Skip to content

Windows 11 migration: why it matters

Windows 10 support ended in October 2025. If you are still finishing the migration — or paying for Extended Security Updates while you do — these are the questions to settle and a readiness check to score yourself against.

Support for Windows 10 ended on 14 October 2025. For organisations that finished migrating ahead of that date, the job is done. For a great many others it is not — machines are still being replaced, budgets are still being argued over, and some fleets are running on Extended Security Updates while the rest of the programme catches up.

Either way, a Windows 11 migration was never just a desktop refresh. It is the one moment in a decade when you are forced to look at every device you own, what it costs, what it runs and how long it has left. That makes it the natural point to review your asset lifecycle management, your software licence position and your Microsoft licensing.

Done properly, the migration maintains compliance and audit readiness, reduces licensing risk, and keeps disruption low across hybrid environments. Done as a scramble, it does the opposite of all three.

Frequently asked questions

1. When did support for Windows 10 end?

14 October 2025. After that date there are no free security updates, no bug fixes and no technical support from Microsoft.

2. What are the risks of staying on Windows 10?

Running Windows 10 without cover means:

  • No security patches, leaving those machines exposed to attack.
  • No bug fixes, increasing the risk of instability.
  • No official Microsoft support for troubleshooting.
  • Potential compliance and regulatory problems, particularly in regulated sectors where “unsupported operating system” is a finding in its own right.

3. Can we extend Windows 10 security updates?

Yes. Microsoft’s Extended Security Update programme covers enrolled devices for a maximum of three years past end of support — to October 2028 for commercial and educational organisations. Microsoft 365 apps on Windows 10 receive security updates on a similar timeline, ending 10 October 2028.

ESU is charged per device, and the cost escalates each year of the programme. It is also cumulative: enrolling in year two means paying for year one as well. It is a bridge, not a destination, and the economics are deliberately designed to make it one.

4. How do we check which devices are ready?

A full inventory assessment is the first step, and it needs to cover more than a compatibility flag. You want to identify:

  • Devices meeting the Windows 11 hardware requirements.
  • Systems needing component upgrades or outright replacement.
  • Warranty status, so replacement decisions can be prioritised sensibly.

5. What are the hardware requirements?

  • Processor: 1GHz or faster, 64-bit, with at least two cores, and on Microsoft’s approved processor list.
  • RAM: 4GB minimum.
  • Storage: 64GB minimum.
  • TPM: version 2.0.
  • Firmware: UEFI with Secure Boot capability.
  • Graphics: DirectX 12 compatible with a WDDM 2.0 driver.

TPM 2.0 is the requirement that catches out the most machines, and it is the one least visible in a typical asset register.

6. What if hardware is not compatible?

Three options:

  1. Upgrade the necessary components, where that is physically possible.
  2. Replace the device.
  3. Cover the device with Extended Security Updates while you plan its replacement.

7. How do we estimate the cost?

Assign financial values to replacement devices, calculate the total refresh expense, and forecast IT spending from actual hardware and lifecycle data rather than a per-head average. The difference between those two approaches is usually the difference between a budget that survives contact with reality and one that does not.

8. What does warranty data have to do with it?

Warranty data identifies devices approaching end of life, which makes them the obvious replacement candidates — especially where they also fail the Windows 11 requirements. Using it lets you sequence upgrades intelligently, avoid repair costs on machines you are about to retire, and keep security and compliance intact while the programme runs.

9. What is the first step in a migration plan?

  • Know what you have. Identify every device and its Windows 11 compatibility.
  • Set a budget. Align costs for replacements and upgrades against real data.
  • Phase it. Migrate in stages to keep disruption manageable.

10. How do we make the transition smooth for users?

A phased strategy lets you prioritise critical departments first, minimise business disruption, and provide support and training as each group moves.

11. How does Windows 11 improve on Windows 10 for security?

  • Hardware-backed security as a baseline, via TPM 2.0 and Secure Boot.
  • Stronger protection against ransomware and credential theft.
  • An architecture designed around Zero Trust assumptions.

The hardware requirements people resent are the security improvements they wanted.

12. Can we test applications before migrating?

Yes, and you should. Assess application dependencies, driver support for legacy hardware, and compatibility risks before you move. Usage data helps here too — there is no value in testing an application nobody has opened in six months, and plenty in retiring it instead.

13. How long does a full migration take?

It depends on size, hardware readiness and complexity. The single largest variable is how early the planning started, which is also the only one you control.

Windows 11 readiness check

Seven questions. Score 1, 0.5 or 0 for each.

