Windows 10 ESU or Replace? How to Decide, Device by Device

Windows 10 ESU or Replace? How to Decide, Device by Device

Join IT Pulse

Receive the latest news of the IT world once per week.

Windows 10 reached its end of support date in October 2025, and most fleets have already moved to Windows 11. What's left is a smaller, harder problem: devices that can't make the jump because of their hardware. For those machines, Windows 10 Extended Security Updates (ESU), often shortened to Windows 10 ESU, is the term that keeps coming up.

This piece covers the three real options for a device stuck on Windows 10: paying for ESU, replacing the hardware, or isolating it from the rest of the network. It also covers what usually stalls teams before they get that far: knowing how many devices are affected, and where, without opening a spreadsheet for every machine. Getting that count wrong means overspending on replacements or leaving unpatched devices exposed.

Why some devices can never move to Windows 11

Windows 11 hardware requirements go beyond simple performance minimums. A device needs all of the following:

  • A 64-bit processor with at least two cores running at 1 GHz or faster.
  • 4 GB of memory and 64 GB of storage.
  • Unified Extensible Firmware Interface (UEFI) firmware with Secure Boot enabled.
  • A Trusted Platform Module (TPM) version 2.0.
  • A graphics card compatible with DirectX 12.

None of these are settings a software update can turn on. A processor either has the required instruction set or it does not, and TPM 2.0 is either present on the motherboard or it is not. That is why a meaningful share of every Windows 10 fleet counts as unsupported hardware for Windows 11, more so in industries with older, specialized equipment such as retail point-of-sale systems and logistics scanners.

Extended Security Updates: cost, coverage and expiry

Windows 10 Extended Security Updates give an enrolled device continued access to critical and important security patches after end of support, excluding new features, general technical support, and non-security fixes. Enrollment requires Windows 10, version 22H2, now the only supported build. For organizations, standard pricing follows a fixed yearly escalation, with a discount available through Microsoft Intune or Autopatch:

  • Year one: $61 per device.
  • Year two: $122 per device.
  • Year three: $244 per device, for a cumulative total around $427 if enrolled from the start.

Skipping a year does not lower that total, since Microsoft charges for skipped years before selling the current one. Coverage runs through October 2028 at the latest, three years after Windows 10 reached end of support, and the program ends entirely once that window closes.

Replace, isolate or pay: how to choose per device

Once a device is confirmed incompatible with Windows 11, there are three ways to keep it from becoming a security liability:

  • Enroll it in Extended Security Updates as a temporary bridge.
  • Replace it with Windows 11 compatible hardware.
  • Isolate it from the parts of the network where a breach would matter most, such as shared drives or sensitive systems.

The choice usually comes down to criticality, exposure, and remaining useful life. A point-of-sale terminal on its own network segment, with no direct internet access, scores low on exposure and is often a reasonable isolation candidate, while a laptop that travels and joins public networks does not and needs a replacement or an Extended Security Updates license instead. Cost settles most of the remaining cases: a year of coverage tends to beat an early replacement for a device close to its planned refresh date, while a device already overdue for refresh is usually cheaper to replace outright.

How to find which devices are affected without checking one by one

windows-10-screenshot-invgate-asset-management

Running those comparisons assumes IT already knows which bucket each device falls into, and checking machine by machine does not scale past a handful of devices. IT Asset Management software like InvGate Asset Management builds that inventory automatically, pulling processor, memory, storage and firmware details from every device on the network. It also tracks non-connected assets, so hardware sitting in a storage room stays in the count.

For the Windows 11 decision specifically, that inventory can be filtered by operating system and hardware attributes into three groups: compatible, needs Extended Security Updates or replacement, and already on Windows 11. InvGate Asset Management's Smart Tags apply that grouping automatically and keep it current as new scans come in, and a dashboard turns the three counts into something easy to share with finance or leadership.

Here is what that looks like in practice for a Windows 10 fleet approaching its Extended Security Updates deadline:

  • Automated hardware and operating system discovery: pulls processor, memory, storage, firmware and Windows version from every device, no manual audit needed.
  • Smart Tags for Windows 11 readiness: sorts devices into compatible, needs ESU, or needs replacement, and keeps the groups current.
  • Dashboards for leadership and finance: turns the three counts into a report for the replacement or ESU budget conversation.
  • Non-connected asset tracking: keeps devices in storage rooms or with remote employees in the count.
  • Alerts for devices left behind: flags any device that stays unpatched and unenrolled once support ends.

