Updated: October 23, 2025 (October 21, 2025)
Analyst ReportESUs Protect Systems Past Support
- Customers should subscribe to ESUs for any unsupported Microsoft software they run.
- Systems without ESUs are vulnerable to attack and risk cutoff from e-mail and other services.
- Azure and Windows 365 customers should exploit available discounts on any ESUs they need.
- Routine, long-term use of ESUs is a sign that the organization needs more time and resources to update software, or to replace software with cloud applications.
Extended Security Update (ESU) subscriptions deliver limited security updates for software that Microsoft no longer supports. Without required ESUs, a system running unsupported software versions could become the jumping-off point for an attack, and Microsoft might cut the system off from some services. Customers pay high, increasing fees for ESUs, although some Microsoft cloud services (such as Azure VMs) offer bundled ESUs. ESUs can keep unsupported software secure while the customer migrates to supported versions or alternatives, but they do not offer any other product support, and heavy use of ESUs is a symptom of an IT governance problem.
Atlas Members have full access
Get access to this and thousands of other unbiased analyses, roadmaps, decision kits, infographics, reference guides, and more, all included with membership. Comprehensive access to the most in-depth and unbiased expertise for Microsoft enterprise decision-making is waiting.
Membership OptionsAlready have an account? Login Now