• Client Portal
  • Billing Portal
  • Remote Session
720-443-0445
SpeedWise IT Services
  • Home
  • About
  • Services
  • Blog
  • Contact
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Link to Facebook
  • Link to LinkedIn
  • Link to X

Still on Windows 10? Here’s Why You’re Putting Your Business at Risk

08/20/2026

Article Summary: Windows 10 reached the end of Microsoft support on October 14, 2025, which means it no longer gets security updates. The computers still work, but any new flaw found in Windows 10 will never be fixed, which makes them easier to attack and can cause problems with compliance and cyber insurance. You have three options: upgrade eligible PCs to Windows 11 for free, pay for Extended Security Updates as a short-term bridge, or replace machines too old to upgrade.

Microsoft stopped supporting Windows 10 on October 14, 2025.

If your business is still running it, and plenty are, your computers aren’t getting security updates anymore.

Everything still turns on and works like normal, which is exactly why it’s easy to put off doing anything about it. The trouble is, the longer you stay on Windows 10, the more security holes pile up that nobody is ever going to fix.

So what does it mean for your business, and what are your options?

There are three: upgrade to Windows 11, pay for extended updates to buy some time, or replace the machine.

Let’s go through what you’re dealing with first.

What “end of support” means

When Microsoft ends support for a version of Windows, the updates stop. That includes the monthly security patches that fix newly found flaws.

Microsoft has confirmed that since October 14, 2025, Windows 10 gets no more security fixes, quality updates, feature updates, or technical support.

Your PCs don’t stop working. Nothing switches off the moment support ends. What’s different now is that Microsoft has stopped fixing Windows 10’s security flaws.

Attackers and security researchers keep finding new ones, and now nobody’s patching them. So every new flaw that turns up is another way into your computers, and it never gets fixed.

Why this is a real risk for your business

This is about more than an old, slow computer.

  • They’re an easy target. Attackers go looking for computers running software that doesn’t get fixed anymore, because they know the flaws will just sit there. The UK’s National Cyber Security Centre points out that holes in unsupported products stay exploitable, often by fairly low-skilled attackers.
  • You can fall out of compliance. If you handle card payments, health records, or personal data, rules like PCI DSS and HIPAA expect you to run supported, patched software. Windows 10 no longer counts, which can put you out of compliance.
  • It can hit your cyber insurance. Insurers are asking more and more whether your systems are supported and patched. Running an unsupported operating system can push your premium up, shrink your coverage, or give the insurer a reason to fight a claim.
  • Your other software will drop it. Over time, browsers, accounting tools, and other programs stop supporting Windows 10, so the apps you rely on every day can stop updating, or stop working altogether.

CISA puts running supported, updated software on its short list of basic security steps for businesses.

<H2>Your three options</H2>

You’ve really got three options, and most businesses end up mixing them across their computers.

1. Upgrade to Windows 11(free, if the hardware qualifies)

If you bought the PC in the last few years, upgrading to Windows 11 is free, and it’s usually the right move. The catch is the hardware. Windows 11 needs a supported processor, TPM 2.0, and Secure Boot, and that rules out a lot of older machines. To check whether a particular PC qualifies, run Microsoft’s free PC Health Check app.

2. Buy Extended Security Updates as a bridge

If a PC can’t move to Windows 11 yet, Microsoft will sell you Extended Security Updates (ESU) to keep the security patches coming for a while longer.

For businesses, that’s $61 per device for the first year, and it doubles every year after that, up to three years.

Keep one PC on Windows 10 the whole time and you’re looking at around $427 over those three years.

Home users get a much cheaper deal. A one-time $30 payment covers up to 10 devices with security updates through October 12, 2027, and it’s free if you sync your PC settings.

ESU gives you security patches and nothing else. No new features, no real tech support. It’s there to buy you time while you sort out the upgrade or a new machine.

3. Replace the PC

Some machines are just too old for Windows 11 and not worth paying ESU on year after year.

For those, buying a new PC that already runs Windows 11 usually works out cheaper, once you add up the ESU fees and the cost of keeping an old machine going.

How to plan the move

You don’t have to do all of this at once, but you do need a plan. A sensible order looks like this:

  1. Make a list of every computer still on Windows 10.
  2. Check which ones can move to Windows 11, using the PC Health Check app or your IT provider.
  3. Upgrade the ones that qualify. It’s free, and it keeps your files and programs in place.
  4. For the rest, choose between ESU to buy time or replacing the machine, depending on how old it is and what it’s used for.

