Windows 10 Is Past End of Support — What Denver Businesses Should Do Now
Windows 10 stopped getting security updates in October 2025. Here's how to inventory your fleet, decide what to upgrade or replace, and stop paying for stopgaps.
Windows 10 reached end of support on October 14, 2025. The machines didn't stop working. Nobody's screen went dark. That's exactly why so many small businesses still have a dozen Windows 10 PCs quietly running in the back office almost a year later.
Windows 10 end of support is a slow-motion problem, not a sudden one. Nothing breaks on day one. The risk compounds every month after.
Here's a practical plan for sorting it out — inventory first, decisions second, spending last.
What "End of Support" Actually Means
After October 14, 2025, Microsoft stopped providing four things for Windows 10:
- Security updates for newly discovered vulnerabilities
- Quality updates — the reliability and bug fixes that shipped every Patch Tuesday
- Feature updates
- Technical support
The operating system keeps running. It just stops getting fixed.
That matters because vulnerability disclosures don't stop. Every month, Microsoft publishes details of flaws it patched in Windows 11 — and attackers read those bulletins to work out what's still exploitable on the versions that no longer get patches. An unsupported OS doesn't decay gradually; it accumulates a public, growing list of known ways in.
If you want the broader context on how those openings get used, our guide to protecting your business from ransomware walks through what typically happens next.
Extended Security Updates: The Paid Stopgap
Microsoft offers a way to buy time. It's worth understanding precisely, because the consumer and business versions are not the same program.
Commercial ESU (for organizations) is documented on Microsoft Learn. The key terms:
- $61 USD per device for Year One, purchased through volume licensing
- The price doubles every consecutive year, for a maximum of three years
- It's cumulative — if you skip Year One and buy in Year Two, you pay for both
- Devices must be running Windows 10, version 22H2
- You get critical and important security updates only. No new features, no non-security fixes, and no technical support.
Consumer ESU is a different offer: free by syncing your PC settings, 1,000 Microsoft Rewards points, or a one-time $30 payment, with coverage running through October 12, 2027. But Microsoft explicitly excludes devices joined to an Active Directory domain or Microsoft Entra, or enrolled in an MDM solution. If a consumer-enrolled device later joins a domain or MDM, the enrollment is suspended.
Here's the uncomfortable implication for a lot of small businesses: if your work PCs qualify for consumer ESU, that means they aren't domain-joined or centrally managed. That's a second problem hiding behind the first one.
Either way, ESU is a bridge, not a destination. It buys planning time at an escalating price. Use it deliberately — for the four machines running the software your vendor hasn't updated yet, not for the whole office.
Why This Shows Up in Compliance and Insurance
Beyond the security math, unsupported operating systems create paperwork problems:
- Cyber insurance applications routinely ask whether you run unsupported software. Answering that question inaccurately is a bad position to be in at claim time.
- PCI DSS requires that systems handling cardholder data run supported, patched software. Unsupported endpoints are a finding.
- HIPAA's Security Rule requires a documented risk analysis. "We know these are unpatched and here's our compensating control" is a defensible answer; not knowing is not.
- Colorado's breach notification law (C.R.S. 6-1-716) requires notifying affected Colorado residents within 30 days of determining a breach occurred — one of the tightest windows in the country. The Colorado Attorney General's data privacy resources cover the details.
Step 1: Inventory Before You Buy Anything
You cannot plan a refresh you can't see. For every machine, capture:
- Make, model, and age
- CPU, RAM, and storage
- TPM version and Secure Boot state
- Windows edition and version (22H2 or older)
- Who uses it and what business-critical software runs on it
- Warranty status
That last column is the one people skip and the one that changes decisions. A five-year-old laptop used for email is a different problem from a five-year-old workstation running the only copy of your estimating software.
Step 2: Sort Every Machine Into One of Four Buckets
Bucket 1 — Upgrade in place. The device meets Windows 11 requirements: a 64-bit CPU on Microsoft's supported processor list, 4 GB RAM minimum (8 GB is the realistic floor, 16 GB if it's a daily driver), 64 GB storage, UEFI firmware with Secure Boot, and TPM 2.0.
