BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//amylifecycle//Microsoft deadlines//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Microsoft deadlines 2026 to 2028
X-WR-CALDESC:Retirement and end of support dates that need a plan
BEGIN:VEVENT
UID:basic-auth@amylifecycle.com
DTSTAMP:20260905T013143Z
DTSTART;VALUE=DATE:20260331
SUMMARY:Basic authentication retired in Exchange Online
DESCRIPTION:Basic authentication is gone from Exchange Online. Anything pre
 senting a plain username and password to a mail endpoint no longer connect
 s. The visible failures happened immediately\, but the quiet ones are stil
 l being found: scheduled scripts\, multifunction printers scanning to emai
 l\, monitoring agents\, and service accounts nobody had documented.\n\nWha
 t to check:\n- Search your scheduled tasks and automation servers for stor
 ed mail credentials.\n- Check every multifunction printer and scanner conf
 igured to send email.\n- Review service accounts that authenticate to Exch
 ange but have no owner recorded.\n- Confirm monitoring and alerting agents
  moved to OAuth rather than being silently disabled.\n\nSource: https://te
 chcommunity.microsoft.com/blog/exchange/exchange-online-ews-your-time-is-a
 lmost-up/4492361\nMore: https://amylifecycle.com/deadlines/#basic-auth
URL:https://amylifecycle.com/deadlines/#basic-auth
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P30D
ACTION:DISPLAY
DESCRIPTION:30 days until Basic authentication retired in Exchange Online
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:secure-boot@amylifecycle.com
DTSTAMP:20260905T013143Z
DTSTART;VALUE=DATE:20260627
SUMMARY:Secure Boot 2011 certificates begin expiring
DESCRIPTION:The Microsoft Corporation KEK CA 2011\, Windows Production PCA 
 2011 and UEFI CA 2011 certificates expire in stages between June and Octob
 er 2026. This affects physical and virtual machines across Windows 10\, Wi
 ndows 11 and Windows Server from 2012 onwards\, including LTSC. Machines a
 lready carrying the 2011 UEFI CA continue to boot. What is lost is the abi
 lity to trust newly signed binaries and to apply future Secure Boot update
 s\, which is a failure with no symptom until an audit finds it.\n\nWhat to
  check:\n- Report on which devices already carry the 2023 certificates. Mo
 st hardware built since 2024 does.\n- Identify devices that cannot receive
  them through the normal update path: restricted rings\, offline machines\
 , vendor controlled appliances.\n- Check virtual machine firmware template
 s that were built once and cloned since.\n- Cross reference against the Wi
 ndows 10 replacement list. A device being retired first does not need this
  work.\n\nSource: https://techcommunity.microsoft.com/blog/windows-itpro-b
 log/act-now-secure-boot-certificates-expire-in-june-2026/4426856\nMore: ht
 tps://amylifecycle.com/deadlines/#secure-boot
URL:https://amylifecycle.com/deadlines/#secure-boot
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P30D
ACTION:DISPLAY
DESCRIPTION:30 days until Secure Boot 2011 certificates begin expiring
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:ews-disabled@amylifecycle.com
DTSTAMP:20260905T013143Z
DTSTART;VALUE=DATE:20261001
SUMMARY:Exchange Web Services disabled by default
DESCRIPTION:Phased disablement begins. Tenants that did not explicitly opt 
 out have EWSEnabled set to false. Administrators can still re-enable it an
 d approve named applications through an AppID allow list\, so this is a ha
 rd stop with an escape hatch. That escape hatch closes permanently in Apri
 l 2027.\n\nWhat to check:\n- Pull the EWS usage report from the Microsoft 
 365 admin centre and sort by application ID.\n- Name an owner for every ca
 lling application\, including ones bought by facilities or finance.\n- Che
 ck room and desk booking panels specifically. They authenticate to your te
 nant and appear on no IT inventory.\n- Get every vendor's Graph migration 
 position in writing\, with a date.\n- If you set the allow list\, record i