Your IT provider can run that inventory quickly and tell you the best option for each machine.

Frequently Asked Questions

Is Windows 10 still safe to use after October 2025?

It still works, but it’s not getting security updates anymore, so the risk creeps up as new flaws are found and left unpatched. If you’re going to keep using it, either enroll in Extended Security Updates or plan your move to Windows 11.

What happens if I keep using Windows 10 and do nothing?

Your PCs will keep running, but they turn into an easier target for attackers, can put you out of compliance with payment and privacy rules, and may cause problems with your cyber insurance. And over time, the apps you depend on will start dropping Windows 10 too.

How much does Windows 10 ESU cost for a business?

For businesses, it’s $61 per device for the first year and doubles each year after that, up to three years, which comes to about $427 per device in total. Home users get a better deal: a one-time $30 payment covers up to 10 devices through October 12, 2027, or it’s free if you sync your PC settings.

Can my PC upgrade to Windows 11 for free?

If it meets the hardware requirements, yes. Windows 11 needs a supported processor, TPM 2.0, and Secure Boot. The PC Health Check app will tell you whether a specific machine qualifies, and PCs from the last few years usually do.

Should I just buy a new computer?

If a PC can’t run Windows 11, a new one is often cheaper than paying escalating ESU fees for years on top of running aging hardware. If it can upgrade, start with the free Windows 11 upgrade.

—

Featured Image Credit

This Article has been Republished with Permission from The Technology Press.

https://speedwise.net/wp-content/uploads/2026/07/johnyvino-R54V69BN0MI-unsplash-scaled-1.jpg 1711 2560 admin https://speedwise.net/wp-content/uploads/2020/09/SpeedWise_Final_DropShadow_white_background_300x80.png admin2026-08-20 12:00:002026-07-09 21:21:01Still on Windows 10? Here’s Why You’re Putting Your Business at Risk

5 Microsoft 365 Settings Worth Checking in Your Tenant

07/10/2026

Microsoft has tightened several default settings in Microsoft 365 over the past few years. Newer tenants get more protection out of the box than tenants set up before 2022 or so. The problem is that legacy configurations stay in place. A setting changed for new tenants in 2024 doesn’t retroactively change in yours, and historical user consents, inbox rules, or sharing links granted before the change are still active.

Here are five settings worth checking in your tenant, especially if it’s more than two or three years old, was set up by a previous IT provider, or has not been audited in a while.

A few caveats before we start. Some of these settings require Microsoft 365 Business Premium, E3, or E5 licensing to change, so if a toggle is grayed out, your license tier is most likely the reason. A couple of these changes will generate support tickets from your team because they change how something already works. None of them need to be flipped all at once.

1. The default sharing link in SharePoint and OneDrive

When someone in your organization shares a file from SharePoint or OneDrive, the link they generate has a default scope. In tenants set up before Microsoft tightened the new-site defaults, that scope is often “Anyone with the link,” which means anyone who receives the URL can open the file without signing in. No expiration. No record of who else the link was forwarded to.

Newer Teams-created sites now default to “Only people in your organization.” Older sites and the tenant-level setting often still allow Anyone links. A departing employee who emailed a proposal to their personal account six months ago still has a working link, unless someone manually revoked it.

The default sharing link type sits in the SharePoint admin center under Policies > Sharing. Switching the tenant default to “Specific people” forces every new link to require authentication. You can also set a maximum expiration for any remaining “Anyone” links so they time out automatically.

Rough time to change: 15 minutes. This has no impact on existing links until they’re regenerated.

2. External email forwarding rules

Microsoft now blocks automatic email forwarding to external addresses at the tenant level by default, through the outbound spam policy. This rolled out as part of Microsoft’s secure-by-default effort.

Forwarding rules created before that change can still be active, though, and tenants with custom outbound spam policies configured years ago may not reflect the current default. A user who set up a rule a few years ago to forward every email to a personal Gmail address may still be exporting your data, depending on how their rule was constructed and whether it predates the policy.

Verify two things. In the Microsoft Defender portal, under Email & Collaboration > Policies & Rules > Anti-spam policies > Anti-spam outbound policy, confirm the “Automatic forwarding rules” setting is set to “Off” or “Automatic – System-controlled.” Then audit existing inbox rules across your users for any forward-to-external configurations. The Microsoft Purview audit log lets you search for inbox rule creation events.

