Windows 11 Migration and Windows 10 ESU Transition
Windows 11 Migration and Windows 10 ESU Transition is a 4-week service, priced at $25 per device plus a $1,950 tenant fee, that moves your fleet off Windows 10: hardware compatibility assessment across every in-scope device, Intune-driven in-place upgrades to Windows 11 for the machines that can take it, Extended Security Updates (ESU) enrollment as a bridge for the ones that cannot yet, and a Windows 365 Cloud PC path for devices that will never qualify. Windows 10 support ended on October 14, 2025 — every month on unpatched Windows 10 is unmanaged risk, and Microsoft's ESU list price doubles each year. Hardware procurement is advice-only: we tell you which devices to replace, but we do not sell you the replacements.
What this engagement is
Microsoft ended Windows 10 support on October 14, 2025. Devices still on it receive no security updates unless they are enrolled in Extended Security Updates — and ESU is a deliberately expensive bridge, not a destination: Microsoft's published commercial list price starts at $61 per device for year one and doubles each subsequent year, with the commercial program ending in October 2028. If your organization is sitting on that long tail, the economics get worse every renewal. This service is the structured way off. We inventory the fleet and assess every device against the Windows 11 hardware requirements (TPM 2.0, UEFI Secure Boot, supported CPU, minimum memory and storage), then split it three ways. Devices that qualify get an Intune-driven in-place upgrade to Windows 11 — staged in rings, preserving applications, settings, and user data. Devices that cannot upgrade yet but must stay in service get enrolled in commercial ESU as a documented, time-boxed bridge, so you buy exactly the coverage you need and no more. Devices that will never qualify get a decision path: replacement hardware (we advise on specs and Autopilot-readiness; procurement itself is yours) or a Windows 365 Cloud PC, which turns the old machine into a viewer for a current, managed Windows 11 desktop — see our Windows 365 Cloud PC Implementation service for that route. A note on our catalog history: our Automatic and Manual In-Place Upgrade to Windows 10 services served organizations standardizing on Windows 10 in its day. That era is over — this is the successor engagement for 2026, and if you land on one of those pages today, this is almost certainly the service you actually need.
Success criteria
What you receive
How the work unfolds
Build the device inventory from Intune (or agreed tooling), assess each device against Windows 11 requirements, and produce the three-way disposition list with you: upgrade, ESU bridge, or replace/Cloud PC.
Fix configuration-level blockers, confirm application concerns, configure Intune feature-update policies, and upgrade a pilot ring. Review results before any broad wave.
Roll the in-place upgrade across the qualifying fleet in agreed rings, monitoring Intune update reporting and handling failures device-by-device.
Procure and activate commercial ESU for designated bridge devices, verify they are receiving security updates, and document the exit date for each — the point of ESU is leaving it on schedule.
Deliver the replacement advisory: specs and Autopilot-readiness guidance for new hardware (procurement is yours), or a scoped handoff into Windows 365 Cloud PC Implementation for users better served by a cloud desktop.
Validate fleet state in Intune reporting, hand over the exceptions log and ESU exit plan, and deliver the closeout report.
Prerequisites
Who does what
IT Partner
- Assess every in-scope device and produce the disposition list.
- Configure and run staged Intune-driven in-place upgrades to Windows 11.
- Enroll and activate ESU on designated bridge devices and verify update flow.
- Provide the replacement advisory and the Windows 365 routing recommendation for non-upgradable devices.
- Deliver validation, the exceptions log, the ESU exit plan, and the closeout report.
Your team
- Provide tenant access and confirm the in-scope device list.
- Approve the disposition list, ring schedule, and maintenance windows.
- Purchase replacement hardware if you choose that path (we advise; we do not procure).
- Approve ESU license purchases for bridge devices.
- Communicate the upgrade schedule to users and review deliverables in a timely manner.
What's not included
Limitations & technical notes
Frequently asked questions
What does the Windows 11 Migration and Windows 10 ESU Transition service include?
A per-device compatibility assessment of your Windows 10 fleet, Intune-driven in-place upgrades to Windows 11 for qualifying devices, commercial ESU enrollment as a documented bridge for devices that must stay on Windows 10 temporarily, a replacement or Windows 365 Cloud PC recommendation for devices that cannot upgrade at all, and a closeout report with an ESU exit plan. Pricing is $25 per in-scope device plus a $1,950 tenant fee, over a planned 4 weeks.
