7 Windows 10 End-of-Support Decisions Central Valley Businesses Should Make Before Their Next IT Refresh — Datapath managed IT, cybersecurity, and compliance
Back to Blog
HEALTHCARE Insights • Published September 23, 2026 • Updated September 23, 2026 • 10 min read

7 Windows 10 End-of-Support Decisions Central Valley Businesses Should Make Before Their Next IT Refresh

A practical mid-funnel guide for Modesto and Central Valley business leaders deciding whether to replace, upgrade, virtualize, isolate, or temporarily cover…

Dan J Sturdivant, Vice President at Datapath

By

Dan J Sturdivant

Vice President

Central Valleycloud migrationco-managed IT

Quick summary

  • Immediate risk reduction:
  • What should businesses do about Windows 10 after end of support?
  • 1. Which Windows 10 devices are still business-critical?

What should businesses do about Windows 10 after end of support?

Businesses should treat Windows 10 end of support as an IT risk and budgeting decision, not a simple software update. Microsoft ended support for Windows 10 version 22H2 on October 14, 2025, and organizations still using it should decide which devices to upgrade, replace, virtualize, isolate, or temporarily enroll in Extended Security Updates.1

For Modesto and Central Valley organizations, the hard part is not knowing that Windows 10 is old. The hard part is deciding what to do with mixed fleets: front-office desktops, warehouse PCs, accounting workstations, clinic devices, shared reception machines, line-of-business terminals, and a few “do not touch” computers running specialty software.

A rushed answer creates waste. A slow answer creates security exposure. The right answer is a controlled endpoint refresh plan that ties each Windows 10 device to business function, compliance risk, application dependency, budget, and replacement timing.

Below are seven decisions leadership should make before approving the next refresh, managed IT contract, or security remediation project.

1. Which Windows 10 devices are still business-critical?

The first decision is whether each Windows 10 device still supports a real business process. If a workstation is used daily for billing, dispatch, imaging, payroll, warehouse scanning, or customer service, it needs a documented path. If it is idle, duplicated, or forgotten, retire it instead of spending money to protect it.

This is where many organizations get sloppy. They treat all Windows 10 machines as one category. They are not. A dormant conference-room PC is different from a finance workstation with bank portal access. A warehouse terminal with a local printer dependency is different from a medical office device that touches patient information.

A useful first-pass inventory should include:

  1. Device name and assigned user or location.
  2. Business function.
  3. Operating system version.
  4. Hardware eligibility for Windows 11.
  5. Installed line-of-business applications.
  6. Data sensitivity.
  7. Internet exposure.
  8. Authentication method.
  9. Backup or profile recovery status.
  10. Recommended disposition: upgrade, replace, virtualize, isolate, or retire.

This is not bureaucracy. NIST describes enterprise patch management as identifying, prioritizing, acquiring, installing, and verifying updates across the organization, and frames patching as preventive maintenance needed to reduce compromise, data breach, and operational disruption risk.2 You cannot prioritize what you have not inventoried.

For Central Valley businesses with multiple offices, the inventory should separate headquarters devices from branch, clinic, school, warehouse, and field-office machines. The physical location matters because replacement work is operational: someone has to schedule users, migrate profiles, test printers, validate applications, and confirm the business can work the next morning.

2. Which devices can move directly to Windows 11?

The second decision is whether the machine can be upgraded in place or should be replaced. Microsoft directs organizations to migrate to Windows 11, use tools such as Microsoft Intune or Windows Autopatch where appropriate, replace unsupported PCs, or consider cloud options such as Windows 365.3

A device that meets Windows 11 requirements and runs standard business applications may be a candidate for an in-place upgrade. But “technically eligible” does not always mean “operationally smart.” Older machines may pass minimum requirements but still produce poor user experience, more support tickets, and higher failure risk.

For each eligible Windows 10 device, ask:

  • Is the device still under warranty?
  • Does it have enough RAM and storage for the user’s workload?
  • Does it run accounting, ERP, EHR, CAD, dispatch, label-printing, or scanner software that needs testing?
  • Does the user rely on local files that should be moved to OneDrive, SharePoint, or another managed repository first?
  • Are BitLocker, MFA, EDR, and management agents healthy before the migration?
  • Is there a rollback plan if the upgrade breaks a required workflow?

A good upgrade plan starts with a pilot group. Choose users who represent real workflows: accounting, operations, customer service, leadership, and any department with specialized software. Do not pilot only IT-friendly users with simple setups. The point is to expose compatibility issues before they reach the whole company.

For Datapath’s managed IT customers, this type of work fits naturally into a broader managed IT services or co-managed IT services plan: inventory first, pilot second, staged deployment third, verification last.

