Alastairb25 Posted October 6, 2025 Posted October 6, 2025 Hi, We are using W10 with ESU (Extended Security Updates) According to Microsoft we need:- W10 22H2 KB5046613 Is anyone in a similar boat? We`ve had issues getting KB5046613 to install. Thanks, Alastair
Gongalong Posted October 15, 2025 Posted October 15, 2025 I found that I didn't have to install KB5046613, I think it was superseded anyway. I did have to install the latest cumulative update otherwise trying to apply the MAK would give "Error: 0xC004E016 On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0cV004E016' to display the error text.' I followed everything here https://learn.microsoft.com/en-us/windows/whats-new/enable-extended-security-updates In short, that means: 1. Applying the MAK: slmgr.vbs /ipk <your MAK goes here> 2. Activating the first year key ESU: slmgr.vbs /ato f520e45e-7413-4a34-a497-d2765967d094 3. And you can then check it has applied with: slmgr.vbs /dlv 2
BOOT Posted October 15, 2025 Posted October 15, 2025 And make sure TCP port 1688 outbound is not blocked.
andy_b Posted October 15, 2025 Posted October 15, 2025 (edited) KB5065429 should cover the update prerequisites. Edited October 15, 2025 by andy_b
Gongalong Posted October 15, 2025 Posted October 15, 2025 Ironically, the 2025-10 version came out overnight (KB5066791) and KB5065429 got superseded on my WSUS. I've installed the new version and MAK activation still seems fine. 1
robintech Posted October 15, 2025 Posted October 15, 2025 all seems to go through for us and it says its licenced, but windows update GUI still says you will no longer receive security updates
Gongalong Posted October 16, 2025 Posted October 16, 2025 Curious. It disappeared on the machine I was testing on yesterday. Although ESET keeps telling me it's an unsupported OS, so I need to figure out how to switch that off.
Dan23 Posted October 16, 2025 Posted October 16, 2025 19 hours ago, robintech said: all seems to go through for us and it says its licenced, but windows update GUI still says you will no longer receive security updates Same here. Have only tried on a couple of PCs so far.
robintech Posted October 16, 2025 Posted October 16, 2025 1 hour ago, Dan23 said: Same here. Have only tried on a couple of PCs so far. Found this on a site about TSForge which seems to be more about bypassing Microsoft checks so I won't link it but they're having the same issue. Quote #I activated ESU with the TSforge, but the Windows Update page in Settings still saying "Your device is no longer receiving security updates." Why? Microsoft provides Extended Security Updates (ESU) through several channels, such as CommercialAzureESU, CommercialW365ESU, CommercialKeybasedESU, and ConsumerESU. TSforge activates the Commercial Key-based ESU, which is intended for use by administrators in business environments. The Windows Update page in Settings is currently showing the incorrect status below to all CommercialKeybasedESU users. image It’s just a visual bug, and it even appears on Windows 10 LTSC 2021. Your ESU is activated correctly. Hopefully, Microsoft will fix it in the upcoming updates.
Alastairb25 Posted October 16, 2025 Author Posted October 16, 2025 Was informed that this is way to check for ESU For us planning to do a build, [patch up, confirm reg key then look at a mass redeployment to replace existing builds HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\ConsumerESU If the ESUEligibility value is anything other than zero, ESU is enabled.
andy_b Posted October 16, 2025 Posted October 16, 2025 1 hour ago, Alastairb25 said: Was informed that this is way to check for ESU For us planning to do a build, [patch up, confirm reg key then look at a mass redeployment to replace existing builds HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\ConsumerESU If the ESUEligibility value is anything other than zero, ESU is enabled. Have a 1 there, still complains on Windows Update GUI.
jmak Posted October 17, 2025 Posted October 17, 2025 Just adding a confirmatory data point. License reports installed, or endpoint management software matches, but the GUI says out of support. When I asked my preferred AI how to tell, the answer seems to be that you'll know when you get an update. It couldn't be much less reassuring. Doors anyone remember if it was similar for Windows 7? I'd moved to Windows 10 years before the deadline, so don't have any previous experience.
