Understanding Extended Security Updates (ESU) for Windows 10: Windows 365 Deployment Scenarios

Overview

Microsoft’s Extended Security Updates (ESU) program supplies critical and important security updates for eligible Windows 10 Enterprise and Education devices after the end of support (EOS) on October 14, 2025. This document explains how ESU entitlement, activation, and administration work for deployments using Windows 365, with a focus on supported models, entitlement checks, policies, and the technical implementation steps relevant for IT administrators and customers planning for the Windows 10 lifecycle management.

References: 

Enable Extended Security Updates for Windows 

Windows 10 ESU for Windows 365 

Windows 10 ESU for AVD

1. ESU Entitlement Models 

ESU works differently based on deployment scenario: 

Azure Virtual Desktop (AVD):  Windows 10 multi-session and single-session virtual machines in Azure Virtual Desktop (across commercial, government, and education tenants) are automatically eligible for ESU. No additional license purchase or activation is required.

Windows 365 Cloud PCs: For existing Cloud PCs running Windows 10, version 22H2 in Azure, ESUs are available at no additional cost.

Physical/Other Endpoints:  ESU coverage via Windows 365 license is possible for the underlying device used to connect to a licensed Cloud PC. 

2. ESU Entitlement and Activation Logic 

2.1 Windows 365 Cloud PC Devices.

Starting October 14, 2025, Windows 10 gallery images are removed and are no longer available for creating new provisioning policies. If you still need to create Windows 10–based provisioning policies, please follow the process to create a custom image based on the Azure Marketplace VM images that are available until April 14, 2026. 

2.2 Windows 365-Connected Local Endpoints

2.2.1 Local Endpoint connected to Windows 365 Enterprise Devices

Eligibility Check:  At user sign-in, eligible Windows 10, version 22H2 endpoints verify whether the user is assigned a Windows 365 Enterprise Cloud PC, either through a direct license assignment or group-based licensing.

Entitlement Logic:  If an active Windows 365 Enterprise license and Cloud PC assignment exists, the ESU entitlement is granted to the physical device on that login for the user session.

2.2.2 Local Endpoint Connected to Windows 365 Flex Dedicated Devices

Windows 365 Flex License Nature: Windows 365 Flex licenses are tenant-wide and cannot be individually assigned to users.

Eligibility: Any user with at least one Windows 365 Flex Dedicated Cloud PC provisioned becomes eligible for ESU. Ongoing usage is not required; eligibility is based on the Cloud PC being provisioned.

Eligibility Duration: Users must sign in to their local Windows 10 device using the same Microsoft Entra ID account they use for Windows 365 Cloud PCs at least once every 22 days to maintain eligibility for ESU updates on that device.

Shared Physical Devices Supported: With Windows Enterprise E3 or Microsoft 365 E3/E5, users are licensed to run up to 10 Windows Enterprise instances per user, either physical or virtual. ESU applies to each licensed instance.

Revalidation: A pre-expiry eligibility check may occur (typically up to 7 days before expiration) and requires the user to sign in.

2.2.3 Device & User Association

Per-Device, Per-Session:  ESU entitlement is not transferable. Authorizing ESU for one device during a user session does not propagate to other devices, even when accessed by the same user.

Post-October 2025 Limitation:  After October 15, 2025, there will be no administrator or end-user tool available to identify which endpoints have claimed ESU entitlement through Windows 365.

3. Administration, Policy & Opt-In Controls 

Explicit Policy Enablement: Devices require explicit ESU policy enablement (via Microsoft Intune policy or registry configuration) before they can begin receiving ESU updates. For policy details, see Enable Windows 10 Extended Security Updates (ESU) for clients accessing cloud and virtual machines | Microsoft Learn 

Assignments & Enforcement:  IT Admins are responsible for ensuring ESU policies are configured and correctly scoped to eligible devices; improper configuration may result in devices missing eligible ESU. 

User/Device Limits: ESU entitlements are calculated per user and allow up to 10 eligible devices per user, in accordance with current policy.

Reporting:  After October 15, 2025, user-to-device ESU mapping and reporting are no longer available through Microsoft administrative tooling.

4. Technical Implementation Steps 

For Local Windows 10 Endpoints via Windows 365 

Ensure Licensing: Verify that the user has a Windows 365 Enterprise or Windows 365 Flex license and an assigned Cloud PC.

Login-Triggered Check:  Signing in to the local device using the same Microsoft Entra ID account used to access the Cloud PC triggers device eligibility verification through a Microsoft cloud handshake.

Policy Enablement:  IT administrators must configure ESU enablement through Microsoft Intune policy or registry settings on these devices. 

Connectivity Requirement: The device must connect regularly to Microsoft services (at least once every 22 days, or per session) to maintain ongoing ESU eligibility.

5. Best Practices 

Prioritize Windows 11 Migration:  Use ESU for Windows 10 only when hardware limitations or workload dependencies prevent an upgrade to Windows 11.

Rigorous Device Tracking:  Maintain your own records of ESU-eligible endpoints, no central admin enumeration is available after October 2025. 

Automate Where Possible:  Automate ESU eligibility checks, policy assignment, and patch deployment wherever possible, particularly in dynamic or shared device environments.

  • Review Policy Scope Regularly: Periodically review Group Policy and MDM scoping to ensure ESU is applied only to eligible endpoints. Retired, repurposed, or decommissioned devices should be explicitly excluded.