventory that tells you which devices can and cannot be upgraded is what determines everything downstream, from the capital request to the rollout calendar.

Fleet inventory against the hardware bar

Windows 11 requires TPM 2.0, Secure Boot and a supported processor, which in practice means Intel 8th generation, AMD Ryzen 2000 or later. Microsoft has confirmed it will not lower these requirements. The first task is a device-level inventory that says, for every machine, upgrade in place, enable a firmware setting first, or replace. In most Indian estates the answer is a meaningful share of each, and the replace share is what sets the budget.

Application compatibility, which is quieter than expected

Most applications that run on Windows 10 run on Windows 11 without change, and the exceptions are predictable: old line-of-business software with kernel-level components, legacy printer and scanner drivers, and anything depending on features Windows 11 removed. The work is finding the exceptions before the rollout rather than during it, and it is usually a short list with a long tail of vendor conversations.

The ESU decision, made deliberately

Extended Security Updates cover devices that cannot move yet, in annual periods that run to October 2026 for Year 1 and October 2027 for Year 2. Pricing escalates each year and is cumulative, so joining late means paying for the years you skipped. ESU belongs on a defined subset of devices with a defined exit date, not across the fleet as a way of deferring the decision.

Device refresh, planned rather than reactive

The replace share of the inventory becomes a procurement and rollout plan: phasing by department and risk, standardising on a smaller number of models, sequencing around business calendars, and disposing of the outgoing fleet properly. Buying devices as machines fail is the most expensive way to do this and it produces a fleet nobody can manage consistently.

Provisioning with Autopilot rather than hands

Windows Autopilot lets a device configure itself out of the box: policies, applications and Intune enrolment without an engineer touching it. Since January 2026 it can apply quality updates during the out-of-box experience, and the application limit during setup rose from ten to twenty five. For a refresh of any size this is the difference between a rollout measured in weeks and one measured in quarters.

The security posture Windows 11 makes possible

The hardware requirements exist because Windows 11 is built around them: virtualisation-based security, hardware-backed credential protection and a firmware baseline that Windows 10 could not assume. A migration that upgrades the operating system and leaves the security configuration at Windows 10 defaults has spent the money and skipped the benefit. We configure the posture the platform was designed for.

User experience and the change nobody plans for

Windows 11 changes the interface in ways that generate support tickets for a fortnight: the Start menu, the taskbar, right-click menus, Settings. None of it is difficult and all of it is disruptive if nobody says anything in advance. A short piece of communication and a one-page guide per user reduces the ticket spike considerably, and it costs almost nothing.

Decommissioning the outgoing fleet

Devices that cannot run Windows 11 need a defined end: data wiped to a standard you can evidence, asset records closed, and disposal or resale handled through a route that gives you a certificate. Under the DPDP Rules a laptop with residual personal data is a breach waiting to be reported, so this is a compliance step rather than a housekeeping one.

The three device outcomes

Upgrade, fix then upgrade, or replace, and how to tell which.

Every device in the fleet lands in one of three buckets, and the inventory is what sorts them. Getting this right early is what makes the capital request accurate and the rollout calendar realistic.

Upgrade in place

Supported processor, TPM 2.0 present and enabled, Secure Boot on, enough storage. These devices move with a managed upgrade through Intune or your existing tooling and need no hardware spend.

  • Confirm with a real compatibility scan, not with the purchase date
  • Check storage headroom, since the upgrade needs working space
  • Still needs the Windows 11 security configuration applied afterwards

Enable firmware, then upgrade

A surprisingly common category: the hardware is capable but TPM or Secure Boot is disabled in firmware, usually because the device was imaged years ago with those settings off.

  • Remote firmware configuration is possible on most business models
  • Test the procedure per model before rolling it out
  • Cheapest win in the whole programme, and frequently missed

Replace

Processor generation below the bar, or no TPM 2.0 at all. Microsoft has said repeatedly the requirements will not change, so these devices have a defined end date whatever else happens.

  • This share of the fleet sets the budget, so establish it accurately
  • Prioritise by role and risk rather than by age alone
  • Bridge with ESU only where a device genuinely cannot be replaced yet

The unsupported workaround, and why we do not do it

Windows 11 can be installed on unsupported hardware by bypassing the checks. It is unsupported, may not receive updates, and creates a fleet you cannot describe to an auditor or a customer.

  • No support commitment from Microsoft on bypassed installs
  • Update behaviour on unsupported hardware is not guaranteed
  • Replace or bridge with ESU rather than building on an exception

Devices that should simply be retired

Every inventory finds machines with no assigned user, no recent sign-in, and no purpose anybody can name. They need neither upgrade nor replacement, only a wipe and a disposal record.

