A Windows 10 computer does not stop working when support ends. That is exactly why the deadline is easy to ignore. The desktop looks the same, the accounting software opens, and employees can still answer email. The change is happening underneath: Microsoft no longer provides the normal operating-system security and quality updates for Windows 10 editions that reached end of support on October 14, 2025.
For a small business, the right response is not to replace every computer in a panic. It is to identify what is still running Windows 10, understand why, and give each device a documented path. Some PCs can move to Windows 11 with little effort. Some should be replaced. A small number may need Extended Security Updates while a critical application or piece of equipment is being modernized.
What Windows 10 end of support means in 2026
Microsoft's Windows 10 release information confirms that support ended on October 14, 2025. For affected editions, the October 2025 monthly security update was the final standard update. Microsoft says it no longer provides technical support, feature updates, or quality updates—including normal security and reliability fixes—for those systems.
The operating system does not become unsafe at one precise minute. Risk grows over time. Newly discovered weaknesses may remain unpatched, software vendors can stop testing against Windows 10, and troubleshooting becomes harder as supported drivers and applications move forward. The Canadian Centre for Cyber Security recommends automatically patching operating systems and applications and replacing software or hardware that no longer receives vendor updates.
| What continues | What has ended | Business implication |
|---|---|---|
| The PC can start and existing applications may run | Normal Windows 10 security and quality updates | Working today does not mean adequately protected tomorrow |
| Existing files and local accounts remain | Standard Microsoft technical support for the operating system | Recovery and compatibility problems may take longer to resolve |
| Some third-party products may still support Windows 10 | New Windows 10 features | Vendor support dates must be checked individually |
| Microsoft 365 Apps can still receive specified security updates during Microsoft's transition period | Support for running Microsoft 365 Apps on an unsupported operating system | App updates do not restore support or patch the Windows 10 operating system |
Step 1: Find every Windows 10 device
Begin with evidence, not a purchasing list. Include office desktops, laptops used at home, reception PCs, workshop terminals, point-of-sale devices, loaners, shared meeting-room computers, and machines attached to scanners, label printers, laboratory tools, or industrial equipment. Devices that are rarely connected to the company network are often the easiest to miss.
- Device name, assigned user, location, owner, and primary business purpose
- Windows edition, version, update status, processor, memory, storage, TPM, and Secure Boot status
- Warranty status, approximate age, battery condition, and repair history
- Business applications, browser extensions, printers, scanners, and specialized peripherals
- Whether the device stores local business data and whether that data is backed up
- Whether it is managed through Intune, another endpoint platform, or not managed at all
A very small company can record this in a controlled spreadsheet. A larger environment should use its endpoint-management or asset-inventory platform. Microsoft Intune can inventory and manage enrolled devices, deploy policies and applications, and control updates. The important outcome is one accountable list rather than several partial lists owned by different people.
Step 2: Put each device on one of four paths
| Path | Use it when | Required action |
|---|---|---|
| Upgrade | The PC meets Windows 11 requirements and its applications and peripherals are compatible | Back up, pilot, upgrade, verify, and place under normal update management |
| Replace | Hardware is ineligible, unreliable, slow, out of warranty, or expensive to maintain | Choose a business-grade Windows 11 device, migrate data and settings, then securely retire the old PC |
| Temporary ESU | A documented dependency prevents immediate migration | Enroll the eligible device, restrict its use, monitor it, and assign a firm replacement date |
| Retire | The device is unused, duplicated, or no longer supports a business process | Remove access, preserve required records, wipe data securely, and update the inventory |
Avoid a fifth, unofficial category called “leave it for now.” Every exception needs an owner, reason, compensating controls, and target date. Without those fields, a temporary exception tends to become permanent.
Step 3: Check Windows 11 eligibility properly
Microsoft's minimum Windows 11 requirements include a compatible 64-bit processor, at least 4 GB of memory, at least 64 GB of storage, UEFI firmware with Secure Boot capability, and TPM 2.0. Meeting the minimum does not automatically make a PC a good business investment. A device with limited memory, a small drive, a weak battery, or no remaining warranty may qualify technically and still be a poor upgrade candidate.
For an individual PC, Microsoft's PC Health Check app reports whether the device is eligible and explains common blockers. For a fleet, collect compatibility information centrally. Confirm that TPM or Secure Boot is not simply disabled in firmware before replacing otherwise suitable hardware, but change firmware settings only with the recovery keys, backups, and rollback plan in place.
Step 4: Use Windows 10 ESU only where it buys useful time
Microsoft's commercial Windows 10 Extended Security Updates program provides critical and important security updates for enrolled, eligible devices. Commercial organizations can obtain coverage for a maximum of three years after end of support. Microsoft's published Year One price is US$61 per device, and the price doubles in each consecutive year. Licensing routes and terms can change, so confirm the current Canadian price, taxes, eligible edition, activation method, and annual coverage before budgeting.
