A helpdesk-grade checklist for Windows 10 ESU in 2026: fix missing enroll buttons, 'Something went wrong' errors, COMMERCIAL_DEVICE blocks, MAK activation and Intune rollout.
Windows 10 Extended Security Updates (ESU) is the paid or account-linked program that keeps Windows 10 22H2 receiving monthly security patches after the October 14, 2025 end-of-support date. Consumers get coverage through October 13, 2026 (extended to October 12, 2027 in the current program update), and commercial customers can subscribe through October 2028. Honestly, most enrollment failures we see in helpdesk tickets aren’t payment problems: they’re prerequisite gaps, device-classification mismatches, or the enroll wizard simply hasn’t rolled out to the device yet. This guide is the checklist my Tier 1 team follows for every ESU ticket, refined after a very messy October 2025.
ESU requires Windows 10 version 22H2 with the August 2025 cumulative (KB5063709) or later. Devices on 21H2 or older cannot enroll until they update to 22H2 first.
The consumer enrollment wizard only surfaces on devices Windows classifies as a “consumer” PC. Anything joined to Active Directory, Microsoft Entra ID, or an MDM is treated as COMMERCIAL_DEVICE and must use volume licensing or CSP.
The three consumer enrollment paths are: sync your Settings backup to OneDrive (free), redeem 1,000 Microsoft Rewards points, or pay the one-time $30 USD fee that covers up to ten devices tied to one Microsoft Account.
EEA residents receive free consumer ESU without the OneDrive-backup requirement under regional consumer-protection rules.
Commercial ESU activates with MAK keys via slmgr.vbs /ipk then slmgr.vbs /ato against the Year 1/2/3 Activation IDs. Intune can push both the MAK and the ESU add-on licence.
After a successful enrollment, Windows Update often still says “your device is not up to date” for up to 24 hours. That’s a known cosmetic bug, not a real failure.
Windows 10 ESU eligibility and prerequisites for 2026
Before you touch a single setting, verify the machine is actually eligible. In my queue at least one in four ESU tickets closes at this step, either because the device was never patched to 22H2 in the first place, or because a leftover work account is still attached from a laptop that got recycled between teams.
The hard requirements for both consumer and commercial ESU are:
Windows 10 version 22H2 (build 19045.x). That covers Home, Pro, Pro for Workstations, Pro Education, Education, Enterprise, or IoT Enterprise. Run winver to confirm. Devices on 21H2 or older editions must upgrade to 22H2 first; the enablement package is KB5015684.
The August 2025 cumulative or later, specifically KB5063709 or newer, which introduced the enrollment wizard code path. Devices missing this KB have no ESU UI at all.
The October 2025 servicing stack update, which is KB5066791 (it pulls in SSU KB5066790). This is what restored the ESU flow after the first rollout wave broke enrollment for a subset of consumer devices.
Windows must be activated. Settings → Update & Security → Activation must say “Windows is activated.” A machine with an activation grace period cannot enroll.
An administrator Microsoft Account. Consumer ESU is bound to an MSA, and that account must be an admin on the device. Child accounts are blocked by design.
For the commercial path, add a valid volume licensing agreement (MPSA, Enterprise Agreement, or CSP) plus the ESU add-on subscription. Server SKUs are out of scope here. Windows Server 2012/2012 R2 ESU is a separate program, and there’s overlap with what we cover in the Windows Autopatch troubleshooting guide around WSUS migration and ESU strategy.
How do I enroll in Windows 10 Extended Security Updates?
For a healthy consumer device on 22H2 with the October 2025 rollup installed, enrollment is genuinely three clicks. Walk your user through this before you touch anything else. Nine times out of ten the wizard just works and the whole ticket closes in ninety seconds.
Sign in to Windows 10 with an administrator Microsoft Account. Local accounts and child accounts are not eligible.
Open Settings → Update & Security → Windows Update. Just above the “Check for updates” button you should see a banner: “Your version of Windows has reached the end of service. Enrol in Extended Security Updates to keep receiving security updates.”
Click Enrol now. Pick one of the three paths: (a) sync PC settings backup to OneDrive (free), (b) redeem 1,000 Microsoft Rewards points, or (c) pay $30 USD one time to cover up to ten devices tied to that MSA.
If the banner is missing, don’t immediately assume the device is broken. Microsoft rolled the wizard out in waves through late October and November 2025, and a handful of late-adopter devices still receive the UI only after the November 2025 cumulative. Force a Windows Update scan, install everything pending, reboot, and re-check.
