# Windows 10 ESU After October 2026: Year 2 Options for IT

Source: https://srvscripts.com/guides/windows-10-esu-after-october-2026/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

**Short answer:** For organizations, Windows 10 ESU Year 1 coverage ends on October 13, 2026. To keep receiving security updates you must buy Year 2 (Microsoft prices commercial ESU at $61 per device for Year 1 and says the price doubles each year, so Year 2 is $122 per device, and buying Year 2 means paying for Year 1 too), then install the ESU key and activate it with the Year 2 activation ID. Year 2 runs to October 12, 2027 and Year 3 to October 10, 2028. Consumer ESU is different: Microsoft has extended it, and its consumer page now says enrolled home PCs stay covered through October 12, 2027 with no action needed.

Commands checked against the official documentation (linked below) on 6 October 2026; not yet run on our lab servers.

## The dates and prices that matter

Windows 10 reached end of support on October 14, 2025. Since then, only devices enrolled in Extended Security Updates (ESU) receive Critical and Important security updates. Microsoft’s ESU lifecycle table for Windows 10:

| ESU period | Coverage ends | Commercial price per device |
| --- | --- | --- |
| Year 1 | October 13, 2026 | $61 USD |
| Year 2 | October 12, 2027 | Doubles: $122 USD |
| Year 3 | October 10, 2028 | Doubles again: $244 USD |

Microsoft states the Year 1 price and that “the price doubles every consecutive year”; the Year 2 and 3 figures above are that rule applied, so confirm the exact quote with your licensing partner. ESU is bought by full year only, is cumulative (joining in Year 2 means also paying for Year 1), and has a minimum purchase of one license.

Who qualifies:

- **Commercial ESU**: Windows 10 Enterprise, Education, and Pro in commercial use, on version 22H2, through Microsoft Volume Licensing. Up to three years.

- **Consumer ESU**: home users, enrolled through Settings (free with Windows Backup settings sync, 1,000 Microsoft Rewards points, or a one-time $30 USD purchase), up to 10 devices per license. As of 6 October 2026 Microsoft’s consumer page says the program ends on October 12, 2027, that existing enrollments continue automatically through that date, and that you can still enroll until then. Terms vary by region, for example in the European Economic Area.

- **Free ESU in Microsoft cloud services**: Windows 10 VMs in Windows 365, Azure Virtual Desktop, Azure VMs, Azure Local and several other Azure-hosted services get ESU at no extra cost, and Windows 10 endpoints connecting to Windows 365 Cloud PCs are entitled to ESU with an active Windows 365 subscription.

- LTSB/LTSC editions are not part of ESU; they have their own lifecycle dates.

Business PCs must not rely on the consumer program. If a device is owned by your organization, commercial ESU (or Windows 11) is the supported route.

## Option 1: buy and activate ESU Year 2

If you are already on Year 1, check each device’s current ESU state from an elevated Command Prompt:

```
slmgr.vbs /dlv
```

Look for the ESU entry: the name shows which year (for example Win10 ESU Year1) and License Status: Licensed. Prerequisites from Microsoft for activation: Windows 10 22H2 with KB5066791 or later, and the ESU Licensing Preparation Package KB5072653 installed after it.

Once you have bought Year 2, a user with the Product Key Reader or VL Administrator role can find the ESU Multiple Activation Key (MAK) in the Microsoft 365 admin center under **Billing > Your Products > Volume licensing > View contracts > View product keys**. Then on each device, replacing the X placeholder with your ESU MAK:

```
slmgr.vbs /ipk XXXXX-XXXXX-XXXXX-XXXXX-XXXXX
slmgr.vbs /ato 1043add5-23b1-4afb-9a0f-64343c8f3f8d
slmgr.vbs /dlv
```

Activation IDs published by Microsoft (the same on every eligible edition):

| ESU year | Activation ID |
| --- | --- |
| Year 1 | f520e45e-7413-4a34-a497-d2765967d094 |
| Year 2 | 1043add5-23b1-4afb-9a0f-64343c8f3f8d |
| Year 3 | 83d49986-add3-41d7-ba33-87c7bfb5c0fb |

Devices need to reach Microsoft’s activation endpoints (listed in Microsoft’s ESU enablement article); for offline devices Microsoft documents phone activation. At scale, push the same three commands through Intune, Configuration Manager or your RMM tool and collect the `/dlv` output, or query it with PowerShell:

```
Get-CimInstance -ClassName SoftwareLicensingProduct -Filter "Name LIKE '%ESU%'" |
    Select-Object Name, ID, LicenseStatus
```

`LicenseStatus` 1 means licensed. Run it after activation to confirm the Year 2 entry shows as licensed before the Year 1 coverage ends.

## Option 2: upgrade eligible PCs to Windows 11

Every PC that can run Windows 11 is cheaper to upgrade than to keep on ESU. Windows 11 minimum requirements, from Microsoft:

- A compatible 64-bit processor, 1 GHz or faster, two or more cores.

- 4 GB RAM and 64 GB storage.

- UEFI firmware, Secure Boot capable, and TPM 2.0.

- DirectX 12 compatible graphics with a WDDM 2.0 driver, and a 720p display of 9″ or more.

- For a direct in-place upgrade: Windows 10 version 2004 or later with the September 14, 2021 security update or later.