toffee_paul Posted October 21, 2025 Posted October 21, 2025 I'm having the same problem here. After installing and activating the ESU key we purchased from our reseller ("Windows 10 ESU Year 1 (2025 - 2026"), the Windows Update page in the Settings app is showing "Your version of Window has reached the end of support". I get confirmation the product key has installed and activated successfully. This is all 5 devices I've tried so far. All the devices are using Active Directory Based Activation against a KMS host server. We have the Volume Activation Tools role installed on a server and this has been setup with our KMS key and has always worked really well, activating everything. In the registry (HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\ConsumerESU), the ESUEligibility value is 1. Not sure how reliable this is an indicator of whether we will receive future security updates though. I've contacted our reseller and asked them to escalate this to Microsoft on our behalf but not heard anything back yet.
Gongalong Posted October 21, 2025 Posted October 21, 2025 I'm now wondering if I really did see the "end of support" message disappear, as I've had it remain with further machines. Probably comes down to it being badly setup by Microsoft.
3s-gtech Posted October 21, 2025 Posted October 21, 2025 Oddly, when looking at a a client with slmgr /dlv it shows the ESU activation and it's Licensed, but also shows the old KMS activation too. Don't want to remove that from AD as it activates some servers.
toffee_paul Posted October 21, 2025 Posted October 21, 2025 (edited) 2 hours ago, 3s-gtech said: Oddly, when looking at a a client with slmgr /dlv it shows the ESU activation and it's Licensed, but also shows the old KMS activation too. Don't want to remove that from AD as it activates some servers. I get this too. Here's a typical output of slmgr /dlv here. Microsoft (R) Windows Script Host Version 5.812 Copyright (C) Microsoft Corporation. All rights reserved. Software licensing service version: 10.0.19041.6456 Name: Windows(R), Education edition Description: Windows(R) Operating System, VOLUME_KMSCLIENT channel Activation ID: <withheld> Application ID: <withheld> Extended PID: <withheld> Product Key Channel: Volume:GVLK Installation ID: <withheld> Partial Product Key: <withheld> License Status: Licensed Volume activation expiration: 250630 minute(s) (175 day(s)) Remaining Windows rearm count: 1001 Remaining SKU rearm count: 1001 Trusted time: 21/10/2025 10:52:35 Configured Activation Type: All Most recent activation information: AD Activation client information Activation Object name: Windows 10/11 Product Activation <withheld> AO DN: <withheld> AO extended PID: <withheld> AO activation ID: <withheld> Name: Windows(R), Client-ESU-Year1 add-on for Education,EducationN,Enterprise,EnterpriseN,Professional,ProfessionalEducation,ProfessionalEducationN,ProfessionalN,ProfessionalWorkstation,ProfessionalWorkstationN,ServerRdsh,Core,CoreN,CoreCountrySpecific,CoreSingleLanguage,IoTEnterprise,PPIPro Description: Windows(R) Operating System, VOLUME_MAK channel Activation ID: f520e45e-7413-4a34-a497-d2765967d094 Application ID: <withheld> Extended PID: <withheld> Product Key Channel: Volume:MAK Installation ID: <withheld> Use License URL: https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail Validation URL: https://validation-v2.sls.microsoft.com/SLWGA/slwga.asmx Partial Product Key: <withheld> License Status: Licensed Remaining Windows rearm count: 1001 Remaining SKU rearm count: 1001 Trusted time: 21/10/2025 10:52:37 I actually tried removing the KMS activation from a test device and installing/activating the ESU MAK key and Windows didn't like this at all and refused to activate. Wondering whether the ESU licence isn't actually a standalone licence and it needs a 'base' licence installed for it to show as 'Licenced'. The words 'add-on' in the Name field might suggest this is true but regardless, even when slmgr /dlv shows it as Licenced, Windows Update is saying otherwise. I thought there may be others having this same issue but it doesn't seem as widespread as I thought. Maybe most organisations have already upgraded to Win11. We still have about 15% of our devices on Win10 and as this ESU programme exists we thought it best to pay a nominal fee to keep them going for a year before replacing with new machines in next years budget. Read somewhere that Microsoft issued some faulty ESU keys to resellers. Who knows, we could be affected by that. Can't even get a response from our reseller/distributor at the moment. Edited October 21, 2025 by toffee_paul
3s-gtech Posted October 21, 2025 Posted October 21, 2025 You can screenshot what you see in Windows Update? I'm just testing this on one of my old clunker laptops.
