Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Important
Looking for consumer information? For individuals or Windows 10 Home customers, more information about Extended Security Updates for Windows 10 is available in the following resources:
- For more information on enabling ESU for home use see, Windows 10 Consumer Extended Security Updates (ESU) program
- For general information, see the frequently asked questions section of the End of support for Windows 10 page.
The Windows 10 Extended Security Updates (ESU) program allows organizations to receive critical and important security updates for PCs enrolled in the paid subscription service. ESU extends the use of Windows 10 devices past the end of support date on October 14, 2025. This article provides instructions on how to enable the ESU keys in commercial environments.
Prerequisites
To enable ESU for Windows 10, you must meet the following prerequisites:
- Windows 10, version 22H2 with KB5046613, or a later update installed
- Administrative privileges on the device
Endpoints for client activation:
- https://go.microsoft.com/
- https://login.live.com
- https://activation.sls.microsoft.com/
- http://crl.microsoft.com/
- https://validation.sls.microsoft.com/
- https://activation-v2.sls.microsoft.com/
- https://validation-v2.sls.microsoft.com/
- https://displaycatalog.mp.microsoft.com/
- https://licensing.mp.microsoft.com/
- https://purchase.mp.microsoft.com/
- https://displaycatalog.md.mp.microsoft.com/
- https://licensing.md.mp.microsoft.com/
- https://purchase.md.mp.microsoft.com/
Microsoft 365 admin center:
Cloud and virtualization scenario considerations
Some cloud and virtualization scenarios have specific considerations for enabling ESU. In some cases, ESU is already enabled for you and in others, you may need to take additional steps. The following list summarizes these scenarios:
- Extended Security Updates (ESU) are available at no additional cost for Windows 10 virtual machines in the following Microsoft-hosted or Azure-integrated environments. No additional configuration or keys are needed in the following environments: - Azure Virtual Desktop
- Azure virtual machines
- Azure Dedicated Host
- Azure Local (Azure Local is the new name for Azure Stack HCI)
- Azure Stack Hub
- Azure Stack Edge
- Windows 365 Cloud PCs
 
- Other virtualization platforms (such as Nutanix, Citrix, or Omnissa Horizon on Azure VMware Solution): These platforms require manual ESU key activation. Contact your Microsoft account team to obtain a 5x5 key. Activation can be managed with the Volume Activation Management Tool or with a script. 
Extended Security Update for local devices accessing Windows 365
Windows 10 devices accessing Windows 365 Cloud PCs: Windows 10 devices accessing Windows 365 Enterprise Cloud PCs and Windows 365 Frontline Cloud PCs in dedicated mode are automatically entitled to ESU for the duration of the ESU offer if the user has an active Windows 365 Enterprise license assigned or Windows 365 Frontline Cloud PC in dedicated mode provisioned, provided the following conditions are met:
- The local Windows 10 device is either Microsoft Entra joined or Microsoft Entra hybrid joined.
- Devices that are only Entra registered or on-premises Active Directory joined aren't eligible for commercial ESU access with Windows 365. Windows Autopatch enrollment is not a requirement. Personal or BYOD devices that are not managed by the organization and are only Entra registered will not qualify for this entitlement. These devices should be enrolled via the Consumer ESU program. An eligible user can activate up to 5 devices.
 
- Users must sign in to their Windows 10 devices using the same Microsoft Entra ID account they use for Windows 365 Cloud PCs at least once every month to maintain eligibility for ESU updates.
- IT administrators must use Microsoft Intune or another MDM provider to deploy a custom policy that enables the EnableESUSubscriptionCheck flag. This policy helps verify whether a device is enrolled in the Windows 10 ESU subscription program. For more details, refer to Licensing Policy CSP.
Note
ESU licenses will be automatically backfilled to your Windows 365 subscription and will appear in the Microsoft 365 admin center.
Verify ESU Enrollment for Windows 365 Users and Devices
Windows 365 Enterprise
To confirm ESU enrollment for Windows 365 Enterprise users:
- Go to Microsoft 365 admin center → Billing → Licenses. 
- Select Windows 365 Enterprise → Assign licenses. 
- Confirm the user has the Windows 10 ESU Commercial license. 
Windows 365 Frontline
To confirm ESU enrollment for Windows 365 Frontline users:
- In Microsoft 365 admin center: Billing → Your Products → Windows 365 Frontline. 
- In Intune admin center: Devices → Windows 365 → All Cloud PCs → Filter by Frontline Type = Dedicated. 
Verify ESU Enrollment on Devices
To verify if a device is enrolled in the ESU program:
- Deploy a PowerShell script via Intune to query the following registry key: - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\ESU- EnableESUSubscriptionCheck should be set to 1. 
Verify ESU Eligibility and Update Readiness
To confirm that a device has completed enrollment and is eligible to receive ESU updates:
- Use PowerShell via Intune to query: - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\ESU- Win10CommercialW365ESUEligible should be set to 1. 
- Check for Event ID 113 in Event Viewer → Applications and Services Logs → Microsoft → Windows → ClipESU. This event indicates that the W365 ESU license was successfully installed. 
