On October 8, Microsoft called on users of older versions of Windows and long-unpatched PCs to take action, because certificates used to connect to Windows Update will expire on May 17 and June 19, 2027. Affected devices that haven't received the new certificates will be unable to connect to Windows Update after the deadline, and will not be able to receive any type of update through the service. Most devices running a supported OS with monthly updates applied need no additional action. However, updating the certificates does not mean an outdated version of Windows can keep being used. Microsoft's official announcement lays out the required steps for each OS version and asks users to check support end dates and where devices actually get their updates.
Expired certificates can cut off Windows Update access
Windows Update uses digital certificates to confirm that a PC is connecting to a legitimate update server. Before receiving updates, the PC verifies that the server it is talking to can be trusted. These certificates have expiration dates, and as part of routine security practice, Microsoft periodically switches to new ones.
The issue this time is the connection used to obtain updates from Windows Update. According to Microsoft's explanation, affected devices that haven't installed the new certificates by the deadline will be unable to connect to Windows Update and will not receive any type of update. Unlike skipping a single fix for a specific vulnerability, the path for obtaining future updates itself could become unusable.
Particular caution is needed in environments that have put off Windows updates for a long time to avoid disrupting operations. Before the deadline, devices can receive the new certificates through regular monthly security updates. But if the required updates are not applied before the deadline passes, updates will have to be installed by some means other than Windows Update. The longer updates are postponed, the more devices administrators may have to recover manually later.
Also, even a relatively new version of Windows 11 doesn't necessarily have its monthly updates applied. To judge whether action is needed, you have to check not only the OS version but also which updates are actually installed.
Required action differs for Windows 11, Windows 10 and Windows Server
According to Microsoft, Windows 11 25H2 and later require no additional action for this certificate update. Earlier versions of Windows 11, as well as Windows 10 and Windows Server, need different updates and have different deadlines depending on the OS version. Based on the table Microsoft published on October 8, the requirements are as follows.
| OS / version | Required action | Deadline |
|---|---|---|
| Windows 11 25H2 and later | No additional action needed for this certificate update | Not applicable |
| Windows 11 24H2, Windows Server 2025 | Apply the September 2025 or later security update | June 19, 2027 |
| Other supported Windows 11 versions, Windows Server 2022 | Apply the July 2026 or later security update | June 19, 2027 |
| Supported Windows 10 | Apply the July 2026 or later security update | June 19, 2027 |
| Windows 10 Enterprise 2019 LTSC, Windows Server 2019, Windows Server 2016 | Apply the July 2026 or later security update | May 17, 2027 |
| Other Windows versions | Move to a supported version of Windows or Windows Server | Plan the move before the relevant certificate expires |
Note that Windows 11 24H2 and Windows Server 2025 require the September 2025 or later security update, while the other affected OS versions generally require the July 2026 or later update. Windows 10 Enterprise 2019 LTSC, Windows Server 2019 and Windows Server 2016 have a deadline of May 17, 2027, about a month earlier than the June 19 date that applies to most other affected OS versions. These dates are the deadlines by which the required updates must be applied. They do not mean you can wait until the deadline passes.
On the other hand, you do not need to hunt down old updates and reinstall them one by one. Microsoft is asking for the update from the specified month, or any later update, to be applied. According to Microsoft's explanation of how monthly updates work, Windows monthly security updates are generally cumulative and include previously released fixes. So on a supported version of Windows, applying the latest monthly security update handles this certificate change and ordinary vulnerability protection at the same time.
However, monthly updates are separate from feature updates, which change the Windows version. Monthly updates add fixes to the OS version you are currently using, while feature updates move Windows itself to a newer version. If you are using a version whose support has already ended, updating the certificates alone will not make it eligible for security updates again.
Watch the end-of-support date for Windows 11 24H2 as well
It is important not to confuse the deadline for connecting to Windows Update with the OS's own end-of-support date. For example, for Windows 11 24H2 the certificate deadline is June 19, 2027, but the OS end-of-support date varies by edition.
According to Microsoft's lifecycle information for Windows 11 Home and Pro and Enterprise and Education, the end-of-support dates for Windows 11 24H2 are as follows.
| Windows 11 24H2 edition | OS end-of-support date | Certificate update deadline |
|---|---|---|
| Home / Pro | October 13, 2026 | June 19, 2027 |
| Enterprise / Education | October 12, 2027 | June 19, 2027 |
OS end-of-support dates are based on Pacific Time (PT) as indicated by Microsoft. The certificate update does not extend the OS support period.
