Windows 10 ESU Endpoints: How to Isolate the Machines You Can’t Patch

Windows 10 ESU doubles to ±€112 per device on 14 October 2026. The cost maths for a 200-device fleet, 5 device classes, and the agentless alternative.
Technician running diagnostics on an older industrial workstation on a production floor beside newer equipment

On 14 October 2026 the price of keeping a Windows 10 machine patched doubles: ESU Year 2 costs about €112 per device ($122 list), against roughly €56 ($61) in Year 1 — and joining late means paying both, around €168 up front. With roughly 30% of the world’s desktops still on Windows 10 and some 240 million PCs physically unable to run Windows 11, most organisations face the same three-way choice this autumn: upgrade what can move, pay ESU for what will move soon, and isolate what will never move. This is the decision framework, with the costs attached.

Key takeaways

  • The ESU clock compounds: ≈€56 (Year 1) → ≈€112 (Year 2, from 14 October 2026) → ≈€225 (Year 3), cumulative for late joiners, totalling roughly €393 per device over three years — and it ends permanently in October 2028.
  • ESU buys patches only: critical/important security fixes, no features, no bug fixes, no general support. Azure Virtual Desktop and Windows 365 Cloud PCs get ESU free; consumer licences are banned on domain-joined business machines.
  • The tail is structural, not lazy: 43% of audited enterprise devices fail Windows 11’s CPU baseline, 35% lack TPM 2.0 — and OT terminals, medical consoles and POS fleets can’t be touched without voiding certifications.
  • Regulators and insurers have converged: CISA calls EOL software its “Bad Practice #1”, NIS2/CyFun demand lifecycle governance or documented compensating controls, and insurers surcharge 15–30% or deny claims outright — one cited denial: €2.1 million.
  • The maths favours isolation for the permanent tail: over three years, a 200-device fleet costs ≈€78,600 on ESU, ≈€193,000 on hardware refresh, or roughly €50,600 under a compensating-controls stack — agentless, so warranties survive.

What ESU actually buys, and what it never will

Windows 10’s free support ended on 14 October 2025. Since then, only ESU enrolment (on version 22H2, with the prerequisite updates) delivers monthly patches — and only those rated critical or important by MSRC. No feature updates, no non-security bug fixes, no general technical support, per Microsoft’s ESU documentation. The pricing mechanics matter for this autumn’s decision:

Parameter Year 1 (Oct 2025–Oct 2026) Year 2 (from 14 Oct 2026) Year 3 (Oct 2027–Oct 2028)
List price per device ≈€56 ($61) ≈€112 ($122) ≈€225 ($244)
Cloud-managed (Intune/Autopatch, ~25% off) ≈€41 ≈€83 ≈€166
Late-joiner entry cost (cumulative rule) ≈€56 ≈€168 (Year 1 + Year 2) ≈€393 total
AVD / Windows 365 Cloud PCs €0 — included in the subscription

Euro figures converted from Microsoft’s USD list prices (≈€0.92 per dollar, August 2026) and rounded; local EUR pricing may differ — verify at purchase.

Three fine-print items: the ~€30 consumer ESU (ending October 2027) is explicitly ineligible for domain-joined, MDM-enrolled or kiosk-mode business machines; Windows 10 Enterprise LTSC 2021 runs its own calendar, with ESU purchasable from 1 September 2026 and support extendable to January 2030; and Microsoft 365 Apps keep receiving security fixes on Windows 10 until October 2028. The absolute end of the commercial programme is 10 October 2028 — ESU is a bridge with a far bank, not a destination.

How big is the tail — and why it isn’t going away

Statcounter puts Windows 10 at 29.83% of desktops worldwide in July 2026 (26.88% in Europe), a year after it still held 45.65%. The remainder is increasingly the immovable part: Canalys estimates 240 million functional PCs cannot meet Windows 11’s requirements (TPM 2.0, 8th-gen Intel/Ryzen 2000 CPU floors, Secure Boot), and Lansweeper’s audit of 30 million enterprise devices found 43% failing the CPU bar, 35% without workable TPM, and 99% of virtual workstations failing on unconfigured vTPM. Then come the machines where upgrading is forbidden rather than impossible: OT HMIs and SCADA terminals on 10–20-year hardware lifecycles where OS changes void OEM warranties and safety certifications, medical consoles where an OS swap changes the device’s SBOM and triggers regulatory re-evaluation under FDA 524B and EU MDR, and POS/kiosk fleets scattered across sites. Kaspersky ICS CERT counted 19.6% of industrial automation systems facing attack attempts in early 2026 — the population least able to patch is among the most attacked, the same problem profiled in securing the devices you cannot patch.

