Latest / The Windows Podcast with Fexingo: Microsoft, PC, and Enterprise Windows Conversations / Why Enterprise Windows 11 Requires a New PC Strategy
Transcript
- Lucas: So Microsoft has been pretty clear that Windows 11 requires specific hardware — TPM 2.0, a supported processor, at least 4 gigs of RAM. But here's the thing that a lot of enterprise IT teams are only waking up to now: running Windows 10 past the October 2025 end of support deadline is about to get a lot more expensive and risky. Luna: Right, because extended security updates aren't cheap. But I think the bigger surprise is how many machines in active enterprise use still can't run Windows 11 at all. Lucas: Exactly. Lansweeper did a survey in late 2025 — they looked at over 10 million Windows devices across enterprise environments. And roughly 15 percent of them still lacked TPM 2.0. Another 20 percent were running processors that Microsoft explicitly excludes from the supported list. That's a huge chunk of hardware that's effectively stranded. Luna: Stranded is the right word. Those machines can't be upgraded in place, and they can't be reimaged with Windows 11. So IT has to either replace them or pay for extended support on an operating system that's increasingly vulnerable. Lucas: And the extended support pricing is designed to discourage exactly that. Microsoft's published rates for Windows 10 Extended Security Updates in 2026 are 75 dollars per device for the first year. That doubles in year two, and doubles again in year three. For a company with 10,000 stranded machines, that's 750,000 dollars in year one, then one point five million, then three million. Luna: And that's just the Microsoft fee. It doesn't account for the IT labor to apply those patches, the compliance audits, or the potential cyber insurance premium hikes if you're running an unsupported OS. Lucas: Right. I talked to the director of IT infrastructure at a mid-sized manufacturer — about 4,000 employees. They did a hardware audit in January and found 600 machines that are Windows 11 incompatible. Most were Dell OptiPlex 3050s from 2017. The cost to replace them is about 1,200 dollars per machine, so roughly 720,000 dollars. But the three-year extended support cost for those same machines would be about 585,000 dollars. So replacement actually looks cheaper when you factor in the productivity gains from newer hardware. Luna: That math is really tight. But I think a lot of CFOs still balk at the upfront capital expenditure. They'd rather spread the cost with extended support, even if it's more expensive over time. Lucas: And that's the tension. The IT team sees the long-term risk, but the finance team sees the budget line. The thing that's shifting the conversation now is cyber insurance. More carriers are explicitly asking about OS version support status during underwriting. If you're running Windows 10 without ESU after October 2025, some policies may exclude coverage for breaches that exploit known vulnerabilities. Luna: That is a huge deal. Suddenly the discussion isn't just about IT budget — it's about corporate risk exposure at the board level. Lucas: So there's a real argument for accelerating the refresh cycle. And that's actually what a lot of enterprises are doing. Gartner projected that 2026 would see the highest PC refresh rate since 2020, driven almost entirely by Windows 11 compatibility. Luna: Which brings up a practical question: for those machines that are compatible but older — say a 2019 Intel Core i5 — does it make sense to upgrade the hardware or just replace the whole unit? Lucas: For enterprises, replacing the whole unit is almost always the better call. The labor cost to upgrade a TPM module or swap a motherboard is high, and you still end up with an old machine that may have other failure points. Most IT departments I've talked to have a three to four year refresh cycle for standard office workers, and they're just pulling forward replacements for the 2027 cohort into late 2026. Luna: That makes sense. But what about the virtualization workaround? Some IT teams are talking about running Windows 11 as a virtual machine on older hardware using Hyper-V or VMware. Is that viable? Lucas: Technically, yes, but it's a management headache. You need the host OS to be supported, and the VM still has to meet the hardware requirements. Plus you're adding overhead and complexity. I've seen it done in labs or for specific legacy apps, but not as a broad strategy. Microsoft's licensing also gets tricky — you need Windows Enterprise per-device or per-user licenses for each VM. Luna: So really, the only clean solution is to buy new hardware. And that means IT procurement teams need to be planning their 2027 budgets right now, because lead times on enterprise desktops are still around 8 to 12 weeks. Lucas: Especially if you're ordering in volume. I've heard of companies waiting 16 weeks for custom-configured Lenovo ThinkCentres. So the window to order for a January 2027 deployment is basically closing this fall. Luna: And if today's tech conversation gave you something usable — a number, a timeline, a way to frame the budget discussion — that's exactly the kind of thing that keeps this show ad-free. If you'd like to support the work, you can buy us a coffee at buy me a coffee dot com slash fexingo. Lucas: Yeah, honestly it makes a real difference. Even a small contribution helps cover hosting and research time, and it means we never have to run ads or sponsored segments. Luna: So back to the hardware timeline — one thing that's interesting is that Microsoft has been quietly expanding the supported processor list. In early 2026, they added some Intel 7th-gen chips that were originally excluded. Do you think that trend will continue? Lucas: Possibly, but I wouldn't count on it. The additions have been very narrow — mostly specific SKUs that were already in wide enterprise deployment. Microsoft's goal is to drive the hardware base forward, not to accommodate legacy machines indefinitely. My read is that the list is basically final for mainstream support. Luna: So the takeaway for IT leaders is: audit your fleet now, identify incompatible machines, and build a replacement plan that accounts for both the hardware cost and the extended support penalty. Because waiting until September 2026 is going to be painful. Lucas: Absolutely. And the most painful part might be the security gap. Even with ESU, you're only getting critical security patches — not feature updates, not non-security fixes, and definitely not the hardware driver support that keeps newer peripherals working. Over time, those machines become islands. Luna: Islands that are expensive to maintain. So the decision really is: pay now or pay more later. Lucas: Exactly. And for most organizations, paying now — with a structured, multi-year refresh plan — is the smarter financial move. The key is to start the conversation with finance and the board before the emergency hits. Luna: And that's a conversation that's easier to have when you have the numbers. A 15 percent stranded-device rate at a company with 50,000 endpoints means 7,500 machines to replace. At 1,200 each, that's 9 million dollars. But spread over three years, it's manageable. Lucas: Right. And if you can bundle that with a broader technology refresh — say moving to Windows 11 Enterprise with Microsoft 365 E5 — you can often negotiate volume discounts that bring the per-unit cost down. I've seen deals where the hardware effectively costs 900 dollars per seat after bundling. Luna: So there's actually a strategic opportunity here, not just a compliance burden. Companies that refresh early can standardize on a modern security baseline and potentially reduce their cyber insurance premiums. Lucas: That's the optimistic framing. But I also want to be realistic: not every IT department has the political capital to push through a nine-figure refresh. So what we're seeing is a lot of tiered approaches — replace machines for high-risk users first, then roll out to the general population over 18 months. Luna: Makes sense. Prioritize executives, remote workers, and anyone handling sensitive data. Meanwhile, the manufacturing floor or the call center can wait a bit longer, as long as they're on extended support. Lucas: Exactly. And that's actually the most practical path for most enterprises. The key is to have a documented plan that your auditor and your insurer can see. Because the worst outcome isn't running Windows 10 — it's running Windows 10 without a plan. Luna: Well said. Next time, we'll talk about the specific security features in Windows 11 that actually justify the hardware upgrade — the ones that aren't just marketing. Lucas: That's a great follow-up. We'll see you then.