What and why
Certificates that help devices establish trusted connections to Windows Update will expire on May 17, 2027, and June 19, 2027. Devices must contain the replacement certificates to continue connecting to Windows Update and receiving updates after the applicable expiration date.
Microsoft has delivered the replacement certificates through Windows security updates. Most devices running an in-support version of Windows require no additional action if they are current with monthly Windows updates.
Rollout schedule
The applicable certificates expire on May 17, 2027, and June 19, 2027. Required actions vary by Windows version.
Impact on your organization
Supported and updated devices will continue receiving updates without interruption. Supported devices need to be up to date to continue accessing Windows Update services after the applicable expiration date.
Devices running unsupported versions of Windows will lose access to Windows Update services and will not receive updates as a result.
This change does not apply to devices receiving updates from Windows Server Update Services (WSUS).
Action required/recommendations
Identify devices that require action and update or upgrade them before the relevant expiration date:
- Windows 11, version 25H2 and later: No action is required.
- Windows 11, version 24H2 and Windows Server 2025: Install the September 2025 security update or a later update before June 19, 2027.
- Other in-support versions of Windows 11 and Windows Server 2022: Install the July 2026 security update or a later update before June 19, 2027.
- In-support versions of Windows 10: Install the July 2026 security update or a later update before June 19, 2027.
- Windows 10 Enterprise 2019 LTSC, Windows Server 2019, and Windows Server 2016: Install the July 2026 security update or a later update before May 17, 2027.
- Other Windows versions: Upgrade devices to a supported version of Windows client or Windows Server.
If a supported device is not current after the applicable expiration date, obtain the required update from the Microsoft Update Catalog or distribute it through your regular management tools.
Review the following resources:
Compliance considerations
No compliance considerations are identified. Review as appropriate for your organization.