Prepare for Windows Update certificate rotation in 2027



 Windows IT Pro Blog:

It's time to update your devices to ensure connectivity to Windows Update moving forward.

Windows Update uses certificate-based trust to confirm that your devices are connecting to authoritative Windows Update servers, so that you can have confidence in the update content delivered to your devices. As a standard security practice, these certificates have an expiration date. This means that they eventually need to be rotated (that is, replaced by new certificates). A set of these certificates will expire on May 17, 2027 and June 19, 2027.

While Microsoft is delivering solutions for most devices through normal monthly updates, some Windows versions will need IT action. If unaddressed, affected devices will stop connecting and receiving all types of updates from Windows Update. However, the key to getting updates from Windows Update beyond 2027 is to keep your devices up to date today.

Note: This doesn't apply to devices receiving updates from Windows Server Update Services (WSUS).

Identify and prepare devices that require action​

Our goal is to accomplish this certificate rotation with minimal impact to your organization. In most cases, no action is required. That's your case if your devices are running an in-support version of Windows and are up to date with recent monthly quality updates. For older or out-of-date Windows versions, however, take action as recommended in the table and described below.

Windows version​
Action required​
Windows 11, version 25H2 and laterNone.
Windows 11, version 24H2 and Windows Server 2025Install the September 2025 Windows security update or later before June 19, 2027.
Other Windows 11 versions in support and Windows Server 2022Install the July 2026 Windows security update or later before June 19, 2027.
Windows 10 versions in supportInstall the July 2026 Windows security update or later before June 19, 2027.
Long-Term Servicing Branch (LTSB)/Long-Term Servicing Channel (LTSC) releases of Windows 10 Enterprise 2019 LTSC, Windows Server 2019, and Windows Server 2016Install the July 2026 Windows security update or later before May 17, 2027.
Other Windows versionsUpgrade these devices to a supported version of Windows for client or server. Because these devices are out of support, they'll lose access to Windows Update services.

To find and access release notes for your versions of Windows, browse Windows release health.

What happens after the expiration date​

Devices on supported and updated versions of Windows
These devices continue receiving updates without interruption. They already have the necessary updated certificates.

Devices on supported versions of Windows that aren't up to date
After the May and June 2027 certificate expiration dates, these devices won't be able access Windows Update services. Reference the table above to install the appropriate Windows security update or later depending on your OS version. These updates contain the new certificates. Use Microsoft Update Catalog to directly download and install required updates on these devices. Alternatively, distribute them via your regular management tools.

Devices on unsupported versions of Windows
These devices will lose access to Windows Update services and won't receive any updates as a result. We recommend upgrading to a supported version of Windows client or server.

Recommended action plan for IT admins​

If your organization has devices that require action, here's your action plan:
  1. Identify devices running older or unsupported versions of Windows.
  2. Keep supported devices current with monthly Windows updates.
  3. Create an upgrade plan for unsupported devices before May and June 2027.

Start today for early readiness​

Keep supported Windows devices current for a smooth certificate rotation. Doing this today has the following benefits beyond June 2027:
  • Avoid update disruptions.
  • Reduce security and compliance risk.
  • Minimize last-minute remediation.
  • Use the timeline to align upgrade, servicing, and lifecycle planning.
And if you do need to act on older device populations, there's still time! Review, update, and plan upgrades for unsupported versions before the May 2027 or June 2027 certificate expiration dates.


 Source:

 
I'm wondering for unsupported devices (which won't get the replacement cert), if you're still allowed to download the missing updates from the Microsoft Update Catalog.

This also finally kills off Defender for those devices in 2027, unless you install a custom task to download updates directly from MS.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Hello! I have an unsupported laptop running Windows 11 23H2 because the CPU doesn't support SSE4.2 (see first system specs). Can I download any update from Microsoft Update Catalog to keep Windows Update working? Any other workaround? Will Windows Defender be updated from Windows Defender, or I will need to manually download and install the update like I do for an old computer running Windows 7 with Microsoft Security Essentials?
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 23H2 (7584), 26H2 (9550)Mobile DualCore Intel Core 2 Duo T7250, 2000 MHz4GBMobile Intel(R) GMA 4500M (Mobile 4 series)
    OS
    Windows 11 Pro 23H2 (7584), 26H2 (9550)
    Computer type
    Laptop
    Manufacturer/Model
    Acer Extensa 5630EZ
    CPU
    Mobile DualCore Intel Core 2 Duo T7250, 2000 MHz
    Motherboard
    Acer Extensa 5630
    Memory
    4GB
    Graphics Card(s)
    Mobile Intel(R) GMA 4500M (Mobile 4 series)
    Sound Card
    Realtek ALC268 @ Intel 82801IB ICH9 - High Definition Audio Controller
    Monitor(s) Displays
    1
    Screen Resolution
    1280x800
    Hard Drives
    Samsung SSD 850 EVO 250GB SATA Device (250 GB, SATA-III)
    Internet Speed
    802.11g wireless 54 Mbps
    Browser
    MICROSOFT EDGE
    Antivirus
    WINDOWS DEFENDER
    Other Info
    Legacy MBR installation, no TPM, no Secure Boot, no WDDM 2.0 graphics drivers, no SSE4.2, cannot get more unsupported ;) This is only my test laptop. I had installed Windows 11 here before upgrading my main PC. For my main PC I use everyday see my 2nd system specs.
  • At a glance

