Jump to content

Recommended Posts

Posted

Sources: Microsoft / ZDNet / NCSC

 

Today is the 14th of January. If you look after Windows devices on an enterprise network, that date may be ringing a few bells. If not, it probably should be, because we’re exactly one year away from Windows 7 going out of extended support.

 

Why is this important?

As Microsoft say in their article on what this means, “An unsupported version of Windows will no longer receive software updates from Windows Update. These updates include security updates that can help protect your PC from harmful viruses, spyware, and other malicious software which can steal your personal information. Windows Update also installs the latest software updates to improve the reliability of Windows—such as new drivers for your hardware”.

 

Many of you will remember when Windows XP went out of support in 2014. It wasn’t long after that before exploitation of the final version of the platform became fairly widespread. Malware can spread much more easily on obsolete platforms because, without security updates, known vulnerabilities will remain un-patched. As a result, it’s crucial to move away from them as quickly as possible.

 

Stay up to date

Windows 10, version 1809 is the latest version of the Windows and we’re working on guidance for its new features as I write this. We currently have published EUD guidance for Windows 10 1803 when using both MDM management, or traditional Active Directory management. However, don’t wait for us to release guidance for the new version (1809) before upgrading – the 1803 guidance will continue to work just fine on 1809.

 

Whilst we’re on the subject, it’s worth thinking about how long your Windows 10 devices will be supported for. Windows 10 support lifetime depends on which edition you use: Home/Pro editions of 1709 go out of support in April this year, and Enterprise/Education editions of 1607 do likewise, so you should be updating as soon as possible if you haven’t already.

 

Upgrade not an option?

If you’re really stuck and unlikely to make the deadline, there are some steps you can take to minimise the risk of using obsolete platforms.

 

Whilst these measures won’t remove the risks entirely, there are some practical steps you can take to lower them in our Obsolete Platforms Security Guidance. Risk managing obsolete platforms comes at a cost (e.g. of usability due to limited access or functionality), so you should really only do this as a last resort.

 

We know there are costs involved in keeping up to date. However, doing so is one of the most effective ways of keeping your networks and devices secure - this is why planning your upgrades far in advance is especially important.

 

Microsoft introduced Windows 7 in July, 2009. A number of enterprise customers didn't begin deploying Windows 7 well into its lifecycle, and in some cases, only months before Windows 10 debuted in July, 2015. Microsoft officials said as of last fall that more than half of all Windows devices in the enterprise were running Windows 10, with the rest running Windows 7 and other older versions of Windows. Yet the support clock has ticked on.

 

Microsoft officials have announced two ways that Windows 7 users can continue to get security updates beyond the January 14, 2020 date. Both of these ways are designed for business customers, not consumers.

 

Microsoft will sell paid Windows 7 Extended Security Updates (ESUs) on a per-device basis, with the price increasing each year. These ESUs will be available to any Windows 7 Professional and Windows 7 Enterprise users with volume-licensing agreements, and those with Windows Software Assurance and/or Windows 10 Enterprise or Education subscriptions will get a discount. These ESUs will provide Windows 7 Extended Security Updates through January 2023.

 

Microsoft also will provide ESUs for no additional cost to customers who buy the Microsoft Windows Virtual Desktop service, which is designed to to allow users to virtualize Windows 7 and 10, Office 365 ProPlus apps and other third-party applications by running them remotely in Azure virtual machines. Those wanting to virtualize Windows 7 after Microsoft support ends in January 2020 will be able to do so for three years by using WVD. WVD still is not available in public preview, but is expected to be sometime this calendar quarter. Microsoft has not yet announced a final availability date or pricing for WVD.

 

A related reminder: As of January 14, 2020 -- the date when Microsoft is slated to stop providing support for Windows 7 -- Microsoft will no longer support Office 365 ProPlus on Windows 7. Customers paying for ESUs will continue to receive support for Office 365 ProPlus on Windows 7 for up to three years after that date, however. In addition, there are more Microsoft products for which support is ending on January 14, 2020: Exchange Server 2010, Windows Server 2008/R2, and Windows 7 for Embedded Systems (but not Windows Embedded Standard 7)..

 

I've had several Windows 7 users ask me if Microsoft might end up extending Windows 7 support for everyone beyond January because a number of customers won't be ready to move off it. I have not seen or heard any indications for such a move. And users shouldn't read into Microsoft's decision to bring the coming Chromium-based version of Edge to Windows 7 as Microsoft planning to extend Windows 7 support. Microsoft's plan to bring Edge to Windows 7 is meant to support those who pay for extended support beyond January 2020 -- and to throw a bone to those still figuring out their post-Windows-7 migration plans.

Posted

Also don't forget your 2008 and 2008R2 machines which have the same end of life. These likely have more troublesome software.

 

Whilst I'm at it, CentOS 6 ends only a couple of months later.

Posted (edited)
I did most of the AD/GP (and profiles) prep needed for 7 when I played with Vista, but never deployed that, so I rolled it out quite early in its lifecycle. Never regretted it. It feels dated now, but it and its server variants were quality software. Edited by 3s-gtech
Posted
I feel old. I remember deploying Windows 7 when it was quite new.

 

So when do we have to upgrade @FN-GM by? ;)

 

[Don't worry, in a work sense I used to deploy XP when it was new and 98 before that.]

  • Thanks 1
Posted
So when do we have to upgrade @FN-GM by? ;)

 

[Don't worry, in a work sense I used to deploy XP when it was new and 98 before that.]

 

Ha Ha. I am still in support!

  • Thanks 1
Posted
I dis most of the AD/GP prep needed for 7 when I played with Vista, but never deployed that, so I rolled it out quite early in its lifecycle. Never regretted it. It feels dated now, but it and its server variants were quality software.

 

At least Windows 7 actually listened to the AD/GP prep you did! :S

Posted
I've been playing a bit with OpenVAS lately to proactively check systems for known vulnerabilities. One of the things it threw up when I was playing with it was a massive "10.0" red alert for OS EOL on one of my Linux VMs. Ubuntu 12.04 LTS and I'd completely forgotten that it needed upgrading. I can see me using OpenVAS or similar a lot more from now on as security and updates become even bigger parts of the job.
  • Thanks 1
Posted (edited)
Also don't forget your 2008 and 2008R2 machines which have the same end of life. These likely have more troublesome software.

 

Whilst I'm at it, CentOS 6 ends only a couple of months later.

 

Technically the plain Windows Server 2008 is already End Of Life (so, if you have that, upgrade asap ;)). It's only Windows Server 2008 R2 that is supported in the same time frame.

 

 

[update] Ok, I stand corrected: See below.

Edited by DJ-1701
  • 4 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...