Rough time: 10 minutes to verify the tenant setting, longer to review existing rules across all mailboxes.

3. Historical third-party app consents

A Microsoft-managed user consent policy was enabled by default in July 2025, preventing users from consenting to most third-party applications that request access to their files and sites. New consent requests now route to an admin for review.

The change applies going forward. Apps that were granted user consent before the policy took effect still have whatever permissions they were given, including the ability to read mail, calendars, and files on behalf of the user. Some of those apps may be tools an employee installed years ago and no longer uses, or apps installed during a one-off project that nobody remembers approving.

To review what’s already there, go to Microsoft Entra ID > Enterprise Applications > All applications. Sort by user consent and look at what currently has access to mail, files, or calendars. Anything you don’t recognize or no longer need can be revoked from the same screen.

Rough time: 30 to 60 minutes for the review, depending on how many historical apps are in the list.

4. Mailbox and tenant audit log retention

The default audit log retention period in Microsoft 365 changed in October 2023. Audit (Standard) logs are now retained for 180 days, up from the previous 90 days. Customers with E5 licensing or the Microsoft Purview Audit (Premium) add-on get one year of retention for Exchange, SharePoint, OneDrive, and Entra ID audit records, with other activity types staying at 180 days.

If you’re in healthcare, financial services, legal, or any other regulated industry, 180 days may not match your retention obligations. HIPAA, the FTC Safeguards Rule, and most state bar rules around client data assume you can produce records on request, and the relevant period is often measured in years, not months.

Audit retention policies live in the Microsoft Purview compliance portal under Audit > Audit retention policies. Extending retention beyond 180 days requires E5 or the Purview Audit add-on. The configuration itself takes about 15 minutes once you’ve confirmed your license supports it.

5. MFA enforcement and Security Defaults

MFA enforcement is the area most likely to be inconsistent in older tenants. Microsoft introduced Security Defaults in late 2019, and the feature now enforces MFA automatically on new tenants. Microsoft has also been progressively making MFA mandatory for admin actions in the Microsoft 365 admin center and Azure portal through 2024 and 2025.

Tenants created before Security Defaults rolled out may have no baseline enforcement. There’s also a common configuration trap. When an admin enables a Conditional Access policy, which is available with Business Premium and above, Microsoft expects you to take over MFA enforcement through that policy and may turn Security Defaults off. If the transition was done quickly, you can end up with Security Defaults off and a Conditional Access policy that doesn’t cover every user.

Check three places. In the Entra ID admin center under Properties > Manage Security Defaults, confirm whether Security Defaults is on or off. Under Protection > Conditional Access, confirm a policy is actively enforcing MFA for all users, including administrators. Pay particular attention to break-glass admin accounts, which are sometimes excluded from Conditional Access for emergency access reasons and left with no MFA as a result.

Rough time: about an hour, longer if Conditional Access has been configured with several existing policies you need to map.

A sensible order to roll the changes

Some of these changes are silent to your users. Others change how something they do every day works.

Audit log retention (#4) and the historical app consent review (#3) carry no user-facing impact. Start there.

Verifying external forwarding (#2) is silent unless someone has a legitimate forwarding rule, which is rare. Do this next.

The sharing default (#1) will eventually generate user questions, particularly from anyone used to clicking “share” and pasting the link into an email. Communicate the change before you flip the tenant setting.

The MFA and Conditional Access review (#5) is the highest-stakes change and the one most likely to lock people out if it’s done badly. Save it for last and budget the time to do it properly.

Frequently asked questions

Are my Microsoft 365 settings still vulnerable if my tenant was set up recently?

New tenants get more protection out of the box than tenants set up a few years ago. Even so, certain settings, including sharing scope, app consents granted by users, and historical inbox rules, need to be reviewed in any tenant regardless of age.

What is the current Microsoft 365 default for “Anyone with the link” sharing?

At the tenant level, many existing tenants still permit “Anyone with the link” sharing. Newer Teams-created SharePoint sites default to “Only people in your organization.” Verify both the tenant-level setting and the site-level setting if you want to know what your users see in practice.

Did Microsoft turn off external email forwarding by default?

