First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Windows 11 Migration and Windows 10 ESU Transition
Migration

Windows 11 Migration and Windows 10 ESU Transition

Windows 11 Migration and Windows 10 ESU Transition is a 4-week service, priced at $25 per device plus a $1,950 tenant fee, that moves your fleet off Windows 10: hardware compatibility assessment across every in-scope device, Intune-driven in-place upgrades to Windows 11 for the machines that can take it, Extended Security Updates (ESU) enrollment as a bridge for the ones that cannot yet, and a Windows 365 Cloud PC path for devices that will never qualify. Windows 10 support ended on October 14, 2025 — every month on unpatched Windows 10 is unmanaged risk, and Microsoft's ESU list price doubles each year. Hardware procurement is advice-only: we tell you which devices to replace, but we do not sell you the replacements.

Timeline 4 weeksService owner Roman SotnikWindows 11Microsoft IntuneMicrosoft 365

What this engagement is

Microsoft ended Windows 10 support on October 14, 2025. Devices still on it receive no security updates unless they are enrolled in Extended Security Updates — and ESU is a deliberately expensive bridge, not a destination: Microsoft's published commercial list price starts at $61 per device for year one and doubles each subsequent year, with the commercial program ending in October 2028. If your organization is sitting on that long tail, the economics get worse every renewal. This service is the structured way off. We inventory the fleet and assess every device against the Windows 11 hardware requirements (TPM 2.0, UEFI Secure Boot, supported CPU, minimum memory and storage), then split it three ways. Devices that qualify get an Intune-driven in-place upgrade to Windows 11 — staged in rings, preserving applications, settings, and user data. Devices that cannot upgrade yet but must stay in service get enrolled in commercial ESU as a documented, time-boxed bridge, so you buy exactly the coverage you need and no more. Devices that will never qualify get a decision path: replacement hardware (we advise on specs and Autopilot-readiness; procurement itself is yours) or a Windows 365 Cloud PC, which turns the old machine into a viewer for a current, managed Windows 11 desktop — see our Windows 365 Cloud PC Implementation service for that route. A note on our catalog history: our Automatic and Manual In-Place Upgrade to Windows 10 services served organizations standardizing on Windows 10 in its day. That era is over — this is the successor engagement for 2026, and if you land on one of those pages today, this is almost certainly the service you actually need.

Success criteria

01Every in-scope device has a documented disposition: upgraded to Windows 11, enrolled in ESU with an exit date, or flagged for replacement/Cloud PC with a recommendation.
02Devices that passed assessment are running Windows 11 with applications, settings, and user data intact.
03Upgrade rings completed without unresolved widescale failures; individual device issues are logged with a remediation path.
04ESU-enrolled devices are receiving security updates, and you hold a costed plan for retiring them before the next ESU price step.
05Your administrators can see fleet-wide Windows version and update compliance in Intune reporting.

What you receive

Fleet inventory and per-device Windows 11 compatibility assessment (TPM 2.0, UEFI Secure Boot, CPU support, memory, storage), with a disposition list: upgrade, ESU bridge, or replace/Cloud PC.
Upgrade-readiness fixes where configuration (not hardware) is the blocker — for example enabling TPM/Secure Boot settings where the platform supports them.
Intune feature-update and update-ring policies configured to deliver Windows 11 in staged rings, pilot first.
In-place upgrades executed across the qualifying fleet, preserving applications, settings, and user data.
Commercial ESU enrollment and activation for the devices you designate as bridge devices, with license procurement handled through your agreement or our CSP relationship (Microsoft's ESU fees are separate from our service fee).
Replacement advisory for non-upgradable devices: recommended specifications, Autopilot enrollment readiness, and the Windows 365 Cloud PC alternative, costed as options for your decision.
Post-migration validation, an exceptions log with remediation paths, and a closeout report including the ESU exit plan.

How the work unfolds

1. Inventory and compatibility assessment

Build the device inventory from Intune (or agreed tooling), assess each device against Windows 11 requirements, and produce the three-way disposition list with you: upgrade, ESU bridge, or replace/Cloud PC.

2. Readiness and pilot ring

Fix configuration-level blockers, confirm application concerns, configure Intune feature-update policies, and upgrade a pilot ring. Review results before any broad wave.

