Jump to content

Recommended Posts

Posted

Hi,

 

We are using W10 with ESU (Extended Security Updates)

 

According to Microsoft we need:-

 

W10 22H2

KB5046613

 

Is anyone in a similar boat?

 

We`ve had issues getting KB5046613 to install.

 

 

Thanks,

Alastair

  • 2 weeks later...
Posted

I found that I didn't have to install KB5046613, I think it was superseded anyway. I did have to install the latest cumulative update otherwise trying to apply the MAK would give "Error: 0xC004E016 On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0cV004E016' to display the error text.'

 

I followed everything here https://learn.microsoft.com/en-us/windows/whats-new/enable-extended-security-updates

In short, that means:

1. Applying the MAK: slmgr.vbs /ipk <your MAK goes here>

2. Activating the first year key ESU: slmgr.vbs /ato f520e45e-7413-4a34-a497-d2765967d094

3. And you can then check it has applied with: slmgr.vbs /dlv

 

  • Like 2
Posted

Ironically, the 2025-10 version came out overnight (KB5066791) and KB5065429 got superseded on my WSUS. I've installed the new version and MAK activation still seems fine.

  • Like 1
Posted

Curious. It disappeared on the machine I was testing on yesterday. Although ESET keeps telling me it's an unsupported OS, so I need to figure out how to switch that off.

Posted
19 hours ago, robintech said:

all seems to go through for us and it says its licenced,  but windows update GUI still says you will no longer receive security updates

 

Same here. Have only tried on a couple of PCs so far.

Posted
1 hour ago, Dan23 said:

 

Same here. Have only tried on a couple of PCs so far.

Found this on a site about TSForge which seems to be more about bypassing Microsoft checks so I won't link it but they're having the same issue.

 

Quote

 

#I activated ESU with the TSforge, but the Windows Update page in Settings still saying "Your device is no longer receiving security updates." Why?

 

Microsoft provides Extended Security Updates (ESU) through several channels, such as CommercialAzureESU, CommercialW365ESU, CommercialKeybasedESU, and ConsumerESU.

TSforge activates the Commercial Key-based ESU, which is intended for use by administrators in business environments.

The Windows Update page in Settings is currently showing the incorrect status below to all CommercialKeybasedESU users.

image

It’s just a visual bug, and it even appears on Windows 10 LTSC 2021. Your ESU is activated correctly. Hopefully, Microsoft will fix it in the upcoming updates.

 

 

Posted

Was informed that this is way to check for ESU

For us planning to do a build, [patch up, confirm reg key then look at a mass redeployment to replace existing builds

 

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\ConsumerESU
If the ESUEligibility value is anything other than zero, ESU is enabled.

 

 

Posted
1 hour ago, Alastairb25 said:

Was informed that this is way to check for ESU

For us planning to do a build, [patch up, confirm reg key then look at a mass redeployment to replace existing builds

 

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\ConsumerESU
If the ESUEligibility value is anything other than zero, ESU is enabled.

 

 

Have a 1 there, still complains on Windows Update GUI.

Posted

Just adding a confirmatory data point. License reports installed, or endpoint management software matches, but the GUI says out of support.

 

When I asked my preferred AI how to tell, the answer seems to be that you'll know when you get an update. 

 

It couldn't be much less reassuring. Doors anyone remember if it was similar for Windows 7? I'd moved to Windows 10 years before the deadline, so don't have any previous experience.

Posted

I'm having the same problem here.  After installing and activating the ESU key we purchased from our reseller ("Windows 10 ESU Year 1 (2025 - 2026"), the Windows Update page in the Settings app is showing "Your version of Window has reached the end of support".  I get confirmation the product key has installed and activated successfully.

 

This is all 5 devices  I've tried so far.  All the devices are using Active Directory Based Activation against a KMS host server. We have the Volume Activation Tools role installed on a server and this has been setup with our KMS key and has always worked really well, activating everything.

In the registry (HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\ConsumerESU), the ESUEligibility value is 1.  Not sure how reliable this is an indicator of whether we will receive future security updates though.

I've contacted our reseller and asked them to escalate this to Microsoft on our behalf but not heard anything back yet.

Posted

I'm now wondering if I really did see the "end of support" message disappear, as I've had it remain with further machines. Probably comes down to it being badly setup by Microsoft.

Posted

Oddly, when looking at a a client with slmgr /dlv it shows the ESU activation and it's Licensed, but also shows the old KMS activation too. Don't want to remove that from AD as it activates some servers.

Posted (edited)
2 hours ago, 3s-gtech said:

Oddly, when looking at a a client with slmgr /dlv it shows the ESU activation and it's Licensed, but also shows the old KMS activation too. Don't want to remove that from AD as it activates some servers.

I get this too. Here's a typical output of slmgr /dlv here.

 

Microsoft (R) Windows Script Host Version 5.812
Copyright (C) Microsoft Corporation. All rights reserved.