Windows 10 support already ended — how exposed are we right now?
Microsoft ended Windows 10 support on October 14, 2025. A Windows 10 device that is not enrolled in Extended Security Updates has received no security patches since then, while attackers keep working. That exposure is silent — everything still functions — which is exactly why unmanaged Windows 10 fleets persist. The assessment gives you a factual picture of the exposure within the first week.
What is ESU and why do you call it a bridge, not a destination?
Extended Security Updates is Microsoft's paid program that delivers security-only patches to Windows 10 after end of support — no new features, no non-security fixes, no general support. Microsoft's published commercial list price starts at $61 per device for the first year and doubles each subsequent year, and the commercial program runs only until October 2028. It is engineered to make staying more expensive every year, so we enroll only the devices that genuinely need time and write an exit date for each one.
Can we just use the consumer ESU program we read about?
No — the consumer program, which Microsoft extended for personal devices into 2027, is aimed at individuals and is not designed for company-managed fleets; commercial devices under management need the commercial ESU path. We handle commercial enrollment and activation as part of the service, and we confirm Microsoft's current pricing and eligibility rules before any purchase rather than relying on headlines.
Which devices can be upgraded to Windows 11?
Windows 11 requires TPM 2.0, UEFI with Secure Boot, a supported CPU, and minimum memory and storage. Some 'incompatible' devices are actually configuration problems — TPM or Secure Boot disabled in firmware on hardware that supports them — and we fix those rather than writing the device off. The assessment gives you a per-device verdict, not a fleet-level guess.
Will users lose applications or data during the upgrade?
An in-place upgrade preserves applications, settings, and user data by design, and we run it that way — staged in rings with a pilot first. We still require current backups or OneDrive/Known Folder Move as a rollback story, because a per-device failure rate above zero is a planning assumption, not a surprise.
How much disruption should users expect?
The upgrade itself runs through Intune during agreed maintenance windows, typically requiring one or more restarts per device. Users sign back in to the same applications and files on Windows 11. We schedule waves around your business calendar and handle failed devices individually through the exceptions log.
What happens to devices that cannot run Windows 11 at all?
You get two costed options per device: replacement hardware — we specify what to buy and prepare Autopilot enrollment readiness, but procurement is yours — or a Windows 365 Cloud PC, where the old device becomes a viewer for a managed cloud-hosted Windows 11 desktop. One detail worth knowing for the Cloud PC route: Microsoft has stated that Windows 10 endpoints accessing Windows 365 Enterprise Cloud PCs can be entitled to ESU at no additional Microsoft charge, subject to Microsoft's conditions — which can make that path cheaper than it first looks.
How does the pricing work?
The service is $25 per in-scope device plus a $1,950 tenant fee, fixed and quoted in writing before work begins — you pay after you approve delivery. The per-device fee covers assessment and disposition of every device in scope, whichever of the three paths it lands on. Microsoft's charges — ESU license fees, Windows 365 licensing if you choose that route — are separate and quoted transparently before purchase.
Do our devices need to be in Intune first?
The upgrade machinery in this service is Intune-driven, so yes — devices need to be enrolled or enrollable. If your fleet is not there yet, our Microsoft Intune Initial Setup for Windows Device Management service establishes management first, and the two engagements chain cleanly.
You still list In-Place Upgrade to Windows 10 services — which one do we need?
Those services moved organizations onto Windows 10 while it was the standardization target, and they remain in the catalog honestly rather than silently vanishing. If your problem in 2026 is being on Windows 10, this service — off Windows 10, onto Windows 11 or a managed bridge — is the one you need.
How long does the migration take?
The engagement is planned as 4 weeks: assessment and pilot in the first half, staged waves, ESU enrollment, and closeout in the second. Fleet size, maintenance-window availability, and how quickly disposition decisions get approved are the main variables; very large fleets get their own quoted schedule.
What do we hold at the end of the engagement?
A fleet where every device has a documented disposition: upgraded and reporting compliant in Intune, ESU-enrolled with a written exit date, or flagged for replacement/Cloud PC with a recommendation. Plus the exceptions log, the ESU exit plan, and a closeout report your leadership and your cyber-insurance questionnaire can both live with.