Latest / The Windows Podcast with Fexingo: Microsoft, PC, and Enterprise Windows Conversations / Why Microsoft Is Killing Windows 10 With Configuration Changes
Transcript
- Lucas: If your enterprise is still running Windows 10 on older hardware, you may have noticed something frustrating happening this month. PCs that were working fine in April suddenly started showing a 'Your PC doesn't meet the minimum hardware requirements' watermark in the bottom-right corner. And in some cases, they're refusing to install the May cumulative update entirely. Luna: That sounds like Microsoft is quietly enforcing Windows 11's hardware requirements on Windows 10 machines. Are they actually backporting that check? Lucas: Exactly what happened. The May 2026 cumulative update for Windows 10 — KB5028245 — added a new compatibility check that flags CPUs older than Intel 8th-gen or AMD Ryzen 2000. If your system fails, the update either won't install or it installs and then triggers a 'hard block' flag that disables certain features. Luna: Wait, a hard block flag? That's a step beyond the watermark they showed on Windows 11 unsupported devices. What features get disabled? Lucas: It's mostly cosmetic and security-related at this point. The watermark, obviously. But also Windows Update will stop offering feature updates — not just the big 24H2-type updates, but also driver updates and critical security patches labeled as 'optional'. The system still gets mandatory security patches, for now. But the writing is on the wall. Luna: So Microsoft is effectively accelerating the end of life for Windows 10, which officially hit end of support in October 2025. But they extended paid support for enterprise customers through October 2027. This move seems to bypass that promise. Lucas: That's exactly the tension. Enterprises that paid for the Extended Security Updates, or ESU, expected three more years of full support. But Microsoft is now saying, 'You can have security patches, but we're not going to keep the OS running smoothly on old hardware.' It's a soft nudge — or maybe not so soft — toward upgrading. Luna: How many PCs are we talking about? I know Windows 10 still has a huge install base. Lucas: As of Q1 2026, about 38 percent of enterprise-managed PCs are still running Windows 10, according to Lansweeper. That's roughly 400 million devices globally. Of those, maybe a third have CPUs older than Intel 8th-gen — so we're looking at over 130 million machines that could be affected by this policy. Luna: And upgrading those machines isn't cheap. Even if you just swap the motherboard and CPU, you're looking at maybe $300 per device in parts and labor. But if you have to replace the whole system because the chassis doesn't support TPM 2.0, that's easily $800 to $1,200 per seat. Lucas: Right. And for many enterprises, they just finished a big Windows 10 deployment cycle in 2020 and 2021. They were expecting a 10-year lifecycle. Now Microsoft is saying, effectively, 'That lifecycle is now seven years.' The budget cycle doesn't align. Luna: So what's Microsoft's stated justification for this? They must have a rationale beyond just pushing Windows 11 adoption. Lucas: Their official line is security. They say that CPUs older than 8th-gen Intel lack certain hardware-level mitigations for speculative execution vulnerabilities like Spectre and Meltdown. And that running Windows 10 on those CPUs creates a support burden because they have to maintain separate code paths. But the timing is suspicious, coming right after Windows 10's mainstream support ended. Luna: There's also the TPM 2.0 requirement. Windows 11 requires it, Windows 10 doesn't — but now Microsoft is effectively saying that without TPM 2.0, you won't get a smooth Windows 10 experience either. That's a big deal for enterprises that skipped TPM 2.0 on their last hardware refresh. Lucas: And TPM 2.0 has been standard on business-class PCs since about 2016, so most enterprises that bought from Dell, HP, or Lenovo in the last five years should have it. But the problem is the CPU generation. If you bought a fleet of Dell OptiPlex 3060s in 2018, those have Kaby Lake CPUs — 7th-gen Intel. They have TPM 2.0, but they're now flagged as unsupported. Luna: That's the cruel part. Those machines are perfectly capable. They have SSDs, 16 gigs of RAM, TPM 2.0. They run Windows 11 just fine if you bypass the CPU check. But Microsoft is now saying no, even on Windows 10. Lucas: I've seen IT admins on Reddit and Spiceworks reporting that some of these machines actually boot-looped after the May update. Others got the watermark but no functional issues. It seems inconsistent, which makes it worse for IT support. They can't predict which machines will break. Luna: Is there a workaround? Can enterprises block the update or revert the check? Lucas: You can block the specific KB using Windows Update for Business or WSUS. But Microsoft has been known to force-apply compatibility checks through subsequent updates. The more sustainable fix is to either upgrade the hardware or move to Windows 11 on the same hardware with a registry bypass. But that bypass could stop working at any time. Luna: This feels like a repeat of the Windows 7 to Windows 10 transition, where Microsoft used similar tactics — like ending support for older processors in Windows 7 updates. But the difference is that Windows 7 had a much longer tail. Windows 10's tail is being cut short. Lucas: And that's partly because of the shift to a windows as a service model. Microsoft wants everyone on the latest feature update within 18 months. They've been explicit that Windows 10 is a 'dead end' for security innovation. They want to funnel everyone into Windows 11 and eventually the next version. Luna: For enterprises, the