3s-gtech Posted October 22, 2025 Posted October 22, 2025 (edited) Well, my test laptop got the Windows 10 22H2 October 2025 CU last night, now it's showing it has reached end of support. Will be interesting to see what happens. We may have to wait a month! Edited October 22, 2025 by 3s-gtech Checked last CU
NegativeKillDeath Posted October 22, 2025 Posted October 22, 2025 I thought Oct patch was last one Win10 would get as patch Tuesday was the 14th.
toffee_paul Posted October 22, 2025 Posted October 22, 2025 19 hours ago, 3s-gtech said: You can screenshot what you see in Windows Update? I'm just testing this on one of my old clunker laptops. This is what all my test machines show. I had a response back from our reseller and the say the distributor is aware of other customers having issues with ESU but didn't go into details about what that might be. Just have to play the waiting game and see what they come back with.
brianhig Posted October 22, 2025 Posted October 22, 2025 yeah, tons of folks ran into that one. kb5046613 is finicky with win10 esu, especially on 22h2 systems that had paused updates or older servicing stacks. try manually installing the latest ssu (kb5039354 i think) before running the kb5046613 standalone installer. if that fails, clear out the softwaredistribution folder and run dism /online /cleanup-image /restorehealth. that usually gets it to stick.
toffee_paul Posted October 23, 2025 Posted October 23, 2025 I get "This update is not applicable to your computer" with both of these updates. All my devices are Win10 22H2 and are on the October 2025 cumulative update so these updates aren't applicable. Windows Update for Business is in place and they've never been paused for updates. Tried deleting SoftwareDistribution folder and the DISM command and still no luck.
Gongalong Posted October 23, 2025 Posted October 23, 2025 KB5046613 is just the Nov 24 CU, no? https://www.catalog.update.microsoft.com/Search.aspx?q=KB5046613 As above, I applied the latest CU. Without it the MAK gave an error when trying to apply. I think it's a case of seeing if further security updates apply. I've got a Win 10 machine at home which is enrolled in the free updates, so my plan is to keep an eye on what that gets and see whether it's reflected on the machines here. It's further complicated here by updates coming via MEMCM, but that's still set to pick up Win 10 updates and apply them.
Ditto Posted October 26, 2025 Posted October 26, 2025 I've been thinking I might grudginly go ESU (Home environment). I'd like to install the final Win 10 update before hand - KB5066791. I'm short on diskspace but in spite of a large amount of files to a 1TB, I constanly get c drive full. Diskcleanup no longer seem to work. The file properties for size just doesn't seem to update reliably. The Windows update is now saying I need anywhere from 77MB to 790MB of space. I suspect the fact it is also trying to install KB5066747 and KB890830 isn't helping. Is there a way to clear down updates (empty C:\Windows\SoftwareDistribution\Download) downloads and then run the 2 other update manually before once again trying KB5066791? Ultimately I need a large boot device and I have plans, but right now I just want to get up to date and then go ESU.
Ditto Posted October 27, 2025 Posted October 27, 2025 So I finally got it to install eventually by releasing about 4Gb (massive OST move - and that was a pain) but Windows update continued to report lack of space, but after a few reboots and runs of Windows update troubleshooter and another reboot I finally slumped over the line. So that's the last Win 10 update other than if/when I sign up to ESU. That was the worst and most troublesome Win 10 update I've had to deal with - sad finish really to Win 10 - coincidence or bad luck - you decide! I know I'm just delaying the inevitable, even if that inevitability is a Rufus Win 11 install.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now