Home
%3CLINGO-SUB%20id%3D%22lingo-sub-825618%22%20slang%3D%22en-US%22%3EExtended%20Security%20Updates%20and%20Configuration%20Manager%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-825618%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%20style%3D%22font-family%3A%20'Segoe%20UI'%2Csans-serif%3B%22%3ESupport%20for%20Windows%207%20comes%20to%20an%20end%20on%20January%2014%2C%202020%2C%20and%20to%20remain%20current%20and%20supported%2C%20customers%20need%20to%20make%20the%20shift%20to%20Windows%2010.%20For%20help%20planning%20and%20deploying%20Windows%2010%2C%20Microsoft%20offers%20%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fen-US%2Fmicrosoft-365%2Fmodern-desktop%2Fenterprise%3F%26amp%3BOCID%3DAID793796_SEM_wp9HidD0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3E%3CSPAN%20style%3D%22font-family%3A%20'Segoe%20UI'%2Csans-serif%3B%22%3Eguidance%20and%20other%20resources%20to%20accelerate%20the%20migration%3C%2FSPAN%3E%3C%2FA%3E%3CSPAN%20style%3D%22font-family%3A%20'Segoe%20UI'%2Csans-serif%3B%22%3E.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20style%3D%22font-family%3A%20'Segoe%20UI'%2Csans-serif%3B%22%3EAs%20a%20last%20resort%20option%20for%20volume%20licensing%20customers%20running%20Windows%207%20(Professional%20or%20Enterprise)%20and%20Windows%20Server%202008%20after%20the%20end%20of%20support%20date%2C%20Microsoft%20recently%20announced%20the%20Extended%20Security%20Updates%20(ESU)%20program.%20Security%20updates%20released%20under%20the%20ESU%20program%20will%20be%20published%20to%20Windows%20Server%20Update%20Services%20(WSUS).%20%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20style%3D%22font-family%3A%20'Segoe%20UI'%2Csans-serif%3B%22%3EThis%20article%20describes%20software%20update%20management%20and%20OS%20deployment%20using%20Configuration%20Manager%20for%20clients%20covered%20under%20the%20ESU%20program.%20In%20general%2C%20products%20that%20are%20beyond%20their%20support%20lifecycle%20are%20not%20supported%20for%20use%20with%20any%20version%20of%20Configuration%20Manager%20as%20clients%20or%20in%20server%20roles.%20As%20such%2C%20following%20the%20end%20of%20support%20date%20for%20Windows%207%20and%20Windows%20Server%202008%2FR2%2C%20these%20operating%20systems%20will%20no%20longer%20be%20tested%20nor%20supported%20with%20Configuration%20Manager.%20%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20style%3D%22font-family%3A%20'Segoe%20UI'%2Csans-serif%3B%22%3EFor%20those%20clients%20covered%20under%20the%20ESU%20program%2C%20the%20latest%20released%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsccm%2Fcore%2Fservers%2Fmanage%2Fupdates%23version-details%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Eversion%3C%2FA%3Eof%20Configuration%20Manager%20current%20branch%20can%20be%20used%20to%20deploy%20and%20install%20Windows%20security%20updates%20released%20under%20the%20program%20and%20deploy%20supported%20OSes%20via%20operating%20system%20deployment%20(OSD).%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-1845976131%22%20id%3D%22toc-hId-1818359006%22%3EFrequently%20Asked%20Questions%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId--902694335%22%20id%3D%22toc-hId--930311460%22%3ECan%20older%20versions%20of%20Configuration%20Manager%20(2007%2C%202012)%20be%20used%20to%20deploy%20and%20install%20security%20updates%20released%20under%20the%20extended%20security%20updates%20program%3F%3C%2FH3%3E%0A%3CP%3ENo.%20If%20you%20have%20a%20requirement%20to%20patch%20operating%20systems%20covered%20under%20the%20extended%20security%20updates%20program%20using%20Configuration%20Manager%2C%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fsccm%2Fcore%2Fmigration%2Fplanning-for-migration%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Emigrate%3C%2FA%3Eor%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fsccm%2Fcore%2Fservers%2Fdeploy%2Finstall%2Fupgrade-to-configuration-manager%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Eupgrade%3C%2FA%3Eto%20the%20latest%20released%20version%20of%20Configuration%20Manager%20(current%20branch).%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId-840116000%22%20id%3D%22toc-hId-812498875%22%3ECan%20all%20supported%20versions%20of%20Configuration%20Manager%20current%20branch%20be%20used%20to%20deploy%20and%20install%20security%20updates%20released%20under%20the%20extended%20security%20updates%20program%3F%3C%2FH3%3E%0A%3CP%3ENo.%20Only%20the%20latest%20released%20version%20of%20Configuration%20Manager%20current%20branch%20should%20be%20used.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId--1712040961%22%20id%3D%22toc-hId--1739658086%22%3EI%20plan%20to%20migrate%20my%20Windows%202008%2FR2%20servers%20to%20Azure.%20Today%2C%20I%20patch%20them%20on-premises%20using%20Configuration%20Manager.%20Can%20I%20continue%20to%20patch%20them%20using%20Configuration%20Manager%20once%20I%20move%20them%20to%20Azure%3F%3C%2FH3%3E%0A%3CP%3EYes%2C%20if%20you%E2%80%99re%20using%20the%20latest%20released%20version%20of%20Configuration%20Manager%20current%20branch.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId-30769374%22%20id%3D%22toc-hId-3152249%22%3ECan%20I%20continue%20to%20use%20Configuration%20Manager%20for%20non-patch%20related%20client%20management%3F%3C%2FH3%3E%0A%3CP%3EClient%20management%20features%20not%20related%20to%20Windows%20patch%20management%20or%20operating%20system%20deployment%20will%20no%20longer%20be%20tested%20on%20the%20operating%20systems%20covered%20under%20the%20extended%20security%20updates%20program%20and%20we%20do%20not%20guarantee%20that%20they%20will%20continue%20to%20function.%20It%20is%20highly%20recommended%20to%20upgrade%20or%20migrate%20to%20a%20current%20version%20of%20the%20operating%20systems%20to%20receive%20client%20management%20support.