  • Usually more of the fleet than anybody expected
  • Removing them shrinks both the licence count and the rollout
  • Wipe to an evidenced standard before disposal

Devices bridged on ESU with an exit date

Machines that genuinely cannot move by the deadline, held on ESU for a defined period with a named replacement date. A bridge, not a category.

  • Enrol only the devices that need it, since it is per device
  • Set the exit date at enrolment, because the price escalates
  • Review quarterly so the list shrinks rather than grows

Special cases: kiosks, shop floor and shared machines

Devices with a single fixed purpose, on a factory floor or a reception desk, often running software with its own constraints. They need individual decisions rather than a fleet rule.

  • Vendor support for the application decides these, not the hardware
  • Some are candidates for Windows 365 Cloud PC or a thin client
  • Isolate on the network anything that has to stay behind

How the buckets get agreed

The inventory proposes and the business decides, particularly on the replace list where the budget lives. We present the sorted fleet with reasoning, and expect the replacement schedule to be negotiated.

  • Department heads review their own device list before it is fixed
  • Disagreements usually surface a device the scan mis-categorised
  • The agreed list becomes the procurement plan and the calendar
Why bring us in

We run fleets on Intune, so we build the migration to be operated.

We sort the fleet from a real scan

Purchase records and model names do not tell you whether TPM is enabled or which firmware version a device is on. We run a compatibility scan across the estate and sort every device from evidence, which is what makes the replace list, and therefore the budget, accurate.

Microsoft Partner, so Autopilot and Intune are daily work

The provisioning approach that makes a rollout finish in weeks rather than quarters is one we configure for clients constantly. Profiles, compliance policies, application deployment and the security baseline are built and tested before the first device ships.

We will tell you which devices to bridge and which to replace

ESU is sometimes the right call and fleet-wide ESU almost never is. We give you a named list with exit dates rather than a renewal, because the escalating and cumulative pricing punishes deferral more each year.

We manage estates afterwards, so we care how this ends

A migration partner who leaves after the last device ships has no reason to care whether the fleet is standardised, the posture is configured, or the outgoing machines were wiped. We operate fleets for clients continuously, so we build the migration we would want to inherit.

Where it lands hardest

What the migration looks like, by sector.

Manufacturing

Shop-floor and quality systems on old hardware with vendor constraints. The replace list is dominated by special cases needing individual decisions, and network isolation for whatever has to stay behind.

BFSI and regulated

Unsupported operating systems are an audit finding, which turns the migration from an IT project into a compliance deadline. Documentation of the ESU bridge and its exit matters as much as the technical work.

Healthcare

Clinical devices and diagnostic workstations with vendor-certified software, where the vendor conversation determines the schedule and some machines will be bridged for longer than anyone would like.

Education

Large fleets of older devices bought in bulk, so the replace share is high and the budget conversation is the whole project. Windows 365 Cloud PC or thin clients are worth assessing for labs.

GCCs and technology

Usually the newest hardware and the most capable estate, so mostly upgrade in place. The work is the security posture and Autopilot, and the migration is a chance to move fully to Intune.

Retail and distributed offices

Many small sites with no local IT, which makes Autopilot the only realistic provisioning approach and makes the disposal logistics for outgoing devices a real problem to plan.

The timeline

The dates that matter, and what each one means for a fleet still on Windows 10.

The headline date has passed. The dates that matter now are the ESU periods, because each one is a step up in cost and a narrowing of options.
DateWhat happensWhat it means for you
14 October 2025Windows 10 end of supportNo security updates without ESU. Every unenrolled Windows 10 device from this point is accumulating unpatched vulnerabilities.
October 2025 to October 2026ESU Year 1Critical and important security updates only, per device, for enrolled machines. The cheapest year, and the one most organisations are in now.
October 2026ESU Year 1 ends, Year 2 beginsThe price steps up. Enrolling late is cumulative, so a device joining in Year 2 pays for Year 1 as well. Plan to exit rather than renew.
October 2026 to October 2027ESU Year 2A second escalation. Devices still here should be a short, named list with a replacement order already placed.
October 2027 onwardsESU Year 3, the final yearThe last bridge. Any device still on Windows 10 after this has no supported path, and the hardware will be several years past its refresh date anyway.
Any timeWindows 11 hardware requirementsFixed. Microsoft has confirmed TPM 2.0 and the processor bar are not changing, so waiting does not make an unsupported device supported.
Two programmes

Reactive upgrade against a planned migration.

