How to Secure Windows 10 in 2026 (After End of Support)

·
7 min read

Help Desk Geek is reader-supported. We may earn a commission when you buy through links on our site. Learn more.

Windows 10 reached end of support on October 14, 2025, with no free security patches unless you’re enrolled in Extended Security Updates (ESU). If your hardware can run Windows 11 24H2, upgrading is the strongest move; the steps below are for machines that must stay on Windows 10.

Check Your Version and Install All Updates

Before changing any setting, confirm you’re on Windows 10 22H2, the final Windows 10 release, and that every available update is installed.

  1. Press Windows + I to open Settings.
  2. Go to System > About and confirm Version shows 22H2 under Windows specifications.
Windows 10 Settings > System > About showing Version 22H2 under Windows specifications
  1. Go to Update & Security > Windows Update.
  2. Click Check for updates and install everything listed.
Windows 10 Settings > Update & Security > Windows Update page with Check for updates button highlighted

If Windows Update reports you’re fully current but there’s no mention of ESU, your device is getting no new security patches. Home users can enroll in ESU for paid coverage through October 12, 2027; business and education customers through October 10, 2028. Without ESU, unpatched vulnerabilities accumulate. It’s a slow bleed, not a cliff.

Configure Microsoft Defender (Virus & Threat Protection)

Windows Security is the central console for all of Windows 10’s built-in defenses. Start here.

  1. Click Start, type Windows Security, and open the app.
  2. Click Virus & threat protection.
  3. Under Virus & threat protection settings, click Manage settings.
  4. Confirm all three are On:

Real-time protectionCloud-delivered protectionAutomatic sample submission

Windows Security > Virus & threat protection > Manage settings panel with Real-time protection, Cloud-delivered protection, and Automatic sample submission all toggled On

If a third-party antivirus is installed, it may own these settings from its own dashboard. That’s fine, but verify its real-time protection is actually active.

Enable Tamper Protection

Tamper Protection stops malware and careless apps from quietly switching off Defender’s real-time scanning without your approval.

  1. Still in Virus & threat protection > Manage settings, scroll down to Tamper Protection.
  2. Toggle it On.
Windows Security > Virus & threat protection > Manage settings showing Tamper Protection toggle set to On

Some systems ship with it off. Check it now; it’s one toggle and takes five seconds.

Turn On Ransomware Protection (Controlled Folder Access)

Controlled Folder Access blocks untrusted apps from writing to your Documents, Pictures, and other protected folders. It’s the best built-in defense against ransomware encrypting your files.

  1. In Windows Security, click Virus & threat protection.
  2. Scroll to Ransomware protection and click Manage ransomware protection.
  3. Toggle Controlled folder access to On.
  4. Click Protected folders to add any other folders you want covered.
Windows Security > Virus & threat protection > Ransomware protection page with Controlled folder access toggled On and Protected folders link visible

Some apps will get blocked from saving files after you enable this; photo editors and design tools are the common offenders. Fix it by going to Allow an app through Controlled folder access and adding the program.

Verify Windows Firewall Is On

  1. In Windows Security, click Firewall & network protection.
  2. Confirm the firewall shows On for all three profiles: Domain network, Private network, and Public network.
Windows Security > Firewall & network protection showing Domain, Private, and Public network profiles all displaying as On
  1. Click Allow an app through firewall and scroll the list.
  2. Under the Public column, uncheck File and Printer Sharing and any Remote services (Remote Assistance, Remote Desktop) unless you actively use them.
Windows Defender Firewall allowed apps list with File and Printer Sharing and Remote Desktop unchecked in the Public column

On public Wi-Fi, including at airports and coffee shops, a reputable VPN adds a layer of encryption the firewall alone can’t provide.

Enable SmartScreen (App & Browser Control)

SmartScreen flags malicious downloads and known-bad sites before they do damage.

  1. In Windows Security, click App & browser control.
  2. Click Reputation-based protection settings.
  3. Turn on:

Check apps and filesSmartScreen for Microsoft EdgePotentially unwanted app blocking

Windows Security > App & browser control > Reputation-based protection settings with Check apps and files, SmartScreen for Microsoft Edge, and Potentially unwanted app blocking all toggled On

If you use Chrome or Firefox, confirm each browser’s built-in phishing and malware protection is enabled in its own settings, and keep browsers updated automatically.

Secure Your Sign-In

  1. Open Settings > Accounts > Sign-in options.
  2. Set up a Windows Hello PIN if you haven’t. A PIN is tied to this device only, so a stolen password alone won’t unlock it.
  3. If your hardware has a fingerprint reader or IR camera, add Fingerprint or Face recognition under Windows Hello.
  4. Set Require sign-in to When PC wakes up from sleep.
Windows 10 Settings > Accounts > Sign-in options showing Windows Hello PIN, Fingerprint, and Face recognition setup options with Require sign-in set to When PC wakes up from sleep

If you sign in with a Microsoft account, enable two-factor authentication (MFA) at the Microsoft account security page. A password manager covers the rest; unique passwords per site mean one breach stays contained instead of spreading.

