Inventory
- Export device, edition, build, hardware compatibility, owner and last connection.
- Add critical applications, drivers, peripherals, security agents and recovery method.
- Separate active workstations from spares, laboratories, operational equipment and unused nodes.
- Review LTSC and IoT separately because their lifecycle may differ from Windows 10 22H2.
Choose a route
- Upgrade a compatible device to a supported OS after application testing.
- Replace hardware when the limitation is genuinely physical and verified.
- Use ESU temporarily with an owner, budget and end date.
- Isolate a specialist node and remove ordinary mail and web access.
- Retire the device or move the workload to a supported alternative platform.
One route for every machine looks simple in a report but is usually more expensive and risky than segmentation.
Validate applications and data
- Test authentication, printing, digital signatures, VPN, macros, browser extensions and integrations.
- Verify user profiles, encryption, backup and rollback.
- Use pilot groups from real business teams, not only IT.
- Give support explicit success criteria and known limitations.
Govern residual risk
An ESU device remains a transition asset, not the new baseline. Limit administrator rights, control applications, use modern authentication and segment the network. A dashboard should show a declining count and a reason for every delay.
The project ends when old devices leave directories, access is revoked, data is erased or transferred, and users and support understand the new operating process—not when hardware is purchased.

