Windows Update Certificate Rotation 2027: Deadlines by Windows Version
Certificates that Windows devices use to trust Windows Update expire in 2027, and a device without the replacement certificates loses access to Windows Update after the date that applies to it: May 17, 2027 for Windows Server 2016, Windows Server 2019 and Windows 10 Enterprise 2019 LTSC, and June 19, 2027 for the other versions Microsoft lists. Microsoft announced the change on October 8, 2026 in the Windows IT Pro Blog post Prepare for Windows Update certificate rotation in 2027 and in the Windows release health message center. The replacement certificates ship in the normal monthly security updates, so a device that is in support and current needs nothing extra. Microsoft's own summary is that "the key to getting updates from Windows Update beyond 2027 is to keep your devices up to date today."
This page covers the certificate deadline only: which update each Windows version needs, who is exempt, and what it means for versions that are already out of support. The support dates for each release are in our Windows Server 2016 and Windows Server 2019 end of life guides.
Microsoft's table, as printed
Microsoft's post sorts every Windows version into one of six rows. The wording below is Microsoft's.
| Windows version | Action required |
|---|---|
| Windows 11, version 25H2 and later | None. |
| Windows 11, version 24H2 and Windows Server 2025 | Install the September 2025 Windows security update or later before June 19, 2027. |
| Other Windows 11 versions in support and Windows Server 2022 | Install the July 2026 Windows security update or later before June 19, 2027. |
| Windows 10 versions in support | Install the July 2026 Windows security update or later before June 19, 2027. |
| Long-Term Servicing Branch (LTSB)/Long-Term Servicing Channel (LTSC) releases of Windows 10 Enterprise 2019 LTSC, Windows Server 2019, and Windows Server 2016 | Install the July 2026 Windows security update or later before May 17, 2027. |
| Other Windows versions | Upgrade these devices to a supported version of Windows for client or server. Because these devices are out of support, they'll lose access to Windows Update services. |
Source: Microsoft, Prepare for Windows Update certificate rotation in 2027, Windows IT Pro Blog, October 8, 2026. The message center entry posted the same day gives the same versions, updates and dates in shorter wording.
What changes
Windows Update uses certificate-based trust so that a device can confirm it is talking to the authoritative Windows Update servers. Microsoft describes expiring and replacing these certificates as standard security practice, and says a set of them expires on the two dates in the table. The replacement certificates are delivered inside the monthly Windows security updates listed for each version. Nothing in Microsoft's post asks admins to install a certificate by hand.
Windows Server 2016 and Windows Server 2019: the earlier date
Windows Server 2016, Windows Server 2019 and Windows 10 Enterprise 2019 LTSC share the earlier deadline: the July 2026 Windows security update or later must be on the device before May 17, 2027. Any monthly security update from July 2026 onward meets the condition, so a server that is patched each month already has the certificates.
For Windows Server 2016 the timing is tight. Its extended support ends on January 12, 2027, before the certificate date. Microsoft's row names Windows Server 2016 directly and does not distinguish servers enrolled in Extended Security Updates from those that are not; its condition is the July 2026 update or later. A 2016 server that has been left unpatched since before July 2026 is the case to find now, while it is still in support. Windows Server 2019 is in extended support until January 9, 2029, so its monthly updates continue well past the certificate date.
Live status for each release: Windows Server 2016, Windows Server 2019 and Windows 10 Enterprise LTSC 2019 (Microsoft's post writes the last one as "Windows 10 Enterprise 2019 LTSC").
Windows 11 and Windows 10
- Windows 11, version 25H2 and later: no action.
- Windows 11, version 24H2 and Windows Server 2025: the September 2025 Windows security update or later.
- Other in-support Windows 11 versions, Windows Server 2022 and in-support Windows 10 versions: the July 2026 Windows security update or later.
All three groups with an action share the later deadline of June 19, 2027. Microsoft's rows say "in support" without listing which Windows 10 versions that covers. Windows 10, version 22H2 reached the end of support on October 14, 2025. A device that is not enrolled in Extended Security Updates has received no monthly security update since then, so it cannot have the July 2026 update; on our reading, Microsoft's last row, for out-of-support versions, is the one that applies to it. Our Windows 10 migration guide covers the move.
Who is exempt
Microsoft names one exemption, in both the post and the message center: devices receiving updates from Windows Server Update Services (WSUS). The post puts it as "This doesn't apply to devices receiving updates from Windows Server Update Services (WSUS)." Microsoft names no other management tool as exempt, so a device that pulls its updates from Windows Update, whatever manages its policy, should be treated as in scope.
Out-of-support versions: upgrade, no update path
Any Windows version not named in the first five rows falls into Microsoft's last row, and Microsoft's instruction for it is to upgrade. In the post's words, these devices "will lose access to Windows Update services and won't receive any updates as a result." The post gives these devices no update to install, only the upgrade.
Windows Server 2012 and 2012 R2 are a server example: their final Extended Security Updates year ends on October 13, 2026, and Microsoft's table does not name them. See our Windows Server 2012 ESU guide and the Windows Server lifecycle page for where each release stands.
What to do, in order
- Inventory by row. Sort every Windows device into one of Microsoft's six rows. Windows Server 2016, Windows Server 2019 and Windows 10 Enterprise 2019 LTSC go on the list with the earlier deadline.
- Check the installed update. In each device's update history or your management tool's patch compliance report, confirm a Windows security update from the month Microsoft names for its row, or any later one. Microsoft's post names months, not KB numbers; each version's release notes are on Windows release health.
- Patch the stragglers. Microsoft points to the Microsoft Update Catalog to download and install the required update directly, or to distribution through your regular management tools.
- Plan upgrades for the last row. Microsoft's action plan says to create an upgrade plan for unsupported devices before May and June 2027. Our EOL Checker answers which of your versions are still in support.
Frequently Asked Questions
When do the Windows Update certificates expire?
Microsoft says a set of the certificates Windows Update uses will expire in 2027, and the date that applies depends on the Windows version: May 17, 2027 for Windows 10 Enterprise 2019 LTSC, Windows Server 2019 and Windows Server 2016, and June 19, 2027 for the other versions in Microsoft's table. Devices without the replacement certificates lose access to Windows Update after the applicable date.
What do Windows Server 2016 and Windows Server 2019 need?
Microsoft's table says to install the July 2026 Windows security update or later on Windows Server 2016, Windows Server 2019 and Windows 10 Enterprise 2019 LTSC before May 17, 2027. Those updates contain the new certificates. A server that already installs the monthly security updates has nothing extra to do.
What do Windows 11 and Windows 10 devices need?
Windows 11, version 25H2 and later need no action. Windows 11, version 24H2 and Windows Server 2025 need the September 2025 Windows security update or later, and other in-support Windows 11 versions, Windows Server 2022 and in-support Windows 10 versions need the July 2026 Windows security update or later, before June 19, 2027.
Are devices that use WSUS affected?
No. Microsoft states that the change does not apply to devices receiving updates from Windows Server Update Services (WSUS). Microsoft names only WSUS; it does not name other management tools as exempt.
What happens to Windows versions that are out of support?
Microsoft's table tells other Windows versions to upgrade to a supported version of Windows for client or server, and says that because these devices are out of support, they will lose access to Windows Update services and will not receive any updates.
Related
- Windows Server 2016 End of Life — the release's dates and the three upgrade targets
- Windows Server 2016 ESU — security updates after the end of extended support
- Windows Server 2019 End of Life — the release's dates and where to move
- Windows Server · Windows — every version's dates
- How we verify our dates — the rules every number on this site is held to