Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Windows 10 version 21H1 reached end of servicing on December 13, 2022. Do not use it as a new production baseline in 2026. Use the procedure below only for a controlled legacy environment, lab, recovery requirement, or historical runbook. For supported production devices, evaluate Windows 11, or Windows 10 22H2 with applicable Extended Security Updates where Windows 11 is not yet feasible. Microsoft’s current Configuration Manager support matrix lists Windows 10 22H2 rather than 21H1: Windows 10 support in Configuration Manager.

“SCCM” is the common legacy name for Microsoft Configuration Manager. This guide covers an in-place upgrade that is intended to preserve applications, settings, and user data; it is not a clean-install or reimage workflow.

What Windows 10 21H1 was

Windows 10 21H1, the May 2021 Update, shared its underlying code base with Windows 10 2004 and 20H2. Microsoft could therefore activate 21H1 features with a small enablement package instead of replacing the whole operating-system image. That path was substantially faster than a full feature upgrade, but only when the source device met Microsoft’s prerequisite state.

Microsoft ended servicing for Windows 10 21H1 editions on December 13, 2022: Microsoft’s Windows 10 servicing announcement. A technically successful deployment does not make 21H1 a supported security baseline.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose the upgrade method before building anything

Method Use it when Content and main risks
Feature update or enablement package in a task sequence The historical source is Windows 10 2004 or 20H2, the update is applicable, and you need task-sequence actions before or after servicing. Usually smaller servicing content; depends on Software Update Point (SUP), Upgrades synchronization, applicability, and prerequisite updates.
OS upgrade package and in-place-upgrade task sequence The source is older than the enablement-package path, full installation media is required, or extensive orchestration is needed. Larger source package; edition, architecture, language, driver, application, and Windows Setup compatibility are critical.
Direct feature-update deployment No pre-upgrade or post-upgrade task-sequence logic is required. Simpler than a task sequence, with fewer orchestration and content-management failure points.

Feature updates became available in task sequences in Configuration Manager 2103; version 2107 added a task-sequence wizard that can use only a feature update. See Microsoft’s task-sequence documentation. A task sequence is not automatically better than servicing directly: choose it when its conditions, scripts, applications, restarts, and validation steps provide real value.

Prerequisites and compatibility checks

Historical 21H1 enablement-package requirements

  • Source operating system: Windows 10 version 2004 or 20H2.
  • September 8, 2020 servicing-stack update or later.
  • May 11, 2021 cumulative update KB5003173 or later.
  • A restart after installation.

These requirements are documented in KB5000736. A device can display 2004 or 20H2 and still be inapplicable if its servicing stack or cumulative-update state is wrong.

ConfigMgr and infrastructure

  • A supported Configuration Manager current-branch site and client.
  • For a feature-update task sequence, a SUP synchronized with the Upgrades classification and Windows 10 product.
  • A deployment package for the feature update, distributed to accessible distribution points, unless the deployment is configured for peer or Microsoft cloud content.
  • Distribution points for OS upgrade media, applications, packages, drivers, and updates used by the sequence.
  • Matching edition, architecture, and language. An OS upgrade package must match the client on all three dimensions: in-place upgrade requirements.

Inventory the estate

Separate devices by source build, edition, x86/x64 architecture, language, BitLocker state, model, VPN, endpoint-security product, encryption driver, and business-critical applications. Check a representative sample with:

Get-ComputerInfo |
    Select-Object WindowsProductName, WindowsVersion, OsBuildNumber, OsArchitecture

For a quick interactive check, run winver. Use build and edition data in ConfigMgr collections rather than an informal label such as “21H1.” Exclude devices with known driver, application, encryption, or hardware blockers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prepare the update content

  1. In the console, open Administration > Site Configuration > Sites and verify the software-update infrastructure.
  2. Confirm the SUP synchronizes Windows 10 and Upgrades, then run synchronization.
  3. Open Software Library > Windows Servicing > All Windows Feature Updates and locate the 21H1 update, if retained in the legacy environment.
  4. Verify architecture, language, edition or business classification, applicability, download state, deployment-package association, and any required license-term acceptance.
  5. Download the correct variant, distribute it to required distribution points, validate content, and test retrieval from a pilot client.