Yes. Microsoft’s outbound spam policy now blocks automatic external forwarding by default at the tenant level. Existing inbox rules created before that change may still be active and worth auditing.

How long are Microsoft 365 audit logs kept by default?

180 days for Audit (Standard), as of October 2023. One year for key workloads (Exchange, SharePoint, OneDrive, Entra ID) if you have E5 or the Microsoft Purview Audit (Premium) add-on.

Does Security Defaults cover all my users?

On a new tenant, yes, including MFA enforcement. On an older tenant that has had Conditional Access policies enabled, Security Defaults may have been turned off, and MFA coverage now depends on how Conditional Access has been configured.

Sources and further reading

  • Microsoft Learn: Manage sharing settings for SharePoint and OneDrive
  • Microsoft Learn: Configuring external email forwarding in Microsoft 365
  • Microsoft Learn: Configure how users consent to applications
  • Microsoft Learn: Manage audit log retention policies
  • Microsoft Learn: Configure Security Defaults for Microsoft Entra ID
  • CISA: Microsoft 365 Secure Configuration Baselines (SCuBA)

If you’re not sure when your tenant was last reviewed, or whether any of these settings need attention, your IT provider should be able to walk through them with you. And if you don’t have an IT provider, feel free to reach out to us and we’ll help you sort it.

—

Featured Image Credit

This Article has been Republished with Permission from The Technology Press.

https://speedwise.net/wp-content/uploads/2026/05/pexels-cottonbro-6803531-scaled-1.jpg 1707 2560 admin https://speedwise.net/wp-content/uploads/2020/09/SpeedWise_Final_DropShadow_white_background_300x80.png admin2026-07-10 12:00:002026-05-25 21:03:455 Microsoft 365 Settings Worth Checking in Your Tenant

Beyond Licensing: How to Stop Wasting Money onYour Microsoft 365 Security and Copilot Add-Ons

12/05/2025

Microsoft 365 is a powerful platform that helps a business in many ways. It boosts collaboration and streamlines operations, among other benefits. However, many companies waste money on unnecessary licenses and features that are not fully used. 

Fortunately, you can avoid this waste and take your business to the next level by adopting smarter use of M365 security and Copilot add-ons. This article will provide practical insights, help you avoid costly mistakes, and support you in making informed decisions that fit your business objectives.

What Does Microsoft 365 Provide as Baseline Security & Copilot Features? 

Even without premium add-ons, Microsoft 365 offers a solid set of built-in security and AI features that are useful. You have tools for identity and access management, such as Azure Active Directory (now Entra ID), multi-factor authentication, single sign-on, and conditional access. The basic plans also deliver threat and malware protection, with built-in scanning for emails, phishing protection through Microsoft Defender, and safeguards for attachments and links. 

Depending on your plan, you might also have data loss prevention (DLP) features and tools for auditing and compliance to monitor user activity, support regulatory reporting, and enforce data retention policies. That said, before you adopt premium tiers, you have to scrutinize your needs. By knowing what is already available, you avoid paying for what you won’t use. Moreover, understanding what is included in every plan also helps you avoid overlapping features. 

How Organizations Overspend on Microsoft 365 Security and Copilot Add-Ons

Before we explore solutions, it’s essential to understand how this waste occurs in the first place. Overspending is often not obvious. It is hidden in scenarios that go unnoticed.

Purchasing Higher-Tier Plans  

As noted earlier, many organizations quickly upgrade to higher-tier plans like E3 or E5, or add premium features for every user, often paying for tools that remain unused. 

Licenses Left Running  

Another major source of waste comes from licenses that are assigned but no longer in use. Employees may have shifted roles, gone on leave, moved to part-time, or even left the company, yet their premium licenses remain active. If left unchecked, these idle licenses quietly drain the budget, adding up to significant financial loss over time.

Deleting Users During Offboarding  

Organizations may delete user accounts during offboarding without first unassigning licenses. Deleting a user account does not automatically reclaim those licenses in Microsoft 365. Therefore, unless you manually unassign licenses or set up automation, you will continue paying for unused licenses long after the employee has left.

Duplicate Functionality Assigned to the Same User  

Microsoft 365’s admin portal does not flag duplicate assignments. This increases the chance that your organization may assign redundant tools or capabilities to a single user. For example, giving someone both an E3 and a standalone Defender license that already comes with E3. This simply means you are paying twice for the same feature. 

