Windows 10 stopped receiving security updates on October 14, 2025, and Windows Server 2016 loses all support on January 12, 2027. For most businesses the pressing date sits between the two: October 13, 2026, when the consumer Extended Security Updates program ends and every Windows 10 machine leaning on it goes unpatched.

If your office still runs on either system, and a very large number of businesses do, this guide covers what actually changes, what the real risks are, and how to sequence the transition so it is a planned project rather than an emergency.

What “end of support” actually means

Nothing dramatic happens on the deadline. The machines boot, the software runs, the files open. That is the problem: end of support is invisible.

What ends is maintenance. Microsoft stops shipping:

  • Security updates: fixes for newly discovered vulnerabilities
  • Quality updates: bug and reliability fixes
  • Technical support: no help from Microsoft when something breaks

The security piece is the one that matters. Attackers reverse-engineer every patch Microsoft ships for supported systems and check whether the same flaw exists in the unsupported versions, where it will now never be fixed. An unpatched, internet-connected machine does not get slightly riskier over time; it accumulates known, published, permanently open holes.

There is a paper cost too. Compliance frameworks and cyber-insurance questionnaires ask directly whether you run unsupported operating systems. “Yes” can mean a denied claim or a failed audit, independent of whether anything has actually gone wrong yet.

Windows 10: the deadline has already passed

Support ended in October 2025. As of now, an ordinary Windows 10 machine only receives security updates if it is enrolled in Microsoft’s Extended Security Updates (ESU) program. ESU is a paid bridge, not a fix:

  • Consumer ESU covers enrolled PCs through October 13, 2026. That is the date to circle: it is a few months away, and when it passes, every machine leaning on it goes unpatched.
  • Commercial ESU is an annual subscription available for up to three years, ending October 2028, with pricing that roughly doubles each year to push migration.
  • Either way, ESU requires Windows 10 version 22H2 and delivers security fixes only. No feature updates, no support.

One footnote: Microsoft 365 Apps (Word, Excel, Outlook) will keep receiving security updates on Windows 10 through October 2028. That keeps Office itself patched. It does not make the operating system underneath it any less exposed.

The decision for each machine is binary. If the hardware meets Windows 11’s requirements (TPM 2.0 and a supported CPU, which broadly means machines from about 2019 onward), the upgrade is free and mostly uneventful. If it does not, the machine needs replacing, and ESU is the mechanism that buys you an orderly schedule instead of a scramble.

Windows Server 2016: January 12, 2027

Server 2016 has been out of mainstream support since January 2022 and has received only security fixes for years. On January 12, 2027, those stop too.

Unlike Windows 10, no ESU program has been announced for Server 2016 as of mid-2026. Unless that changes, there is no paid bridge. January 12, 2027 is the real deadline.

Servers are also a different kind of project than desktops. A Server 2016 box is rarely just an operating system; it is the file server, the domain controller, the host for the line-of-business app that the whole company runs on. The migration paths, roughly in order of how often they make sense:

  1. Move the workload to a service, not a newer server. File shares to SharePoint or Azure Files, the aging on-prem app to its vendor’s hosted version. Many businesses discover the 2016 box is the last server they need to own.
  2. Upgrade to a current Windows Server (2022 or 2025), on new hardware or virtualized. This is the right answer when the workload genuinely must stay on-prem.
  3. Migrate the server to Azure. Historically Microsoft has granted free extended updates to servers moved into Azure, and that pattern may repeat for 2016, but do not build your plan on an announcement that has not happened.

Whichever path fits, plan for months of runway rather than weeks, and make sure a tested backup and recovery setup is in place before anyone touches anything. Migration day is exactly when restore capability matters most.

A realistic timeline from here

Working backward from the deadlines, a sane sequence looks like this:

  1. Now: inventory. Every Windows 10 machine (and whether its hardware qualifies for Windows 11), every Server 2016 instance and what actually runs on it. With the right tooling this is an afternoon of work, and it turns a vague worry into a concrete list.
  2. Before October 2026: resolve every Windows 10 machine. Upgrade the eligible ones, schedule replacement for the rest, and put commercial ESU only on the machines that genuinely cannot move yet.
  3. Q4 2026: server decisions made, migration path chosen, budget approved. Hardware lead times and vendor scheduling both get worse as a deadline approaches, because everyone else is running at the same date.
  4. Well before January 2027: Server 2016 workloads migrated and verified, old systems retired.

The pattern we see repeatedly: businesses that start a year out do this as routine maintenance; businesses that start three months out pay rush pricing for the same outcome.

Where to start

If you have an IT partner, ask them for the inventory: the list of what is unsupported, what qualifies for upgrade, and what the migration plan is. If the answer is vague, that is information too.

If you do not have one, this is exactly the category of problem managed IT exists for: lifecycle tracking, patching, and migrations handled as ongoing maintenance instead of periodic emergencies. Get in touch and we will start with the inventory. It is the fastest way to find out whether you have a small problem or a large one.