Most of you don't need to do anything special. If your PCs and servers run a supported Windows version and get their monthly patches, the new certificates are already installed or arriving through normal servicing. The risk sits with machines that have fallen behind, such as the forgotten LTSC box in a lab, the Server 2016 VM nobody wants to reboot, or the kiosk that hasn't been patched since 2025.
Why Windows Update cares about certificates
This isn't a cosmetic expiry. Microsoft Learn's Windows Update security documentation says the metadata connections Windows Update uses to scan for updates run over HTTPS and are certificate-pinned. When a device connects, Windows checks the server certificate's trust, expiry, revocation status and subject alternative names. It also confirms that the issuer is a genuine Microsoft Windows Update intermediate certificate. If the issuer is unexpected or invalid, the connection fails. Microsoft says the design ensures devices reach legitimate Microsoft servers and blocks man-in-the-middle attacks.
That is why the expiry matters. Pinning is strict by design, so a device that only trusts the old certificates will refuse to connect to servers presenting new ones once the rotation happens. The same mechanism that stops an attacker posing as Windows Update will also lock out an out-of-date client.
Section summary: Windows Update trusts only specific Microsoft certificates. When those certificates are rotated, devices that don't have the new trust material can't complete the connection.
The version-by-version action table
According to Microsoft's notice, these are the minimum requirements:
| Windows version | Action required | Deadline |
|---|---|---|
| Windows 11, version 25H2 and later | None | — |
| Windows 11, version 24H2 and Windows Server 2025 | Install the September 2025 security update or later | June 19, 2027 |
| Other supported Windows 11 versions and Windows Server 2022 | Install the July 2026 security update or later | June 19, 2027 |
| Supported Windows 10 versions | Install the July 2026 security update or later | June 19, 2027 |
| Windows 10 Enterprise 2019 LTSC, Windows Server 2019, Windows Server 2016 (LTSB/LTSC) | Install the July 2026 security update or later | May 17, 2027 |
| Any other Windows version | Upgrade to a supported client or server release | — |
Some details are easy to miss:
- "Or later" sets a minimum. You don't have to install that exact month's package. Any later cumulative security update for the same release also works.
- The earlier deadline hits the oldest servers. Windows 10 Enterprise 2019 LTSC, Windows Server 2019 and Windows Server 2016 must be ready by May 17, which is about five weeks before everyone else.
- Microsoft's post gives no KB numbers, certificate names or verification method. Find the exact package for each release in the Windows release health notes. Don't trust anyone who claims to have the definitive KB list unless they cite Microsoft.
Reading between the lines: lifecycle traps
The table refers to "supported" versions, and support status changes over time. Two points from Microsoft's published lifecycle schedule matter here. They come from general industry knowledge, not from the certificate notice itself:
- Windows 11, version 23H2. Home and Pro editions left support in November 2025. Enterprise and Education editions are scheduled to reach end of servicing in November 2026, a few weeks from now. After that, 23H2 machines will likely move out of the "other supported Windows 11 versions" row and into "upgrade these devices." For organizations still on 23H2, the July 2026 update is only a temporary fix. Moving to 24H2 or 25H2 is the durable one.
- Windows Server 2016. Its extended support is scheduled to end in January 2027, before the May 17, 2027 certificate deadline. Microsoft lists Server 2016 with the July 2026 update requirement. Whether an out-of-support Server 2016 machine keeps reaching Windows Update afterward is a separate question. The notice says unsupported versions "will lose access to Windows Update services," so plan Server 2016 migrations as if the certificate deadline makes them urgent.
- Windows 10. Mainstream consumer support for Windows 10 ended in October 2025. Microsoft doesn't define "Windows 10 versions in support" in the post. In practice it probably means LTSC editions still in their lifecycle and devices enrolled in Extended Security Updates, but that's an interpretation and Microsoft hasn't confirmed it.
What happens after the deadline
Microsoft describes three outcomes:
- Supported and up to date: These devices keep updating without interruption because they already have the new certificates.
- Supported but behind: These devices lose access to Windows Update after the May or June 2027 expiry. The fix is to install the required update. Microsoft says you can download it directly from the Microsoft Update Catalog or push it through your normal management tools.
- Unsupported: These devices lose access to Windows Update and get no further updates. Microsoft's only recommendation is to upgrade.
Act before the deadline, not after. If a device has already lost access to Windows Update, it can't fetch the fix from Windows Update. You'd have to install the package from the Update Catalog by hand or through another channel. That's manageable for one machine and painful across a fleet.