This difference matters especially for Home and Pro users on Windows 11 24H2. Waiting until the June 2027 certificate deadline to act would be too late. Support for 24H2 Home and Pro ends on October 13, 2026, so users need to move to a supported version before then. Even if the required monthly updates are applied and the new certificates have been received, no new security fixes will be provided after support ends.
Enterprise and Education editions of 24H2, meanwhile, are supported until October 12, 2027, so the certificate deadline falls within their support period. Those who continue to use 24H2 need to confirm that the required monthly updates have been applied before the deadline.
The same goes for Windows 10. Microsoft's table says "supported Windows 10," but that does not mean security fixes will continue to be provided to every Windows 10 device. Whether a device can keep connecting to Windows Update and whether its OS is still eligible for new security updates must be checked separately.
Companies using WSUS should check where updates actually come from
Microsoft explains that this change does not apply to devices that receive updates from Windows Server Update Services (WSUS). WSUS is a mechanism that lets companies and organizations manage and distribute Windows updates using an internal server. However, having WSUS deployed does not necessarily mean every device is unaffected.
According to Microsoft's documentation on update management, Windows lets you specify the update source for each type of update through policy. For example, feature updates and monthly quality updates can be delivered from different sources, and driver and firmware updates can be split between WSUS and Windows Update.
That means a configuration in which monthly updates come from WSUS while driver updates come from Windows Update is possible. In such an environment, the mere existence of a WSUS server in the organization does not tell you whether an individual device connects to Windows Update. Administrators need to check the policies set on each device and understand the actual source for each type of update.
Microsoft's notice also does not explain which errors would occur with which updates in every configuration that combines WSUS and Windows Update. Rather than excluding every device in an organization simply because WSUS is in use, it is more appropriate to identify devices that need to connect to Windows Update and check their OS versions and update status.
Manual updates may be needed after the deadline
Even on a supported version of Windows, a device that reaches the certificate expiration without the required updates may lose access to Windows Update. In that case, Microsoft's official notice describes obtaining the necessary updates directly from the Microsoft Update Catalog and applying them, or distributing them through regular management tools.
In other words, even if a device can no longer connect to Windows Update, it may be possible to recover by installing updates through another route. But downloading and installing a single update file will not necessarily restore it.
Particular attention is needed to checkpoint cumulative updates in Windows 11 24H2 and later. According to Microsoft's technical documentation, monthly updates for Windows 11 24H2 and later may be delivered as packages that use an earlier update as a baseline and contain only the changes made since then. As a result, you may need to apply a required checkpoint cumulative update before installing a particular update.
Windows Update and WSUS handle this automatically. When updating manually from the Microsoft Update Catalog, however, you need to read the description of the target update and understand which prerequisite updates are needed and in what order to apply them.
Such manual recovery is also intended only for devices on a supported OS that are missing updates. For versions of Windows whose support has already ended, Microsoft recommends moving to a supported version. Adding certificates or updates manually does not resume the delivery of new security fixes for an outdated OS.
A separate issue from the 2026 Secure Boot certificates
This Windows Update certificate change is different from the Secure Boot certificate issue that begins in 2026. Secure Boot is a security feature that verifies that trusted software is used when a PC starts up.
According to Microsoft's explanation of the Secure Boot certificates, certificates issued in 2011 begin expiring in stages from June 2026, and the transition to new certificates is under way.
However, an expired Secure Boot certificate does not mean Windows will immediately stop booting. Microsoft explains that devices that haven't received the new certificates can still start normally and continue to install ordinary Windows updates. On the other hand, they may no longer receive early-boot security protections, such as fixes for newly discovered boot-time vulnerabilities. Depending on the model, a firmware update may also be needed to properly update the Secure Boot certificates.
By contrast, the 2027 certificate update at issue here concerns the trust relationship with Windows Update servers. If the necessary certificates aren't updated, the connection to Windows Update itself could be lost. The two changes therefore protect different things and have different consequences if the certificates expire. Having completed the Secure Boot certificate update does not mean the Windows Update certificate update is done. Each needs to be checked as a separate measure.
What to check before the 2027 deadlines
For most devices running a supported version of Windows with monthly security updates applied, this certificate update requires no special action. Devices still running older versions of Windows, or those that haven't been updated for a long time, may lose access to Windows Update if they aren't dealt with by the deadline.
Corporate IT administrators in particular should check each device's OS version, edition and most recently applied monthly security update, and look into where it gets its updates if necessary. It is then important to separate devices that can be handled simply by applying monthly updates from those that need to move to a newer OS version.
May 17 and June 19, 2027 are not dates to start preparing but deadlines by which the necessary measures should already be complete. To keep devices able to receive updates, it is best to identify affected devices early and proceed with a planned response.