One thing worth checking before you write a machine off: on a great many 2018–2020 business PCs, the TPM is physically present but disabled in firmware. That's a BIOS setting, not a purchase order. We've seen entire "unsupported" fleets turn out to be upgradeable after someone actually looked.
Bucket 2 — Replace. The CPU isn't on the supported list, or there's no TPM 2.0 at all. Spread these purchases across quarters rather than absorbing them in one hit.
Bucket 3 — Retire or repurpose. Machines nobody uses, or that only exist to run one utility that now lives in a browser.
Bucket 4 — Special cases. The lab instrument, the imaging system, the CNC controller, the line-of-business app whose vendor certified it against Windows 10 and hasn't moved. These are the legitimate ESU candidates. Pair ESU with network isolation — put them on their own VLAN with tight firewall rules so an unpatched endpoint can't become a path to everything else. That's a network design conversation, not just a licensing one.
Step 3: Sequence the Rollout
Do not upgrade the whole office on a Saturday.
- Pilot with 2–3 users who represent the real workload — including the person with the weirdest software.
- Test line-of-business applications against Windows 11 before the pilot, not during it. Call vendors and get support statements in writing.
- Check peripherals. Label printers, scanners, signature pads, and older multifunction copiers are where driver surprises live.
- Standardize the build. If you're touching every machine anyway, this is the moment to move to a managed deployment with consistent configuration, disk encryption, and MDM enrollment.
- Roll out in waves by department, with a rollback plan and a support window after each wave.
- Tell people what's changing. The Start menu moved. The right-click menu changed. Five minutes of communication prevents a week of tickets.
Step 4: Fix the Thing That Caused the Crunch
The reason this became an emergency is that most small businesses buy computers reactively — when one dies, or when someone new starts. Then a support deadline arrives and the whole fleet turns out to be the same age.
The fix is boring and it works:
- Adopt a 4–5 year refresh cycle and replace roughly a fifth to a quarter of the fleet every year
- Keep an asset register with purchase date, warranty end, and OS support end
- Put hardware in the operating budget as a recurring line, not a capital surprise
That's a core part of what an ongoing managed IT support relationship should be doing for you, and it's the difference between a planned expense and a scramble. We wrote more about that trade-off in how managed IT services save Denver companies time and money.
What About Office?
Worth checking at the same time: Office 2016 and Office 2019 also reached end of support on October 14, 2025. If you're running perpetual-license Office alongside Windows 10, you have two unsupported products on the same desktop. Microsoft 365 Apps running on Windows 10 devices continue to receive security updates through October 10, 2028, which gives you a little more room — but only on the app side, not the OS.
Frequently Asked Questions
Will our Windows 10 PCs stop working? No. They boot and run indefinitely. They simply never receive another security fix from Microsoft.
Can we just use the free consumer ESU at our business? Not if your devices are domain-joined, Entra-joined, or MDM-enrolled — Microsoft excludes them. Businesses need commercial ESU through volume licensing.
Is Windows 11 the only option? No. Depending on the role, Cloud PCs (Windows 365), Macs, or ChromeOS devices can be a better fit — especially for staff who live entirely in a browser and a few SaaS apps. That's worth an honest look during an IT consulting engagement rather than a default.
How long does a fleet migration take? For a 20–50 person office with reasonable inventory data, plan on a few weeks of waves rather than a single event. The unknown is always application compatibility, which is why testing comes first.
Get an Honest Read on Your Fleet
If you don't know how many Windows 10 machines you have — or whether they can take Windows 11 — that's the actual first problem, and it's a solvable one.
netkraft works with Denver-area small and mid-size businesses on exactly this: inventory the fleet, separate the upgradeable from the replaceable, isolate the machines that genuinely can't move yet, and build a refresh schedule that keeps this from happening again.
Contact netkraft for a straightforward hardware and OS assessment. If you'd like to know what that first conversation looks like, we wrote it up in what to expect from your first IT consultation.