Loading...

Action Required to Enable Extended Security Update for local devices accessing Windows 365

Action Required to Enable Extended Security Update for local devices accessing Windows 365

Windows 10 devices accessing Windows 365 Enterprise Cloud PCs and Windows 365 Frontline (Dedicated) Cloud PCs are automatically entitled to ESU under certain conditions. IT administrators must use Microsoft Intune or another MDM provider to deploy a custom policy that helps verify whether a device is enrolled in the Windows 10 ESU subscription program. Action is required in order for these devices to install the upcoming November 2025 Windows security update, which will be available on November 11, 2025. Learn more about this change at Enable Windows 10 Extended Security Updates (ESU) for clients accessing cloud and virtual machines. When will this happen: The upcoming November 2025 Windows security update will be available on November 11, 2025. It’s necessary to take action prior to this date, in order for devices to be eligible for this update.   Entitlement to ESU is available for qualifying devices any time. We advise taking action prior to November 11 in order to receive this month’s update. How this will affect your organization: Windows 10 devices accessing Windows 365 Enterprise Cloud PCs and Windows 365 Frontline Cloud PCs in dedicated mode are automatically entitled to ESU for the duration of the ESU offer if the user has an active Windows 365 Enterprise license assigned or Windows 365 Frontline Cloud PC in dedicated mode provisioned, provided the following conditions are met: IT administrators must deploy a custom policy that enables the EnableESUSubscriptionCheck flag. This policy helps verify whether a device is enrolled in the Windows 10 ESU subscription program. Microsoft Intune or another MDM provider can be used to deploy this custom policy. See the documentation To configure EnableESUSubscriptionCheck flag with Intune and the resources in the Additional Information section, below. The local Windows 10 device is either Microsoft Entra joined or Microsoft Entra hybrid joined. Users must sign in to their physical Windows 10 device using the same Microsoft Entra ID account they use for Windows 365 Cloud PCs at least once every 22 days to maintain eligibility for ESU updates on that device. Please also note the following: Physical devices that are only Microsoft Entra registered or […]

The post Action Required to Enable Extended Security Update for local devices accessing Windows 365 appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Action Required to Enable Extended Security Update for local devices accessing Windows 365

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

External messaging limits for onmicrosoft.com-only organizations in Microsoft Teams

Microsoft Teams will impose outbound external messaging limits starting mid-September 2026 for organizations using only the default onmicrosof...

3 days ago

Microsoft Teams: Enable agents for existing applications in your organization

For third-party applications already being used in your organization, admins can now discover and enable the corresponding Teams agents from w...

3 days ago

Microsoft Viva: Campaigns Hub in Engage and Engage in Teams mobile

The Campaigns Hub in Viva Engage provides a centralized mobile destination where employees can discover and participate in organizational camp...

4 days ago

Planner: Conditional Coloring

Conditional Coloring highlight tasks based on selected criteria, making priorities, status, and important task details easier to spot. Product...

4 days ago

Outlook: Offline settings “Days of email to save” admin policy

Tenant admins will be able to define the default value for “Days of email to save” in Offline settings and designate whether end u...

4 days ago

Microsoft Copilot Studio: Agent Sharing amongst makers

Enables sharing of agents with other makers in the new GHCP harness. Makers can grant other makers Agent Viewer (view analytics/evaluations on...

4 days ago

OneDrive Photos on Windows: admin controls and policy support

OneDrive Photos, integrated into the OneDrive sync app for Windows 10/11, is currently available only for personal Microsoft accounts, with wo...

4 days ago

Admin app retiring in Teams, Outlook and Microsoft365.com

The Admin app for very small businesses in Teams, Outlook, and Microsoft365.com will retire by October 2026, with rollout starting August 2026...

4 days ago

Calls popout into a new window on the browser to support multi-tasking and collaboration during a meeting

Microsoft Teams for Web will introduce a Picture-in-Picture Call Monitor in October 2026, allowing users to manage meeting controls in a separ...

4 days ago

Microsoft Windows Autopatch: September 2026 Windows security update requires a restart for hotpatch-enabled devices

The September 2026 Windows security update requires a restart for hotpatch-enabled devices because it is a standard update. Devices will remai...

4 days ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.