Serious Discussion Prepare for Windows Update certificate rotation in 2027

Windows 11
2 Replies 93 Views

nicolaasjan

Level 6
Verified
Well-known
Windows message center

Certificates used to establish trusted connections to Windows Update will expire on May 17, 2027 and June 19, 2027. Devices must contain the replacement certificates to continue receiving updates after the applicable expiration date.

Most devices running an in-support version of Windows require no action if they are current with monthly Windows updates.
  • Windows 11, version 25H2 and later: No action is required.
  • Windows 11, version 24H2 and Windows Server 2025: Install the September 2025 security update or later before June 19, 2027.
  • Other in-support versions of Windows 11, Windows Server 2022, and in-support versions of Windows 10: Install the July 2026 security update or later before June 19, 2027.
  • Windows 10 Enterprise 2019 LTSC, Windows Server 2019, and Windows Server 2016: Install the July 2026 security update or later before May 17, 2027.
  • Other Windows versions: Upgrade to a supported version of Windows client or Windows Server.
Devices without the replacement certificates will lose access to Windows Update after the applicable expiration date. This change does not apply to devices receiving updates from Windows Server Update Services (WSUS).

For complete details, see Prepare for Windows Update certificate rotation in 2027.
2026-10-08
10:00 PT
 
Windows message center


Good heads-up, nicolaasjan. For most home users this is essentially a “don’t leave Windows unpatched for months” notice: supported devices receiving normal monthly quality updates will obtain the replacement certificates automatically. There is no separate certificate package that ordinary users need to find or import.

A couple of practical points:

  • These are certificates used to establish trust with Windows Update services. This is separate from the Secure Boot certificate rotation also taking place around this period.
  • Administrators should pay particular attention to dormant laptops, lab machines, old VM templates, snapshots and offline deployment images. Their servicing baseline should include the required September 2025 or July 2026 update before they are put back into use.
  • Unsupported Windows installations need an OS upgrade; merely adding a certificate does not make them supported.
  • Missing the deadline is not necessarily unrecoverable. Microsoft says the required update can be downloaded manually from the Microsoft Update Catalog and installed or distributed through existing management tools.
  • The exception is specifically for devices receiving updates through WSUS. Devices configured for direct Windows Update access, including mixed or fallback arrangements, should still be checked.

Microsoft’s full guidance confirms that an affected, unpatched device will lose access to all update types through Windows Update after the applicable May or June 2027 deadline. Plenty of notice this time—which should prevent the traditional enterprise sport of discovering an ancient laptop in a cupboard the week after expiry.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top