Quick checks on one machine (elevated PowerShell):

```
Get-Tpm | Select-Object TpmPresent, TpmReady
Get-CimInstance -Namespace root/cimv2/security/microsofttpm -ClassName Win32_Tpm | Select-Object SpecVersion
Confirm-SecureBootUEFI
Get-CimInstance Win32_Processor | Select-Object Name, NumberOfCores
[math]::Round((Get-CimInstance Win32_ComputerSystem).TotalPhysicalMemory / 1GB, 1)
```

For a fleet, Microsoft publishes `HardwareReadiness.ps1` (download link `https://aka.ms/HWReadinessScript`). Run it through your management tool; it returns JSON with `returnResult` set to `CAPABLE` or `NOT CAPABLE` and a `returnReason` listing what failed. It is distributed under the MIT license and is not covered by Microsoft support.

Common fixes that turn a “not capable” result into “capable”: enabling the firmware TPM (Intel PTT or AMD fTPM) and Secure Boot in UEFI setup, and converting the system disk from MBR to GPT with `mbr2gpt` so the PC can boot in UEFI mode. Back up and suspend BitLocker before changing firmware boot settings.

To manage the upgrade itself, deploy the Windows 11 feature update through Intune feature update policies, Windows Update for Business or WSUS. Our [Windows 11 compatibility hold guide](/guides/windows-11-compatibility-hold/) covers safeguard holds that can block the offer, and [Windows Update Group Policy](/guides/windows-update-group-policy/) covers the targeting policies.

## Option 3: replace, virtualize or retire

- **Replace** hardware that fails the processor or TPM check and is close to its normal refresh date anyway; Year 2 and Year 3 ESU fees add up quickly per device.

- **Move users to Windows 365 or Azure Virtual Desktop**: the Cloud PC runs Windows 11, and Microsoft gives the old Windows 10 endpoint ESU entitlement while the Windows 365 subscription is active.

- **Isolate what must stay**: a machine that runs a legacy app or instrument controller and cannot upgrade should be on ESU, on a restricted VLAN, without email or web browsing.

## Decide device by device

| Device situation | Best option |
| --- | --- |
| Meets Windows 11 requirements | Upgrade now; do not buy Year 2 for it |
| Fails only because TPM/Secure Boot is off | Fix firmware settings, then upgrade |
| Old CPU, due for replacement within a year | Year 2 ESU as a bridge, then replace |
| Old CPU, runs a legacy app that needs Windows 10 | Year 2 ESU plus network isolation; plan the app replacement |
| Remote worker with a personal-grade PC | Replace, or Windows 365 Cloud PC |

## Check that it worked

- `slmgr.vbs /dlv` on ESU devices shows the Year 2 ESU entry as Licensed before October 13, 2026.

- Those devices install the November 2026 security update (check Windows Update history or your patch tool’s compliance report).

- Every remaining Windows 10 device in your inventory is either on Year 2 ESU or has a dated upgrade or replacement plan.

**Official documentation:** [Extended Security Updates program for Windows 10](https://learn.microsoft.com/en-us/windows/whats-new/extended-security-updates) · [Enable Windows 10 ESU (keys and activation IDs)](https://learn.microsoft.com/en-us/windows/whats-new/enable-extended-security-updates) · [Lifecycle FAQ: ESU dates](https://learn.microsoft.com/en-us/lifecycle/faq/extended-security-updates) · [Windows 10 Consumer ESU](https://www.microsoft.com/en-us/windows/extended-security-updates)

**Related:** [Windows 11 Compatibility Hold: Avoid 25H2 and 26H1 Upgrade Problems](/guides/windows-11-compatibility-hold/) · [Windows Update Group Policy: 7 Settings for Windows 11](/guides/windows-update-group-policy/) · [Intune Bulk Enrollment: Windows 11 Provisioning Package](/guides/intune-bulk-enrollment-provisioning-package/) · [WSUS Windows Server 2025: Reliable Install and Configuration](/guides/wsus-windows-server-2025/) · [A basic RMM monitoring policy for small-business endpoints: disk, patching and antivirus](/guides/rmm-monitoring-policy-endpoints/)

**See also:** [Windows Server 2025 Hotpatch: Azure Arc Setup and Baselines](/guides/windows-server-2025-hotpatch/)

## Frequently asked questions

### Does Windows 10 ESU end on October 13, 2026?

Year 1 of commercial ESU ends then. Organizations can buy Year 2 (to October 12, 2027) and Year 3 (to October 10, 2028). Microsoft’s consumer ESU page now says consumer coverage runs to October 12, 2027.

### Can a business use the $30 consumer ESU?

No. Commercial devices should use commercial ESU through Volume Licensing. The consumer program is for personal devices.

### How much is Windows 10 ESU Year 2 for businesses?

Microsoft lists $61 per device for Year 1 and says the price doubles every year, which makes Year 2 $122 per device. Year 1 must also be paid if you join late.

### Do I need a new key for Year 2?

You activate Year 2 with its own activation ID (1043add5-23b1-4afb-9a0f-64343c8f3f8d) after installing the ESU MAK from your Year 2 purchase, shown in the Microsoft 365 admin center.

### Will Windows 10 PCs stop working without ESU?

No. They keep running but get no security updates, which makes them a growing risk on any network.