- ESU does not include new features or general operating-system improvements.
- ESU does not include normal technical support.
- ESU does not make an old device compatible with every future application, browser, driver, or security product.
- Only enrolled and correctly activated devices receive the applicable ESU updates; buying licences without verifying activation is not enough.
- A device on ESU still needs endpoint protection, application updates, backups, monitoring, access controls, and an exit plan.
ESU is most defensible when a specialized application, regulated validation process, hardware controller, or vendor contract creates a genuine migration dependency. It is less persuasive when the only reason is that nobody inventoried the computers before the deadline.
Step 5: Test the work, not just the operating system
A successful login is not a successful migration. Build a checklist around real jobs employees perform. Ask finance to open and export a representative report. Ask reception to scan and print. Test VPN, Wi-Fi, smart cards, browser-based portals, shared drives, macros, add-ins, line-of-business software, remote support, video meetings, and any device that connects through USB or a serial adapter.
- Identify a small pilot group representing different roles and device models.
- Record each critical workflow and its expected result before upgrading.
- Confirm software licensing and vendor support for Windows 11.
- Upgrade the pilot, then test sign-in, applications, data, printing, security controls, and performance.
- Document problems and fixes before expanding to the next group.
- Keep a rollback or replacement path available until the user accepts the migrated device.
Step 6: Protect data and recovery before migration
An upgrade should not be the first time anyone asks where an employee's files are stored. Move business records from unmanaged local folders into an approved, backed-up location. Verify backup success, test access to a sample restore, and record BitLocker recovery keys before making firmware or operating-system changes. Cloud synchronization can help protect user files, but synchronization and backup solve different problems and should be designed accordingly.
For replacement devices, plan how user profiles, browser data, certificates, templates, application settings, and local archives will move. Decide what should not move. Years of temporary downloads, unknown utilities, and stale administrator tools are not valuable migration cargo.
Step 7: Make the Windows 11 destination better managed
The project is an opportunity to fix inconsistent endpoint management, not merely change the Windows version. Standardize device naming, supported editions, update rings, encryption, endpoint protection, local administrator access, browser settings, application deployment, compliance checks, and offboarding. Enrol new computers in management before handing them to employees whenever possible.
- Use employee accounts for normal work and tightly control local administrator rights.
- Enable disk encryption and escrow recovery information in an approved system.
- Apply operating-system, browser, driver, firmware, and third-party application updates on a defined schedule.
- Use endpoint protection and verify that alerts reach someone responsible for responding.
- Require device compliance where appropriate before allowing access to Microsoft 365 and business data.
- Remove manufacturer trialware and install only approved business applications.
A realistic migration schedule for a small business
| Phase | Main work | Exit condition |
|---|---|---|
| Week 1: Discover | Inventory devices, users, applications, peripherals, and local data | Every Windows 10 device has an owner and business purpose |
| Week 2: Decide | Check eligibility and assign upgrade, replace, ESU, or retire | Every device has a funded path and target date |
| Week 3: Pilot | Back up and migrate representative users | Critical workflows and recovery steps are verified |
| Weeks 4–6: Roll out | Migrate in manageable groups with support available | Users accept devices and controls report healthy |
| Final: Close | Remove stale access, wipe retired devices, and review ESU exceptions | Inventory and management tools match reality |
The exact duration depends on device count and application complexity. Avoid upgrading everyone immediately before payroll, month-end, a sales event, or a staff vacation. A technically efficient schedule can still be a poor business schedule.
Budget for more than the price of the PC
Compare the full cost of each path: hardware, warranty, Windows edition, ESU, management licences, security software, adapters, docks, data migration, application upgrades, employee downtime, support, and secure disposal. A cheaper computer that needs an early memory upgrade, has a short warranty, or cannot support the required dock may cost more over its useful life.
Prioritize devices that handle sensitive data, belong to privileged users, access financial systems, travel outside the office, or already show reliability problems. If budget prevents a single replacement wave, schedule the highest-risk and highest-impact systems first and document how the remaining Windows 10 devices are protected.
A 30-minute Windows 10 exposure review
- Run an operating-system inventory and count active Windows 10 devices.
- Identify devices with no assigned user, no recent check-in, or no endpoint-management record.
- Confirm which Windows 10 devices are receiving ESU updates and which are not.
- Check Windows 11 eligibility for at least one device from every hardware model.
- List the applications and peripherals that currently block migration.
- Assign an owner and target date to every exception.
The bottom line
Windows 10 end of support is no longer a future planning item. In 2026, it is an active asset-management and security issue. The most useful first move is not buying hardware—it is producing a reliable list of devices and deciding what each one needs.
Upgrade compatible, healthy PCs. Replace equipment that no longer deserves more investment. Use ESU selectively when it supports a documented transition. Retire what the business does not need. Then keep the new Windows 11 environment consistently managed so the next lifecycle deadline is a planned project rather than an emergency.