Start a 30-day free trial to see this in action, or talk to Sales for a walkthrough tailored to your fleet.

How to set this up in InvGate Asset Management

The general shape of this workflow matches what InvGate customers already use for any Windows 10 to 11 transition, adjusted for the three-way decision this article covers:

  1. Identify every device running Windows 10. Filter the inventory by operating system to get a baseline count of what is affected.

  2. Tag devices by hardware compatibility. One Smart Tag for devices that meet Windows 11 hardware requirements, one for devices that do not, built from the processor, memory, and storage data already in the inventory. Microsoft's minimums work as the baseline condition for this tag, and the filter can be tightened to a stricter bar, such as 4 or more cores and 16 GB of memory, for teams that want to flag devices that are technically eligible but likely to run Windows 11 poorly.

  3. Build a dashboard on top of those tags. A single view showing how many devices are compatible, how many need Extended Security Updates or replacement, and how many are already on Windows 11.

  4. Split the "not eligible" group further. Layer criticality and network exposure onto the same tag logic to sort those devices into replace, isolate, or cover with Extended Security Updates.

  5. Set reminders ahead of each Extended Security Updates renewal. An automation tied to the enrollment date flags devices before the price doubles, so the call to keep paying, replace, or isolate gets made on purpose and on time.

Planning the replacement budget

Once devices are grouped into compatible, needs ESU, and needs replacement, the replacement group drives the budget conversation. Multiplying that count by an average replacement cost for the hardware class gives a starting number, and comparing it against one or more years of Extended Security Updates shows which devices are worth covering instead of replacing right away.

Phasing the rollout by risk keeps the ask from landing all at once. Devices with the highest exposure or least remaining life should move first, while lower-risk devices run on Extended Security Updates for a year as their replacement budget gets approved. Folding this into a broader hardware lifecycle plan also helps avoid the same scramble the next time an operating system reaches end of support.

Conclusion

Windows 10 ESU works as a temporary bridge for devices that cannot move to Windows 11 yet, buying time to replace them, isolate them, or take on the cost of coverage on purpose rather than by default. The right call differs per device, depending on exposure, remaining useful life, and how the numbers compare once group sizes are known.

Reaching those group sizes without a manual, device-by-device audit turns this from a guessing exercise into a plan with real numbers behind it. Once IT knows how many devices need Extended Security Updates, how many need replacing, and how many can be isolated, the budget and the timeline both get easier to build.

FAQs

What is Windows 10 ESU?

Windows 10 ESU, short for Extended Security Updates, is a paid Microsoft program that keeps delivering critical and important security patches to Windows 10 devices after end of support. It excludes new features and general technical support, covering only security fixes for devices on Windows 10, version 22H2.

How much does Windows 10 ESU cost?

For organizations, pricing starts at $61 per device in year one and doubles each year after, reaching $244 by year three. Enrolling late still requires paying for the years that were skipped, so the total ends up the same regardless of when a business joins.

Can I still enroll a device in Extended Security Updates after the first year has passed?

Yes, but Microsoft requires paying for the skipped years first. That makes enrolling from year one the cheaper option for any device a business already plans to keep on Windows 10 for the full three years.

What happens to a Windows 10 device that gets neither ESU nor a replacement?

It keeps running without security patches, exposed to any vulnerability discovered after end of support. On a networked device, that risk usually extends to whatever systems it can reach.

How do I know which of my devices cannot run Windows 11?

Checking the processor, Trusted Platform Module version, and firmware settings works for a single device, but confirming this across a whole fleet needs an inventory that already records those attributes. Asset Management software that scans the network and tags devices by hardware profile turns that check into a filtered list instead of a manual walk-through.

Simplify your IT ecosystem with InvGate Asset Management

30-day free trial - No credit card needed

Clear pricing

No surprises, no hidden fees — just clear, upfront pricing that fits your needs.

View Pricing

Easy migration

Our team ensures your transition to InvGate is fast, smooth, and hassle-free.

View Customer Experience