Where each version stands
| Version | Status | Support ends | Notes |
|---|---|---|---|
| Windows 11 25H2 | Current | 12 October 2027 | Current servicing branch. |
| Windows 11 24H2 | Supported | 13 October 2026 | Under two months of runway. If your fleet is here, the next feature update is already due. |
| Windows 11 23H2 | Out of support | 11 November 2025 | Home and Pro out of servicing. |
| Windows 10 (all editions) | Out of support | 14 October 2025 | No feature or security updates. ESU enrolment runs to 12 October 2027 as a bridge only. |
Supported upgrade routes
Read this before you plan anything else. A route that is not supported is not a route, and finding that out mid-window is how a maintenance weekend turns into a restore from backup.
- Windows 10 22H2 Windows 11 25H2 Direct In-place works where the hardware qualifies. TPM 2.0 and Secure Boot are the usual blockers on a 2019-era workstation.
- Windows 10, hardware not eligible hardware replacement Windows 11 25H2 Two step There is no supported software route past the TPM and CPU requirements. Budget the machine.
- Windows 11 23H2 or 24H2 Windows 11 25H2 Direct Feature update, not a migration. But it is annual, and that is the part that gets missed.
Windows 10 went out of support on 14 October 2025. Almost a year later, at least one major VMS still lists it as a supported client platform, which tells you something useful about how far vendor support matrices lag the platforms underneath them.
Operator workstations are usually further behind than the servers, and they get less attention, because the server is the thing with a maintenance contract and the workstation is the thing in the guard house. They also carry more peripheral risk than any other machine in the estate.
Find them separately from the office fleet
Security operator workstations are frequently outside the standard build, because at some point the VMS client needed something the corporate image did not permit and somebody made an exception. That exception means they do not appear in the normal refresh cycle.
Look for Security Desk and Config Tool, badge printing stations, alarm monitoring positions, and any workstation driving a video wall. The last one is often the oldest machine in the building and the hardest to replace.
Hardware is the gate, and it is not about performance
The Windows 11 requirements that catch operator workstations are TPM 2.0, Secure Boot, and the supported CPU list. A machine bought in 2019 to drive a six-panel video wall usually has plenty of performance left and still fails on CPU generation. That is a procurement conversation, not a technical one, and it needs to start early enough to land in a budget.
There are unsupported ways around the hardware check. Do not use them on a workstation that watches a building. An unsupported install can stop receiving updates at any point, which puts you back in the position you were trying to leave, with less visibility into it.
Peripherals are what actually break
This is the part that separates a security workstation from a desktop. PTZ joysticks and keyboard controllers, badge printers, card encoders, signature pads, smart card middleware for operator logon, and video wall controllers. Every one needs a driver for the target build, and some vendors simply never shipped one.
Badge printers deserve special mention because they fail quietly. The driver installs, the printer works, and the colour handling has changed just enough that the cards come out slightly wrong. Nobody notices until a batch has been issued.
Move one position, run a shift
A control room is a poor place to discover that PTZ control feels different or that the monitor order changed. Migrate one operator position, run it through a complete shift including a handover to the next crew, and collect what the operators actually say. Then roll the fleet.
This is now an annual task
The part that gets missed in budgeting: Windows 11 feature updates retire on roughly a twelve-month cadence. 24H2 goes out of servicing in October 2026, 25H2 a year after that. Staying supported is a recurring operational task, not a migration you complete once.
Get it into the operational calendar alongside the server lifecycle, because the two need to stay inside each other’s support matrices, and a workstation that drifts three feature updates behind can be the thing that blocks a VMS upgrade under the three-version rule.
The plan
- 01
Separate operator workstations from office desktops in the inventory
They get managed differently, refreshed on different cycles, and often sit outside the standard SOE because a VMS client needed something the image did not allow. Find them specifically: Security Desk, Config Tool, badge printing, alarm monitoring, and any workstation with a video wall output.
- 02
Check the VMS client against Windows 11, and check the version
Client platform support lags. Confirm the exact VMS client build is supported on the exact Windows 11 servicing branch you are targeting, not just on Windows 11 generally.
