Windows machines that are not current with updates face a significant change in access to Windows Update, with two critical certificate expirations set for May 17, 2027, and June 19, 2027. According to a recent post on the Windows IT Pro Blog, published on October 8, 2026, devices running supported versions must install a specific security update prior to these dates to maintain their connection to Windows Update services.
As outlined in the blog, “Windows Update uses certificate-based trust to confirm that your devices are connecting to authoritative Windows Update servers.” As a standard security measure, these certificates have expiration dates and need to be renewed. While most devices will receive the necessary updates through regular monthly patches, certain Windows versions will require proactive action from IT administrators. Failure to address these updates will result in affected devices losing their ability to connect and receive any updates from Windows Update.
What Microsoft requires depends on the version
The requirements for updates vary by Windows version, with some needing no action at all, while others must install a specific security update before the deadlines:
- Windows 11, version 25H2 and later: No action required.
- Windows 11, version 24H2 and Windows Server 2025: Must install the September 2025 Windows security update or later, before June 19, 2027.
- Other in-support Windows 11 versions and Windows Server 2022: Must install the July 2026 Windows security update or later, before June 19, 2027.
- In-support Windows 10 versions: Must install the July 2026 Windows security update or later, before June 19, 2027.
- Windows 10 Enterprise 2019 LTSC, Windows Server 2019 and Windows Server 2016: Must install the July 2026 Windows security update or later, before May 17, 2027.
- Any other Windows version: Upgrade to a supported release, as these devices will lose access to Windows Update services.
Three outcomes after the expiry dates
According to Microsoft, devices running a supported version that are up to date will “continue receiving updates without interruption,” as they already possess the necessary updated certificates. Conversely, machines that are behind on updates will be unable to access Windows Update services after the specified expiration dates. Microsoft advises users to refer to the Microsoft Update Catalog for direct downloads of the necessary updates or utilize their organization’s management tools.
For devices operating on versions of Windows that are out of support, the situation is more dire; they will lose access to Windows Update services entirely and will not receive any updates as a result.
At present, there is no immediate cause for concern, as both expiration dates are set for 2027. A PC that consistently receives its monthly updates will seamlessly navigate through this transition without any required action. Notably, Microsoft has clarified that this situation does not apply to devices receiving updates from Windows Server Update Services (WSUS).
While the communication primarily targets IT administrators, the versions mentioned are relevant to everyday users, including those running Windows 10 and earlier releases of Windows 11. Additionally, Microsoft has acknowledged a separate issue affecting some users: a defect in the September update that may cause games utilizing AC-3 audio to close unexpectedly.
The notice regarding the certificate expiration was also posted on Microsoft’s Windows message center on October 8, and it was noted again on October 10, emphasizing the importance of addressing these updates: “Devices without the replacement certificates will lose access to Windows Update after the applicable expiration date.”