3. Staged upgrade waves

Roll the in-place upgrade across the qualifying fleet in agreed rings, monitoring Intune update reporting and handling failures device-by-device.

4. ESU bridge enrollment

Procure and activate commercial ESU for designated bridge devices, verify they are receiving security updates, and document the exit date for each — the point of ESU is leaving it on schedule.

5. Non-upgradable device routing

Deliver the replacement advisory: specs and Autopilot-readiness guidance for new hardware (procurement is yours), or a scoped handoff into Windows 365 Cloud PC Implementation for users better served by a cloud desktop.

6. Validation and closeout

Validate fleet state in Intune reporting, hand over the exceptions log and ESU exit plan, and deliver the closeout report.

Prerequisites

Administrative access to your Microsoft 365 tenant (we request granular, time-bound GDAP access that you approve — never standing global admin).
In-scope Windows 10 devices enrolled in Microsoft Intune, or an agreed management path — if the fleet is not yet in Intune, our Microsoft Intune Initial Setup for Windows Device Management service establishes it first.
Windows licensing in order: the Windows 11 upgrade itself is available at no additional Microsoft charge for eligible, licensed Windows 10 devices; ESU licenses for bridge devices are a separate Microsoft cost.
A named point of contact, maintenance windows for upgrade waves, and pilot users for the first ring.
Current backups or OneDrive/Known Folder Move in place for user data; in-place upgrades preserve data by design, but we do not run upgrade waves without a rollback story.

Who does what

IT Partner

  • Assess every in-scope device and produce the disposition list.
  • Configure and run staged Intune-driven in-place upgrades to Windows 11.
  • Enroll and activate ESU on designated bridge devices and verify update flow.
  • Provide the replacement advisory and the Windows 365 routing recommendation for non-upgradable devices.
  • Deliver validation, the exceptions log, the ESU exit plan, and the closeout report.

Your team

  • Provide tenant access and confirm the in-scope device list.
  • Approve the disposition list, ring schedule, and maintenance windows.
  • Purchase replacement hardware if you choose that path (we advise; we do not procure).
  • Approve ESU license purchases for bridge devices.
  • Communicate the upgrade schedule to users and review deliverables in a timely manner.

What's not included

Hardware procurement, staging, or disposal — we provide specifications and Autopilot-readiness advice only; you buy through your preferred channel.
Microsoft license costs: ESU per-device fees and any Windows 365 or Microsoft 365 licensing are billed by Microsoft or through your CSP agreement, separate from our service fee.
Application remediation, repackaging, or vendor-compatibility work beyond identifying the affected devices and applications during assessment.
Windows 365 Cloud PC deployment itself — routed devices hand off into our Windows 365 Cloud PC Implementation service as a separate engagement.
Migration between management platforms (for example domain-joined to Entra ID) — that is our Device Migration Automation for Windows service.
Ongoing patch and fleet management after closeout — available separately as Device as a Service.

Limitations & technical notes

!ESU delivers security updates only: no new features, no non-security fixes, and no general Microsoft support. We position it strictly as a bridge with a written exit date per device.
!Microsoft's ESU pricing and program dates are Microsoft's to change; figures on this page reflect Microsoft's published commercial pricing at the time of writing, and we confirm current numbers before any purchase. The consumer ESU program (extended for personal devices into 2027) is not designed for company-managed fleets and we do not build business transitions on it.
!In-place upgrades preserve applications and data by design, but individual devices can fail for device-specific reasons; that is what the pilot ring, staged waves, and exceptions log are for.
!The $25 per-device fee applies to each in-scope device we assess and disposition; devices added mid-engagement extend the count and the quote in writing before we touch them.
!The 4-week duration assumes timely access, agreed maintenance windows, and a fleet already manageable through Intune; very large fleets or constrained change windows are quoted on their own schedule.

Frequently asked questions

What does the Windows 11 Migration and Windows 10 ESU Transition service include?

A per-device compatibility assessment of your Windows 10 fleet, Intune-driven in-place upgrades to Windows 11 for qualifying devices, commercial ESU enrollment as a documented bridge for devices that must stay on Windows 10 temporarily, a replacement or Windows 365 Cloud PC recommendation for devices that cannot upgrade at all, and a closeout report with an ESU exit plan. Pricing is $25 per in-scope device plus a $1,950 tenant fee, over a planned 4 weeks.

Windows 10 support already ended — how exposed are we right now?

Microsoft ended Windows 10 support on October 14, 2025. A Windows 10 device that is not enrolled in Extended Security Updates has received no security patches since then, while attackers keep working. That exposure is silent — everything still functions — which is exactly why unmanaged Windows 10 fleets persist. The assessment gives you a factual picture of the exposure within the first week.

What is ESU and why do you call it a bridge, not a destination?

Extended Security Updates is Microsoft's paid program that delivers security-only patches to Windows 10 after end of support — no new features, no non-security fixes, no general support. Microsoft's published commercial list price starts at $61 per device for the first year and doubles each subsequent year, and the commercial program runs only until October 2028. It is engineered to make staying more expensive every year, so we enroll only the devices that genuinely need time and write an exit date for each one.

Can we just use the consumer ESU program we read about?

No — the consumer program, which Microsoft extended for personal devices into 2027, is aimed at individuals and is not designed for company-managed fleets; commercial devices under management need the commercial ESU path. We handle commercial enrollment and activation as part of the service, and we confirm Microsoft's current pricing and eligibility rules before any purchase rather than relying on headlines.

Which devices can be upgraded to Windows 11?

Windows 11 requires TPM 2.0, UEFI with Secure Boot, a supported CPU, and minimum memory and storage. Some 'incompatible' devices are actually configuration problems — TPM or Secure Boot disabled in firmware on hardware that supports them — and we fix those rather than writing the device off. The assessment gives you a per-device verdict, not a fleet-level guess.

Will users lose applications or data during the upgrade?

An in-place upgrade preserves applications, settings, and user data by design, and we run it that way — staged in rings with a pilot first. We still require current backups or OneDrive/Known Folder Move as a rollback story, because a per-device failure rate above zero is a planning assumption, not a surprise.

How much disruption should users expect?

The upgrade itself runs through Intune during agreed maintenance windows, typically requiring one or more restarts per device. Users sign back in to the same applications and files on Windows 11. We schedule waves around your business calendar and handle failed devices individually through the exceptions log.

What happens to devices that cannot run Windows 11 at all?

You get two costed options per device: replacement hardware — we specify what to buy and prepare Autopilot enrollment readiness, but procurement is yours — or a Windows 365 Cloud PC, where the old device becomes a viewer for a managed cloud-hosted Windows 11 desktop. One detail worth knowing for the Cloud PC route: Microsoft has stated that Windows 10 endpoints accessing Windows 365 Enterprise Cloud PCs can be entitled to ESU at no additional Microsoft charge, subject to Microsoft's conditions — which can make that path cheaper than it first looks.

How does the pricing work?

The service is $25 per in-scope device plus a $1,950 tenant fee, fixed and quoted in writing before work begins — you pay after you approve delivery. The per-device fee covers assessment and disposition of every device in scope, whichever of the three paths it lands on. Microsoft's charges — ESU license fees, Windows 365 licensing if you choose that route — are separate and quoted transparently before purchase.

Do our devices need to be in Intune first?

The upgrade machinery in this service is Intune-driven, so yes — devices need to be enrolled or enrollable. If your fleet is not there yet, our Microsoft Intune Initial Setup for Windows Device Management service establishes management first, and the two engagements chain cleanly.

You still list In-Place Upgrade to Windows 10 services — which one do we need?

Those services moved organizations onto Windows 10 while it was the standardization target, and they remain in the catalog honestly rather than silently vanishing. If your problem in 2026 is being on Windows 10, this service — off Windows 10, onto Windows 11 or a managed bridge — is the one you need.

How long does the migration take?

The engagement is planned as 4 weeks: assessment and pilot in the first half, staged waves, ESU enrollment, and closeout in the second. Fleet size, maintenance-window availability, and how quickly disposition decisions get approved are the main variables; very large fleets get their own quoted schedule.

What do we hold at the end of the engagement?

A fleet where every device has a documented disposition: upgraded and reporting compliant in Intune, ESU-enrolled with a written exit date, or flagged for replacement/Cloud PC with a recommendation. Plus the exceptions log, the ESU exit plan, and a closeout report your leadership and your cyber-insurance questionnaire can both live with.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$25 per device + $1,950 tenant fee
4 weeks
Book a Windows 11 scoping call