Windows 10 Extended Security

David Pereira 65 Reputation points
2025-05-22T20:19:56.8566667+00:00

As per https://learn.microsoft.com/en-us/windows/whats-new/extended-security-updates Windows 10 Extended Security Updates are available for 3 years at no additional cost when using Azure Virtual Desktop and other listed services. I currently use MECM to deploy patches to my Azure Virtual Desktops and while we are working on Windows 11 we will need to use the ESU for a few months. My question is how will Microsoft determine that I have the correct licenses in order to Patch my devices, will MECM be able to pull these updates and apply them or will we need to point the AVD directly at the Windows Update source in order to receive the patches.

 

Technical guidance here would be appreciated as it’s critical there is no gap in security updates.

Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
0 comments No comments
{count} votes

Accepted answer
  1. Marcin Policht 51,365 Reputation points MVP Volunteer Moderator
    2025-05-22T21:16:33.1166667+00:00

    This entitlement is automatically recognized for VMs running on AVD. You do not need to purchase or manually install ESU keys. Microsoft identifies the eligibility for free ESUs via the Azure metadata and platform identifiers, AVD session host role assignment on the VM, and licensing info reported to Windows Update services and telemetry.

    As long as the VM is running on Azure and is a registered AVD session host, Microsoft considers it ESU-eligible.

    Endpoint Configuration Manager can be used to deploy ESU patches to AVDs, just as with any standard patching workflow. To accomplish this, it must be able to correctly identify the device as ESU-entitled (which it does via normal telemetry and update classification sync from Windows Update for Business or WSUS). You do not need to point AVDs directly to Windows Update as long as ECM is synchronized with a WSUS instance that’s getting the correct ESU updates, and the devices are recognized as AVD-hosted (which they are if you’ve set them up properly).


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.