    Windows 11 Pro 26H2 (build 26300.9550)Intel Core-i7 3770 3.40GHz s1155 (3rd generat...2x Kingston Hyper-X Blu 8GB DDR3-1600GIGABYTE GeForce RTX 3050 WINDFORCE OC V2 6GB...
    Operating System
    Windows 11 Pro 26H2 (build 26300.9550)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom-built PC
    CPU
    Intel Core-i7 3770 3.40GHz s1155 (3rd generation)
    Motherboard
    Asus P8H61 s1155 ATX
    Memory
    2x Kingston Hyper-X Blu 8GB DDR3-1600
    Graphics card(s)
    GIGABYTE GeForce RTX 3050 WINDFORCE OC V2 6GB (GV-N3050WF2OCV2-6GD)
    Sound Card
    Realtek HD audio (ALC887)
    Monitor(s) Displays
    Sony Bravia KDL-19L4000 19" LCD TV via VGA
    Screen Resolution
    1440x900 32-bit 60Hz
    Hard Drives
    WD Blue SA510 2.5 1000GB SSD as system disk, Western Digital Caviar Purple 4TB SATA III (WD40PURZ) as second
    PSU
    Thermaltake Litepower RGB 550W Full Wired
    Case
    SUPERCASE MIDI-TOWER
    Cooling
    Deepcool Gamma Archer CPU cooler, 1x 8cm fan at the back
    Keyboard
    Mitsumi 101-key PS/2
    Mouse
    Microsoft Compact Optical Mouse
    Internet Speed
    802.11ac 5GHz wireless 260Mpbs
    Browser
    Microsoft Edge, Mozilla Firefox
    Antivirus
    Microsoft Windows Defender
    Other Info
    Legacy BIOS (MBR) installation, no TPM, no Secure Boot, WDDM 3.0 graphics drivers, WEI score 7.4
Does this mean if you have installed KB5101650 (OS Builds 26200.8875 and 26100.8875) — July 14, 2026 the new certificates have been installed?
 

My Computer My Computer

At a glance

Windows 11 Pro 26H2 (Build 26300.9550)Intel Core Ultra 9 285 5.6 GHz32.00 GBIntel Integrated Graphics (128 MB)
OS
Windows 11 Pro 26H2 (Build 26300.9550)
Computer type
PC/Desktop
Manufacturer/Model
Dell Pro Max Tower T2 FCT2250
CPU
Intel Core Ultra 9 285 5.6 GHz
Motherboard
64-bit operating system, x64-based processor
Memory
32.00 GB
Graphics Card(s)
Intel Integrated Graphics (128 MB)
Sound Card
Realtek Audio
Monitor(s) Displays
Dell P2714H Monitor
Screen Resolution
1920 x 1080
Hard Drives
1 x 512GB M.2 XG10d SED KIOXIA PCIe solid state drive (Internal)
1 x 2TB Seagate ST2000DM008-2UB102 HDD (Internal)
1 x 4TB Seagate STGX4000400 External HDD
1 x 6TB WD Elements AE 2689 External HDD
PSU
500 Watts
Cooling
Air
Keyboard
Microsoft Wired Keyboard 600
Mouse
Microsoft USB Basic Optical Mouse v2.0
Browser
Firefox
Antivirus
Windows Defender + Malwarebytes Premium
Other Info
BaseBoard Manufacturer Dell Inc.
BaseBoard Product 022RY57
BaseBoard Version A01
Most (but not all) of the WU-delivered updates are available on the Catalog.

MS is known for withdrawing some older, "problematic" KB's which it believes are harmful if users install the old KB's by accident. And OOBE or ZDP KB's are never listed on the Catalog. But generally everything else should be there,

Whether some of them will disappear or not in 2027, isn't clear because they haven't provided any assurances.

As for Defender, most of the time the updates are downloaded from a secure WU server. But you won't know that there's a new update availab;e without talking to WU, so you would need a custom task to keep pulling the same files off the fwlink's.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Does this mean if you have installed KB5101650 (OS Builds 26200.8875 and 26100.8875) — July 14, 2026 the new certificates have been installed?
No. They mean you need the Sept 2026 CU for 25H2 & 26H2.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7

Latest Support Threads

Back
Top Bottom