Inventory and discovery

Do you have a complete inventory of every device still running Windows 10?

  • 1 — Yes, fully mapped.
  • 0.5 — Partly, but gaps remain.
  • 0 — No, we do not have full visibility.

Do you know which devices meet the Windows 11 hardware requirements?

  • 1 — Yes, all devices assessed.
  • 0.5 — Partly, more analysis needed.
  • 0 — No, we have not started.

Budget and cost

Do you have a cost estimate for upgrading or replacing incompatible devices?

  • 1 — Yes, a budget is in place.
  • 0.5 — We have an estimate but need more clarity.
  • 0 — No, the costs are unknown.

Have you factored warranty status into replacement priority?

  • 1 — Yes, warranty data drives the plan.
  • 0.5 — Partly, but not for all devices.
  • 0 — No, warranty is not part of our approach.

Strategy and planning

Do you have a structured migration plan with timelines?

  • 1 — Yes, a full roadmap.
  • 0.5 — A rough plan that needs detail.
  • 0 — No planning yet.

Have you tested applications for Windows 11 compatibility?

  • 1 — Yes, all critical applications tested.
  • 0.5 — Some applications assessed.
  • 0 — Not yet.

Have you secured budget approval?

  • 1 — Yes, funding approved.
  • 0.5 — Not yet, but in discussion.
  • 0 — No clear financial plan.

Your score

6–7 — On track. You are well prepared. The remaining risk is execution slipping, not planning.

3.5–5.5 — Moderate risk. You are making progress but gaps remain. Prioritise completing the inventory, then budgeting, then sequencing.

0–3 — High risk. You are exposed to disruption, security vulnerabilities and compliance findings, and every month on ESU costs more than the last. Start with the inventory.

How CerteroX ITAM handles this

The reason a migration stalls is almost never the upgrade itself. It is that nobody can produce a trustworthy list of what needs upgrading, what it will cost and what breaks if it moves.

Discovery first. Ten discovery methods land in one schema — native agent, agentless, command-line, standalone, Active Directory import, network scan, third-party ITAM import, cloud connectors, browser monitoring and file metering. Network Discovery sweeps a class-C subnet in under five seconds. You get the whole list, including the machines that were never enrolled anywhere.

Readiness, not guesswork. Hardware inventory carries the attributes the Windows 11 requirements actually turn on, so device readiness is a query rather than a survey. Dynamic groups built in the query builder let you carve the fleet into ready, upgradeable and replace — and keep those groups current as work proceeds.

Warranty and cost, in the same record. Hardware warranty retrieval and expiry tracking sit next to cost tabs with manual and automatic costing rules, so the replacement schedule and the budget come out of one place instead of two spreadsheets that disagree.

Then actually do the upgrade. CerteroX ITAM ships Windows 11 upgrade orchestration, software distribution for MSI, EXE and Click-to-Run packages, WSUS-integrated patch management with downstream server support, and an SCCM interface that can import and drive SCCM applications, packages and jobs. The console that found the machines is the console that moves them.

Prove it as you go. Governance Policies work as compliance-as-code — BitLocker enabled, Defender running — so post-migration security posture is evidenced continuously rather than sampled at the end. Trend charts, KPIs and threshold alerts on role-shared dashboards give programme reporting without anyone building a weekly deck, and a read-only API with a documented Power BI data source covers the board pack.

Retire what you were about to migrate for no reason. AppsMonitor meters file-based software usage with first-used and last-used tracking and a % Used metric over a rolling 90-day window. Migration is the cheapest moment you will ever get to stop paying for applications nobody opens.

The point

Windows 10 end of support has already happened. What is left is a lifecycle programme with a security deadline attached and a meter running on every device still uncovered.

The organisations handling it well are not the ones with the biggest budget. They are the ones that could answer “what do we own, what does it cost, and what runs on it” on the first day.

Book a demo, or read more about CerteroX ITAM.

Related reading

Other posts covering the same ground.

  • Manage Android Devices and iOS Across Your IT Ecosystem

    Mobile device management works properly when phones and tablets sit in the same inventory as everything else you own. Here is what CerteroX ITAM does with enrolled iOS and Android devices, and why the single record matters.

    • ITAM
    • Governance
    • Security
    6 min
  • IT Hardware Asset Management and Microsoft's "New WannaCry" Security Threat

    When Microsoft patched a wormable Remote Desktop flaw serious enough to warrant emergency updates for Windows XP, the hard part was not the patch. It was working out which machines you owned that needed it. That is a hardware asset management problem, and it has not gone away.

    • ITAM
    • Governance
    • Security
    5 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.