The WSUS exception, and its limits
Microsoft says the notice doesn't apply to devices that get updates from Windows Server Update Services (WSUS). Microsoft Learn explains why: WSUS clients connect to their organization's WSUS server, not to Microsoft's servers over the internet. The organization chooses whether that connection uses HTTP or TLS.
That exemption covers the clients. It doesn't automatically cover the WSUS server. Microsoft Learn notes that when a WSUS server syncs its catalog, it connects to Microsoft's sync services over TLS and verifies a Microsoft certificate, much like a Windows Update client does. The October notice doesn't say whether the 2027 rotation affects that upstream link. It does say the notice doesn't apply to devices receiving updates from WSUS, so keeping your WSUS hosts patched is a sensible precaution even though Microsoft hasn't required it. Watch for any separate WSUS guidance.
Also check how updates actually reach your devices. Mixed environments are common: WSUS on the corporate network, direct Windows Update for remote laptops, and Windows Update for Business policies on top. A device that falls back to Windows Update when it's off the network is subject to the deadline.
Don't confuse this with the Secure Boot rotation
Windows admins have just been through a different certificate rotation. The Secure Boot one involved the UEFI KEK and DB certificates from 2011. Reporting from 4sysops and others noted that Microsoft began distributing the new certificates through monthly Windows updates in February 2026. In July, PCWorld noted that Microsoft said the Secure Boot certificate rollout was still ongoing and could take a few more months.
The two issues are separate:
- Secure Boot concerns trust at the firmware level and depends on the OEM firmware cooperating. As earlier WindowsForum coverage put it, the OS can only write those certificates into UEFI variables if the firmware design allows it and OEMs don't lock updates out.
- Windows Update's certificates cover the TLS connection between the update client and Microsoft's servers. The OS handles them entirely through cumulative updates. No firmware changes are involved.
The failure modes are different too. Asus's guidance, for example, says devices without the new Secure Boot certificate can still start and operate normally, and standard Windows updates will continue to be installed. The 2027 Windows Update rotation is the reverse: the device boots fine but stops getting updates. Neither is good, but they need different checks.
An action plan for IT admins
Microsoft's own plan has three steps: identify old and unsupported devices, keep supported ones patched monthly, and plan upgrades. Here is a more detailed version:
- Inventory by OS version and patch level. Pull build numbers from Intune, Configuration Manager, Azure Arc or whatever inventory tool you use. Sort devices into the rows of the table above.
- Deal with the May 17 group first. List every Windows Server 2016, Windows Server 2019 and Windows 10 Enterprise 2019 LTSC device. Servers tend to sit at the back of the patch queue, and this deadline puts them at the front.
- Check the minimum update level. Confirm that each device has the July 2026 cumulative update or later (September 2025 or later for 24H2 and Server 2025). Use release health to match build numbers to update releases.
- Find devices that are stuck. Machines that keep failing updates, have servicing-stack problems or sit offline for long stretches won't catch up by themselves. Install the package manually from the Update Catalog or redeploy it through your tooling.
- Map update sources. Record which devices use WSUS, which go directly to Windows Update and which switch between the two depending on location.
- Plan upgrades for anything unsupported. Microsoft offers no certificate workaround for out-of-support releases. Budget for the hardware and migration work now, not next spring.
- Keep TLS inspection away from Windows Update. Microsoft Learn already advises that TLS proxies should pass Windows Update connections through without intercepting them, because pinning will reject an interception certificate. The 2027 notice doesn't list proxy changes as a step. But if a device fails after you patch it, check for inspection first.
Analysis: routine maintenance with a hard deadline
Credit where it's due: Microsoft has given more than seven months' notice, the requirements are clear, and the main instruction is simply to stay patched. For most organizations this will pass without incident.
The notice is also thin in places. There are no certificate names, no KB identifiers, no way to confirm the new trust material is installed, and nothing on WSUS server sync. Admins who want proof, not just assurance, will have to infer readiness from build numbers. That works, but it's indirect. Expect follow-up questions on Microsoft's discussion board, and possibly a more detailed support article before May.
The deadline also gives organizations one more reason to retire old Windows releases. A server running unsupported Windows that can't even reach Windows Update is hard to defend in an audit or after a breach.
Bottom line: Patch supported machines to the minimum level in the table, get the Server 2016, Server 2019 and LTSC 2019 machines ready before May 17, 2027, and plan replacements for anything that's out of support.
References
- Prepare for Windows Update certificate rotation in 2027 Microsoft - Message Center · 2026-10-08 10:00 PT
- Windows Secure Boot certificate expiration and certificates updates asus.com
- Still don't have updated Windows Secure Boot certificates? Don't panic pcworld.com