Windows 11 22H2 (E) EOL 2025: Action Plan
The Clock Is Ticking on Windows 11 22H2 (E)
Microsoft Windows 11 22H2 (Enterprise) — version 10.0.22621 — reaches end of life (EOL) on October 14, 2025. That date marks the end of active support: no more security patches, no bug fixes, and no vendor SLAs for any issue.
If you still have systems running 22H2 (E), a complete migration to a newer release before October 14 is probably no longer realistic for most estates. That doesn't mean you're out of options. What matters now is using the remaining weeks wisely to minimize risk.
Here is what changes on October 14, what you should do immediately, and a week-by-week checklist to get your estate ready for life after EOL.
What Actually Changes on October 14, 2025
On the EOL date, Microsoft stops delivering:
- Security updates (including out-of-band patches for critical vulnerabilities)
- Non-security hotfixes
- Paid support incidents
- Public-facing documentation updates for 22H2 (E)
Your systems will still boot and run. But any new vulnerability discovered after October 14 will remain unpatched. Compliance frameworks (PCI DSS, SOC 2, HIPAA, etc.) and cyber-insurance policies often require active vendor support, so your risk profile changes the moment the clock strikes zero.
What to Do in the Next 12 Weeks
1. Inventory Every Affected System
Run a full discovery across your environment. Identify every device running Windows 11 22H2 (E). Include virtual machines, remote workers' endpoints, and any system that is not easily reachable via your management tools. Document the hostname, location, owner, and what role it serves.
2. Prioritize and Plan for the Holdouts
Not every system can be upgraded before October 14. For those that cannot, decide on a risk tier:
- Critical (exposed to internet or sensitive data): Isolate or harden immediately.
- Internal (limited network access): Apply additional access controls and monitoring.
- Legacy (air-gapped or isolated): Document the business justification and accept the residual risk.
3. Isolate and Harden Remaining Systems
- Place unsupported systems on a separate VLAN with strict firewall rules.
- Remove internet access unless absolutely necessary.
- Enable AppLocker or WDAC to block unauthorized executables.
- Ensure endpoint detection and response (EDR) agents are up to date.
- Disable unnecessary services and legacy protocols (SMBv1, RDP if not required).
4. Document Exposure for Auditors and Insurers
Create a formal risk acceptance memo that lists:
- All systems that will remain on Windows 11 22H2 (E) after October 14
- Justification for each system (e.g., application incompatibility, pending upgrade project)
- Mitigation controls already in place
- Planned remediation date (even if tentative)
- Signature of the risk owner (e.g., IT director or CISO)
Your auditors and cyber-insurance carrier will expect this documentation.
5. Line Up a Support Contract for Day One After EOL
Once vendor support ends, third-party support for Microsoft software can fill the gap. A provider like 3rd Party Support can deliver critical security patches, provide technical assistance, and help maintain compliance — all without forcing an immediate upgrade.
A support contract should be in place before October 14 so there is no gap in coverage. Negotiate now while you still have a few weeks.
Week-by-Week Action Checklist
Week 1–2: Discovery and Inventory
- Run automated scan across all endpoints.
- Cross-reference with CMDB or asset register.
- Identify all 22H2 (E) systems.
Week 3–4: Risk Triage
- Assign each system a criticality tier (Critical / Internal / Legacy).
- Identify systems that can be upgraded before October 14; start those upgrades immediately.
- For the rest, draft the risk acceptance memo.
Week 5–6: Isolation and Hardening
- Move critical holdout systems to isolated VLAN.
- Apply firewall rules to restrict outbound traffic.
- Enable and verify EDR / AV coverage.
- Harden OS settings per Microsoft security baseline for Windows 11.
Week 7–8: Documentation and Communication
- Finalize risk acceptance memo.
- Present to CISO / compliance team for sign-off.
- Notify affected business units about expected service levels.
- Update incident response runbooks to account for unsupported systems.
Week 9–10: Final Validation and Rollback Plans
- Test backup and restore procedures for each holdout system.
- Verify that isolation measures are working correctly.
- Ensure monitoring alerts are configured for anomalous behavior.
Week 11–12: Secure Post-EOL Support
- Sign third-party support agreement (if not already done).
- Confirm onboarding and escalation paths.
- Apply any final Microsoft patches released before October 14.
- Schedule a review for 30 days after EOL to reassess the risk posture.
After October 14: Life With Unsupported Windows 11 22H2 (E)
With the right preparation, running Windows 11 22H2 (E) after EOL does not have to mean running blind. Third-party maintenance can keep your systems patched, your auditors satisfied, and your operations stable while you plan a longer-term migration.
If your team needs help closing the gap before the deadline, contact us to discuss a support arrangement that starts on day one after EOL.
This article is based on lifecycle data from endoflife.date/windows.
Get support for what you run
How we can help
Keep it supported after end of life
The vendor's date doesn't have to be yours. Our engineers keep Microsoft Windows 11 22H2 (E) running after official support ends — independent third-party support that covers most operational issues, typically at 40-70% below the last renewal quote.
Microsoft software support →Migration services
When you do decide to move, we plan and execute the migration. Your current environment stays under vendor support while your contract is active — and if the renewal lapses mid-move, our third-party support covers most issues until the last workload is off it.
Migration & hybrid cloud services →24×7 remote administration
Short on hands to run it day to day? Our NOC engineers monitor, patch and administer your environment around the clock — incident response included, at a fraction of the cost of an in-house night shift.
24/7 operations & remote administration →More EOSL Alerts
VMware Site Recovery Manager 9.0: EOL September 2027
VMware Site Recovery Manager 9.0 reaches end of life on September 17, 2027. Learn what that means for your budget, migration timelines, and third-party support
August 17, 2026
VMware Cloud Foundation 9.0 EOL September 2027
Plan your budget now: VMware Cloud Foundation 9.0 ends support Sept 17, 2027. Compare upgrade, vendor extended support, and third-party support costs to stay se
August 17, 2026
VMware ESXi 9.0 EOL September 2027
VMware ESXi 9.0 ends support Sept 17, 2027 – 13 months away. Plan next year's budget: compare migration costs with third-party support savings of 40–70%.
August 17, 2026