If using full media, import an OS upgrade package whose source matches the client’s edition, architecture, and language, then distribute it. Do not combine an enablement package and a full OS upgrade package indiscriminately; they are different deployment mechanisms.

Create the task sequence

  1. Go to Software Library > Operating Systems > Task Sequences and select Create Task Sequence.
  2. Choose Upgrade an operating system from an upgrade package for full installation media, or the feature-update-based workflow available in your ConfigMgr branch.
  3. Give the sequence a versioned name and description that identify source builds, target build, architecture, language, and retirement date.
  4. Select the upgrade content. Add only software updates and applications that are required for the migration.
  5. Configure restart behavior, maintenance-window requirements, user notifications, and failure handling.
  6. Add preflight, preparation, upgrade, post-upgrade, and failure groups before deploying to a pilot collection.

Recommended sequence groups

Preflight validation

  • Supported source build, edition, architecture, and language.
  • Free space on the system drive and system-reserved partition.
  • AC power for laptops, no pending reboot, and an appropriate maintenance window.
  • BitLocker state and recovery-key escrow.
  • Required servicing-stack and cumulative updates.
  • VPN, endpoint-security, third-party encryption, drivers, and known-blocking applications.

Make a failed check return a clear status message and stop before Windows Setup begins.

Preparation

  • Suspend BitLocker only where policy requires it, and plan to resume it.
  • Temporarily stop tested conflicting services; do not remove drivers or language packs with untested cleanup scripts.
  • Close or defer user applications, save logs, apply prerequisite updates, and set model or department variables.

Upgrade and restart

Use the Upgrade Operating System step. For a custom sequence, Microsoft identifies it as the core required step; follow it with Restart Computer configured to restart into the currently installed operating system, not Windows PE: Microsoft’s upgrade guidance.

Post-upgrade validation

  • Confirm Windows version and build independently of ConfigMgr status.
  • Resume BitLocker, re-enable services, repair or reinstall management and security agents, and reapply policy.
  • Trigger hardware inventory and software-update evaluation.
  • Validate critical applications, endpoint protection, client health, and recovery-key escrow.

Deploy in controlled rings

  1. Lab: IT-owned physical devices and virtual machines.
  2. Pilot: Representative hardware, applications, VPN clients, encryption products, and user profiles.
  3. Early production: Low-risk departments with help-desk coverage.
  4. Broad production: Remaining eligible devices after pilot evidence is reviewed.
  5. Exception: Devices requiring manual remediation or a different migration plan.

Choose Available or Required intentionally. Define postponement limits, download behavior, AC-power requirements, reboot deadlines, maintenance windows, and the user message. Do not conceal a long reboot interval.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Verify that the upgrade really completed

Monitor deployment state, step failures, content-download errors, rollbacks, unchanged source builds, repeated retries, and post-upgrade client failures. A ConfigMgr “success” state proves orchestration completed; it does not prove Windows changed versions.

Rank #2
Ralix Reinstall USB Compatible with Windows 10 All Versions 32/64 bit. Recover, Restore, Repair Boot USB, and Install to Factory Default Will Fix PC Easy!
  • Comprehensive Solution: This Windows 10 reinstall DVD provides a complete solution for resolving various system issues, including crashes, malware infections, boot failures, and performance slowdowns. Repair, Recover, Restore, and Reinstall any version of Windows.
  • USB will work on any type of computer (make or model). Creates a new copy of Windows! DOES NOT INCLUDE product key.
  • Windows not starting up? NT Loader missing? Repair Windows Boot Manager (BOOTMGR), NTLDR, and so much more with this DVD. Clean Installation: Allows you to perform a fresh installation of Windows 11 64-bit, effectively wiping the system and starting from a clean slate.
  • Step by Step instructions on how to fix Windows 10 issues. Whether it be broken, viruses, running slow, or corrupted our disc will serve you well
  • Please remember that this DVD does not come with a KEY CODE. You will need to obtain a Windows Key Code in order to use the reinstall option
$os = Get-ComputerInfo
[pscustomobject]@{
    ProductName  = $os.WindowsProductName
    Version      = $os.WindowsVersion
    Build        = $os.OsBuildNumber
    Architecture = $os.OsArchitecture
}

