What actually changed in June — and who it left out
Windows 10 reached end of support on October 14, 2025. Microsoft's bridge for the machines that couldn't move was the Extended Security Updates program: security patches only, for a fee, for a limited time. On June 25, 2026, Microsoft changed the consumer half of that bridge without much ceremony, announcing that consumer ESU coverage "will now be available through October 12, 2027" to give customers "more time and flexibility to find the best PC for their needs while keeping them protected." Anyone already enrolled was extended automatically; new enrollment remains free for consumers who sync their PC settings to a Microsoft account, or available for 1,000 Microsoft Rewards points or a one-time fee of $30, covering up to ten devices.
The fine print is what matters to anyone who manages a fleet. The consumer program is not available to devices joined to Active Directory or Microsoft Entra, or managed through mobile device management. A domain-joined desktop or an Intune-enrolled laptop is a commercial device in Microsoft's eyes even if it is sitting in someone's home office. Those devices belong to the commercial ESU program — and the commercial program's dates did not move.
The enterprise clock: October 13, then double
Microsoft's published volume-licensing terms for commercial ESU are simple and unforgiving. Year one runs from November 2025 through October 13, 2026 at $61 per device. Year two runs through October 12, 2027 at $122 per device. Year three runs through October 10, 2028 at $244. The program is cumulative — an organization that decides to start in year two must also buy year one — so there is no discount for waiting. Per thousand devices, the three-year path totals roughly $427,000 in licensing alone, before the operational cost of keeping aging hardware in service. (ESU is included at no extra charge for Windows 10 running in Windows 365, Azure Virtual Desktop, and other Azure virtual environments, which is relevant to organizations that have already virtualized the desktop.)
The scale of the decision is not small. Reporting on the June extension cited StatCounter data putting roughly one in four Windows users still on Windows 10. Enterprise fleets skew toward the managed end of that population, and the organizations with the largest remaining Windows 10 footprints are, almost by definition, the ones with the most hardware that could not take the Windows 11 upgrade in the first place.
Three paths for every device — and one of them is disposition
Every managed Windows 10 device resolves to one of three outcomes, and the sorting can be done from inventory data today.
Path one: upgrade in place
Devices that meet Windows 11's requirements — a supported processor and TPM 2.0, requirements Microsoft has publicly described as non-negotiable for current and future Windows versions — take the free upgrade. This is a project-management problem, not a hardware problem, and it has no disposition component beyond the usual attrition.
Path two: ESU as a bridge
Devices that can't upgrade but must stay in service — because they run a line-of-business application, drive a piece of equipment, or simply can't be replaced before a budget cycle — buy time with commercial ESU. The doubling price schedule is Microsoft's way of making sure "bridge" doesn't quietly become "destination." Year two is a defensible purchase; year three, at four times the year-one rate, is an expensive way to avoid a decision.
Path three: retire
Everything else — ineligible for Windows 11, not worth $122 a year to keep patched — is a retirement. This is the cohort that matters for this industry, and it has a property the other two paths lack: it is fixed in size and knowable in advance. The TPM and processor tests don't change. Whatever fraction of the fleet fails them today will fail them in October. That makes the Windows 10 retirement a schedulable disposition event, which is a rare gift in a discipline that usually runs on surprises.
Why this retirement wave is different
Enterprises retire hardware constantly. Three things make the Windows 10 cohort different from ordinary attrition, and all three argue for moving early rather than late.
It is compressed. The decision date is shared by every organization on the same calendar, so a lot of similar equipment tends to reach the secondary market in the same window. The used-equipment market behaves like any other market when supply arrives all at once: resale values for the affected generations come under pressure. Equipment retired ahead of the crowd generally recovers more than equipment retired with it. (Our brief on what used IT equipment is actually worth covers the value curve.)
It is data-bearing and unsupported. A retired Windows 10 laptop that sits in a storeroom is a device holding corporate data that will never receive another security patch. The longer the interval between "removed from service" and "certified destroyed," the longer that exposure lasts — and storerooms are where disposition breaches come from. The Windows 10 closet is not a holding pattern; it is a liability with a shelf.
It is coupled to a deployment. Unlike attrition, this retirement happens because new equipment is arriving. That coupling is the opportunity: the replacement deployment is a logistics event already, and the old hardware can ride the same truck out that the new hardware rode in on.
Plan the disposition inside the refresh, not after it
The organizations that will handle this well are the ones that treat the refresh and the retirement as one project with two directions of flow. Concretely, that looks like a short list.
- Pull the ineligible list now. Your inventory or endpoint-management tool can already tell you which devices fail the Windows 11 checks. That list is your disposition scope, and its size determines everything downstream: budget, timing, vendor capacity.