Both end with Windows 11 on most devices eventually. One consumes your IT team for a year and produces a fleet nobody can describe; the other finishes.
Feature
Dimension
Reactive
Planned
Starting point
Upgrade whatever works, replace what failsA scanned inventory sorted into three buckets
Hardware
Bought as devices die, model by modelStandardised, phased, budgeted once
ESU
Fleet-wide, renewed annuallyNamed devices with exit dates
Provisioning
An engineer at every deskAutopilot, devices configure themselves
Security posture
Windows 10 configuration carried acrossConfigured for what Windows 11 makes possible
Users
Discover the new interface on MondayTold in advance, with a guide
Outgoing devices
In a cupboard, data intactWiped, recorded, disposed with a certificate
End state
A mixed fleet, indefinitelyA fleet you can describe in one sentence

ESU across the whole fleet is the most expensive way to not decide.

Extended Security Updates are a legitimate bridge for devices that genuinely cannot move by the deadline. They are a poor substitute for a decision, and enrolling the entire fleet to buy a year of thinking time is the pattern we most often see and most often regret with clients. The price steps up each year, it is cumulative so late joiners pay for the years they missed, and the hardware being bridged is getting older throughout. The money spent on a fleet-wide ESU renewal is money that could have replaced a meaningful share of the machines it is protecting.

  • Enrol only the devices that cannot be upgraded or replaced by the current period end
  • Give every enrolled device a named replacement date at the moment of enrolment
  • Review the ESU list quarterly and expect it to shrink
  • If you find yourself renewing for Year 2 fleet-wide, the programme has stalled
The engagement

Five stages, and the inventory is the one that sets the budget.

  1. 1

    Scan the fleet and sort every device

    A compatibility scan across the estate producing a device-level verdict: upgrade, enable firmware then upgrade, replace, or retire. Reviewed with department heads so the replace list is agreed rather than imposed, because that list is the capital request.

  2. 2

    Decide the bridge and the refresh

    ESU enrolment limited to named devices with exit dates. The replace list turned into a phased procurement plan with standardised models, sequenced around business calendars. Application compatibility exceptions identified and assigned an owner for the vendor conversation.

  3. 3

    Build the platform

    Intune policies, compliance, the Windows 11 security baseline and application deployment configured. Autopilot profiles built and tested on a device from the actual order rather than a lab machine. Firmware enablement procedure tested per model for the fix-then-upgrade bucket.

  4. 4

    Roll out in waves

    In-place upgrades pushed through Intune by department, new devices provisioned through Autopilot, users told what changes and given a guide before their wave, and support capacity arranged for the days afterwards when the interface questions arrive.

  5. 5

    Decommission and close out

    Outgoing devices wiped to an evidenced standard, asset records closed, disposal through a route that provides a certificate. ESU list reviewed and shrunk. Then handover to your team or ongoing fleet management, whichever you want.

Before the rollout

Twelve things to have settled before the first wave.

The list we work through before scheduling a first migration wave. Most rollout trouble traces to one of these being assumed rather than confirmed.

The fleet

  • Every device sorted into upgrade, fix, replace or retire
    From a scan, not from purchase records
  • Replace list agreed by department heads and budgeted
    This is the capital conversation
  • Firmware enablement tested per model
    The cheapest win, and the most often skipped
  • ESU enrolment limited to named devices with exit dates
    Per device, cumulative, escalating

The platform

  • Application compatibility exceptions identified and owned
    Usually a short list, a long tail of vendors
  • Printer and peripheral drivers confirmed for Windows 11
    Older devices are the recurring problem
  • Intune policies, compliance and security baseline ready
    Windows 11 defaults are not the target posture
  • Autopilot profiles built and tested on a real device
    Not in a lab, on a machine from the actual order

The people

  • Waves sequenced by department, risk and business calendar
    Not by who asked first
  • Users told what changes and given a one-page guide
    Halves the fortnight of interface tickets
  • Support capacity arranged for the days after each wave
    Volume spikes, then falls quickly
  • Wipe and disposal route for the outgoing fleet arranged
    A DPDP matter, not housekeeping
Questions we get asked

Windows 11 migration, answered plainly.

Next step

Find out how much of your fleet can actually move.

The scan is quick, it sorts every device into upgrade, fix, replace or retire from evidence rather than purchase records, and it produces the one number that sets the budget. Tell us roughly how many devices you have and whether you are on ESU. Remote-first from Hyderabad, serving all of India.