Windows 10 stopped receiving security updates on 14 October 2025. The machines did not stop working, which is exactly why this keeps getting postponed — nothing visibly broke, so it never becomes this week’s problem.

What follows is how to do the upgrade properly, in the order that wastes the least of your time. It applies whether you have three computers or thirty.

First: find out what you actually have

Before deciding anything, count. Most offices are surprised twice — once by how many machines there are, and once by how many already qualify.

On each computer, press Windows + R, type winver, and press Enter. That tells you which version it is running. Then open Settings → System → About and note the processor, the installed memory and the system type.

Microsoft’s PC Health Check app answers the compatibility question directly and is the fastest route for a handful of machines. For anything above about ten computers it is worth having someone script this rather than walking desk to desk.

What you want at the end is a list with three columns: machines that qualify, machines that could qualify with a firmware change, and machines that genuinely cannot.

The requirements, and the one that trips everyone up

Windows 11 needs a 64-bit processor from Microsoft’s approved list — broadly Intel 8th generation or newer, and AMD Ryzen 2000 series or newer — plus 4 GB of memory, 64 GB of storage, UEFI firmware with Secure Boot, and TPM 2.0 (Microsoft).

TPM 2.0 is where most of the false negatives come from.

A great many business computers built between 2018 and 2020 have a TPM chip that is switched off in firmware, or have Secure Boot disabled because someone needed to boot something years ago and never turned it back on. The machine reports as incompatible and looks like a replacement candidate, when in fact it needs two settings changed in the BIOS setup screen.

It is worth being systematic about this, because the difference between “not compatible” and “compatible after a five-minute change” is often several hundred dollars per machine. On a fleet of fifteen, that is the whole project budget.

Do one machine first

Not the owner’s. Not the machine that runs the thing nobody understands. Pick a normal computer belonging to somebody patient, upgrade it, and write down everything that needed attention afterwards.

Almost every office has one surprise on that list, and it is nearly always software rather than Windows: a scanner utility that needs reinstalling, a VPN client that lost its configuration, an accounting package whose licence re-checks on a hardware change, a label printer with a driver that predates the decade.

Finding that on machine one costs an hour. Finding it on machine fourteen, on a Friday, costs considerably more.

Back up before, not after

Upgrades usually go fine. Usually is not a backup strategy.

Before touching a machine, confirm that the files are somewhere other than that machine, and that you have actually opened one of them from the backup. In-place upgrades preserve files and applications by design, but the failure mode when they go wrong is total, and it always lands on the one computer whose files were never anywhere else.

If your office uses OneDrive or SharePoint, verify that the folders you care about really are syncing rather than assumed to be. The desktop that was never added to sync is a recurring discovery at exactly the wrong moment.

The upgrade itself

For a machine that qualifies, Settings → Windows Update will offer Windows 11 directly, and that is the route to use. Microsoft also publishes an Installation Assistant and media creation tool for machines where the update has not appeared yet (Microsoft).

Plan on roughly an hour per computer, mostly unattended, and schedule it when losing that machine does not matter. Do them in small batches rather than all at once — if something systematic goes wrong, you want it to affect three people rather than the whole office.

After each one: sign back into the applications, print a test page, check the scanner, and open the line-of-business software before declaring it done. The upgrade is not finished when Windows says it is; it is finished when the person can do their job.

What to do with the machines that cannot upgrade

You have three honest options, and the right one depends on what the machine does.

Replace it. Straightforward, and the correct answer for anything doing daily work with client or financial data.

Buy time with Extended Security Updates. Microsoft’s ESU programme keeps security patches flowing on Windows 10 past the deadline for a fee (Microsoft). This is a bridge, not a destination — it buys a planning window, and the cost climbs the longer you stay. Our post on Windows 10 going unsupported covers the numbers and the deadlines in detail.

Move it off the network. A machine that only drives a cutting plotter or an old test rig does not need internet access. Isolating it is legitimate and cheap, and it converts a security problem into a contained one.

What is not an option, for a business, is leaving unsupported machines on the same network as everything else and hoping.

Where Massachusetts makes this a compliance question

If you hold personal information about a Massachusetts resident — employees count — you are inside 201 CMR 17.00, which requires reasonably up-to-date security patches on systems that hold that data. There is no headcount threshold.

An operating system that no longer receives patches is not a grey area under that standard. It is a documented gap in a program you are required to have in writing, and it is the first thing anyone looks at after an incident. Our post on what 201 CMR 17.00 actually requires sets out the rest of the program.

The short version

Count the machines. Check TPM and Secure Boot before writing any of them off. Upgrade one and take notes. Back up first. Do the rest in small batches. Deal with the leftovers deliberately rather than by default.

If you would rather hand the whole thing to someone, you can text or email us with how many machines you have to get a straight answer about the scale of it.

Sources

Frequently asked questions

Is the Windows 11 upgrade still free?
For a machine with a valid Windows 10 licence that meets the hardware requirements, yes — the upgrade path has stayed free and there is no sign of that changing. What costs money is the hardware that does not qualify. That is the real budget line, and it is worth counting the machines before assuming the number is small.
My computer says it is not compatible. Is that final?
Often not. A large share of the machines that report incompatible are actually capable, but have TPM or Secure Boot switched off in firmware — both are frequently disabled by default on business hardware from 2018 to 2020. Turning them on is a five-minute change in the BIOS setup and the machine then qualifies. It is worth checking that before writing off a computer, because the difference between the two outcomes is a few minutes versus a few hundred dollars.
Can I force Windows 11 onto an unsupported PC?
There are documented registry workarounds, and we do not recommend them for anything a business depends on. Microsoft states that unsupported installations are not entitled to updates, which defeats the purpose of upgrading in the first place — you would be leaving the security problem exactly where it was while adding an unsupported configuration on top. For a hobby machine, fine. For the computer your invoices live on, no.
How long does the upgrade actually take per machine?
Budget an hour per computer, most of it unattended, and expect the person to lose the afternoon rather than the day. The upgrade itself typically runs thirty to ninety minutes depending on the disk. What consumes the rest is the human part: re-signing into applications, checking that the printer still works, and finding the one piece of software that needs reinstalling. Doing a single machine first and writing down what broke makes every subsequent one much faster.
What happens if we just stay on Windows 10?
The machines keep working. They simply stop receiving security fixes, so every vulnerability found from October 2025 onward stays open permanently. In Massachusetts that is not only a technical risk — 201 CMR 17.00 requires reasonably up-to-date security patches on systems holding personal information, so an unsupported operating system is a gap in a program you are legally required to maintain.