- Make the ESU decision per device class, not per fleet. A year of ESU for the fifty machines running the plant floor application is prudent; a year of ESU for eight hundred general-purpose laptops that are being replaced anyway is a bill you can skip by sequencing the refresh.
- Sequence retirement ahead of the market where you can. Devices that can leave before the shared deadline should. Value recovery and security exposure both improve with every week the cohort spends in a certified chain instead of a closet.
- Pair every deployment with a takeback. When new devices are installed on site, the old ones leave on the same visit — the model behind technology staging & deployment. For remote employees, the new device ships with a mail-back kit so the old one comes back in the same box.
- Destroy data before anything else happens. Every retiring device is data-bearing. Certified sanitization or destruction with a serialized certificate per device — per NIST 800-88 — is the record that closes the security exposure and the compliance question at once.
- Let value recovery fund the program. Ineligible for Windows 11 does not mean worthless; Windows 11 is a Microsoft requirement, not a hardware failure. Sanitized devices have legitimate reuse markets, and the remainder has recoverable materials. A certified ITAD partner routes each device to the right one.
None of this is exotic. It is the standard discipline of a good disposition program applied to a cohort that, for once, announced its own retirement date. The consumer extension bought individual users a year. Managed fleets don't get the year; they get eight weeks to plan, and a decision schedule that punishes delay. The organizations that read the June announcement as a reprieve will be the ones paying year-two rates for hardware they meant to retire — and storing the rest.
Windows 10 ESU & disposition FAQ
Did Microsoft extend Windows 10 support to 2027?
For consumers, yes. On June 25, 2026 Microsoft extended the consumer Extended Security Updates program from October 13, 2026 to October 12, 2027, automatically for anyone already enrolled, and consumer enrollment remains free via Windows Backup settings sync, 1,000 Microsoft Rewards points, or a one-time $30 fee. The extension does not apply to devices joined to Active Directory or Microsoft Entra or managed through mobile device management. Those devices fall under the commercial ESU program, whose dates and pricing did not change.
What does commercial Windows 10 ESU cost, and when does year one end?
Per Microsoft's published volume-licensing terms, commercial ESU is $61 per device for year one, doubling to $122 for year two and $244 for year three. Year one runs from November 2025 through October 13, 2026; year two through October 12, 2027; year three through October 10, 2028. The program is cumulative: an organization that starts in year two must also pay for year one. ESU is available at no additional cost for Windows 10 running in Windows 365, Azure Virtual Desktop, and other Azure virtual environments.
Which Windows 10 devices can't be upgraded to Windows 11?
Windows 11 requires TPM 2.0 and a processor on Microsoft's supported list, requirements Microsoft has publicly described as non-negotiable for current and future Windows versions. Devices that fail either test cannot take the in-place upgrade through supported channels. In most enterprise fleets that cohort is fixed and identifiable from inventory data today, which is what makes it a plannable disposition event rather than a surprise.
Is it safe to keep using Windows 10 devices without ESU?
Unsupported devices stop receiving security fixes, so every new vulnerability disclosed after their coverage ends stays open. For managed fleets that also creates compliance exposure under frameworks that require supported, patched systems, and the devices still hold data. If a device is neither upgradeable nor enrolled in ESU, the defensible path is to retire it through certified data destruction rather than let it age in service or in a storeroom.
How should we plan disposition around the Windows 10 refresh?
Treat the ineligible cohort as a scheduled retirement, not leftover inventory. Pull the list from your inventory tool, decide the ESU-versus-retire question per device class, and tie the retirement to the deployment of replacements so old equipment leaves on the same visit new equipment arrives. For remote staff, pair the new device shipment with a mail-back kit for the old one. Retire earlier rather than later where you can, since compressed retirement waves tend to pressure resale values, and keep serialized destruction certificates for every data-bearing device.
NEW FLEET IN, OLD FLEET OUT
Retire the ineligible cohort on the same visit the replacements arrive
CyberCrunch stages and deploys your new equipment and takes the Windows 10 hardware away on the same trip — certified data destruction, serialized certificates, value recovery on what has a second life, and documented recycling for the rest. One vendor, one chain of custody, no closet.
Dates, pricing, and eligibility rules in this article reflect Microsoft's published Windows 10 ESU documentation and Microsoft's June 25, 2026 consumer-ESU announcement as reported at publication (August 19, 2026); Microsoft can change program terms, and pricing shown is Microsoft's published U.S. volume-licensing list pricing, not a quotation. Market-share context is from StatCounter as cited in trade reporting. This is general information about a vendor's product lifecycle and about disposition planning, not legal, licensing, or security advice for your environment; confirm current terms with Microsoft or your licensing partner.