Windows 10 reached end of support on October 14, 2025. Since then, home PCs have stayed patched only through the one-year consumer Extended Security Updates (ESU) program, which stops on October 13, 2026. Microsoft has announced no paid consumer renewal, so the clock on home devices is nearly out. This guide covers the exact dates, ESU enrollment methods, upgrade paths, and the commands to verify your status.
Quick Takeaways
- Consumer ESU ends October 13, 2026. It is both the last enrollment date and the last day of security patches for Home, Pro, Pro Education, and Pro for Workstations.
- Business ESU continues in annual paid tiers through October 2028 (Year 1 ends October 13, 2026, Year 2 in October 2027, Year 3 in October 2028).
- ESU is security-only. No features, no non-security fixes, no general technical support.
- Your real choices: upgrade to Windows 11, move to Linux or ChromeOS Flex, enroll in commercial ESU (organizations), or accept the risk of an unpatched OS.
| Milestone | Date | Applies To |
|---|---|---|
| Windows 10 end of support | October 14, 2025 | All Windows 10 editions |
| Consumer ESU window | Oct 15, 2025 – Oct 13, 2026 | Home, Pro, Pro Education, Pro for Workstations |
| Commercial ESU Year 1 ends | October 13, 2026 | Business/enterprise devices |
| Commercial ESU Year 2 ends | October 2027 | Business/enterprise devices |
| Commercial ESU Year 3 ends | October 2028 | Business/enterprise devices |
What “End of Support” Actually Means
After October 14, 2025, Microsoft stopped shipping free monthly cumulative updates for Windows 10. The OS still boots and runs. It simply no longer receives fixes for newly discovered vulnerabilities unless the device is enrolled in ESU.
ESU delivers only updates Microsoft rates Critical or Important. Microsoft also stops answering general support tickets for the OS itself, and third-party vendors steadily drop Windows 10 from their supported platform lists.
Browsers and security tools follow their own schedules. Edge and Chrome typically keep updating on Windows 10 for a limited time, but that does not patch kernel, driver, or Windows component flaws.
Prerequisites: Check Your Build First
ESU requires Windows 10, version 22H2 with the latest cumulative updates installed. Verify your version:
Get-ComputerInfo | Select-Object WindowsProductName, WindowsVersion, OsBuildNumber
Get-ComputerInfopulls OS metadata from WMI.WindowsVersionmust read 22H2.OsBuildNumbershould start with 19045.
Or run winver from the Run dialog (Win + R).
If you are on 21H2 or older, install the 22H2 feature update through Settings > Update & Security > Windows Update before anything else.
Consumer ESU: Three Enrollment Methods
Consumer ESU is a per-device enrollment tied to a Microsoft account. You pick one method.
| Method | Cost | Requirement | Trade-Off |
|---|---|---|---|
| Sync PC settings (Windows Backup) | Free | Signed in with a Microsoft account, settings sync on | Pushes settings data to OneDrive |
| Microsoft Rewards points | 1,000 points | Microsoft account with enough points | Points are consumed |
| One-time purchase | About $30 USD | Microsoft account; one purchase covers up to 10 devices on that account | Cost, but no cloud sync needed |
Users in the European Economic Area have a modified free path that does not require syncing settings, but it needs periodic Microsoft account sign-ins. Check Microsoft’s current ESU page for the exact terms in your region.
Step-by-Step Enrollment
- Sign in with a Microsoft account (not a local account).
- Open Settings > Update & Security > Windows Update.
- Select Enroll now in the ESU banner.
- Choose a method: sync, Rewards, or purchase.
- Restart and run Check for updates.
Late enrollment is allowed until October 13, 2026. If you enroll late, you receive all ESU patches released earlier in the program.
If the “Enroll now” Banner Is Missing
Work through this order:
- Confirm 22H2 and install all pending updates.
- Confirm the device is a Home, Pro, Pro Education, or Pro for Workstations edition and not domain-joined.
- Sign in with a Microsoft account and not a local account.
- Repair system files:
DISM /Online /Cleanup-Image /RestoreHealth
sfc /scannow
DISM /RestoreHealthrepairs the component store from Windows Update.sfc /scannowverifies and replaces corrupted protected system files.
- Reset Windows Update services:
net stop wuauserv
net stop bits
ren C:\Windows\SoftwareDistribution SoftwareDistribution.old
net start bits
net start wuauserv
net stop wuauservstops the Windows Update service.- Renaming SoftwareDistribution forces a clean update cache.
- Restart the PC, then check Windows Update again.
