If you do not have any Windows 7, Windows Server 2008 or Office 2010 on your network,
you can safely ignore the rest of this article. If you are really sure that you do not,
that is.
The problem is that most organisations’ inventories of their IT assets have significant
gaps — black holes might be the better analogy — where older machines, remote locations
or whole subnets simply never appear on the asset register.
So your inventory might look healthy. Every machine you have inventoried is running a
current operating system and a current version of Office. The reality could be that you
are about to see — or rather, not see — a significant increase in the security threats
facing your organisation.
The real issue is that it takes one outdated system to open you up to catastrophic
damage. Take WannaCry. The global ransomware attack of May 2017 spread through outdated
Microsoft Windows systems, and in that case Microsoft had already released a patch before
the attack. From 14 January 2020 there will be no more patches for Windows 7 or Windows
Server 2008 at all. Office 2010 follows on 13 October 2020.
Every end-of-support programme fails in the same place. Not at the upgrade — at the
census. You cannot plan a migration around an asset register that does not know about the
machine in the server room nobody has opened since the last refresh, the PC driving the
welcome screen in reception, the box in a remote office, or the desktop being used as a
printer stand.
That is an inventory problem, and it is solvable with technology rather than a search
party:
- Sweep the network before you trust the agents you already have deployed. CerteroX ITAM
runs Network Discovery across NetBIOS, SNMP and ICMP, covering a class-C subnet in
under five seconds, then probes to work out where an agent can actually be deployed. It
finds machines you do not yet manage, which is the entire point.
- Cover the awkward cases. A native agent handles Windows, macOS, Linux, AIX, HP-UX
and Solaris. Agentless and command-line inventory cover locked-down environments.
Standalone inventory covers offline and air-gapped systems that no network sweep will
ever reach.
- Let the platform tell you what is expiring. You should not be maintaining a
spreadsheet of Microsoft lifecycle dates. The Software Recognition Service in CerteroX
SAM carries release date, end-of-support date and extended-support date against
recognised titles, so end-of-life exposure is a filter over live inventory rather than
a research project.
Then build the plan and prove it moved
Once you can see everything, the sequence is unremarkable:
- Locate every instance of the affected products — Windows 7, Windows Server 2008,
Office 2010 and, on a similar timeline, SQL Server 2008.
- Decide per instance whether to upgrade, replace, migrate or retire. A server hosting
one legacy application is a different decision to a desktop.
- Build the plan, with owners and dates.
- Execute it, and report progress against it.
Steps three and four are where an asset platform earns its place. Software distribution
handles MSI, EXE and Click-to-Run packages; WSUS-integrated patch management covers the
machines that are staying; Windows 11 upgrade orchestration covers the ones that are
moving. Governance Policies let you express the control itself as a rule — BitLocker
enabled, Defender running, no unsupported operating system in this location — and then
show, continuously, which machines still violate it. That is the difference between a
migration plan and a status report.
This deadline was not the last one
This post was written a month before the January 2020 cut-off. That date has long since
passed, and so has the one after it: Microsoft ended support for Windows 10 on 14 October
2025. There will be another.
The lesson generalises, which is why the post is still here. End of support is not a
patching problem that arrives every few years. It is a permanent inventory discipline,
and the organisations that handle it calmly are the ones who already know what they own
before the announcement lands. The ones who scramble are the ones running a census under
deadline.
If your asset register has black holes in it, the time to find them is not the month
before support ends. Talk to us about what full coverage would actually take.