If you need to open the enrollment wizard manually (useful when the banner does not render but the underlying flow is present), paste this URI into Microsoft Edge’s address bar:
This launches the Settings deep link that the banner button uses internally. I keep it pinned in my runbook as a shortcut for remote sessions.
Why is the ‘Enroll now’ option missing from Windows Update?
This is the single most common ESU ticket in my helpdesk queue. The button is missing for three reasons in decreasing order of frequency: (1) the device is not on the current cumulative, (2) the device is classified as commercial, or (3) the wizard rollout hasn’t reached the device yet.
Work through this ordered checklist. Don’t skip ahead. Each step rules out a whole class of tickets.
Verify Windows 10 build.winver should show Version 22H2 (OS Build 19045.xxxx). If it says 21H2 or 21H1, install KB5015684 to move to 22H2, reboot, then re-check.
Install all pending cumulative and preview updates. Settings → Update & Security → Windows Update → Check for updates. You want at minimum KB5063709 (August 2025) and ideally KB5066791 (October 2025).
Confirm activation. Settings → Activation must read “Windows is activated with a digital licence.” Non-activated devices see no ESU UI.
Sign out and back in with an admin MSA. If the primary user is signed in with a local account or a domain account, add a Microsoft Account and elevate it to admin, then sign back in as that account.
Wait 24–48 hours if the fleet is small and you upgraded recently. Wizard rollout is server-flighted, so if you just installed KB5063709, the ESU UI may take a day or two to appear on that specific device.
If the banner is still missing after all five, treat the device as classified as commercial and jump to the next section.
Fixing ‘Something went wrong, we can’t enroll you right now’
This is the second-most-common ticket. The wizard appears, the user clicks “Enrol now,” a browser tab opens, they sign in with their MSA, and Windows throws “Something went wrong. We can’t enroll you in Extended Security Updates right now. Please try again later.” The error is deliberately generic; behind it are five distinct failure modes.
1. Child or family-managed Microsoft Account
If the MSA is a member of a Microsoft Family group with a “Child” role, enrollment is blocked with this exact error. Ask the family organiser to sign in at family.microsoft.com, either remove the account from the family group or convert its role to Adult / Organizer, then retry. I hit this exact bug on a Saturday call-out with a customer whose teenage son’s laptop was still attached to their family plan from 2022, and, honestly, we spent forty minutes on the KB search before I clocked it.
2. Region mismatch
Settings → Time & language → Region → Country or region must match the MSA’s registered country. A UK MSA on a device with region set to United States will fail with the generic error until the region matches.
3. OneDrive backup not actually completing
The “free via Windows Backup” path requires that Settings → Update & Security → Backup actually complete a successful sync of PC settings to OneDrive. If OneDrive is signed in but the folders you have selected (Desktop, Documents, Pictures) exceed the account’s free 5 GB quota, backup silently fails and ESU enrolment silently fails with it. Either free up quota or pick a different enrolment path.
4. Missing servicing stack update
Devices with KB5063709 but not KB5066791 can see the wizard but fail at the final step. Install the October 2025 rollup, reboot, retry.
5. Stale identity provider cache
Rare, but I’ve closed maybe a dozen tickets this quarter by clearing the WAM identity broker cache. From an elevated PowerShell:
Get-Process -Name explorer | Stop-Process -Force
Remove-Item -Recurse -Force "$env:LOCALAPPDATA\Microsoft\TokenBroker\Cache\*"
Start-Process explorer
Then sign the user out and back in, and retry enrollment. This is the same cache we clear when Microsoft 365 apps refuse to prompt for MFA. That behaviour is documented in our Microsoft 365 MFA troubleshooting guide.
COMMERCIAL_DEVICE and Active Directory classification blocks
Windows uses a device-classification signal called COMMERCIAL_DEVICE to decide whether the consumer ESU wizard should be offered. Anything Windows considers “managed” is flagged commercial and the consumer wizard is hidden entirely. Not disabled with an error, just hidden. This is where I get the “my personal laptop won’t enrol!” tickets from people who forgot they used to sign into a work account on it.
A device is treated as commercial if any of these are true:
Joined to on-premises Active Directory (whoami /upn returns a domain UPN).
Joined or registered to Microsoft Entra ID (dsregcmd /status returns AzureAdJoined: YES or WorkplaceJoined: YES).
