Microsoft: Unsupported Windows devices to lose security updates after 2027 certificate rotation

Windows Update certificates expire in May and June 2027, with Microsoft urging administrators to upgrade before then

By LineZotpaper
Published
Read Time2 min
Microsoft has warned that devices running unsupported versions of Windows will stop receiving security updates after the Windows Update certificate rotation next year. The certificates are set to expire on May 17, 2027 and June 19, 2027, and Microsoft is advising administrators to identify outdated systems and plan upgrades before those dates.

Microsoft said on Thursday that a set of Windows Update certificates will expire in May and June 2027, and devices on unsupported Windows versions "will lose access to Windows Update services and won't receive any updates as a result."

"As a standard security practice, these certificates have an expiration date. This means that they eventually need to be rotated (that is, replaced by new certificates)," the company said.

According to Microsoft, replacement certificates have already been delivered to systems running a supported Windows version and require no additional action if those systems are up to date. The company has issued version-specific guidance: Windows 11 version 25H2 and later need no action; Windows 11 24H2 and Windows Server 2025 must install the September 2025 security update or later before June 19, 2027; other supported Windows 11 versions, Windows Server 2022, and Windows 10 must install the July 2026 security update or later before the same date; and Windows 10 Enterprise 2019 LTSC, Windows Server 2019, and Windows Server 2016 must install the July 2026 security update or later before May 17, 2027.

Other Windows versions should be upgraded to a supported edition of Windows client or Windows Server, Microsoft said. The company advised IT administrators to inventory devices running older or unsupported versions, deploy monthly updates on supported systems, and create an upgrade plan before the certificate expirations.

"And if you do need to act on older device populations, there's still time! Review, update, and plan upgrades for unsupported versions before the May 2027 or June 2027 certificate expiration dates," Microsoft added.

The change does not affect devices that receive updates through Windows Server Update Services (WSUS), which distributes updates across enterprise networks independently. Last month, Microsoft released Windows 11 version 26H2, the Windows 11 2026 Update, as a small enablement package for eligible Windows 11 24H2 and 25H2 systems in a phased rollout.

§

Analysis

Why This Matters

  • Organizations still running unsupported Windows versions could lose access to security updates entirely, leaving systems exposed to known vulnerabilities.
  • The May and June 2027 deadlines give enterprises a fixed window to plan migrations, but legacy hardware may not support newer Windows versions.
  • The certificate rotation is a reminder that even out-of-support software relies on infrastructure that eventually expires.

Background

Microsoft periodically rotates the certificates used to secure Windows Update traffic, treating expiry as a standard security practice. In the past, similar rotations have prompted warnings about older systems losing update access. The current announcement extends that pattern, setting firm dates when older and unsupported Windows clients and servers will no longer receive patches through Windows Update.

Key Perspectives

Microsoft: Positions the rotation as routine security hygiene and says replacement certificates are already in place for supported, up-to-date systems. It stresses that there is still time for administrators to review and upgrade older device populations. IT administrators: Face the practical burden of inventorying devices, testing updates, and migrating legacy machines, some of which may not be eligible for newer Windows releases and could require hardware replacement. Critics and skeptics: May question whether the deadline pressures organisations into costly upgrades, and note that machines left behind could become a security risk on corporate networks even if they are no longer receiving updates.

What to Watch

  • Whether Microsoft extends the certificate expiration dates if many organisations are not ready, as it has done with some past Windows support deadlines.
  • How enterprises respond to the guidance for Windows 10, which has broader legacy device populations that may not support Windows 11.
  • Whether the affected unsupported systems, once cut off from Windows Update, become a visible source of new vulnerabilities in enterprise environments.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.

How we workSubscribe