GeneralMedium

Microsoft: Unsupported Windows devices will lose Windows Update after 2027 certificate rotation

Windows Update certificates expire in May and June 2027; devices without the replacement certificates, including all unsupported versions, will stop receiving updates.

Microsoft: Unsupported Windows devices will lose Windows Update after 2027 certificate rotation

At a glance

  • Windows Update certificates expire on May 17 and June 19, 2027, and must be rotated, Microsoft said.
  • Devices on unsupported Windows versions will lose access to Windows Update and receive no further updates.
  • Supported systems need recent cumulative updates (September 2025 or July 2026, depending on version) installed before the deadlines.
  • Devices that get updates from WSUS are not affected by the change.

Microsoft has warned that devices running unsupported Windows versions will stop receiving updates once Windows Update certificates are rotated next year, BleepingComputer reported on October 9. The company said in its Windows release health message center on Thursday that such devices "will lose access to Windows Update services and won't receive any updates as a result," giving organizations months to identify and upgrade outdated systems.

What happened

According to Microsoft, the certificates used by Windows Update expire on May 17, 2027 and June 19, 2027 and must be replaced, as is standard practice for certificates with expiration dates. Replacement certificates have already been delivered to systems on supported Windows versions, and devices that are up to date need no additional action, the company said. The change is also covered in Microsoft 365 Message Center update MC1491763.

The change does not apply to devices that receive their updates through Windows Server Update Services (WSUS), BleepingComputer noted.

Who is affected

Microsoft listed the following requirements by version, according to BleepingComputer:

  • Windows 11, version 25H2 and later: no action required.
  • Windows 11, version 24H2 and Windows Server 2025: install the September 2025 security update or later before June 19, 2027.
  • Other supported Windows 11, Windows Server 2022 and Windows 10 versions: install the July 2026 security update or later before June 19, 2027.
  • Windows 10 Enterprise 2019 LTSC, Windows Server 2019 and Windows Server 2016: install the July 2026 security update or later before May 17, 2027.
  • All other Windows versions: upgrade to a supported version of Windows client or Windows Server.

The practical effect is that machines running end-of-support releases, or supported releases that have fallen far behind on patches, risk being cut off from Windows Update entirely, leaving them exposed to newly discovered vulnerabilities.

What to do

Microsoft advises administrators to inventory devices running older or unsupported Windows versions well ahead of the 2027 rotation, keep deploying monthly cumulative updates on all supported devices, and build an upgrade plan for unsupported systems before the May and June 2027 deadlines. Organizations with legacy systems that cannot be upgraded should plan compensating controls, such as network isolation, since those devices will no longer receive security fixes through Windows Update.

BleepingComputer also noted that Windows 11, version 26H2 was released last month as a small enablement package for eligible Windows 11 24H2 and 25H2 systems, rolling out in phases.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.