Enrolled in an MDM (Intune, Workspace ONE, MobileIron, Kandji, and so on). Check Settings → Accounts → Access work or school.
Running in kiosk / assigned-access mode.
Has an unexpired work or school account in the credential store, even if the account itself is no longer signed in.
For a personal PC that got mis-flagged, the fix is to unregister everything and reboot:
REM Remove Entra ID / workplace registration
dsregcmd /leave
REM Remove any lingering work-or-school accounts
REM (Settings > Accounts > Access work or school > Disconnect)
REM If domain-joined, unjoin (requires local admin credentials with rejoin permission)
netdom remove %computername% /Domain:CONTOSO /UserD:admin /PasswordD:*
REM Reboot, then sign in with a personal MSA that is a local admin
shutdown /r /t 0
For genuinely commercial devices (the ones that belong on the domain), you do not want to unjoin them. Those go through commercial ESU with MAK activation, covered in the next section.
Commercial ESU activation with MAK keys and slmgr.vbs
Commercial ESU ships as a Multiple Activation Key (MAK) that you receive after purchasing the ESU add-on subscription through volume licensing or a CSP partner. Each year of ESU has its own MAK and its own Activation ID, and you must install and activate them in order. Year 2 cannot be activated on a device that never had Year 1 applied.
The Activation IDs are stable across the entire program and worth committing to your runbook:
Year
Coverage period
Activation ID
Year 1
Oct 15, 2025 – Oct 13, 2026
f520e45e-7413-4a34-a497-d2765967d094
Year 2
Oct 14, 2026 – Oct 12, 2027
1043add5-23b1-4afb-9a0f-64343c8f3f8d
Year 3
Oct 13, 2027 – Oct 10, 2028
83d49986-add3-41d7-ba33-87c7bfb5c0fb
To install and activate the Year 1 key on a domain-joined device, open an elevated command prompt and run:
REM Install the ESU product key
slmgr.vbs /ipk XXXXX-XXXXX-XXXXX-XXXXX-XXXXX
REM Activate against Microsoft activation servers
slmgr.vbs /ato f520e45e-7413-4a34-a497-d2765967d094
REM Verify activation
slmgr.vbs /dlv f520e45e-7413-4a34-a497-d2765967d094
The /dlv output should show Licence Status: Licensed and an expiration date matching the coverage period. If /ato fails with error 0xC004F074, the machine could not reach the Microsoft activation servers. Check outbound HTTPS to activation.sls.microsoft.com and any TLS-inspecting proxy that might be interfering. If it fails with 0xC004C060, the MAK has hit its activation cap and you need to contact the reseller for a new key. Microsoft’s canonical error-code reference lives in the Windows Server KMS activation planning guide, which despite the name is the authoritative source for these codes on the client side too.
For air-gapped or offline devices, use phone activation. Running slui.exe 4 launches the phone-activation wizard, which reads back an installation ID that you enter into the Microsoft activation call centre in exchange for a confirmation ID.
Deploying Windows 10 ESU with Intune and MDM
At scale, running slmgr.vbs by hand on 3,000 devices is not a plan. Intune and every serious UEM platform can push both the MAK and the activation trigger. The pattern I use for our own fleet has three moving parts.
Assign the ESU add-on licence to the device in the Microsoft 365 admin centre (or via CSP), grouped by an Entra ID device dynamic group filtered on device.operatingSystem eq “Windows” and device.operatingSystemVersion startsWith “10.0.19045”.
Push the MAK as a Win32 app or PowerShell script that runs slmgr.vbs /ipk with the key stored in a secure variable.
Push the activation trigger as a second script that runs slmgr.vbs /ato <Activation ID> and reports back exit code and licence status to Intune.
A minimal Intune remediation script looks like this. Drop it into the “Devices → Scripts and remediations” blade and target the same dynamic group:
If Intune remediation returns exit code 1 across many devices at once, check the Endpoint Analytics report for common patterns. In my experience it’s almost always a proxy rule blocking activation.sls.microsoft.com. For general Intune enrolment ticket triage before you get to this stage, see our Intune device enrolment troubleshooting guide.
Verifying ESU activation and troubleshooting missing updates
Once a device is enrolled, three signals should light up. If any of them is missing, you have work to do. If all three are present but Windows Update still claims “you are not up to date,” you’re looking at a known cosmetic bug and not a real failure.
Signal 1: Registry
For commercial ESU, this key confirms the ESU licence is present and current:
Expected: Licence Status: Licensed and a partial product key that matches what you installed.