- 03
Test the hardware gates before promising a date
TPM 2.0, Secure Boot, and the supported CPU list are where operator workstations fail. A 2019 machine bought for a video wall often misses on CPU generation even when it has plenty of performance left. Run the readiness check across the fleet before committing to a schedule.
- 04
Rebuild the peripheral story
Operator workstations carry hardware that office desktops do not. Multi-monitor and video wall controllers, joystick and keyboard controllers for PTZ, badge printers, signature pads, card encoders. Every one of those needs a driver for the target build, and some vendors never shipped one.
- 05
Move one position, run a full shift, then move the rest
A SOC is not a place to discover that PTZ control feels different. Migrate one operator position, run it through a complete shift including a handover, collect what the operators say, then roll the fleet.
- 06
Set the annual servicing expectation with whoever owns the budget
Windows 11 feature updates retire on roughly a twelve-month cadence. That is a recurring task now, not a one-off migration, and it needs to be in the operational plan rather than rediscovered each October.
Pre-flight checklist
Print it, or hand it to whoever is doing the work. Every line is something I have seen bite a real migration.
- Every workstation running a VMS or access control client, listed separately from office desktops
- Current Windows build and edition on each
- TPM 2.0 present and enabled, Secure Boot state, CPU against the supported list
- VMS client version, and whether it is supported on the target Windows build
- Attached peripherals: video wall controllers, PTZ keyboards, badge printers, encoders, signature pads
- Local accounts, cached credentials, and anything stored only on the machine
- Driver availability confirmed for every peripheral on the target build
- VMS client compatibility confirmed against the exact servicing branch
- Operator profile, layout, and saved views documented or exported
- Video wall layout captured, because it will not survive
- One position identified as the pilot, with a shift agreed for it
- Rollback: a known-good image and the time it takes to restore
- Hardware that passes on performance but fails on CPU generation
- PTZ joystick and keyboard drivers with no Windows 11 release
- Badge printer drivers that install but silently change colour handling
- Multi-monitor arrangements that reorder after the upgrade
- Saved operator layouts that live in a local profile and are not backed up
- Smart card middleware and reader drivers used for operator logon
- Full shift run on the pilot position before the fleet moves
- PTZ control tested by an operator, not by a technician clicking once
- Badge print output compared against a known-good card
- Video wall layout rebuilt and saved
- Alarm audio confirmed at the right output and volume
- Annual feature-update cadence added to the operational calendar
Questions that come up
Windows 10 is out of support but our VMS still lists it as supported. What do we do?
Treat the Microsoft date as the real one. A vendor support matrix telling you Windows 10 is supported means the vendor will help you troubleshoot their software on it. It does not mean the operating system is receiving security patches, and it is not. Plan the move.
How long can Extended Security Updates carry a Windows 10 fleet?
Enrolment runs until the programme ends on 12 October 2027. That is a bridge for machines you genuinely cannot move yet, and it is worth using to sequence a fleet rather than rushing it. It is not a substitute for the migration.
Our operator workstations fail the Windows 11 hardware check. Is there a workaround?
There are unsupported workarounds and you should not use them on a workstation that watches a building. An unsupported install can stop receiving updates at any time, which puts you back where you started with less visibility. Budget the hardware.
What is the thing that most often goes wrong?
Peripherals. Not the operating system, not the VMS client. The PTZ keyboard, the badge printer, or the video wall controller turns out to have no driver for the target build, and it surfaces in the middle of a shift because nobody tested it under real use.
Do we have to do this every year now?
Effectively yes. Windows 11 feature updates retire on roughly a twelve-month cadence, so staying supported is an annual task rather than a one-time migration. Get it into the operational calendar and the budget line, because rediscovering it each autumn is how fleets fall behind.
References
- Windows 10 support has ended on October 14, 2025Microsoft Supportsupport.microsoft.com
- Extended Security Updates (ESU) program for Windows 10Microsoft Learnlearn.microsoft.com
- Windows lifecycle FAQMicrosoft Learnlearn.microsoft.com
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.