Key Takeaway: Windows 10 reached end of support on October 14, 2025. Every device still running it is accumulating unpatched vulnerabilities. The MSP that has not completed the Windows 11 migration conversation with every client is carrying a security and compliance liability that will show up in cyber insurance renewals. Categorize every device: eligible for upgrade, eligible for ESU, or requires replacement.
Windows 10 reached end of support on October 14, 2025. Every device still running Windows 10 is now accumulating unpatched vulnerabilities. The MSP that has not completed the Windows 11 migration conversation with every client is carrying a security and compliance liability that will show up in cyber insurance renewals, regulatory audits, and eventually in incidents.
This guide covers the Windows 11 migration process from the MSP’s perspective: how to assess the client’s environment, how to handle devices that cannot run Windows 11, how to manage the migration without disrupting client operations, and how to have the conversation with clients who are resistant to the change.
The Assessment: What You Need to Know Before You Start
The Windows 11 migration starts with a hardware assessment. Windows 11 has specific hardware requirements that many older devices do not meet, and the assessment determines which devices can be upgraded, which need to be replaced, and which require the Extended Security Update (ESU) program as a bridge.
The minimum hardware requirements for Windows 11 include a 64-bit processor running at 1 GHz or faster with at least 2 cores, 4 GB of RAM, 64 GB of storage, UEFI firmware with Secure Boot capability, and TPM version 2.0. The TPM 2.0 requirement is the most common barrier: many devices manufactured before 2018 do not have TPM 2.0.
Your RMM should be able to generate a report of all devices by operating system version and hardware specifications. Run this report for every client and categorize each device into one of three groups: eligible for Windows 11 upgrade, eligible for ESU program, or requires replacement.
The Three Migration Paths
Path 1: In-place upgrade. For devices that meet Windows 11 hardware requirements, the in-place upgrade is the simplest path. The upgrade is free, can be deployed through your RMM, and preserves the user’s applications and data. The process: verify hardware compatibility, back up the device, deploy the upgrade through your RMM, verify the upgrade completed successfully, and document the new OS version in your asset inventory.
The in-place upgrade typically takes 30 to 90 minutes per device and can be scheduled during off-hours to minimize disruption. The most common failure mode is insufficient disk space: Windows 11 requires at least 64 GB of storage, and devices with older, smaller drives may need disk cleanup or storage expansion before the upgrade can proceed.
Path 2: Extended Security Updates (ESU). For devices that cannot run Windows 11 but cannot be replaced immediately, the ESU program provides security updates through October 12, 2027. The ESU program costs $61 per device for the first year (2025-2026) and $122 per device for the second year (2026-2027). It is a bridge, not a destination.
The ESU program is appropriate for devices that are running specialized software that has not been tested on Windows 11, devices that are approaching the end of their useful life and will be replaced within the ESU period, and devices where the replacement budget has not yet been approved. Document every device on the ESU program and the planned replacement timeline.
Path 3: Device replacement. For devices that cannot run Windows 11 and are more than four years old, replacement is usually the right answer. The replacement cost is a one-time expense. The ongoing security risk of keeping an unsupported device is a recurring liability. The RAM shortage of 2025 and 2026 has made hardware replacement more expensive than it was when Windows 11 launched, but the cost of a security incident on an unsupported device is significantly higher.
Managing the Migration Without Disrupting Operations
The Windows 11 migration is a significant operational project for most MSP clients. Managing it without disrupting client operations requires planning, communication, and a phased approach.
Phase the migration by risk and priority. Start with the devices that are most exposed: those running Windows 10 without the ESU program, those in the most security-sensitive roles, and those that are most likely to be targeted in an attack. Complete the high-priority devices before moving to the lower-priority ones.
Schedule upgrades during off-hours. The in-place upgrade requires a restart and takes 30 to 90 minutes. Schedule upgrades during off-hours or during periods of low activity to minimize disruption. Communicate the schedule to the client in advance so users know what to expect.
Test line-of-business applications before broad deployment. Some applications that run on Windows 10 may have compatibility issues on Windows 11. Test the client’s critical applications on a Windows 11 device before deploying the upgrade broadly. Identify and resolve compatibility issues before they affect production users.
The Client Conversation
The clients who are most resistant to the Windows 11 migration are usually the ones who are most exposed. They have deferred the decision because it feels expensive and disruptive. The MSP’s job is to make the cost of inaction visible.
The conversation that works: we have identified [number] devices in your environment that are running Windows 10, which reached end of support in October 2025. These devices are no longer receiving security updates, which means every new vulnerability discovered will remain unpatched on those devices. Your cyber insurance carrier is going to ask about this at your next renewal. We need to address it before then. Here is what that looks like and what it costs.
Frequently Asked Questions
Will Windows 10 devices stop working after end of support?
No. Windows 10 devices will continue to function. They will not receive security updates, bug fixes, or technical support from Microsoft, but the operating system will continue to run. The risk is not that the device stops working. The risk is that it accumulates unpatched vulnerabilities over time.
What is the Windows 10 Extended Security Update program?
The ESU program provides security updates for Windows 10 through October 12, 2027, at a cost of $61 per device for the first year and $122 per device for the second year. It is a temporary bridge for organizations that cannot complete their Windows 11 migration before the end of support date.
How do I handle a client whose line-of-business application does not run on Windows 11?
Contact the application vendor to understand their Windows 11 compatibility timeline. Most major business applications have released Windows 11 compatible versions. If the vendor does not have a Windows 11 compatible version, the client has a vendor problem that needs to be addressed regardless of the Windows migration. Enroll the affected devices in the ESU program while the vendor compatibility issue is resolved.
About Brent Lacy: Brent Lacy is a technology advisor and the voice behind Rewired MSP. He is the author of Rewired MSP: Mastery, Scalability & Performance, vCIO Rewired: Virtually Conquering IT Obstacles, and Near Miss: Preventable IT Failures Threatening Your Business Security.
Related Reading
- Windows 10 End of Support: The Client Conversation Your MSP Should Be Having
- Microsoft Deleted Its 32GB RAM Advice: What Clients Should Actually Buy
- Cyber Insurance Requirements 2026: What Carriers Actually Check
- The MSP Client Onboarding Checklist
- MSP Cybersecurity Hub