Windows 10 Extended Security Updates

rr-4098 2,121 Reputation points
2025-09-24T18:40:43.7333333+00:00

My organization purchased several ESU licenses so our remaining Windows 10 workstation can get updates while we migrate. From what I have read the license key needs to be updated on the impacted workstations, correct? If so, can this be done via KMS or AD Activation? Also we are using Intune to manage the devices

Windows for business | Windows Client for IT Pros | Devices and deployment | Install Windows updates, features, or roles
0 comments No comments
{count} votes

Answer accepted by question author
  1. Oliver Nguyen 1,400 Reputation points
    2025-09-24T19:56:25.2033333+00:00

    Hi rr-4098,

    You are correct that Windows 10 ESU licenses require activation on the affected workstations, but ESU licenses only use MAK (Multiple Activation Key) activation and cannot be activated through KMS or AD Activation.

    ESU Activation Method

    MAK Only - No KMS Support: Windows 10 ESU licenses are exclusively MAK-based and do not support KMS activation. There is no "ESU KMS" option available - Microsoft only provides ESU MAK keys through the Volume Licensing Service Center.

    Intune Deployment Method: Since you're using Intune, you can deploy the ESU MAK keys efficiently using PowerShell scripts. Create a PowerShell script with the ESU MAK and appropriate activation ID, then deploy it through Intune's Scripts or Remediation features.

    Implementation Steps

    Retrieve ESU MAK Keys: Access your ESU MAK keys through the Microsoft 365 admin center under Billing > Your Products > Volume licensing tab > View contracts > View product keys. The MAK keys will be listed along with your contract details.

    Use this PowerShell script template for Intune deployment:

    $ESU_MAK = "XXXXX-XXXXX-XXXXX-XXXXX-XXXXX"

    $ESU_Year = 1 # Set to 1, 2, or 3 based on your license

    $ActivationIDs = @{1 = "f520e45e-7413-4a34-a497-d2765967d094"

    2 = "1043add5-23b1-4afb-9a0f-64343c8f3f8d"

    3 = "83d49986-add3-41d7-ba33-87c7bfb5c0fb"

    }

    $ActivationID = $ActivationIDs[$ESU_Year]

    cscript.exe /b %windir%\system32\slmgr.vbs /ipk $ESU_MAK

    cscript.exe /b %windir%\system32\slmgr.vbs /ato $ActivationID

    Intune Deployment Process: Navigate to Devices > Scripts in the Intune portal, create a new PowerShell script deployment with administrative privileges enabled, and assign it to your Windows 10 device groups. Configure the script to run in 64-bit PowerShell with system privileges.

    =================================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.