Microsoft has a deadline that enterprise IT teams can’t afford to ignore: November 10, 2026. On that date, Windows 11 Enterprise and Education version 23H2 will stop receiving monthly security and quality updates. No patches for new vulnerabilities. No more support calls. The operating system millions of business PCs rely on will officially be at end of life.

For organizations still running 23H2, the clock isn’t just ticking towards November; it’s forcing a decision that will ripple through fleet management for years. The question isn’t simply when to upgrade, but which version to target. And while the immediate instinct might be to jump to the next sequential release—24H2—Microsoft’s own support lifecycle data reveals a smarter path: aim directly for 25H2 and buy yourself nearly a full extra year before the next forced migration.

The Clock Is Ticking for 23H2

Here’s the breakdown from Microsoft’s official lifecycle page:

Windows 11 Version Enterprise/Education End of Servicing
23H2 November 10, 2026
24H2 October 12, 2027
25H2 October 10, 2028

The arithmetic is stark. Moving from 23H2 to 24H2 buys you less than 11 months of additional servicing before you’re back in the same situation. Leaping to 25H2 extends that runway to nearly two full years post-deadline, giving IT teams breathing room and a more stable targeting baseline.

For IT administrators, this means the planning horizon shifts dramatically. A fleet that migrates to 25H2 in 2026 won’t need another major feature update project until 2028—ample time to validate, test, and phase without panic. Choosing 24H2, however, guarantees a repeat performance in 2027, compressing the validation cycle and increasing the risk of deployment fatigue.

24H2 vs. 25H2: A Numbers Game

The choice boils down to how much operational pain your organization is willing to schedule. Microsoft recommends both 24H2 and 25H2 as enterprise deployment targets, but only 25H2 offers a servicing window that aligns with sensible long-term planning. For most established Enterprise, Education, and IoT Enterprise environments, a direct move is the logical default.

There are exceptions. If your team has already fully tested and validated 24H2 for a specific device group, or if a near-term project demands the older release, staging through 24H2 might be defensible. But this should be a documented exception, not the fleet-wide norm. The burden of proof lies on the reason to stop short.

Crucially, devices already on a current 24H2 cumulative update can transition to 25H2 via an enablement package—a far less disruptive process than a full upgrade. That means a two-step approach is technically possible, but it remains an unnecessary extra step for most 23H2 endpoints when the final destination is the same.

Why 26H1 Is a False Hope

Some fleet managers, eyeing spreadsheets, might wonder: why not wait for 26H1 or even 26H2? Microsoft’s guidance, as documented, explicitly states that Windows 11 version 26H1 is a hardware-specialized release designed exclusively for new devices with select silicon platforms. It is not offered through Windows Update as an in-place upgrade for existing PCs. Attempting to force a 23H2-to-26H1 migration is impossible through standard channels. So for the vast majority of current enterprise estates, 25H2 is the furthest point on the horizon that’s actually reachable.

The consumer cutoff for Windows 11 Home and Pro 23H2 occurred on November 11, 2025, serving as an early warning for enterprises. Many organizations watched that deadline pass, perhaps without realizing their own clock was ticking on a different schedule. Now, with over a year’s notice, there’s no excuse for a last-minute scramble.

From Inventory to Go-Live: Your Migration Roadmap

A successful migration to 25H2 doesn’t start with a big red button. It starts with clarity. Here’s a phase-by-phase plan to move from 23H2 with controlled risk:

  1. Comprehensive inventory — Identify every device still running 23H2 using Microsoft Intune, Configuration Manager, or third-party tools. Pay special attention to remote machines, kiosks, and rarely connected endpoints. Veriyon build numbers, not just “Windows 11” labels.

  2. Set 25H2 as the default target — Unless a specific application, driver, or hardware model is proven incompatible, make 25H2 the standard destination. Document every exception with a named owner and a resolution deadline. This prevents a slow creep of “just 24H2” becoming the accidental fleet architecture.

  3. Build a pilot ring that mirrors reality — Don’t test only on IT staff laptops. Include devices with line-of-business apps, VPN clients, specialized peripherals (barcode scanners, label printers), medical equipment, or non-standard driver stacks. Validate the entire upgrade path: installation, first sign-in, core application launch, peripheral connectivity, and the ability to roll back.

  4. Validate thoroughly — A successful OS upgrade is not the same as a usable endpoint. Check that printing, scanning, authentication flows, remote access, and update compliance remain functional. If your organization uses VDI or virtual desktops, test there as well.

  5. Expand in controlled waves — Use ring-based deployment (Ring 1 for early adopters, Ring 2 for broader pilot, Ring 3 for general production) with sufficient soak time between expansions. A hold group should contain only devices with documented blockers, not simply “to be scheduled later.”

  6. Leverage management tooling — For Intune, configure feature update policies to target 25H2 and monitor compliance dashboards. If using Windows Autopatch, ensure exclusion rules are reviewed and aligned. For WSUS, verify that 25H2 is approved and correctly scoped to avoid accidental mass-deployment or orphaned machines.

  7. Plan for rollback — Every deployment ring needs a rollback owner and a decision trigger. Define what constitutes a deployment-stopping issue, who gathers evidence, and how the fix or bypass is tested. A rollback plan isn’t a sign of doubt; it’s a sign of operational maturity.

  8. Set an internal finish line — Target September 2026 for 95%+ completion. The final two months are not for initiating new deployments; they’re for resolving stubborn edge cases and reclaiming devices that have been offline.

The Bottom Line

Microsoft’s enterprise servicing strategy continues to evolve. While 26H1 is a niche off-ramp, the eventual release of 26H2 or beyond may again shift long-term plans. But for now, the math is simple: 25H2 offers the longest support window for a 23H2 fleet, and every day spent on the old build is a day closer to a security cliff. The November 2026 deadline is fixed. The path to the safest version is clear. The only variable left is whether organizations start moving now, or wait until it’s too late.