What happens to the unpatched?

History answers precisely: when WannaCry hit in May 2017, roughly 98% of infected endpoints ran Windows 7 — a patch existed two months earlier, but unsupported and unmanaged machines never got it, and a worm did the rest. Non-ESU Windows 10 machines now accumulate unpatched CVEs monthly across exactly the components attackers automate against: LSASS, RDP, kernel, network drivers. Endpoint security software does not close that gap — once a kernel-level exploit yields SYSTEM privileges, protections running on the machine itself can be disabled, which is why neither auditors nor insurers accept endpoint tooling as a substitute for patching. CISA’s language leaves little room: EOL software in service of critical functions is its “Bad Practice #1” — “especially egregious in technologies accessible from the Internet” — and its September 2025 advisory adds that the expanding attack surface “cannot be mitigated by conventional endpoint security solutions alone”. NCSC requires removing direct internet access and segmenting what must remain; the CCB requires an EOL inventory, an executive-signed risk acceptance and compensating controls under CyFun’s lifecycle-governance measures. Insurers translate the same position into money: 15–30% surcharges for declared EOL endpoints, exclusions where the breach vector is unsupported software, and documented denials including a €2.1 million ransomware claim.

The compensating-controls stack, control by control

For machines that will never move, the defensible posture is a layered isolation architecture — each control mapped to the frameworks auditors cite:

Control What it mitigates Agentless? Framework anchor
Micro-segmentation / VLAN quarantine Lateral movement, worm propagation Yes — network layer NIST SP 800-82r3, IEC 62443-3-3
No direct internet + SWG routing Drive-by downloads, C2 traffic Yes — enforced upstream CIS v8 7.5, CyFun
ZTNA per-app access (replacing flat VPN reach) Perimeter exposure, subnet scanning from/to the device Yes — brokered NIST SP 800-207
Agentless browser/app isolation Web exploits and browser zero-days on the legacy machine Yes — rendered upstream, pixels only NIST SP 800-53 SC-18, PCI DSS v4.0
Application whitelisting (WDAC/AppLocker) Unauthorised binary execution Built into Windows CIS 2.2, CISA mitigations
Virtual patching / IPS Network exploits against unpatched services (RDP/SMB/RPC) Yes — inline NIST SI-16, PCI DSS 6.3.3

The agentless column is the point. On OT, medical and kiosk hardware, installing software is exactly what you may not do — agents consume resources, destabilise certified applications and void warranties. Every control above except whitelisting is enforced from the network or an upstream gateway, leaving the endpoint untouched: the legacy machine loses its internet, its flat network reach and its direct exposure, while its web access — if it needs any — arrives as rendered pixels from an isolation gateway. The segmentation half of that design is covered in network segmentation in 2026; the admin-access half in jump servers vs ZTNA; the same pattern protects IP cameras and building systems under NIS2.

The 200-device maths

Three-year cost (200 devices) A: ESU route B: Hardware refresh C: Isolation stack
Year 1 ≈€11,200 ≈€193,000 (≈€830/PC + ≈€140 labour) ≈€23,000 (licence + setup)
Year 2 ≈€22,400 ≈€13,800
Year 3 ≈€44,900 ≈€13,800
Total / per device ≈€78,600 / ≈€393 ≈€193,000 / ≈€965 ≈€50,600 / ≈€253
Residual risk after year 3 Critical — ESU ends Oct 2028 Low Low/managed — no cliff
OT/medical warranty impact None High (voids certifications) None — agentless

The strategies are not rivals; they are lanes. Refresh is right for machines that can move and stay. ESU is right for machines leaving within a year or two. Isolation is right for the permanent tail — and it is the only lane without an October 2028 cliff at the end.