How to Reduce Waste in Microsoft 365 Security and Copilot Add-Ons

The good news is that much of this waste can be avoided. With discipline, proper tools, and regulation, you can redirect your budget to a smarter use of Microsoft 365. Below are some of the main strategies to adopt.

Downgrade Light Users

Not all users require an E3 or E5 license. For example, why give your receptionist a complete E5 license with enhanced compliance tools if they’re only emailing and using Teams? By monitoring actual usage, you can downgrade such users to E1 or another lower-tiered plan without affecting productivity. Low-usage discovery utilities enable you to downgrade confidently without speculation.

Automate Offboarding of Ex-Employees  

By automating offboarding processes, licenses are unassigned automatically once you mark an employee as departed. Use workflow tools like Power Automate linked to HR systems or forms to revoke access, remove group memberships, convert mailboxes, and unassign licenses in one automated process.

Consolidate Overlapping Features  

Review your security, compliance, collaboration, and analytics tools to find overlaps. If your plan already offers advanced threat protection or endpoint detection, consider canceling redundant third-party tools. If Copilot add-ons duplicate other AI or automation tools you already use, streamline them under one system.

Review Group and Shared Mailboxes  

Many organizations mistakenly assign premium licenses to shared mailboxes, service accounts, or inactive mailboxes. This doesn’t offer any functional benefits. Think about converting them to free shared mailboxes or archiving them to free up license slots. That way, you ensure that your M365 budget is only spent on value-generating users.

Enable License Expiration Alerts and Governance Policies

Avoid wastage in the future by setting up policy checks and notifications, and make sure you respond as needed. Note down renewal dates for contracts so you don’t accidentally auto-renew unused licenses. Also, track levels of inactivity and flag for review licenses that have passed the threshold.

Make Microsoft 365 Work Smarter for You  

Don’t let Microsoft 365 licenses and add-ons quietly drain your resources. Take control by reviewing how each license is used. When you match your tools with actual business needs, you save money, simplify management, and improve productivity in your organization. 

Optimizing your Microsoft 365 environment is all about getting the most value from what you already own. By using M365 security and Copilot add-ons wisely, your business can operate more efficiently and securely. If you’re looking to better manage licensing and make smarter technology decisions, reach out to our team of experts who have helped organizations do exactly that. Let’s get started today.

—

Featured Image Credit

This Article has been Republished with Permission from The Technology Press.

https://speedwise.net/wp-content/uploads/2025/11/Beyond-Licensing_-How-to-Stop-Wasting-Money-on-Your-Microsoft-365-Security-and-Copilot-Add-Ons-scaled-1.jpg 1707 2560 admin https://speedwise.net/wp-content/uploads/2020/09/SpeedWise_Final_DropShadow_white_background_300x80.png admin2025-12-05 12:00:002025-11-03 21:00:12Beyond Licensing: How to Stop Wasting Money onYour Microsoft 365 Security and Copilot Add-Ons
Search Search

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • June 2017
  • May 2017
  • March 2017
  • February 2017
  • January 2017
  • December 2016
  • November 2016
  • October 2016
  • September 2016
  • August 2016
  • July 2016
  • June 2016
  • May 2016
  • April 2016
  • March 2013
  • September 2012
  • April 2012
  • February 2012
  • November 2011
  • October 2011
  • September 2011
  • August 2011

Interesting links

Here are some interesting links for you! Enjoy your stay :)

Pages

  • About
  • Blog
  • Contact
  • doc-repository
  • doc-repository-x0425ui
  • Email Disclaimer
  • Home
  • Managed IT Services Inclusion List
  • New Client Information Form
  • Privacy Policy
  • Recommended Technology Platform
  • Service Level Objective (SLO)
  • Services
  • Taxes, Surcharges & Fees
  • Third Party Service Provider EULAs

Categories

  • AI
  • Business
  • Cloud
  • Cybersecurity
  • IT Management
  • Microsoft
  • New Technology
  • Online Presence
  • Productivity
  • SpeedWise News, Info, & Tips
  • Uncategorized
  • Working from Home
© Copyright - SpeedWise IT Services - 720-443-0445
  • Client Portal
  • Billing Portal
  • Remote Session

This site uses cookies. By continuing to browse the site, you are agreeing to our use of cookies.

OKLearn more

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

Privacy Policy
Accept settingsHide notification only
Scroll to top