WorkspaceDNA Blog | Expert Insights on Application Lifecycle & Workspace Automation

Blog | Windows 10 ESU Costs Double. We Have Your Exit Plan.

Written by Misty Scott | 09/28/2026

If you're still running Windows 10, your security updates get twice as expensive in about two weeks.

Year 1 of Extended Security Updates cost $61 a device. Year 2 starts October 14 and costs $122. Year 3 is $244. Same updates, same laptops. Double the bill, then double it again.

And here's the part nobody says out loud: most teams aren't stuck on Windows 10 because Windows 11 is hard. They're stuck because nobody has proven the apps work. So nobody wants to go first.

What staying actually costs

Here's Microsoft's commercial ESU pricing, run against a 1,000-device estate (Microsoft Learn).

ESU yearPer device1,000 devicesRunning total
Year 1 (Oct 2025 to Oct 2026)$61$61,000$61,000
Year 2 (starts Oct 14, 2026)$122$122,000$183,000
Year 3 (final year)$244$244,000$427,000

Two numbers matter more than the total.

$366. That's what every device you move before renewal saves you across Years 2 and 3. Move 250 of those 1,000 devices and you've avoided $91,500.

$183. If you skipped Year 1, you don't get to skip paying for it. ESU is cumulative, so buying Year 2 now means paying for both years.

One more thing: ESU is security updates only. No new features, no general support, and devices have to be on Windows 10 22H2.

The upgrade isn't the hard part

Intune can push a Windows 11 feature update to a group in an afternoon. That's not what's holding you up.

What holds you up is the question nobody can answer with a straight face. Does the label printer app still work? The finance add-in? The thing the warehouse runs that nobody remembers buying?

If you're a team of four, running Intune and patching third-party apps by hand, you don't have a project team for this. You have maybe one week of real attention. Honestly, that's enough, as long as you spend it in the right order.

The 7-day plan

Each day is a few hours, and every step fits in under two. By Day 7 your first Windows 11 group is live and you have a plan for everything else.

Day 1: Know your exposure

Pull every Windows 10 device from Intune, plus anything Intune doesn't see. Take out devices that may already be covered: Windows 10 VMs in Windows 365 or Azure Virtual Desktop, and endpoints connecting to Windows 365 Cloud PCs. Multiply what's left by $122. Done: one sentence you can say out loud. "We have X devices, Y need ESU, and Year 2 costs $Z."

Day 2: Check readiness

Run the Windows 11 readiness view in Intune's Endpoint analytics and tag every device Eligible, Fixable or Replace. Then build one app list and put an owner on every row. The owner is whoever can say "yes, this works for my team". Usually that's not IT. Done: a device list in three buckets and an app list with owners.

Day 3: Pick your priority apps

Score each app on reach (how many devices have it) and impact (does work stop without it). Take the top 10 to 20. For each one, write the 3 to 5 steps that prove it works. "Log in, open an order, print a label." Not "it launches." Done: a ranked shortlist with a workflow for each app.

Day 4: Validate your priority apps

Stand up two or three Windows 11 test devices with your real Intune policies, then deploy the apps the way production will. Owners run their workflows while you capture screenshots or a recording. No evidence, no pass. Done: a verdict and evidence for every priority app.

Day 5: Clear blockers

Try the cheap fixes first: update to the vendor's current version, repackage, adjust the policy. Then re-run the workflow. Everything still failing gets one decision: fix, replace, isolate or retire. Done: zero apps without a decision and an owner.

Day 6: Build your first rollout group

Pick a few dozen users on eligible hardware whose apps all passed. Include IT and a few friendly power users, and leave out anyone on a hard deadline. Build the feature update policy, write the rollback plan and send the comms. Done: a group, a policy, a rollback plan and a heads-up in every inbox.

Day 7: Ship it

Deploy, then confirm every device landed with its apps and compliance intact. Run a 30-minute retro. Put Wave 2 on the calendar, and put anything that can't move before renewal on the ESU list, not the "we'll see" list. Done: first group live and leadership told.

Where the week usually breaks

Days 4 and 5 are where this plan stalls. Booking app owners, running the same workflow again after every fix, chasing screenshots: that's the part that turns a week into a quarter.

That's the gap we built ATP360 for. You hand it the workflow you wrote on Day 3, in plain English, a PDF or a video. It runs it on real endpoints in your Azure tenant, in pre-production only, and hands back evidence files. A human still makes the call. Manual certification takes 3 to 4 weeks. On a 13-stage build, ATP360 took 23 minutes.

The other thing eating your week is patching third-party apps by hand. WorkspaceDNA Essentials automates that patching and runs it natively through Intune, with no scripting. It also gives you the app inventory and version view you need on Day 2.

Take the whole week with you

The full plan is in the Windows 10 Exit Kit. It's free and runs 15 pages: every day's steps with who does them, tick-box checklists, the ESU cost table with a blank for your own numbers, an app priority worksheet, and a one-page summary to hand your boss on Day 7.

Get the Windows 10 Exit Kit →

P.S. Even if you never download a thing from us, do Day 1 this week. Knowing your number before October 14 is worth an hour of your time.