Microsoft has set two expiry dates, May 17, 2027 and June 19, 2027, for the certificates that let a Windows device make trusted connections to Windows Update. A PC that has not picked up the replacement certificates by then will be cut off from the service, which means no monthly security fixes and no way to catch up through the normal channel.
The warning went out on October 8, 2026 at 10:00 PT in the Windows message center, and most machines that install monthly updates need to do nothing. The exposed group is PCs and servers that skip required updates or run versions Microsoft no longer services.
The June 19 cutoff and the May 17 exception
Microsoft’s own wording in its Windows message center notice is that devices must contain the replacement certificates “to continue receiving updates after the applicable expiration date,” and that devices without them “will lose access to Windows Update.” June 19, 2027 is the deadline for most supported systems. May 17, 2027 applies to a narrower, older set: Windows 10 Enterprise 2019 LTSC, Windows Server 2019 and Windows Server 2016.
The June date therefore governs ordinary desktops and laptops, and anything on the older long-term-servicing branches runs out of time a month earlier. Microsoft frames the swap as routine, saying the certificates “eventually need to be rotated” as standard security practice, according to BleepingComputer’s account of the notice.
Required update by Windows version
The same notice, mirrored as Message Center item MC1491763, sorts devices by what they must have installed before the deadline. Windows 11 version 25H2 and later need no action. Windows 11 version 24H2 and Windows Server 2025 need the September 2025 security update or later before June 19, 2027. Other in-support versions of Windows 11, Windows Server 2022 and in-support versions of Windows 10 need the July 2026 security update or later before the same date.
The earlier-deadline group, Windows 10 Enterprise 2019 LTSC, Windows Server 2019 and Windows Server 2016, also needs the July 2026 security update or later, but before May 17, 2027. Any other Windows version is told to upgrade to a supported Windows client or Windows Server release, since no update path to the replacement certificates exists for it.
WSUS and the unsupported-version problem
One carve-out matters for businesses. Microsoft states that the change does not apply to devices receiving updates from Windows Server Update Services, so machines managed through WSUS are outside this particular cutoff. The affected population is devices that pull updates directly from Windows Update, a point BleepingComputer’s Sergiu Gatlan reported on October 9, 2026 alongside Microsoft’s advice that administrators inventory older and unsupported devices now and build an upgrade plan before May and June 2027.
Microsoft says the replacement certificates have already been delivered to systems on supported versions through Windows security updates. A device that is supported but not current when the date passes is not stranded forever: the message center item says the update can be obtained from the Microsoft Update Catalog or deployed with a regular management tool to restore access.
The harder case is the PC on a version that has left servicing. Microsoft’s supported-versions page for Windows client shows Windows 10 version 22H2 reaching end of updates on October 14, 2025, Windows 10 Enterprise 2019 LTSC running to January 9, 2029 and Windows 10 2021 LTSC mainstream support ending January 12, 2027. That page does not cover Extended Security Updates, and Microsoft’s notice refers only to “in-support versions of Windows 10,” so a Windows 10 Home or Pro PC outside any paid program is not clearly covered by the 2027 guidance and should be treated as unsupported until Microsoft says otherwise.
Windows 11 24H2 and a separate Secure Boot expiry
For a typical home PC, the practical test is whether Windows Update has installed the July 2026 cumulative update or anything newer. Windows 11 24H2 Home and Pro reach end of updates on October 13, 2026 per the same supported-versions page, so a machine on that release needs a move to 25H2 or 26H2 to keep receiving fixes, even though the September 2025 floor Microsoft sets for 24H2 is the lowest bar for the certificate rotation itself.
The 2027 rotation is also a different clock from the Secure Boot certificate expiry Microsoft is already managing. Its KB5092765 notes, dated May 26, 2026, say the Secure Boot certificates used by most Windows devices “have started expiring in June 2026” and warn that devices not updated in time may be unable to boot securely.
Microsoft’s notice does not say what happens to a device in between, for example a supported PC that has been offline for months. The item names the Update Catalog route for that case but offers no figure for how many devices are expected to miss the dates.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Ford is recalling 223,472 F-150 pickups because the fuel tank can leak or detach
- Hybrids have 15% fewer problems than gas cars, while EVs and plug-in hybrids have about 80% more, Consumer Reports finds
- Regulators cleared the first U.S. small modular reactor, 4 months early
- Lake Powell sank to a record 3,517 feet, nearing the level that stops Glen Canyon Dam’s turbines