3. Which devices should be replaced instead of upgraded?

The third decision is which PCs are no longer worth saving. Replacement is usually the cleaner move when a device is out of warranty, underpowered, failing health checks, missing Windows 11 requirements, or attached to a user whose productivity cost exceeds the hardware cost.

This is where business leaders often undercount the real expense of keeping old endpoints. The purchase price of a new PC is visible. The drag from old devices is spread across help desk tickets, login delays, failed updates, printer problems, user frustration, and after-hours remediation.

Replace instead of upgrade when the device has one or more of these conditions:

  1. It cannot meet Windows 11 hardware requirements.
  2. It is more expensive to troubleshoot than replace.
  3. It supports a high-value role such as finance, executive leadership, healthcare operations, or customer service.
  4. It has recurring disk, battery, boot, or update failures.
  5. It lacks current firmware, TPM, encryption, or endpoint security compatibility.
  6. It uses local admin workarounds that no one wants to inherit.
  7. It stores business data locally because cloud sync or backup was never configured.

A replacement project should include configuration standards, not just hardware ordering. New devices should arrive with encryption, endpoint detection, identity policies, standard applications, browser controls, update rings, and remote support tools already in place.

This is also a good time to standardize the fleet. Too many businesses let endpoint models sprawl across random consumer laptops, aging desktops, one-off purchases, and whatever was available during a prior emergency. Standardization reduces support complexity and makes future refresh cycles less painful.

4. Which Windows 10 machines need Extended Security Updates as a temporary bridge?

The fourth decision is whether any Windows 10 devices need Microsoft’s Extended Security Updates program. ESU is not a modernization strategy. It is a temporary risk-reduction bridge for devices that cannot move immediately.

Microsoft says Windows 10 ESU gives enrolled PCs access to critical and important security updates after end of support, but it does not include new features, customer-requested nonsecurity updates, design changes, or general technical support for Windows versions past end of support.3 For organizations and businesses, Microsoft lists Year One pricing at $61 per device, with the price doubling in consecutive years for up to three years.3

That means ESU should be reserved for cases where delay is justified:

  • A line-of-business application vendor has not certified Windows 11 yet.
  • A medical, manufacturing, finance, or logistics workflow requires staged validation.
  • A replacement project is approved but not complete.
  • A device is being isolated or virtualized but still needs a transition window.
  • A merger, office move, or major platform migration would make simultaneous endpoint replacement too disruptive.

ESU is a bridge with a deadline. Each enrolled device should have an owner, justification, target retirement date, and control plan. If a business buys ESU but does not create an exit plan, it has purchased time without solving the underlying problem.

For regulated organizations, the evidence matters. Keep records showing which devices are enrolled, why they remain on Windows 10, what compensating controls are in place, and when the organization expects to remove them. That documentation is useful for cyber insurance, audits, executive reporting, and vendor risk reviews.

5. Which legacy systems should be virtualized instead of kept on physical PCs?

The fifth decision is whether a legacy Windows 10 dependency belongs on a physical desktop at all. Some applications should move to a virtual desktop, cloud PC, remote app, or controlled jump-host model rather than remain on aging local hardware.

This is especially relevant when a Windows 10 machine exists only because of one stubborn application, device interface, database client, scanner workflow, or vendor portal. If the machine is physically old but the application cannot be replaced immediately, virtualization may reduce hardware risk and improve control.

Potential virtualization candidates include:

  1. Shared workstations used for a single business application.
  2. Legacy apps with limited user groups.
  3. Remote-access workflows that currently depend on VPN into office PCs.
  4. Seasonal or part-time roles that do not justify full device replacement.
  5. Applications that require tighter access logging and isolation.
  6. Systems that need a controlled migration window before full SaaS replacement.

Virtualization is not automatically cheaper. Licensing, performance, printing, peripheral support, and user experience all matter. But it can make sense when the alternative is protecting scattered old machines across multiple sites.

Microsoft’s ESU documentation also notes that ESU is available at no additional cost for Windows 10 virtual machines in several Microsoft cloud and virtualization scenarios, and that Windows 10 endpoints connecting to Windows 365 Cloud PCs may be entitled to ESU for up to three years with an active Windows 365 subscription license.3 The right answer depends on the licensing environment, application stack, and user workflow.

For businesses already reviewing cloud migration services or Microsoft 365 identity security, Windows 10 cleanup is a useful forcing function: decide what belongs on local endpoints, what belongs in SaaS, and what belongs in a controlled virtual environment.

6. Which remaining Windows 10 devices need compensating controls?

The sixth decision is how to contain risk for any Windows 10 device that remains in use. CISA and NSA warn that unsupported hardware or software creates significant security risk because new and existing vulnerabilities are no longer patched, and they recommend evaluating unsupported hardware and software and discontinuing use as soon as possible.4

For any Windows 10 system that cannot be removed immediately, compensating controls should be explicit. At minimum, evaluate:

  • Network segmentation so the device cannot freely reach sensitive systems.
  • Removal of local administrator rights.
  • Phishing-resistant MFA for remote or privileged access.
  • Endpoint detection and response coverage.
  • Restriction of inbound connections.
  • Browser hardening and application allowlisting where practical.
  • USB and removable media restrictions.
  • Centralized logging.
  • Backup validation for any local data.
  • Clear user instructions about what the device may and may not be used for.

