Windows Update certificate expiry to cut off old PCs in 2027
Windows devices running unsupported versions of the operating system will stop getting security updates once Microsoft rotates its Windows Update certificates next year, the company has warned.
The certificates involved expire on May 17, 2027 and June 19, 2027. After that, any machine that has not been moved to a supported Windows release will be cut off from Windows Update entirely.
Microsoft explained the reason in an announcement published on Thursday. "As a standard security practice, these certificates have an expiration date. This means that they eventually need to be rotated (that is, replaced by new certificates)," the company said.
Devices on unsupported versions "will lose access to Windows Update services and won't receive any updates as a result," it added. Its recommendation is "upgrading to a supported version of Windows client or server."
Two deadlines, depending on the version
The steps needed depend on which Windows release a device runs. Microsoft has published guidance for each one:
- Windows 11, version 25H2 and later: nothing needs to be done.
- Windows 11, version 24H2 and Windows Server 2025: install the September 2025 security update or a later one before June 19, 2027.
- Other supported Windows 11 versions, Windows Server 2022 and Windows 10: install the July 2026 security update or a later one before June 19, 2027.
- Windows 10 Enterprise 2019 LTSC, Windows Server 2019 and Windows Server 2016: install the July 2026 security update or a later one before May 17, 2027.
- All other Windows versions: upgrade to a supported Windows client or Windows Server release.
So, for most supported systems, the fix is simply to keep installing monthly patches. Older server releases and the 2019 LTSC (Long-Term Servicing Channel, a Windows 10 edition built for specialised systems that rarely change) face the earlier May deadline.
What admins are asked to do
Microsoft wants IT teams to start with an inventory. Administrators should find every device in their environment that runs an older or unsupported Windows version before the 2027 certificate rotation.
Supported machines should get the monthly Windows updates so they stay current. For unsupported machines, organisations are told to build an upgrade plan well before the May and June deadlines.
"And if you do need to act on older device populations, there's still time! Review, update, and plan upgrades for unsupported versions before the May 2027 or June 2027 certificate expiration dates," Microsoft said.
There is one exception. The change does not apply to devices that get their updates through Windows Server Update Services (WSUS), the Microsoft tool that enterprises use to download updates centrally and push them out across their own networks.
26H2 rollout continues
The warning comes shortly after Microsoft shipped Windows 11, version 26H2, also called the Windows 11 2026 Update, last month. It is generally available for eligible Windows 11 24H2 and 25H2 systems.
Rather than replacing the whole operating system, 26H2 is delivered as a small enablement package. The rollout is phased and will reach more devices over the coming months.
Our Take
For many readers, this announcement turns a slow-moving support problem into a hard technical cutoff. Running an unsupported Windows version has always meant missing new patches. After the 2027 certificate rotation, it appears these machines will not be able to reach Windows Update at all, which removes any chance of picking up stray fixes later.
The practical risk sits in the systems that nobody owns. Old servers, forgotten lab machines and specialised LTSC devices are often the ones left behind, and they tend to be the hardest to upgrade. Unpatched software keeps showing up as a root cause in real incidents, as in the ShinyHunters breach blamed on a missed PeopleSoft patch. Microsoft's call for a full device inventory is therefore the most useful step here, even for teams that think they are already up to date.
The deadlines also mean admins cannot simply skip monthly updates for long. Patches sometimes break things, as seen with the KB5124010 update that crashed some games, and some organisations delay rollouts because of that. Under this plan, delaying past the July 2026 update on affected versions could carry a much higher cost.
It is worth watching whether Microsoft publishes more detail on how WSUS environments will be handled, and whether the May 2027 date for older server releases leaves enough time for organisations with large legacy fleets. Teams that start mapping their devices now will likely have the easiest transition.