 t as a dated exception with a review\, not a resolution.\n\nSource: https:
 //techcommunity.microsoft.com/blog/exchange/exchange-online-ews-your-time-
 is-almost-up/4492361\nMore: https://amylifecycle.com/deadlines/#ews-disabl
 ed
URL:https://amylifecycle.com/deadlines/#ews-disabled
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P30D
ACTION:DISPLAY
DESCRIPTION:30 days until Exchange Web Services disabled by default
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:win10-consumer-esu@amylifecycle.com
DTSTAMP:20260905T013143Z
DTSTART;VALUE=DATE:20261013
SUMMARY:Windows 10 consumer ESU ends
DESCRIPTION:Windows 10 left standard support in October 2025. Consumer Exte
 nded Security Updates end here. Enterprise and education customers can con
 tinue to purchase ESU on a yearly basis for up to three years\, taking cov
 erage to October 2028.\n\nWhat to check:\n- Separate devices that need rep
 lacing from devices that can be upgraded in place.\n- Attach every ESU ren
 ewal to a dated reduction in the number of devices needing it.\n- Identify
  applications with no supported Windows 11 version and assign an owner to 
 each vendor conversation.\n- Work backwards from October 2028 by eighteen 
 months. That earlier date is your real deadline.\n\nSource: https://www.mi
 crosoft.com/en-us/windows/extended-security-updates\nMore: https://amylife
 cycle.com/deadlines/#win10-consumer-esu
URL:https://amylifecycle.com/deadlines/#win10-consumer-esu
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P30D
ACTION:DISPLAY
DESCRIPTION:30 days until Windows 10 consumer ESU ends
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:ews-retired@amylifecycle.com
DTSTAMP:20260905T013143Z
DTSTART;VALUE=DATE:20270401
SUMMARY:Exchange Web Services permanently retired
DESCRIPTION:Final retirement. The allow list mechanism is withdrawn along w
 ith the protocol. Migration to Microsoft Graph is not a protocol swap: Gra
 ph uses a different permission model\, and applications that relied on bro
 ad impersonation across mailboxes need scoped application permissions and 
 the approvals that come with them.\n\nWhat to check:\n- Treat the six mont
 hs from October as execution time\, not decision time.\n- Budget for the s
 ecurity review that Graph application permissions will require.\n- Replace
  any vendor who cannot state a Graph migration date.\n- Test Graph based m
 igration paths before you need them for a live cutover.\n\nSource: https:/
 /techcommunity.microsoft.com/blog/exchange/exchange-online-ews-your-time-i
 s-almost-up/4492361\nMore: https://amylifecycle.com/deadlines/#ews-retired
URL:https://amylifecycle.com/deadlines/#ews-retired
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P30D
ACTION:DISPLAY
DESCRIPTION:30 days until Exchange Web Services permanently retired
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:win10-enterprise-esu@amylifecycle.com
DTSTAMP:20260905T013143Z
DTSTART;VALUE=DATE:20281010
SUMMARY:Windows 10 enterprise ESU ends for good
DESCRIPTION:The last year of the enterprise Extended Security Updates progr
 amme. After this there is no supported path that keeps Windows 10 patched.
  Fleets still running it are unsupported\, which for most regulated enviro
 nments is a compliance position rather than a technical one.\n\nWhat to ch
 eck:\n- Count the devices that physically cannot run Windows 11 and treat 
 that as a capital plan\, not an IT ticket.\n- Start procurement early. The
  last six months is when every other organisation reaches the same supplie
 r.\n- Identify the machines that must not be disturbed and give each one a
  named owner now.\n\nSource: https://www.microsoft.com/en-us/windows/exten
 ded-security-updates\nMore: https://amylifecycle.com/deadlines/#win10-ente
 rprise-esu
URL:https://amylifecycle.com/deadlines/#win10-enterprise-esu
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P30D
ACTION:DISPLAY
DESCRIPTION:30 days until Windows 10 enterprise ESU ends for good
END:VALARM
END:VEVENT
END:VCALENDAR
