Millions of Windows devices could face a new security problem in 2027: losing access to the updates that keep them protected.
Microsoft warned on October 8 that certificates used to establish trusted connections with Windows Update will expire on May 17 and June 19, 2027. Devices running supported but outdated Windows versions could lose access to Windows Update services unless administrators install the necessary security updates. Microsoft also warns that unsupported Windows versions will lose access to those services and recommends upgrading them to supported releases.
For organizations managing older computers and servers, the warning raises a significant security concern. Devices that cannot receive updates may become increasingly vulnerable to newly discovered threats, creating additional risks for enterprise networks.
Why Windows devices could stop receiving updates in 2027
The issue centers on digital certificates that Windows uses to verify trusted connections with Microsoft's update infrastructure.
These certificates help ensure that devices connect to legitimate Windows Update servers. Like other digital certificates, they have expiration dates and must periodically be replaced.
Microsoft is distributing replacement certificates through regular Windows security updates. Most supported devices that have received recent updates already have what they need.
However, systems running older Windows versions or missing required updates could lose access to Windows Update when the existing certificates expire.
Microsoft identified two deadlines:
- May 17, 2027: Applies to certain older Windows Enterprise and Windows Server releases, including Windows 10 Enterprise 2019 LTSC, Windows Server 2019, and Windows Server 2016.
- June 19, 2027: Applies to other affected supported Windows versions, including certain Windows 10, Windows 11, and Windows Server releases.
The consequences extend beyond security patches. Microsoft says affected devices could stop receiving all types of updates delivered through Windows Update.
That interruption could complicate vulnerability remediation, particularly for organizations operating large fleets of endpoints or legacy systems.
The warning also highlights the importance of maintaining consistent patching practices. Microsoft's September 2026 Patch Tuesday release addressed hundreds of vulnerabilities, including two zero-days that have already been exploited in attacks.
Organizations unable to receive future updates could face growing exposure as additional vulnerabilities are discovered.
Which Windows versions are affected, and what should administrators do?
Not every Windows device requires intervention.
According to Microsoft, systems running supported Windows versions with recent monthly security updates should continue receiving updates normally.
Windows 11 version 25H2 and later require no additional action for this certificate rotation. Other supported versions may need specific updates installed before the applicable deadline.
Windows version | Microsoft's recommended action |
| Windows 11 25H2 and later | No action required |
| Windows 11 24H2 and Windows Server 2025 | Install September 2025 security update or later |
| Other supported Windows 11 versions and Windows Server 2022 | Install July 2026 security update or later |
| Supported Windows 10 versions | Install July 2026 security update or later |
| Windows 10 Enterprise 2019 LTSC, Windows Server 2019, and Windows Server 2016 | Install July 2026 security update or later |
| Unsupported Windows versions | Upgrade to a supported Windows version |
The distinction between supported and unsupported devices is important. Installing the appropriate security update can prepare supported systems for the certificate change, but unsupported systems generally require an operating system upgrade.
Microsoft also notes that the warning does not apply to devices receiving updates through Windows Server Update Services (WSUS).
For security teams, the approaching deadlines reinforce the importance of centralized patch management and endpoint visibility.
Organizations managing large numbers of devices may benefit from reviewing available patch management service providers to identify systems that are missing critical updates and to coordinate remediation.
What security teams should do before the 2027 deadlines
Although the certificate expirations are months away, organizations should begin reviewing their Windows environments now rather than waiting until updates fail.
Security administrators should prioritize three actions:
- Inventory Windows devices: Identify unsupported operating systems, outdated builds, and systems that have not received recent security updates.
- Verify required patches: Confirm that supported devices have received the appropriate Windows security updates. Microsoft says administrators can also obtain required updates through the Microsoft Update Catalog or deploy them using existing management tools.
- Plan legacy system upgrades: Establish remediation timelines for unsupported devices, particularly those supporting critical business operations.
Security teams should also account for devices that connect infrequently, operate in restricted environments, or fall outside normal patching schedules.
As eSecurity Planet's endpoint security guide explains, effective endpoint protection involves multiple layers, including vulnerability management, patching, and operating system hardening.
The larger concern is not simply whether a Windows device can receive an update today. It's whether the organization can identify and remediate systems that may lose access to future updates.
Microsoft's warning gives administrators time to address that risk before the certificates expire. Organizations that verify patch levels and resolve unsupported Windows deployments now can avoid unnecessary update disruptions in 2027.
More cybersecurity news: For more guidance on keeping Windows systems secure and up to date, explore eSecurity Planet’s comparison of leading patch management tools and how they help organizations automate updates and address vulnerabilities.





