Skip to content
TrustList
News

Windows devices must carry new Update certificates before 2027

Editorial

By TrustList Editorial

Two sets of Windows Update certificates lapse in 2027, and machines on Windows Server 2016 and 2019 have the earlier deadline. Devices managed through WSUS are not affected.

  • Patch Management
  • Patch Management Software
  • Cybersecurity
  • Vulnerability Management

About Windows devices must carry new Update certificates before 2027

Windows devices must carry new Update certificates before 2027

8 October 2026: Microsoft has told administrators that two sets of certificates used to connect to Windows Update expire in 2027, and any device that has not received the replacement certificates by then will stop receiving every kind of Windows update. Most supported machines that install monthly security updates need no extra work, but older server editions have a deadline a month earlier than everything else.

Not yet independently verified. We read the table in Microsoft's message center notice; the Windows IT Pro Blog post could not be loaded to compare line by line. Check the per-version cut-offs against the blog post before setting deadlines. We will update this when it can be confirmed, and remove this note.

Microsoft sets two expiry dates: 17 May 2027 for the first set of certificates and 19 June 2027 for the second. The replacements arrive through ordinary Windows security updates, so the practical question for an admin is which cumulative update a device must have installed before its deadline.

Minimum update by Windows version

Microsoft's notice gives this mapping:

  • Windows 11 25H2 and later: nothing to do.
  • Windows 11 24H2 and Windows Server 2025: the September 2025 security update or later, before 19 June 2027.
  • Other supported Windows 11 releases, Windows Server 2022 and supported Windows 10: the July 2026 security update or later, before 19 June 2027.
  • Windows 10 Enterprise 2019 LTSC, Windows Server 2019 and Windows Server 2016: the July 2026 security update or later, before 17 May 2027.

Anything on a version that is no longer supported has to be upgraded to a supported Windows client or Windows Server release. Those devices will lose access to Windows Update altogether once the certificates lapse.

Who can ignore it, and what to do with stragglers

The change does not apply to devices that get their updates from WSUS, Microsoft says. Machines that connect to Windows Update directly, including laptops that roam off the corporate network and cloud-hosted virtual machines, are the ones to inventory.

A supported device that misses its deadline is not stranded. Microsoft says the update can be downloaded from the Microsoft Update Catalog or pushed with the management tools an organisation already uses.

The practical test is simple: report every device that has not installed the July 2026 cumulative update, then sort the list by operating system so the Server 2016 and 2019 machines are fixed first. Our patch management software category lists nine products that report patch levels by device.

The message was published as an admin-impact item and lists no compliance considerations.

Sources

Categories & features

  • Patch Management
  • Patch Management Software
  • Cybersecurity
  • Vulnerability Management

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy