Still Running Windows 10? The Risks Now End-of-Life Has Passed
· By Paul Harvey
Windows 10 reached end of support on 14 October 2025. If you still have Windows 10 devices running in your environment today, every one of them is now an unpatched, unsupported endpoint — and the risk profile of your business has materially changed. Microsoft has stopped shipping security updates, feature updates and technical fixes for Windows 10 Home, Pro, Enterprise and Education. The devices still boot, applications still open, and users will not notice anything different on day one. That is exactly what makes this dangerous: the operational experience is unchanged while the underlying security, compliance and insurance posture has quietly collapsed.
At Mycelium 365 we are now receiving weekly calls from Australian businesses who assumed they had more time, missed the deadline, or were blocked by one or two legacy applications. This guide explains what is actually at stake when you keep Windows 10 in production after end of life, what auditors, insurers and the Australian Signals Directorate now expect, and the fastest practical paths to get current.
What does Windows 10 end of life actually mean for a business in 2026?
End of life means Microsoft no longer issues security patches, quality updates or bug fixes for Windows 10 through Windows Update. New vulnerabilities discovered in the operating system — and there will be many, because attackers actively reverse-engineer Windows 11 patches to find equivalent flaws in Windows 10 — will never be fixed on your fleet. Microsoft Defender signature updates continue for a limited period, but signature updates only catch known malware; they do not close the underlying operating system holes that ransomware and credential-theft tooling exploit. Technical support from Microsoft for Windows 10 issues is also withdrawn, which means your managed service provider can no longer escalate a Windows 10 bug to Microsoft for a fix. The only sanctioned way to keep receiving security patches is the paid Extended Security Updates (ESU) program, which is a temporary bridge — not a strategy — and is priced to push organisations toward Windows 11.
What are the real security risks of running Windows 10 after October 2025?
The security risk is not theoretical. Within weeks of any major Windows version going end of life, threat actors begin chaining newly-disclosed Windows 11 vulnerabilities against the unpatched Windows 10 codebase, where many of the same components still exist. Expect three concrete pressures on your environment: an increase in successful ransomware deployments through unpatched local privilege escalation flaws; credential theft via Local Security Authority (LSASS) and browser memory attacks that Microsoft will only harden on Windows 11; and lateral movement from a single compromised Windows 10 laptop into your Microsoft 365 tenant, file shares and finance systems. If you run Microsoft Defender for Endpoint, you will also see your secure score drop as devices are flagged "out of support" — and that score is increasingly what cyber insurers and enterprise customers ask to see during due diligence.
How does Windows 10 affect Essential Eight and cyber insurance compliance?
The Australian Cyber Security Centre's Essential Eight maturity model requires that operating systems are patched within defined windows and that vendor-supported versions are used. An unsupported operating system cannot, by definition, meet Maturity Level One, let alone Two or Three. If you are a Defence contractor working under DISP, an APRA-regulated entity under CPS 234, a law firm aligned to the Law Council's cyber guidance, or a not-for-profit handling donor or client data, running Windows 10 today puts you in active breach of the patching control. Cyber insurance is the more immediate financial risk. Most Australian insurers — including the major underwriters servicing SME and mid-market — now ask at renewal whether all endpoints are on a vendor-supported operating system. Answering "no", or answering "yes" inaccurately, gives the insurer grounds to reduce a payout or deny a ransomware claim entirely. We have seen claim values in the hundreds of thousands materially adjusted on exactly this point.
What happens to Microsoft 365, Defender and Intune on Windows 10 devices now?
Microsoft 365 Apps (Word, Excel, Outlook, Teams) will continue to run on Windows 10 for a defined grace period, but Microsoft has been explicit that they are no longer supported on the platform — meaning if a Microsoft 365 update breaks Outlook on Windows 10, the fix will be "upgrade to Windows 11." Microsoft Defender for Endpoint continues to provide some protection on Windows 10 22H2 through October 2028, but advanced capabilities such as tamper protection improvements, attack surface reduction rule updates and new XDR detections are being released for Windows 11 first and sometimes only. Microsoft Intune still manages Windows 10 devices, but new configuration service providers, Autopilot improvements and Endpoint Privilege Management policies are increasingly Windows 11-only. The practical effect is that your security and management stack is degrading underneath you on every Windows 10 device, even if nothing visible has broken yet.
What are the options if you still have Windows 10 in your environment?
There are four realistic paths, and most Australian businesses will use a combination of them.
Upgrade in-place to Windows 11 for any device that meets the hardware requirements — TPM 2.0, supported 8th-generation Intel or AMD Ryzen 2000 processor or newer, 4 GB RAM and 64 GB storage. For a managed Microsoft 365 fleet using Intune, this is typically a policy push that completes overnight per device with no data loss.
Replace non-compliant hardware with new Windows 11 devices. Most business laptops sold before 2018 will not meet the CPU or TPM requirements. Rolling these into a standard refresh cycle, funded over 24–36 months, is usually cheaper than ESU plus the operational risk of running them unsupported.
Move workloads to Azure Virtual Desktop or Windows 365 Cloud PC, which gives users a fully patched Windows 11 desktop streamed to their existing hardware. This is particularly useful where the blocker is a legacy line-of-business application that has been certified on Windows 10 but not yet on Windows 11 — the application can be isolated in a controlled AVD host pool while the rest of the fleet moves on.
Enrol the remaining devices in Extended Security Updates (ESU) as a bridge of last resort. ESU for commercial customers is priced per device per year, doubles in year two, and triples in year three. It buys time; it does not solve compliance or insurance exposure, because most insurer questionnaires now distinguish between "vendor-supported" and "vendor-supported via paid extended program."
How quickly can a Windows 10 to Windows 11 migration realistically be completed?
For an Intune-managed Microsoft 365 environment with compatible hardware, a fleet of 50–150 devices can typically be moved to Windows 11 within four to six weeks: one week of hardware eligibility reporting and pilot group selection, two weeks of pilot and application validation, and two to three weeks of phased rollout with a help-desk surge. Where hardware needs to be replaced, the timeline is driven by procurement lead times — currently four to eight weeks for business-grade laptops in Australia — rather than by the migration itself. Where legacy applications are the blocker, expect an additional two to four weeks to stand up an Azure Virtual Desktop host pool or Windows 365 Cloud PCs for the affected users. The longest projects we see are not technically complex; they are organisations that have not yet built a complete asset inventory, which is the first thing we fix.
What should you do this week if Windows 10 is still in your environment?
Three actions, in order. First, run a current inventory of every Windows 10 device, who uses it, what applications it runs, and whether it is eligible for Windows 11 — Microsoft Intune, Microsoft Endpoint Configuration Manager or a lightweight discovery scan will produce this in hours, not weeks. Second, notify your cyber insurer in writing of your current state and your remediation plan; insurers respond far better to a documented plan than to silence followed by a claim. Third, decide per-device whether the path is in-place upgrade, hardware replacement, AVD/Cloud PC, or short-term ESU, and lock the dates. Doing nothing is now itself a decision — one that quietly transfers risk from Microsoft, who used to patch the operating system for you, onto your balance sheet.
If you would like help quantifying the exposure on your specific fleet or building the migration plan, our Modern Workplace Audit and Cyber Insurance Controls Review are designed exactly for this scenario, and our Managed Microsoft 365 and Managed Microsoft Defender services keep the new environment patched and monitored once you are current.
Frequently asked questions
Is Windows 10 still safe to use after October 2025?
No. Microsoft stopped issuing security patches for Windows 10 on 14 October 2025. Any vulnerability discovered after that date will remain unpatched on Windows 10, which means ransomware, credential theft and privilege-escalation attacks have a permanent foothold on those devices. Microsoft Defender signatures continue for a limited period, but signature updates do not close the underlying operating system flaws attackers actually exploit.
Will my cyber insurance still cover a ransomware claim if I am running Windows 10?
Most Australian cyber insurers now ask at renewal whether every endpoint runs a vendor-supported operating system. Answering inaccurately, or having Windows 10 devices in production without disclosing them, gives the insurer grounds to reduce or deny a claim. Enrolling devices in Microsoft's paid Extended Security Updates (ESU) program is not always treated as equivalent to vendor-supported; check the exact wording on your policy and disclose your state in writing.
Can I just pay for Extended Security Updates and keep Windows 10?
You can, but it is a bridge, not a destination. Commercial ESU is priced per device per year and roughly doubles in year two and triples in year three, and it only delivers critical and important security updates — no feature, quality or Microsoft 365 support improvements. ESU is best used for a small number of devices blocked by a specific legacy application while the rest of the fleet moves to Windows 11.
How long does a Windows 10 to Windows 11 migration take for a small business?
For an Intune-managed Microsoft 365 environment with hardware-eligible devices, 50 to 150 endpoints can typically be migrated within four to six weeks: one week of inventory and pilot selection, two weeks of pilot and application validation, and two to three weeks of phased rollout. Hardware replacement extends the timeline by procurement lead times (four to eight weeks in Australia); legacy applications can be isolated on Azure Virtual Desktop or Windows 365 to unblock the rest of the fleet.
What if a critical line-of-business application only runs on Windows 10?
Move the application — not the whole fleet — onto Azure Virtual Desktop or Windows 365 Cloud PC, where it can run on a controlled, isolated Windows 10 or Windows Server image while every user device upgrades to Windows 11. This contains the unsupported surface area to a small, monitored environment and lets you keep operating while you push the vendor for a Windows 11-compatible release.