Get the product keys for activating Extended Security Update (ESU) licenses
If you bought ESU licenses, you can activate them with Multiple Activation Keys (MAK) that you get from the Microsoft 365 admin center. To find the ESU license MAK, use the following steps:
- In the admin center, go to the Billing > Your Products page, then select the Volume licensing tab.
- In the Contracts section, select View contracts.
- On the Contracts page, find the License ID that the ESU licenses were purchased under, select the three dots (More actions), then select View product keys. The Product keys details page includes contract details and a list of all keys for that contract.
Note
After you purchase the ESU licenses, the MAK will appear in the Microsoft 365 admin center. You can activate the key and verify activation now, before it's required by updates released under the ESU program. The first ESU update which requires the activation will be the November 2025 security update.
Install and activate the ESU key
You manage licensing and activation on devices using slmgr.vbs. The device needs access to the internet and to Microsoft Activation Servers. If the device can't access either the internet or the Microsoft Activation Servers, see Activate ESU keys by phone. To install the ESU key on clients, use the following steps:
- Open an elevated Command Prompt window on the device. 
- Run the following command to install the ESU key, replacing - <ESU MAK>with the actual ESU MAK you obtained from the Microsoft 365 admin center:- slmgr.vbs /ipk <ESU MAK>- After you run this command, you should see a Windows Script Host dialog box that states the product key was installed successfully. 
- Find the ESU Activation ID using the following table: - ESU Program - Activation ID - Win10 ESU Year1 - f520e45e-7413-4a34-a497-d2765967d094 - Win10 ESU Year2 - 1043add5-23b1-4afb-9a0f-64343c8f3f8d - Win10 ESU Year3 - 83d49986-add3-41d7-ba33-87c7bfb5c0fb - Note - The activation IDs are the same across all eligible Windows ESU editions and all devices enrolled for that program. 
- From the elevated Command Prompt window, run the following command to activate the ESU key, replacing - <Activation ID>with the actual ESU Activation ID you obtained in the previous step:- slmgr.vbs /ato <Activation ID>- After you run this command, you should see a Windows Script Host dialog box that states the product was activated successfully. 
- To verify that the ESU key is installed and activated, run the following command from an elevated Command Prompt: - slmgr.vbs /dlv- The output should show the Name of the corresponding ESU program and the License Status as - Licensedfor that program.
Activate ESU keys by phone
If the device doesn't have access to the internet or to the Microsoft Activation Servers, use the following steps for a manual phone activation:
- Open an elevated Command Prompt window on the device. You'll be managing licensing and activation on devices using slmgr.vbs. 
- Run the following command to install the ESU key, replacing - <ESU MAK>with the actual ESU MAK you obtained in the previous section:- slmgr.vbs /ipk <ESU MAK>- After you run this command, you should see a Windows Script Host dialog box that states the product key was installed successfully. 
- To verify that the ESU key is installed, run the following command from an elevated Command Prompt: - slmgr.vbs /dlv- Note - The activation IDs are the same across all eligible Windows ESU editions and all devices enrolled for that program. 
- Find the ESU Activation ID using the following table: - ESU Program - Activation ID - Win10 ESU Year1 - f520e45e-7413-4a34-a497-d2765967d094 - Win10 ESU Year2 - 1043add5-23b1-4afb-9a0f-64343c8f3f8d - Win10 ESU Year3 - 83d49986-add3-41d7-ba33-87c7bfb5c0fb - Note - The activation IDs are the same across all eligible Windows ESU editions and all devices enrolled for that program. 
- Get the Installation ID (IID) from the device by run the following command in an elevated Command Prompt, replacing - <Activation ID>with the actual ESU Activation ID you obtained in the previous step:- slmgr.vbs /dti <Activation ID>
- Once you have the Installation ID, call the Microsoft Licensing Activation Center for your region. They'll walk you through the steps to get the Confirmation ID. Make a note of your Confirmation ID. You can also request to receive a text message with a link to a web page where you can look up your Confirmation ID by entering the Installation ID. The link can only be used for two devices at a time. 
- From the elevated Command Prompt window, run the following command to activate the ESU key, replacing - <Activation ID>with the actual ESU Activation ID you obtained from the chart and- <Confirmation ID>with the actual Confirmation ID you received from the Microsoft Licensing Activation Center:- slmgr.vbs /atp <Confirmation ID> <Activation ID>- Note - The - <Confirmation ID>shouldn't have spaces in it.
- To verify that the ESU key is installed and activated, run the following command from an elevated Command Prompt: - slmgr.vbs /dlv- The output should show the Name of the corresponding ESU program and the License Status as - Licensedfor that program.
Activate large numbers of devices that don't have internet access
For more information on how to do manual activation of large numbers of devices, review the Volume Activation Management Tool (VAMT) Proxy Activation scenario. You should install the latest Automated Deployment Kit (ADK) tool to ensure that you have the latest VAMT. You'll also need to install an update to the VAMT from https://www.microsoft.com/download/details.aspx?id=106364 so it includes updated PkeyConfig files for Windows 10 ESU MAK keys.
For more information on adding additional activations to a Windows 10 ESU MAK, see Request an increase to MAK activation limits.