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId-1773579709%22%20id%3D%22toc-hId-1745962584%22%3ECan%20I%20continue%20to%20host%20distribution%20points%20on%20Windows%20Server%202008%2FR2%3F%3C%2FH3%3E%0A%3CP%3ENo.%20Any%20active%20distribution%20points%20will%20need%20to%20be%20moved%20to%20a%20supported%20operating%20system%20before%20January%2014%2C%202020%2C%20to%20continue%20to%20be%20supported%20by%20Configuration%20Manager.%20See%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsccm%2Fcore%2Fplan-design%2Fconfigs%2Fsupported-operating-systems-for-site-system-servers%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3ESupported%20operating%20systems%20for%20Configuration%20Manager%20site%20system%20servers%3C%2FA%3Efor%20more%20information.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId--778577252%22%20id%3D%22toc-hId--806194377%22%3EOffice%20365%20ProPlus%20will%20be%20supported%20on%20devices%20with%20active%20Windows%207%20Extended%20Security%20Updates%20(ESU)%20through%20January%202023.%20Can%20I%20continue%20to%20manage%20Office%20365%20ProPlus%20on%20these%20devices%20with%20Configuration%20Manager%20current%20branch%3F%3C%2FH3%3E%0A%3CP%3EWhere%20the%20customer%20has%20Office%20365%20ProPlus%20on%20devices%20with%20active%20Windows%207%20ESU%2C%20ProPlus%20will%20continue%20to%20receive%20monthly%20security%20updates%20for%20the%20duration%20of%20the%20ESU.%26nbsp%3B%20However%2C%20those%20customers%20will%20not%20continue%20to%20receive%20Office%20365%20ProPlus%20feature%20updates.%26nbsp%3B%20The%20Office%20365%20management%20features%20in%20Configuration%20Manager%20will%20no%20longer%20be%20tested%20on%20operating%20systems%20covered%20under%20the%20ESU%20program%20and%20we%20do%20not%20guarantee%20that%20they%20will%20continue%20to%20function.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3E%26nbsp%3B%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-1160746588%22%20id%3D%22toc-hId-1133129463%22%3E%3CSTRONG%3EAdditional%20Resources%3A%3C%2FSTRONG%3E%3C%2FH2%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fsccm%2Fcore%2Fplan-design%2Fconfigs%2Fsupported-operating-systems-for-clients-and-devices%23bkmk_ESU%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3EExtended%20Security%20Updates%20and%20Configuration%20Manager%20documentation%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Faka.ms%2Feos-offer-faq%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3EESU%20FAQ%20for%20SQL%20Server%20and%20Windows%20Server%202008%20and%202008%20R2%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fazure.microsoft.com%2Fblog%2Fannouncing-new-options-for-sql-server-2008-and-windows-server-2008-end-of-support%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3EAnnouncing%20new%20options%20for%20SQL%20Server%202008%20and%20Windows%20Server%202008%20End%20of%20Support%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fgo.microsoft.com%2Ffwlink%2Fp%2F%3Flinkid%3D2086115%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3EEnd%20of%20Support%20FAQ%20for%20Windows%207%20and%20Office%202010%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CA%20style%3D%22background-color%3A%20transparent%3B%20box-sizing%3A%20border-box%3B%20color%3A%20%23146cac%3B%20font-family%3A%20%26amp%3Bquot%3B%20segoeui%26amp%3Bquot%3B%2C%26amp%3Bquot%3Blato%26amp%3Bquot%3B%2C%26amp%3Bquot%3Bhelvetica%20neue%26amp%3Bquot%3B%2Chelvetica%2Carial%2Csans-serif%3B%20font-size%3A%2016px%3B%20font-style%3A%20normal%3B%20font-variant%3A%20normal%3B%20font-weight%3A%20300%3B%20letter-spacing%3A%20normal%3B%20orphans%3A%202%3B%20text-align%3A%20left%3B%20text-decoration%3A%20underline%3B%20text-indent%3A%200px%3B%20text-transform%3A%20none%3B%20-webkit-text-stroke-width%3A%200px%3B%20white-space%3A%20normal%3B%20word-spacing%3A%200px%3B%22%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fhelp%2F4497181%2Flifecycle-faq-extended-security-updates%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3EESU%20Lifecycle%20FAQ%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FWindows-IT-Pro-Blog%2FHow-to-get-Extended-Security-Updates-for-eligible-Windows%2Fba-p%2F917807%22%20target%3D%22_self%22%3EHow%20to%20get%20Extended%20Security%20Updates%20for%20eligible%20Windows%20devices%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fmicrosoft-365%2Fblog%2F2019%2F03%2F01%2Fnow-is-the-time-to-make-the-shift-to-microsoft-365%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3ENow%20is%20the%20time%20to%20make%20the%20shift%20to%20Microsoft%20365%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fhub%2F4095338%2Fmicrosoft-lifecycle-policy%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3EMicrosoft%20Lifecycle%20Policy%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fmicrosoft-365%2Fenterprise%2Fdesktop-deployment-center-home%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3EDesktop%20Deployment%20Center%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-825618%22%20slang%3D%22en-US%22%3E%3CP%3EThis%20article%20describes%20software%20update%20management%20and%20OS%20deployment%20using%20Configuration%20Manager%20for%20clients%20covered%20under%20the%20ESU%20program.%20For%20those%20clients%20covered%20under%20the%20ESU%20program%2C%20the%20latest%20released%20version%20of%20Configuration%20Manager%20current%20branch%20can%20be%20used%20to%20deploy%20and%20install%20any%20Windows%20security%20updates%20released%20under%20the%20program.%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-825618%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECM%20current%20branch%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOS%20deployment%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESoftware%20Update%20Management%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EUnified%20Endpoint%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft

Support for Windows 7 comes to an end on January 14, 2020, and to remain current and supported, customers need to make the shift to Windows 10. For help planning and deploying Windows 10, Microsoft offers guidance and other resources to accelerate the migration.

 

As a last resort option for volume licensing customers running Windows 7 (Professional or Enterprise) and Windows Server 2008 after the end of support date, Microsoft recently announced the Extended Security Updates (ESU) program. Security updates released under the ESU program will be published to Windows Server Update Services (WSUS).

 

This article describes software update management and OS deployment using Configuration Manager for clients covered under the ESU program. In general, products that are beyond their support lifecycle are not supported for use with any version of Configuration Manager as clients or in server roles. As such, following the end of support date for Windows 7 and Windows Server 2008/R2, these operating systems will no longer be tested nor supported with Configuration Manager.

 

For those clients covered under the ESU program, the latest released version of Configuration Manager current branch can be used to deploy and install Windows security updates released under the program and deploy supported OSes via operating system deployment (OSD).

 

Frequently Asked Questions

 

Can older versions of Configuration Manager (2007, 2012) be used to deploy and install security updates released under the extended security updates program?

No. If you have a requirement to patch operating systems covered under the extended security updates program using Configuration Manager, migrate or upgrade to the latest released version of Configuration Manager (current branch).

 

Can all supported versions of Configuration Manager current branch be used to deploy and install security updates released under the extended security updates program?

No. Only the latest released version of Configuration Manager current branch should be used.

 

I plan to migrate my Windows 2008/R2 servers to Azure. Today, I patch them on-premises using Configuration Manager. Can I continue to patch them using Configuration Manager once I move them to Azure?

Yes, if you’re using the latest released version of Configuration Manager current branch.

 

Can I continue to use Configuration Manager for non-patch related client management?

Client management features not related to Windows patch management or operating system deployment will no longer be tested on the operating systems covered under the extended security updates program and we do not guarantee that they will continue to function. It is highly recommended to upgrade or migrate to a current version of the operating systems to receive client management support.

 

Can I continue to host distribution points on Windows Server 2008/R2?

No. Any active distribution points will need to be moved to a supported operating system before January 14, 2020, to continue to be supported by Configuration Manager. See Supported operating systems for Configuration Manager site system servers for more information.

 

Office 365 ProPlus will be supported on devices with active Windows 7 Extended Security Updates (ESU) through January 2023. Can I continue to manage Office 365 ProPlus on these devices with Configuration Manager current branch?

Where the customer has Office 365 ProPlus on devices with active Windows 7 ESU, ProPlus will continue to receive monthly security updates for the duration of the ESU.  However, those customers will not continue to receive Office 365 ProPlus feature updates.  The Office 365 management features in Configuration Manager will no longer be tested on operating systems covered under the ESU program and we do not guarantee that they will continue to function.

 

 

Additional Resources:

Extended Security Updates and Configuration Manager documentation

ESU FAQ for SQL Server and Windows Server 2008 and 2008 R2

Announcing new options for SQL Server 2008 and Windows Server 2008 End of Support

End of Support FAQ for Windows 7 and Office 2010

ESU Lifecycle FAQ

How to get Extended Security Updates for eligible Windows devices

Now is the time to make the shift to Microsoft 365

Microsoft Lifecycle Policy

Desktop Deployment Center