calculation is brutal. Upgrade now at a cost you didn't budget for, or risk being stuck on a degraded Windows 10 experience that might eventually stop getting even security patches. Neither option is good. Lucas: And there's also the Windows 11 adoption rate to consider. As of Q1 2026, only about 62 percent of enterprise PCs are on Windows 11. Microsoft wants that number closer to 90 percent. This policy is a lever to pull. Luna: Let's talk about the specific IT admin pain points. I've heard from a friend who works at a mid-size manufacturing company — they have about 2,000 Windows 10 machines, mostly Dell Precision workstations from 2017. After the May update, about 300 of them showed the watermark. Their IT team spent two weeks troubleshooting before they figured out it was the CPU check. Lucas: That's the kind of story that makes me angry on behalf of IT admins. Microsoft didn't announce this change prominently. It was buried in the KB article as a footnote. The first many admins knew about it was when their helpdesk tickets spiked. Luna: And the cost of troubleshooting those 300 machines — two weeks of a senior admin's time, plus the end-user productivity loss — probably exceeds the cost of upgrading a portion of the fleet. But the upgrade cost itself is significant. Lucas: The estimated per-device upgrade cost for hardware that meets TPM 2.0 but has an older CPU is around $80 if you just swap the motherboard and CPU, assuming you can find compatible parts. But for many enterprise systems, the motherboard is proprietary, so you're looking at a full system replacement. That's $800 to $1,200 per device, as you said. Luna: So for a company with 10,000 affected machines, that's $8 million to $12 million. That's not a trivial budget item. And it comes at a time when many IT departments are already stretched thin by the AI infrastructure buildout. Lucas: Exactly. And the alternative — staying on Windows 10 with degraded functionality — carries its own risks. If Microsoft eventually stops delivering security patches to those machines, they become a liability. You could argue that this is Microsoft's way of forcing enterprises to prioritize security, but the execution is heavy-handed. Luna: I want to step back for a second. We're talking about the Windows Podcast, and we've been able to cover this story without any sponsored content or ads. That's intentional. We deliberately don't run ads on these shows because we want the conversation to be about what actually matters, not what a sponsor wants you to hear. Lucas: That's right. And if you find value in that — if today's conversation gave you something usable for your own planning — the best way to support that choice is a small contribution at buy me a coffee dot com slash fexingo. It's what keeps the show independent. Luna: Yeah, it's a simple way to keep the lights on without any ads. We appreciate everyone who's done that. Now, back to the Windows 10 situation — I want to ask about the legal angle. Are there any grounds for enterprises to push back? Lucas: That's a good question. Some enterprises have volume licensing agreements that explicitly guarantee support for the licensed OS version. But those agreements usually have fine print about hardware compatibility. Microsoft could argue that they're still delivering security updates, just not guaranteeing a full feature set. It's a gray area. Luna: I recall that in 2024, a group of German companies considered a class-action over Windows 10's end of support timing. Nothing came of it. But this kind of move might reignite that sentiment. Lucas: It could. But realistically, most enterprises will just upgrade. The cost of legal action is higher than the cost of upgrading, especially for large companies. The ones that get hurt most are small and medium businesses that don't have the IT budget or the legal resources. Luna: What about the option of moving to Linux? Some enterprises might see this as the last straw. Lucas: There's been chatter about that. But for most enterprise workloads — Active Directory, Microsoft 365, line of business apps written for.NET — the switching cost is enormous. It's not realistic for most organizations. Microsoft knows that. Luna: So the real question is timing. When should an enterprise pull the trigger on upgrades? If they wait, they risk the situation getting worse. If they act now, they might upgrade to Windows 11 only to face a similar situation in a few years with the next Windows version. Lucas: That's the cycle. Microsoft's windows as a service model means you're constantly upgrading. The best strategy is to plan for a 3- to 4-year hardware refresh cycle and budget accordingly. But that's easier said than done when you have 10,000 machines. Luna: I want to end with a forward-looking question. Given this move, do you think Microsoft will apply similar pressure to Windows 11 users when the next version comes out? Will they start blocking older Windows 11 hardware from getting updates? Lucas: I think that's inevitable. Microsoft has signaled that Windows 12, or whatever they call it, will have even stricter hardware requirements — likely requiring NPUs for AI features. So the same playbook will apply. Enterprises need to be ready for a future where each Windows generation has a shorter supported hardware lifecycle. Luna: That means the cost of Windows over time isn't just the software licensing. It's the hardware refresh cycle that Microsoft increasingly controls. Lucas: Exactly. And that's the story that IT leaders need to communicate to their CFOs. Windows is no longer a once a decade capital expense. It's a recurring operational cost tied to hardware. The sooner that's baked into the budget, the fewer surprises like this May update.