Software licensing service version: 10.0.19041.6456

Name: Windows(R), Education edition
Description: Windows(R) Operating System, VOLUME_KMSCLIENT channel
Activation ID: <withheld>
Application ID: <withheld>
Extended PID: <withheld>
Product Key Channel: Volume:GVLK
Installation ID: <withheld>
Partial Product Key: <withheld>
License Status: Licensed
Volume activation expiration: 250630 minute(s) (175 day(s))
Remaining Windows rearm count: 1001
Remaining SKU rearm count: 1001
Trusted time: 21/10/2025 10:52:35
Configured Activation Type: All

Most recent activation information:
AD Activation client information
    Activation Object name: Windows 10/11 Product Activation <withheld>
    AO DN: <withheld>
    AO extended PID: <withheld>
    AO activation ID: <withheld>


Name: Windows(R), Client-ESU-Year1 add-on for Education,EducationN,Enterprise,EnterpriseN,Professional,ProfessionalEducation,ProfessionalEducationN,ProfessionalN,ProfessionalWorkstation,ProfessionalWorkstationN,ServerRdsh,Core,CoreN,CoreCountrySpecific,CoreSingleLanguage,IoTEnterprise,PPIPro
Description: Windows(R) Operating System, VOLUME_MAK channel
Activation ID: f520e45e-7413-4a34-a497-d2765967d094
Application ID: <withheld>
Extended PID: <withheld>
Product Key Channel: Volume:MAK
Installation ID: <withheld>
Use License URL: https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
Validation URL: https://validation-v2.sls.microsoft.com/SLWGA/slwga.asmx
Partial Product Key: <withheld>
License Status: Licensed
Remaining Windows rearm count: 1001
Remaining SKU rearm count: 1001
Trusted time: 21/10/2025 10:52:37

 

 

I actually tried removing the KMS activation from a test device and installing/activating the ESU MAK key and Windows didn't like this at all and refused to activate.  Wondering whether the ESU licence isn't actually a standalone licence and it needs a 'base' licence installed for it to show as 'Licenced'.  The words 'add-on' in the Name field might suggest this is true but regardless, even when slmgr /dlv shows it as Licenced, Windows Update is saying otherwise.

I thought there may be others having this same issue but it doesn't seem as widespread as I thought. Maybe most organisations have already upgraded to Win11.  We still have about 15% of our devices on Win10 and as this ESU programme exists we thought it best to pay a nominal fee to keep them going for a year before replacing with new machines in next years budget.

 

Read somewhere that Microsoft issued some faulty ESU keys to resellers. Who knows, we could be affected by that. Can't even get a response from our reseller/distributor at the moment. 

Edited by toffee_paul
Posted (edited)

Well, my test laptop got the Windows 10 22H2 October 2025 CU last night, now it's showing it has reached end of support.

 

Will be interesting to see what happens. We may have to wait a month!

Edited by 3s-gtech
Checked last CU
Posted
19 hours ago, 3s-gtech said:

You can screenshot what you see in Windows Update? I'm just testing this on one of my old clunker laptops.

This is what all my test machines show.  I had a response back from our reseller and the say the distributor is aware of other customers having issues with ESU but didn't go into details about what that might be.  Just have to play the waiting game and see what they come back with.

Untitled1.png

Posted

yeah, tons of folks ran into that one. kb5046613 is finicky with win10 esu, especially on 22h2 systems that had paused updates or older servicing stacks. try manually installing the latest ssu (kb5039354 i think) before running the kb5046613 standalone installer. if that fails, clear out the softwaredistribution folder and run dism /online /cleanup-image /restorehealth. that usually gets it to stick.

Posted

I get "This update is not applicable to your computer" with both of these updates.

 

All my devices are Win10 22H2 and are on the October 2025 cumulative update so these updates aren't applicable. Windows Update for Business is in place and they've never been paused for updates.

 

Tried deleting SoftwareDistribution folder and the DISM command and still no luck.

Posted

KB5046613 is just the Nov 24 CU, no? https://www.catalog.update.microsoft.com/Search.aspx?q=KB5046613

 

As above, I applied the latest CU. Without it the MAK gave an error when trying to apply.

 

I think it's a case of seeing if further security updates apply. I've got a Win 10 machine at home which is enrolled in the free updates, so my plan is to keep an eye on what that gets and see whether it's reflected on the machines here. It's further complicated here by updates coming via MEMCM, but that's still set to pick up Win 10 updates and apply them.

Posted

I've been thinking I might grudginly go ESU (Home environment). I'd like to install the final Win 10 update before hand - KB5066791. I'm short on diskspace but in spite of a large amount of files to a 1TB, I constanly get c drive full. Diskcleanup no longer seem to work. The file properties for size just doesn't seem to update reliably. The Windows update is now saying I need anywhere from 77MB to 790MB of space. I suspect the fact it is also trying to install KB5066747 and KB890830 isn't helping. Is there a way to clear down updates (empty C:\Windows\SoftwareDistribution\Download) downloads and then run the 2 other update manually before once again trying KB5066791? Ultimately I need a large boot device and I have plans, but right now I just want to get up to date and then go ESU.

Posted

So I finally got it to install eventually by releasing about 4Gb (massive OST move - and that was a pain) but Windows update continued to report lack of space, but after a few reboots and runs of Windows update troubleshooter and another reboot I finally slumped over the line. So that's the last Win 10 update other than if/when I sign up to ESU. That was the worst and most troublesome Win 10 update I've had to deal with - sad finish really to Win 10 - coincidence or bad luck - you decide!

 

I know I'm just delaying the inevitable, even if that inevitability is a Rufus Win 11 install.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...