Signal 3: A successful post-EOL cumulative
Any KB from November 2025 onward is proof the ESU pipeline is working end to end. Recent monthly ESU rollups include:
KB5075912 (November 2025)
KB5087544 (May 2026)
KB5094127 (June 2026)
KB5099539 (July 2026, a record-size Patch Tuesday)
If Windows Update shows the classic yellow “your device is missing important security and quality fixes” banner even after all three signals check out, wait 24 hours before opening a new ticket. Microsoft documented this cosmetic issue in the Enable Extended Security Updates documentation on Microsoft Learn, and it clears itself after the next scan cycle.
Consumer vs commercial ESU comparison
Because roughly a third of my inbound tickets are people asking “which one do I need?”, this table lives on our team wiki and on the fridge in the break room. Print it, laminate it, live it.
Dimension
Consumer ESU
Commercial ESU
Eligible devices
Unmanaged personal PCs on 22H2 signed in with an MSA
Domain-joined, Entra-joined, MDM-enrolled, or kiosk devices
Price (Year 1)
$30 USD one-time, up to 10 devices per MSA, or free via Rewards / OneDrive backup / EEA residency
$61 USD per device (Year 1), doubling each subsequent year
Maximum duration
Through October 12, 2027 (2 years with the current extension)
Through October 10, 2028 (3 years)
Activation method
Enrolment wizard in Windows Update, bound to MSA
MAK key + slmgr.vbs /ipk + slmgr.vbs /ato
Deployment scale
Per-device manual click-through
Intune / SCCM / GPO scripted rollout
Purchase channel
Microsoft Store
Volume Licensing, EA, MPSA, CSP partner
Region-specific rules
Free automatic enrolment for EEA residents
Uniform globally
The one place I see IT teams misroute a ticket: consumer ESU covers up to ten devices per MSA, so BYOD scenarios where a director has a personal laptop and their spouse’s laptop can share one $30 purchase. That’s not a commercial-ESU situation unless one of those devices is joined to your directory.
Frequently Asked Questions
Is Windows 10 ESU free in 2026?
Consumer ESU is free if you meet one of three conditions: sync your PC settings to OneDrive using Windows Backup, redeem 1,000 Microsoft Rewards points, or you live in the European Economic Area. Otherwise it’s a one-time $30 USD purchase tied to your Microsoft Account that covers up to ten devices. Commercial ESU is never free, and Year 1 alone is $61 USD per device.
How long does Windows 10 ESU last?
Consumer ESU currently runs through October 12, 2027 after Microsoft’s program extension, which gives two years of coverage from the October 14, 2025 end-of-support date. Commercial ESU can be renewed annually for up to three years, running through October 10, 2028 at the latest. There will not be a Year 4.
Why can’t I enroll in Windows 10 ESU even though I have a Microsoft Account?
The most common causes are: your MSA is classified as a child account in a Microsoft Family group, the device is on an older cumulative than KB5063709, the device is joined to Active Directory or Entra ID and is therefore flagged COMMERCIAL_DEVICE, or your OneDrive quota is full and the “free via Windows Backup” path silently fails. Work the checklist in the missing enrol button section in order.
Does Windows 10 ESU include feature updates or just security patches?
Security patches only. ESU delivers Critical and Important security updates as classified by the Microsoft Security Response Center, and nothing else. No feature updates, no non-security quality updates, no new drivers, no design changes, no bug fixes for anything that isn’t a security-classified vulnerability. If your users report a non-security bug on an ESU device, the answer is Windows 11 24H2.
Can I deploy Windows 10 ESU with Intune or SCCM?
Yes, commercial ESU is designed for exactly that. Assign the ESU add-on licence to the target Entra ID device group, then push the MAK and activation trigger with a two-part Intune remediation script (detection + remediation) or a ConfigMgr compliance baseline. Consumer ESU cannot be deployed with an MDM, because enrolling with an MDM is what flags a device as commercial in the first place.
Passkeys in Microsoft Entra ID keep failing over the same three things: Authenticator version, AAGUID allowlist, and Conditional Access. Here's the 2026 helpdesk runbook, with PowerShell diagnostics, cross-device QR fixes, and a passkey-vs-FIDO2-vs-Windows Hello comparison.
The five-check DHCP triage every helpdesk needs on Windows Server 2025: service and AD authorization, scope health, failover state, relay agents, and the KB5060842 service hang, all with paste-ready PowerShell.