WINDOWS 7 END OF LIFE (PART II) – Installing Extended Security Updates (ESU)
Last Call
Today, January 14, 2020, marks the day that Microsoft will cease technical support for Windows 7, and will not update its security features again.
However, any size business running Windows 7 Professional or Enterprise can still purchase Windows 7 Extended Security Updates (ESU) through January 14, 2023.
Pre-Installation
-
Install the SHA-2 code signing support update and SSU (servicing stack update)
-
Install the Monthly Rollup and SSU:
- Once activated, continue use of current update and servicing strategy to deploy ESU through Windows Update, Windows Server Update Services (WSUS), Microsoft Update Catalog, or other patch management solution.
Installation and Activation
Install the ESU product key using the Windows Software Licensing Management Tool (slmgr). ESU product key installation does not replace current OS activation method utilized on the device. Use the Activation ID to differentiate between the OS activation and ESU activation.
- Open an elevated Command Prompt.
- Type
slmgr /ipk <ESU key>
and press Enter. - If the product key installed successfully, you will see a message similar to the following:
Find the ESU Activation ID:
- In the elevated Command Prompt, type
slmgr /dlv
and press Enter. - Note the Activation ID as you will need it in the next step.
Activate the ESU product key:
- Open an elevated Command Prompt.
- Type
slmgr /ato <ESU Activation Id>
and press Enter.
The following table outlines possible values for the <ESU Activation ID>
:
Once the ESU product key is activated, verify the status:
- Open an elevated Command Prompt.
- Type
slmgr /dlv
and press Enter. - Verify Licensed Status shows as Licensed for the corresponding ESU program.
- Use a management tool (e.g., System Center Configuration Manager) to send slmgr scripts to enterprise devices.
Install and activate ESU for machines unconnected to the Internet:
- Download and install the Volume Activation Management Tool (VAMT).
- Download the VAMT- ESU configuration file and update your VAMT configuration file.
- Configure the client device’s firewall for VAMT.
- Add the ESU product key to VAMT.
- Install KB4519972 prior to using VAMT to perform proxy activation, which will pick up the activation ID:
Verify Deployment
- Install optional, non-security update outlined in KB4528069. This test package has no security content. It is suitable for test environment deployment, and should be installed on on-premises devices eligible for ESU.
Trusted Tech Team is an accredited Microsoft CSP Direct Bill Partner, carrying multiple Solutions Partner designations and the now-legacy Microsoft Gold Partner competency. Based in Irvine, California, we report trends affecting IT pros everywhere.
If your organization uses Microsoft 365 or Azure, you may be eligible to receive a complimentary savings report from a Trusted Tech Team Licensing Engineer. Click here to schedule a consultation with our team now to learn how much you can save today.
Subscribe to the Trusted Tech Team Blog
Get the latest posts delivered right to your inbox