Do not pretend compensating controls make an unsupported endpoint equivalent to a modern supported endpoint. They do not. Their purpose is to reduce blast radius while the business completes the transition.

This matters for Central Valley organizations with operational technology, warehouse systems, clinic equipment, or branch-office devices. Some machines sit in corners for years because they “just work.” Those are exactly the machines that tend to be unmanaged, undocumented, and over-permissioned.

If the business cannot patch a device normally, it should at least know who owns it, what network it touches, what data it can access, and what would happen if it failed tomorrow.

7. Which refresh decisions should go into the 2026 IT roadmap?

The seventh decision is how Windows 10 cleanup fits into the larger roadmap. Treating this as a one-time endpoint project misses the bigger opportunity. A refresh plan can also improve security, standardization, onboarding, offboarding, cloud storage, identity controls, backup posture, and help desk efficiency.

A practical roadmap should divide work into three lanes:

Immediate risk reduction: Identify unsupported Windows 10 devices, enroll justified devices in ESU, remove or isolate high-risk machines, and replace obvious failures.

Operational modernization: Standardize device models, automate provisioning, migrate local data, clean up stale users, validate MFA, and improve support tooling.

Strategic accountability: Build an annual refresh cycle, define device lifecycle rules, document exceptions, and review progress in quarterly business reviews.

This is where the conversation becomes commercial and strategic. The endpoint refresh is not just an IT expense. It is a way to reduce downtime, clean up unmanaged risk, improve cyber insurance evidence, and make future projects faster.

For organizations with 100 or more employees, multiple offices, or regulated workflows, this should not be handled as an informal “replace devices when users complain” process. It should be part of a managed lifecycle program with reporting.

Datapath helps Central Valley and multi-site organizations build that kind of program through managed IT services, cybersecurity risk assessment services, and vCIO services. The goal is not to sell a pile of laptops. The goal is to make endpoint decisions predictable, documented, and aligned with business risk.

CTA: Need a Windows 10 risk and refresh review?

If your organization still has Windows 10 devices in production, Datapath can help inventory the fleet, identify upgrade and replacement paths, document ESU exceptions, and build a practical refresh roadmap.

Start here: Talk with Datapath about managed IT services

FAQ

Is Windows 10 still safe to use after October 14, 2025?

Windows 10 devices can still run after October 14, 2025, but Microsoft no longer provides normal technical support, feature updates, or quality updates for versions that reached end of support on that date.3 Businesses should not treat continued operation as the same thing as acceptable risk.

Should every business buy Windows 10 Extended Security Updates?

No. ESU should be used selectively as a temporary bridge for devices that cannot be upgraded or replaced immediately. It provides critical and important security updates for enrolled PCs, but it does not provide new features, broad technical support, or a long-term modernization plan.3

Is replacing Windows 10 PCs better than upgrading them?

Replacement is often better when devices are old, slow, unsupported, out of warranty, or used by high-value roles. Upgrade may be reasonable for healthy Windows 11-compatible devices with standard applications. The right answer should come from inventory, user impact, application testing, and lifecycle cost.

What should regulated businesses document?

Regulated businesses should document the device inventory, Windows 11 eligibility, ESU enrollment decisions, compensating controls, retirement timelines, exception owners, and validation evidence. This supports audit readiness, cyber insurance discussions, and executive risk reporting.

How can a managed IT provider help with Windows 10 end of support?

A managed IT provider can inventory endpoints, test application compatibility, plan upgrade waves, replace hardware, configure security baselines, enroll qualified devices in ESU, isolate exceptions, and report progress to leadership. The value is in disciplined execution, not simply knowing that Windows 10 is unsupported.

Footnotes

  1. Microsoft Learn, “Windows 10 reaching end of support,” Source ↩

  2. National Institute of Standards and Technology, “SP 800-40 Rev. 4: Guide to Enterprise Patch Management Planning,” Source ↩

  3. Microsoft Learn, “Extended Security Updates (ESU) program for Windows 10,” Source ↩ ↩2 ↩3 ↩4 ↩5 ↩6

  4. CISA, “NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations,” Source ↩

See also

Disclaimer: This blog is intended for marketing purposes only, and nothing presented in here is contractually binding or necessarily the final opinion of the authors.

Need a practical roadmap for regulated-industry IT performance?

Datapath can benchmark your current model and define the next 90 days of high-impact improvements.

Book an IT Consultation