Commercial ESU: Pricing and Activation
Organizations license ESU per device through a volume licensing channel. Pricing doubles each year, which is deliberate pressure to migrate.
| Year | Per-Device Price (Commercial) | Coverage Ends |
|---|---|---|
| Year 1 | $61 | October 13, 2026 |
| Year 2 | $122 | October 2027 |
| Year 3 | $244 | October 2028 |
Education customers receive steep discounts. Year 1 is listed at about $1 per device, with the price doubling each year. Windows 365 Cloud PCs and Azure virtual machines receive ESU at no extra cost, which makes cloud-hosted legacy workloads easier to carry.
Year 2 requires Year 1. Coverage is cumulative, so skipping a year means paying for the missed year to continue.
Activating an ESU Key
Install the ESU license, then activate it using the year-specific Activation ID. Confirm the current ID values in Microsoft’s documentation before scripting this at scale.
slmgr /ipk <YOUR-ESU-KEY>
slmgr /ato <ESU-ACTIVATION-ID>
slmgr /dlv <ESU-ACTIVATION-ID>
/ipkinstalls the ESU product key./atoattempts activation for the given Activation ID./dlvprints detailed license status, including whether the ESU year is active.
Managed fleets typically use Microsoft Intune, Configuration Manager, or the Microsoft 365 admin center to assign and track ESU licenses rather than keying each device by hand.
Option Comparison: Which Path Fits You?
| Option | Cost | Security Posture | Effort | Best For |
|---|---|---|---|---|
| Windows 11 upgrade | Free (eligible hardware) | Full support | Low to medium | Most users with a compatible PC |
| Consumer ESU | $0 – ~$30 | Security patches until Oct 13, 2026 only | Low | A short bridge on one PC |
| Commercial ESU | $61 – $244 per device/year | Security patches up to 3 years | Medium | Fleets with blocked migrations |
| Linux (Mint, Ubuntu LTS, Zorin) | Free | Long-term supported | Medium to high | Older hardware, tech-comfortable users |
| ChromeOS Flex | Free | Google-managed updates | Low | Browser-centric, low-spec devices |
| Do nothing | Free | Degrades with each new CVE | None | Air-gapped or fully offline machines only |
Check Windows 11 Readiness
Most upgrade failures come from four requirements: TPM 2.0, UEFI with Secure Boot, a supported CPU, and enough RAM and storage.
| Requirement | Windows 11 Minimum |
|---|---|
| CPU | 64-bit, 1 GHz, 2+ cores, on the supported CPU list (generally Intel 8th gen or newer, AMD Zen 2 or newer) |
| RAM | 4 GB |
| Storage | 64 GB |
| Firmware | UEFI with Secure Boot capability |
| Security chip | TPM 2.0 |
Run this in an elevated PowerShell window:
$tpm = Get-Tpm
$sb = try { Confirm-SecureBootUEFI } catch { "Not supported or Legacy BIOS" }
$ram = [math]::Round((Get-CimInstance Win32_ComputerSystem).TotalPhysicalMemory / 1GB, 1)
$disk = [math]::Round((Get-PSDrive C).Free / 1GB, 1)
$cpu = (Get-CimInstance Win32_Processor).Name
[PSCustomObject]@{
TpmPresent = $tpm.TpmPresent
TpmReady = $tpm.TpmReady
SecureBoot = $sb
RAM_GB = $ram
FreeDisk_GB = $disk
CPU = $cpu
}
Get-Tpmreports TPM presence and readiness. Confirm the version intpm.msc; it must show 2.0.Confirm-SecureBootUEFIreturnsTrueonly on UEFI systems with Secure Boot enabled.- A
Falseresult may simply mean Secure Boot is off in firmware. A thrown error means Legacy BIOS mode.
For a graphical result, run the PC Health Check app, or open Settings > Windows Update. Windows shows an upgrade offer when the device qualifies.
Fixing Common Readiness Blockers
- TPM disabled in firmware: Enter UEFI setup and enable Intel PTT or AMD fTPM.
- Legacy BIOS/MBR disk: Convert the disk without reinstalling, then switch firmware to UEFI:
mbr2gpt /validate /allowFullOS
mbr2gpt /convert /allowFullOS
/validatechecks that the disk layout can convert./convertrewrites MBR to GPT and adds an EFI system partition.- Back up first. Then change the firmware boot mode to UEFI before restarting.
Unsupported CPUs can be forced through with registry workarounds, but Microsoft does not support those installs and may withhold updates from them. Avoid this approach on anything that handles sensitive data.
Migration Checklist for Admins
- Inventory every Windows 10 endpoint, including build, TPM state, and CPU generation.
