Microsoft deadlines that need a plan

Six dates between March 2026 and October 2028, each with a client side consequence. What changes, who it hits, and what to check before it does.

At a glance

Counts update every time this page loads.

DateWhat changesStatus
31 Mar 2026 Basic authentication retired in Exchange Online Every client, script and service account still sending a username and password stops working. If something broke quietly in April, this is usually why. Passed
27 Jun 2026 Secure Boot 2011 certificates begin expiring Staged through October. Devices without the 2023 CAs stop trusting newly signed boot components. Existing installs keep booting, but the fleet stops accepting new updates. In progress
1 Oct 2026 Exchange Web Services disabled by default Tenants that did not set an AppID allow list get EWS switched off. Migration tools, backup products, room booking and CRM connectors are the usual casualties. Act now
13 Oct 2026 Windows 10 consumer ESU ends Enterprise customers can renew yearly to October 2028. Anything outside that programme stops receiving security updates entirely. Act now
1 Apr 2027 Exchange Web Services permanently retired No allow list, no re-enabling, no exceptions. Anything not moved to Microsoft Graph by this date stops working and cannot be turned back on. Plan now
Oct 2028 Windows 10 enterprise ESU ends for good The final renewable year. This is the real deadline for fleets that could not make the hardware jump in time. Plan now
Counts recalculate on every page load. Dates are Microsoft's published ones. Add to calendar

Each one in detail

Basic authentication retired in Exchange Online

31 Mar 2026

Basic authentication is gone from Exchange Online. Anything presenting a plain username and password to a mail endpoint no longer connects. The visible failures happened immediately, but the quiet ones are still being found: scheduled scripts, multifunction printers scanning to email, monitoring agents, and service accounts nobody had documented.

What to check

  • Search your scheduled tasks and automation servers for stored mail credentials.
  • Check every multifunction printer and scanner configured to send email.
  • Review service accounts that authenticate to Exchange but have no owner recorded.
  • Confirm monitoring and alerting agents moved to OAuth rather than being silently disabled.

Source: Microsoft Exchange Team blog

Secure Boot 2011 certificates begin expiring

27 Jun 2026

The Microsoft Corporation KEK CA 2011, Windows Production PCA 2011 and UEFI CA 2011 certificates expire in stages between June and October 2026. This affects physical and virtual machines across Windows 10, Windows 11 and Windows Server from 2012 onwards, including LTSC. Machines already carrying the 2011 UEFI CA continue to boot. What is lost is the ability to trust newly signed binaries and to apply future Secure Boot updates, which is a failure with no symptom until an audit finds it.

What to check

  • Report on which devices already carry the 2023 certificates. Most hardware built since 2024 does.
  • Identify devices that cannot receive them through the normal update path: restricted rings, offline machines, vendor controlled appliances.
  • Check virtual machine firmware templates that were built once and cloned since.
  • Cross reference against the Windows 10 replacement list. A device being retired first does not need this work.

Source: Windows IT Pro blog

Exchange Web Services disabled by default

1 Oct 2026

Phased disablement begins. Tenants that did not explicitly opt out have EWSEnabled set to false. Administrators can still re-enable it and approve named applications through an AppID allow list, so this is a hard stop with an escape hatch. That escape hatch closes permanently in April 2027.

What to check

  • Pull the EWS usage report from the Microsoft 365 admin centre and sort by application ID.
  • Name an owner for every calling application, including ones bought by facilities or finance.
  • Check room and desk booking panels specifically. They authenticate to your tenant and appear on no IT inventory.
  • Get every vendor's Graph migration position in writing, with a date.
  • If you set the allow list, record it as a dated exception with a review, not a resolution.
Read the full post: EWS goes dark in October, and your migration tool probably still uses it

Source: Microsoft Exchange Team blog

Windows 10 consumer ESU ends

13 Oct 2026

Windows 10 left standard support in October 2025. Consumer Extended Security Updates end here. Enterprise and education customers can continue to purchase ESU on a yearly basis for up to three years, taking coverage to October 2028.

What to check

  • Separate devices that need replacing from devices that can be upgraded in place.
  • Attach every ESU renewal to a dated reduction in the number of devices needing it.
  • Identify applications with no supported Windows 11 version and assign an owner to each vendor conversation.
  • Work backwards from October 2028 by eighteen months. That earlier date is your real deadline.
Read the full post: Windows 10 ESU is a bridge, not a plan

Source: Microsoft Windows ESU

Exchange Web Services permanently retired

1 Apr 2027

Final retirement. The allow list mechanism is withdrawn along with the protocol. Migration to Microsoft Graph is not a protocol swap: Graph uses a different permission model, and applications that relied on broad impersonation across mailboxes need scoped application permissions and the approvals that come with them.

What to check

  • Treat the six months from October as execution time, not decision time.
  • Budget for the security review that Graph application permissions will require.
  • Replace any vendor who cannot state a Graph migration date.
  • Test Graph based migration paths before you need them for a live cutover.
Read the full post: EWS goes dark in October, and your migration tool probably still uses it

Source: Microsoft Exchange Team blog

Windows 10 enterprise ESU ends for good

Oct 2028

The last year of the enterprise Extended Security Updates programme. After this there is no supported path that keeps Windows 10 patched. Fleets still running it are unsupported, which for most regulated environments is a compliance position rather than a technical one.

What to check

  • Count the devices that physically cannot run Windows 11 and treat that as a capital plan, not an IT ticket.
  • Start procurement early. The last six months is when every other organisation reaches the same supplier.
  • Identify the machines that must not be disturbed and give each one a named owner now.
Read the full post: Windows 10 ESU is a bridge, not a plan

Source: Microsoft Windows ESU

Tell me what is breaking.

Migration work, an estate that has outgrown its last design, or a question about the toolkit. All of it is welcome.

Follow the writing

Prefer RSS? Subscribe to the feed.