EOSL Alerts

Action Plan: Windows 11 23H2 (W) EOL Nov 11, 2025

Updated 3rd Party Support Team

The Deadline Is Real: Windows 11 23H2 (W) EOL on November 11, 2025

Microsoft will end all support for Windows 11 23H2 (W) (build 10.0.22631) on November 11, 2025—roughly three months from today. This is not an LTS release, meaning no extended security updates, bug fixes, or vendor SLAs after that date. If your estate still runs this version, you are about to lose patch coverage, troubleshooting assistance, and compliance standing.

For most organizations, migrating every affected device to a supported version (e.g., 24H2) before November 11 is no longer realistic. That's not a failure—it's a fact of scale. The goal now is to prepare for the day after EOL responsibly and transparently.

What Actually Changes on November 11, 2025

On the EOL date, the following support doors close:

  • No more security patches. Any vulnerabilities disclosed after November 11 will not be addressed by Microsoft for 23H2.
  • No bug fixes or workarounds. Microsoft will not provide patches for stability, compatibility, or functional issues.
  • No vendor SLAs. You cannot open a support case with Microsoft for this version.
  • Compliance clock starts. Auditors, cyber insurers, and regulatory bodies will begin noting the unsupported status.

The system will still boot and run. But it becomes a static, unpatched target. The risk escalates with each subsequent CVE that affects the Windows 10/11 codebase.

What You Must Do Before November 11

You have roughly 12 weeks. Here is a concrete action plan broken into weekly phases.

Weeks 1–2: Inventory and Classify

  • Identify all systems running Windows 11 23H2 (W). Use your CMDB, SCCM, Intune, or a simple PowerShell script to query Get-ComputerInfo | Select-Object WindowsVersion, WindowsBuildNumber. Filter for build 22631.
  • Classify each system by role: user workstation, admin workstation, kiosk, test/dev, or standalone production.
  • Flag systems that cannot migrate before November 11. Note the reason (hardware compatibility, application dependency, vendor certification delays).

Weeks 3–4: Isolate and Harden

For all systems that will remain on 23H2 after EOL:

  • Network segment them. Place unsupported machines on a separate VLAN with restricted egress to the internet and limited lateral access to other segments.
  • Disable unnecessary services. Turn off RDP, SMBv1, remote PowerShell, and any non-essential network protocols.
  • Apply application whitelisting. If possible, use Windows Defender Application Control or AppLocker to allow only approved executables.
  • Lock down local admin rights. Remove all but essential administrative accounts.
  • Enable detailed logging. Forward Windows Event Log (especially Security and System) to your SIEM. Set alerting for anomalous login attempts or service starts.

Weeks 5–6: Document for Auditors and Insurers

  • Create a risk register entry for each segment or group of unsupported systems. Include:
    • System count and location
    • Reason for delayed migration
    • Mitigation measures (isolation, hardening, logging)
    • Planned migration date (and owner)
  • Brief your cyber insurance broker. Some policies require disclosure of unsupported OS versions. Provide your documented mitigations.
  • Update your incident response plan to include a specific procedure for responding to a CVE affecting unsupported 23H2 systems (e.g., immediate disconnection, forensic analysis, manual mitigation).

Weeks 7–8: Secure a Third-Party Support Contract

This is the most critical step for continued safety and compliance. When Microsoft's support ends, a third-party maintenance provider can fill the gap:

  • Patch coverage for critical CVEs that affect the Windows codebase (not just 23H2-specific quirks—Microsoft's own patches for newer versions often apply to the same underlying code).
  • Technical troubleshooting for stability and compatibility issues that arise after EOL.
  • Compliance support: Auditors and regulators accept a documented support contract with a qualified third party as a compensating control.

Choose a provider with demonstrated experience supporting enterprise Windows deployments. Do not wait until November 10 to sign the contract—start due diligence this week.

Weeks 9–10: Test and Plan the Migration Cadence

Even with a support contract in place, your goal should be to migrate off 23H2 as fast as possible. Use these two weeks to

  • Test the 24H2 upgrade in a representative subset of your isolated 23H2 systems. Note app compatibility, driver issues, and any new configuration requirements.
  • Draft a phased migration timeline—for example, 10% weekly after EOL, with go/no-go gates tied to observed stability.
  • Communicate the plan to stakeholders: IT leadership, affected business units, security team, and audit/compliance.

Weeks 11–12: Final Readiness Check

Seven days before the EOL date:

  • Confirm your third-party support contract is active and signed. Get a confirmation letter for your compliance records.
  • Run a final inventory. Are there any stragglers that were missed in week 1?
  • Verify isolation controls. Test that segmented machines cannot reach production VLANs or the internet.
  • Set calendar reminders for future migration milestones.

What Not to Do

  • Do not attempt a rushed, estate-wide 24H2 upgrade in the final weeks. This increases risk of widespread application breaks, user downtime, and support backlogs.
  • Do not assume “no incident means safe.” The EOL date is a binary change in vendor support posture—not a measure of current threat activity.
  • Do not ignore the documentation step. Cyber insurers and auditors will ask for proof of compensating controls. A written risk register and a third-party support contract are your best evidence.

Summary: Plan for the Day After, Not Just the Deadline

You cannot reverse the EOL date. But you can control what happens from November 12 onward. Inventory early. Isolate aggressively. Document everything. And secure a third-party support contract to fill the gap while you methodically migrate each system.

The organizations that treat this as a preparedness exercise—not a panic migration—will come out the other side with fewer incidents and stronger compliance posture.


Vendor lifecycle data sourced from endoflife.date/windows. See our Microsoft software support page for more details.

How we can help

Keep it supported after end of life

The vendor's date doesn't have to be yours. Our engineers keep Microsoft Windows 11 23H2 (W) running after official support ends — independent third-party support that covers most operational issues, typically at 40-70% below the last renewal quote.

Microsoft software support →

Migration services

When you do decide to move, we plan and execute the migration. Your current environment stays under vendor support while your contract is active — and if the renewal lapses mid-move, our third-party support covers most issues until the last workload is off it.

Migration & hybrid cloud services →

24×7 remote administration

Short on hands to run it day to day? Our NOC engineers monitor, patch and administer your environment around the clock — incident response included, at a fraction of the cost of an in-house night shift.

24/7 operations & remote administration →

Talk to a support specialist

Speak with an engineer, not a sales rep. We respond within 24 hours.

Your quote will be sent to this address.

By submitting this form, you agree to our Privacy Policy.