Windows 10 1607 (LTSB) EOL Oct 13, 2026 – 90-Day Action Plan
If you are still running Microsoft Windows 10 1607 (Enterprise LTSB), the support clock is about to run out. October 13, 2026 is the end-of-life (EOL) date, and that is roughly three months away. That is not enough time for a full, planned migration for most estates. The real task now is to contain the risk, document the exposure, and secure a third-party support contract before the first patch gap appears.
This is a long-term support (LTS) release, version 10.0.14393. Active support ended on October 12, 2021. You have been on extended security-only updates since then. When the final date passes, those updates stop entirely.
Here is the practical, week-by-week action plan for the next 90 days.
What actually changes on October 13, 2026
On the EOL date, Microsoft stops producing security patches, hotfixes, and non-security updates for Windows 10 1607. There will be no further CVE mitigations, no driver updates, and no technical support from the vendor. Systems still running this version after that date are operating without a safety net. Malware, exploits, and compliance findings that were previously patched will now remain unpatched.
Week 1: Complete an inventory of all affected systems
You cannot manage what you have not counted. Run discovery across your entire fleet: servers, workstations, virtual machines, and containers. Identify every instance of Windows 10 1607 by build number 10.0.14393. Include systems that may have been forgotten — lab environments, spare machines, edge devices.
- Document the hostname, role, network zone, and business owner for each system.
- Identify dependencies: which applications, databases, or network services rely on these machines.
- Flag any system that has an active internet connection or handles regulated data (PCI, HIPAA, SOX).
Week 2: Segregate and harden what cannot move
For any system that cannot be migrated or decommissioned before October 13, immediately reduce its attack surface.
- Move affected machines to a restricted network segment with strict firewall rules. Block all outbound internet access unless explicitly required and approved.
- Apply application whitelisting (Windows Defender Application Control or a third-party tool) so only approved executables can run.
- Ensure the OS is on the absolute latest cumulative update available. There will be no more after October.
- Disable unnecessary services, RDP if possible, and remove local admin rights for non-administrative users.
- Verify antivirus/EDR agents are installed and receiving updates independently from the OS.
Week 3: Document exposure for auditors and insurers
Your compliance and insurance teams need to know about the EOL systems. Prepare a risk register entry for each affected system.
- State the system purpose, the last patch date, and the compensating controls you have applied (network isolation, whitelisting, monitoring).
- Note the regulatory impact. Many compliance frameworks (PCI DSS 4.0, NIST 800-53, SOC 2) require vendor-supported software. An EOL OS is a finding — but a documented risk acceptance with compensating controls is often acceptable for a finite period.
- Share the register with your internal audit team and your cyber-insurance underwriter before the EOL date. It is better to have a remediation plan on file than to be asked about it after an incident.
Week 4: Establish a third-party support contract
You need a safety net for the day after EOL. A third-party support contract for Windows 10 1607 will provide:
- Custom security patches for critical vulnerabilities discovered after October 13, 2026.
- Technical support for break-fix issues that are not handled by Microsoft after EOL.
- Compliance coverage — the vendor will work within your regulatory framework to provide patched binaries.
Do not wait until a zero-day hits. A contract signed now, with onboarding complete before October, means you have a single point of contact for post-EOL incidents.
Weeks 5–12: Execute migration sprints for the easy targets
Even if a full migration is impossible, you can likely move some systems. Prioritize:
- Systems with no business-critical dependencies.
- Systems that can be re-imaged to Windows 10 22H2 or Windows 11.
- Systems running in virtual machines that can be rebuilt from a templated golden image.
- Systems that can be retired because the application or service they supported has been deprecated.
Assign a clear owner and deadline for each migration sprint. Use the remaining weeks to reduce the count, even if only by 10–20%.
Week 13: Final validation and go-live checklist
One week before EOL:
- Confirm all third-party support agreements are signed and the onboarding is complete.
- Verify the hardening and isolation controls are in place for every remaining Windows 10 1607 system.
- Update your incident response playbook to include a scenario where a post-EOL vulnerability is exploited on one of these machines. Define who to call, what to isolate, and how to apply an emergency patch from the third-party support provider.
- Send a final notification to the business owners of affected systems, acknowledging the risk and stating the remediation timeline.
After October 13, 2026: The ongoing posture
From day one post-EOL, these systems are unsupported by Microsoft. Your third-party support contract is now your primary lifecycle extension. Keep the inventory current, review the risk register quarterly, and plan to migrate each system in the next hardware refresh cycle or application upgrade.
You have roughly three months. Use them wisely: inventory, isolate, document, and contract. That is the realistic path through this last call.
For more details on the lifecycle of this and other Microsoft products, see our vendor page on Microsoft. To discuss a custom support agreement for Windows 10 1607, contact our team.
Get support for what you run
How we can help
Keep it supported after end of life
The vendor's date doesn't have to be yours. Our engineers keep Microsoft Windows 10 1607 (E) (LTS) running after official support ends — independent third-party support that covers most operational issues, typically at 40-70% below the last renewal quote.
Microsoft software support →Migration services
When you do decide to move, we plan and execute the migration. Your current environment stays under vendor support while your contract is active — and if the renewal lapses mid-move, our third-party support covers most issues until the last workload is off it.
Migration & hybrid cloud services →24×7 remote administration
Short on hands to run it day to day? Our NOC engineers monitor, patch and administer your environment around the clock — incident response included, at a fraction of the cost of an in-house night shift.
24/7 operations & remote administration →More EOSL Alerts
VMware Site Recovery Manager 9.0: EOL September 2027
VMware Site Recovery Manager 9.0 reaches end of life on September 17, 2027. Learn what that means for your budget, migration timelines, and third-party support
August 17, 2026
VMware Cloud Foundation 9.0 EOL September 2027
Plan your budget now: VMware Cloud Foundation 9.0 ends support Sept 17, 2027. Compare upgrade, vendor extended support, and third-party support costs to stay se
August 17, 2026
VMware ESXi 9.0 EOL September 2027
VMware ESXi 9.0 ends support Sept 17, 2027 – 13 months away. Plan next year's budget: compare migration costs with third-party support savings of 40–70%.
August 17, 2026