Turn On Device Encryption or BitLocker

Encryption protects your data if the laptop is stolen or the drive is pulled. Without it, anyone with physical access can read your files.

Windows 10 Home (Device Encryption):

  1. Go to Settings > Update & Security > Device encryption.
  2. If available and off, click Turn on.

Windows 10 Pro or Enterprise (BitLocker):

  1. Press Windows + S, type BitLocker, and select Manage BitLocker.
  2. Click Turn on BitLocker next to your system drive (typically C:).
  3. Save the recovery key somewhere safe: print it, or back it up to your Microsoft account. Don’t store it only on the drive you’re encrypting.
Windows 10 BitLocker Drive Encryption control panel with C: drive listed and Turn on BitLocker option visible

If neither option appears, your device may lack a compatible TPM chip. Check Windows Security > Device security to see what your hardware supports.

Confirm Secure Boot Is On

Secure Boot prevents unauthorized code from loading before Windows starts. It’s the barrier against bootkit malware.

  1. In Windows Security, click Device security.
  2. Under Secure Boot, confirm the status shows On.
Windows Security > Device security page showing Secure Boot status listed as On

If it’s off, you’ll need to enable it in your UEFI firmware. The exact menu path varies by manufacturer, so check your PC or motherboard maker’s support site for instructions on entering UEFI at startup.

Reduce Tracking in Privacy Settings

  1. Open Settings > Privacy.
  2. Under General, turn off Let apps use advertising ID, Let websites provide locally relevant content, and Send Microsoft info about how I write.
  3. Work through each category on the left, including Location, Camera, Microphone, and Contacts, and disable access for any app that doesn’t genuinely need it.
Windows 10 Settings > Privacy > General with advertising ID toggle and related settings, most set to Off

You don’t have to disable everything. Turn off what you don’t use; leave on what you do.

Set UAC to Always Notify

  1. Press Windows + S, type UAC, and click Change User Account Control settings.
  2. Drag the slider to Always notify (the top position).
  3. Click OK.
User Account Control Settings dialog with the slider moved to the Always notify position at the top

You’ll see more prompts day to day. That’s the trade-off. Anything attempting unauthorized system changes triggers a warning before it happens.

Set a Lock Screen Timeout

  1. Open Settings > System > Power & sleep.
  2. Set Screen to 5 minutes (or whatever fits your workflow).
  3. Set Sleep to 15 minutes or less.
Windows 10 Settings > System > Power & sleep with Screen and Sleep timeout dropdowns set to short intervals

A machine that stays unlocked while you’re away gives anyone nearby full access to everything on it.

Remove Unused Software and Trim Startup Programs

Every installed app is a potential entry point. Cut what you don’t need.

  1. Go to Settings > Apps > Apps & features.
  2. Scroll through and uninstall anything you haven’t used in months or don’t recognize.
Windows 10 Settings > Apps > Apps & features list with an app selected showing the Uninstall button
  1. Press Ctrl + Shift + Esc to open Task Manager, then click the Startup tab.
  2. Right-click non-essential programs and select Disable.

Fewer startup items also means a faster boot, a side benefit worth having.

Set Up a Backup

Backups won’t stop an attack, but when ransomware hits, they’re the difference between a quick restore and a total loss.

  1. Plug in an external hard drive.
  2. Go to Settings > Update & Security > Backup.
  3. Click Add a drive under Back up using File History and select your drive.
  4. Click More options and set a backup frequency; hourly is reasonable for active machines.
Windows 10 Settings > Update & Security > Backup page with File History turned on and an external hard drive selected as the backup destination

Pair local backups with a cloud backup service for your most important files. Keep at least one copy somewhere physically separate from your desk; a drive that lives next to your laptop gets stolen or destroyed with it.

Should You Upgrade to Windows 11?

If your hardware qualifies, yes. Download the PC Health Check app from Microsoft to find out. If your machine passes, go to Settings > Update & Security > Windows Update; the Windows 11 upgrade offer should appear there.

If your device genuinely can’t run Windows 11, the steps above give you the best security posture Windows 10 can provide. ESU covers critical patches through 2027 (home) or 2028 (business/education). After those dates expire, no in-OS hardening compensates for an OS that isn’t receiving patches. At that point, new hardware is worth the cost.

Conclusion

The four changes with the highest impact: install all pending updates and enroll in ESU if you’re staying long-term, enable Tamper Protection, turn on Controlled Folder Access, and activate device encryption. Get those done first. If your machine is eligible for Windows 11 24H2, that upgrade does more for your security posture than every other step here combined. A supported OS patches new vulnerabilities; a hardened unsupported one doesn’t.