- Segment into three buckets: upgrade-ready, hardware refresh, and blocked (legacy apps).
- Pilot Windows 11 on a small ring using your deployment tooling.
- Test applications with App Assurance or your own regression suite.
- Buy ESU only for the blocked bucket, and set a hard retirement date.
- Track ESU activation status centrally so no device falls out of coverage unnoticed.
Practical Troubleshooting Scenarios
Scenario 1: ESU Enrollment Fails With a Sign-In Error
Symptoms: The enrollment wizard loops or reports it cannot verify the account.
- Sign out of the Microsoft account in Settings > Accounts > Your info, then sign back in.
- Confirm the system clock and time zone are correct. Token validation fails on skewed clocks.
- Run
sfc /scannowand the DISM command above. - Retry from a clean boot if third-party security software is blocking Microsoft endpoints.
Scenario 2: Windows 11 Upgrade Stalls at a Percentage
- Free at least 20 GB on
C:. - Disconnect USB devices and external drives.
- Update chipset, storage, and network drivers from the vendor.
- Review the setup logs in C:$WINDOWS.~BT\Sources\Panther (
setupact.logandsetuperr.log). - As a fallback, use the Windows 11 Installation Assistant or create bootable media with the Media Creation Tool and run
setup.exefrom within Windows to keep files and apps.
Scenario 3: A Legacy App Only Runs on Windows 10
- Run the app inside a Hyper-V or Windows 365 virtual machine. Cloud-hosted Windows 10 receives ESU at no extra cost.
- Isolate the host on a restricted VLAN with no inbound internet access.
- Document a retirement date so the exception does not become permanent.
Scenario 4: Secure Boot Certificate Warnings
Microsoft’s original Secure Boot certificates from 2011 expire during 2026. Devices that have not received the replacement certificates through Windows Update or firmware updates can lose the ability to receive future boot-component security fixes. Check Secure Boot status with Confirm-SecureBootUEFI, install the latest cumulative updates, and apply OEM firmware updates. This applies to Windows 11 devices as well.
Linux and ChromeOS Flex as Exit Routes
Hardware that fails Windows 11 checks often runs a modern Linux distribution well.
| Distribution | Base | Resource Use | Update Support | Ease of Migration |
|---|---|---|---|---|
| Linux Mint | Ubuntu LTS | Low to moderate | Long-term (5 years per release) | High: Windows-like desktop |
| Ubuntu LTS | Debian | Moderate | 5 years standard, longer with Pro | High |
| Zorin OS | Ubuntu LTS | Moderate | Long-term | High: includes layout switcher |
| ChromeOS Flex | ChromeOS | Very low | Google-managed | Very high for web-first users |
Before wiping the disk:
- Back up user data to external storage or cloud.
- Boot a live USB and test Wi-Fi, graphics, audio, and suspend.
- Check application equivalents. Office documents work in LibreOffice, and many Windows-only tools run under Wine or Proton with mixed results.
What Happens After October 13, 2026
On a consumer PC with no further coverage:
- No new security patches for newly discovered Windows vulnerabilities.
- Known flaws accumulate. Attackers reverse-engineer patches for supported Windows versions and test them against unsupported ones.
- Software support erodes. Security suites, drivers, and apps drop Windows 10 over time.
- Compliance risk applies to businesses subject to PCI DSS, HIPAA, or cyber-insurance requirements.
If you must keep a Windows 10 machine running, reduce exposure: use a standard user account for daily work, keep the browser updated, disable unused services such as SMBv1 and Remote Desktop, enable the Windows Defender Firewall, back up offline, and keep the machine off sensitive networks.
Strategic FAQ
When does Windows 10 support end for home users?
Standard support ended on October 14, 2025. Consumer ESU extends security-only updates through October 13, 2026, and Microsoft has announced no further consumer extension.
Is Windows 10 ESU free?
It can be. Consumer enrollment is free if you sync your PC settings to a Microsoft account. The alternatives are 1,000 Microsoft Rewards points or a one-time purchase of about $30 that covers up to 10 devices on the same account. Businesses pay per device, starting at $61 in Year 1.
Can I still use Windows 10 after October 13, 2026?
Yes, the OS keeps running. Consumer devices stop receiving security updates after that date, which increases exposure to malware and exploits over time. Business devices enrolled in commercial ESU stay patched until their coverage year ends, up to October 2028.
Can I upgrade from Windows 10 to Windows 11 for free?
Yes, if the device meets the requirements, including TPM 2.0, UEFI Secure Boot, and a supported CPU. Go to Settings > Update & Security > Windows Update to see whether the upgrade is offered, or run the PC Health Check app.




