Ask an IT director whether the Windows 10 migration is finished, and the answer comes quickly. Ask how many Windows devices touch company data, and the answer slows down. The distance between those two responses is the entire subject.
Microsoft ended support for Windows 10 on October 14, 2025, a date the company published years in advance. Most organizations handled it the way they handle any dated obligation: as a project. Budget approved, machines counted, an upgrade wave scheduled, a completion memo circulated, attention moved on. Projects have the convenient property of ending. Exposure does not.
The refresh list was built from the systems that already knew
Every upgrade plan starts from a source. Usually it is the asset inventory inside the management platform, or a depreciation schedule from finance, or both stapled together. Those two lists rarely agree, and neither of them describes the real device population.
What goes missing is not exotic. A PC embedded inside a piece of equipment, sold as part of the equipment and never thought of as a computer. The machine running the lobby display or the conference room scheduler. A workstation at a second site that a department opened without involving IT. A founder's personal laptop with a saved mail profile. A contractor's machine carrying a VPN certificate issued three years ago and never revoked. A warehouse kiosk. A workstation that talks to a legacy vertical application nobody wants to touch.
None of these appeared on the upgrade list, because the upgrade list was assembled from the systems that already knew about them. That circularity is the heart of the problem: an inventory built from managed devices cannot describe unmanaged ones. The only way to find them is to observe what is actually on the network and authenticating to your services, then reconcile that against what you believe you own. Reconciliation is a standing discipline, not a deliverable.
Extended Security Updates fail without a symptom
For organizations that could not finish in time, Microsoft made paid Extended Security Updates available for Windows 10 under published terms — renewable, priced per device, and limited to a defined number of years rather than offered indefinitely. It was the right call for many businesses and bought genuine time. It also changed the shape of the risk rather than removing it.
Two properties deserve executive attention. ESU delivers security fixes only, so nothing about reliability or forward compatibility improves while the entitlement runs. And enrollment attaches to individual devices, which means it has to be tracked as an asset-level subscription rather than a single line in an annual software budget.
The failure mode is what gets missed. When an entitlement lapses — a renewal skipped, a device rebuilt and never re-enrolled, a purchase order that quietly went unsigned — nothing visible happens. The machine boots. Users log in. Work continues. Patches stop arriving, the gap widens every month, and nothing surfaces until something exploits it. This next point is analysis rather than established fact: organizations that lose ESU coverage will mostly lose it administratively rather than deliberately, and will not notice for months.
What gets stolen from an old PC is usually a session
Executives still picture the risk of an outdated computer as something that happens to that computer. Ransomware encrypts it. Malware slows it down. It gets replaced.
The pattern that matters now is quieter. An unpatched, unmanaged endpoint is an inexpensive foothold, and what an intruder takes from it is frequently not files at all. It is credentials and live session tokens sitting in the browser. Tokens can be replayed from somewhere else entirely, and a replayed session does not trigger a password prompt or a second-factor challenge, because from the service's perspective the user already authenticated. The compromised machine may never do anything alarming again.
This is an identity problem wearing a hardware costume. A device outside your management platform is also outside your endpoint detection, outside your log collection, outside whatever cybersecurity monitoring you already pay for. No alert fires because nothing is watching. Age matters mainly because it lowers the cost of entry; the damage lands in Microsoft 365, in finance systems, in whatever the stolen session can reach.
Which reframes the decision. Hunting down every forgotten Windows 10 machine is worth doing and will never be complete — you cannot prove you found the last one. Making device health a condition of access is completable. If reaching company data requires a managed, known, compliant device, then the machine you never found cannot be used against you, not because it was fixed but because it no longer opens anything. That design carries real friction and real project cost, and it deserves a deliberate decision rather than an aspirational one. It is also the only control in this discussion that improves as time passes instead of degrading.
Some machines genuinely cannot move
Part of the remaining Windows 10 population is not going anywhere. The vendor never certified the application for Windows 11. The instrument controller is locked to a validated configuration. A replacement exists but costs six figures and sits in next year's capital plan.
These are legitimate business positions. The failure is leaving them undocumented, which quietly converts a managed exception into ordinary drift. An exception worth accepting has four attributes: a named owner, a written compensating control, a replacement date, and a review scheduled on that date. The controls themselves are unglamorous and well understood.
- Isolate the device on its own network segment with explicit rules about what it may reach, and deny general internet egress.
- Remove email and web browsing entirely. Most of these machines serve exactly one application.
- Give it credentials that work nowhere else, and never a shared administrative account.
- Image the full machine and verify the restore, so rebuilding it becomes a disaster recovery exercise rather than an archaeological one. Many of these configurations cannot be rebuilt from documentation, because the documentation does not exist.
Three answers to have in writing before the next renewal
The useful move is not another hardware count. It is settling three things on paper.
First: who owns the device inventory, and when was it last reconciled against devices observed on the network rather than devices listed in a spreadsheet? Second: which ESU enrollments expire, on what date, and which named person receives that notice? Third, and this is the one that outlasts the others: can a device you have never seen successfully authenticate to your Microsoft 365 tenant today?
Worth doing alongside those: pull your own cyber insurance application and read what it asked about endpoint operating systems. Somebody in your organization answered that question, and the accuracy of the answer rests on an inventory that may not have been re-run since the upgrade project closed. Better to confirm it before a claim than during one.
The operating system was the deadline. Access is the decision, and it is still open.
Pro Link Systems has supported Los Angeles businesses from Woodland Hills since 1999. If your Windows 10 project produced a completion report but not a current device inventory, our managed IT services team can help you find what is still out there and decide what it should be allowed to reach.
Ready to talk to a real IT engineer?
Pro Link Systems has been protecting and managing IT for Los Angeles businesses since 1999. Book a free 15-minute discovery call — no pressure, no obligation, no scripts.