The decision framework: five device classes

  1. Upgradeable workstations (TPM 2.0, supported CPU): upgrade to Windows 11 in place. Native security baseline and automated patching.
  2. Deferred refresh fleet (replaceable, retiring within 6–12 months): ESU Year 2 as a bridge, plus SWG filtering and central monitoring.
  3. Non-upgradeable office endpoints (failed CPU/TPM, budget-delayed): compensating controls — ZTNA per-app access, agentless browser isolation, isolated VLAN.
  4. OT and industrial HMIs (OS change voids warranty): permanent isolation — micro-segmentation, application whitelisting, no direct web, brokered admin access.
  5. Regulated medical equipment (FDA/MDR oversight): quarantine posture — agentless app isolation, IPS virtual patching, isolated non-ePHI zones.

Classify the fleet once, before 14 October: every device sorted into class 1 or 3–5 by that date is a device that never pays the ≈€112 — or the retroactive ≈€168.

Isolate the tail, skip the cliff

The ESU program is honest about what it is: rented time, at doubling rates, with a hard 2028 stop. For the machines that can never move, the durable answer is the architecture — take away the flat network, the direct internet and the exposed services, and an unpatchable machine becomes a contained one, with a compliance file (inventory, signed risk acceptance, documented controls) that satisfies CyFun, NIS2 and the insurer’s questionnaire. That architecture is exactly what Jimber delivers agentlessly for EU mid-market fleets: network isolation and per-app ZTNA from the infrastructure side, browser and application isolation rendered upstream with nothing installed on the legacy device, one EU-sovereign platform at a flat cost — well under the ESU line, without the cliff. Book a demo before the October renewal and bring your device inventory; classifying it is the first hour of the conversation.

Frequently asked questions

Can we buy ESU Year 2 without having paid Year 1?

Yes, but cumulatively: joining from 14 October 2026 requires paying Year 1 retroactively — about €168 per device instead of €112.

What does ESU actually cover?

Only security updates rated critical or important by MSRC, on Windows 10 22H2 with the prerequisite packages. No feature updates, no non-security fixes, no general support — and everything ends permanently on 10 October 2028.

Does endpoint security software satisfy NIS2 or our insurer on unpatched Windows 10?

No. Auditors and underwriters treat endpoint tooling as visibility, not as a patching substitute — kernel exploits can disable protections running on the machine itself. Compliance requires supported software or documented compensating isolation controls with an executive-signed risk acceptance.

Can we use the cheap consumer ESU for business machines?

No. Microsoft’s terms exclude domain-joined, MDM-enrolled and commercial kiosk devices from the consumer programme, which also ends earlier (October 2027).

Why is agentless isolation preferred for OT and medical devices?

Because installing agents on certified equipment is typically prohibited: it consumes resources, destabilises validated applications and voids OEM warranties and safety or regulatory certifications. Agentless controls enforce isolation from the network and gateway side, leaving the endpoint untouched.

How does ZTNA protect an unpatched machine better than a VPN?

A VPN puts the device on an internal subnet where its unpatched services are reachable — and where its compromise spreads. ZTNA brokers per-application connections in both directions: the legacy machine reaches only what it must, and nothing can scan or reach it laterally.

Does virtual patching remove the need for OS updates?

No. IPS-based virtual patching blocks network-borne exploits against known flaws, but not local vectors like USB malware or privilege-escalation binaries. It works as one layer of the stack, combined with whitelisting and segmentation.

What happens after ESU ends in October 2028?

Commercial Windows 10 patching stops permanently (LTSC 2021 runs to January 2030 on its own ESU). Machines still present then are permanent-tail devices by definition — which is why building the isolation architecture now beats paying roughly €393 per device to defer the same decision.

Find out how we can protect your business

In our demo call we’ll show you how our technology works and how it can help you secure your data from cyber threats.

Cybersecurity
Are you an integrator or distributor?

Need an affordable cybersecurity solution for your customers?

We’d love to help you get your customers on board.

checkmark

White glove onboarding

checkmark

Team trainings

checkmark

Dedicated customer service rep

checkmark

Invoices for each client

checkmark

Security and Privacy guaranteed