Microsoft said on Thursday that a set of Windows Update certificates will expire in May and June 2027, and devices on unsupported Windows versions "will lose access to Windows Update services and won't receive any updates as a result."
"As a standard security practice, these certificates have an expiration date. This means that they eventually need to be rotated (that is, replaced by new certificates)," the company said.
According to Microsoft, replacement certificates have already been delivered to systems running a supported Windows version and require no additional action if those systems are up to date. The company has issued version-specific guidance: Windows 11 version 25H2 and later need no action; Windows 11 24H2 and Windows Server 2025 must install the September 2025 security update or later before June 19, 2027; other supported Windows 11 versions, Windows Server 2022, and Windows 10 must install the July 2026 security update or later before the same date; and Windows 10 Enterprise 2019 LTSC, Windows Server 2019, and Windows Server 2016 must install the July 2026 security update or later before May 17, 2027.
Other Windows versions should be upgraded to a supported edition of Windows client or Windows Server, Microsoft said. The company advised IT administrators to inventory devices running older or unsupported versions, deploy monthly updates on supported systems, and create an upgrade plan before the certificate expirations.
"And if you do need to act on older device populations, there's still time! Review, update, and plan upgrades for unsupported versions before the May 2027 or June 2027 certificate expiration dates," Microsoft added.
The change does not affect devices that receive updates through Windows Server Update Services (WSUS), which distributes updates across enterprise networks independently. Last month, Microsoft released Windows 11 version 26H2, the Windows 11 2026 Update, as a small enablement package for eligible Windows 11 24H2 and 25H2 systems in a phased rollout.