Hi Adin
Since Windows 10 has already hit end‑of‑support, the only way to keep those industrial PCs secure is by applying Extended Security Updates (ESU). The good news is that you don’t have to do this manually Intune and other cloud management tools can push and activate ESU keys across your fleet. The process usually involves importing the ESU volume license keys into your tenant, then using a PowerShell script deployment or Endpoint security policy to register and activate them on each device. Once the script runs, the machines will check in with Microsoft’s activation service and start receiving the ESU patches automatically.
Make sure the devices are Azure AD joined or hybrid joined so they can receive Intune policies, confirm they have internet connectivity to reach activation servers, and test the deployment on a small pilot group before rolling it out to all controllers. Also, keep an eye on Intune’s update compliance reports to verify that ESU patches are being applied as expected.
This way you’ll keep those legacy controllers patched without needing to upgrade the hardware. If this explanation helps you move forward, please hit accept answer