Confirm the expected build, functioning ConfigMgr client, policy receipt, inventory, software-update evaluation, BitLocker state, and critical applications before marking a device successful.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Understand the in-place-upgrade boundaries

Do not use this workflow to change domain membership, alter the local Administrators group as part of deployment, repartition disks, convert x86 to x64, perform UEFI conversion, change the base operating-system language, or satisfy WinPE-offline, custom-image, or certain third-party-encryption requirements. Those scenarios generally require a separate reimage or migration design.

Windows Setup can also block devices booted from Windows To Go, VHD, Safe Mode, or Audit Mode. Mismatched language or architecture, incompatible drivers or applications, BitLocker conditions, pending servicing operations, and insufficient disk or system-partition space are common hard blockers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Troubleshoot common failures

The update is missing in the console

  • Check that synchronization completed and Windows 10 plus Upgrades are selected.
  • Refresh the console and confirm the update is not expired or superseded.
  • Verify applicability, architecture, language, edition, license acceptance, package association, and distribution-point content.

The task sequence skips the upgrade

Check feature-update applicability, KB5003173-or-later and servicing-stack prerequisites, the selected update object, update-store health, content availability, and policy receipt. Inspect task-sequence and software-update logs rather than adding unrelated packages.

Windows Setup rolls back

Collect:

  • C:$Windows.~BTSourcesPanther
  • C:$Windows.~BTSourcesRollback
  • C:WindowsPanther
  • C:WindowsPantherNewOS

Run Microsoft SetupDiag online or against copied logs:

SetupDiag.exe /Output:C:SetupDiagResults.txt
SetupDiag.exe ^
  /Output:C:SetupDiagResults.txt ^
  /LogsPath:D:TempLogs

SetupDiag documentation and rules are listed at Microsoft SetupDiag. Investigate the named driver, application, language pack, Feature on Demand, encryption component, hardware requirement, boot configuration, or disk-space condition. Do not use compatibility-ignore switches as a blanket fix.

The device reboots but remains on the old version

Validate the actual build and inspect both ConfigMgr logs and Windows Setup logs. The update may have been inapplicable, the wrong object may have been selected, a prerequisite may be missing, Setup may have rolled back, or the restart may have occurred before the upgrade phase.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Diagnostic evidence by area

Area Evidence
Task-sequence execution smsts.log; its location varies between full Windows, Windows PE, and post-restart phases.
Windows Setup downlevel phase setupact.log and setuperr.log under Panther.
Rollback Logs under $Windows.~BTSourcesRollback.
SetupDiag SetupDiagResults.log or configured text/XML output.
Content retrieval ConfigMgr content-transfer and Location Services logs.
Software-update applicability Updates deployment and update-store logs.
Post-upgrade management Client-location, policy, inventory, and software-update evaluation logs.

Should you deploy Windows 10 21H1 today?

No, except for a narrowly defined legacy, lab, recovery, or historical-runbook requirement. In 2026, plan migration to an eligible Windows 11 release. If hardware or applications temporarily prevent that move, evaluate Windows 10 22H2 with the applicable Extended Security Updates program; ESU does not make 21H1 current. See Windows 11 and Windows 10 Extended Security Updates. For cloud-managed servicing, Microsoft Intune may complement or replace parts of an existing ConfigMgr design, but it is not a universal drop-in replacement for every on-premises task sequence.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.