Microsoft warns certificate expiration will cut off Windows Update

Microsoft has warned that millions of client PCs, workstations, and servers running older Windows versions will lose access to Windows Update services if they fail to install required security updates before approaching certificate expiration dates in May and June 2027, cutting off future updates entirely.

The 2027 Certificate Expiration Timeline and Affected Builds

The root of the cutoff lies in the cryptographic certificates that authenticate connections to Windows Update services. If a machine misses the window, it loses the handshake capability required to pull monthly patches.

The first batch of certificates expires on May 17, 2027, while a second set expires on June 19, 2027. Devices running unsupported operating systems will completely lose access to Windows Update services after these dates. To maintain connectivity, operating systems must be upgraded or patched with specific baseline updates ahead of schedule.

The mitigation path varies by operating system version:

  • Windows 11, version 25H2 and later: No action is required. Replacement certificates are already integrated.
  • Windows 11, version 24H2 and Windows Server 2025: Must install the September 2025 security update or later before June 19, 2027.
  • Other supported Windows 11 versions, Windows Server 2022, and Windows 10: Must install the July 2026 security update or later before June 19, 2027.
  • Windows 10 Enterprise 2019 LTSC, Windows Server 2019, and Windows Server 2016: Face an earlier deadline, requiring the July 2026 security update or later before May 17, 2027.

Devices managed via Windows Server Update Services (WSUS) are exempt from this direct client-side restriction, as enterprise internal distribution servers handle the update transport layer independently.

Microsoft warns certificate expiration will cut off Windows Update
Photo: bleepingcomputer.com

Windows 10 Extended Security Updates and Virtualization Workarounds

For organizations struggling to migrate legacy hardware off Windows 10 before its standard support expiration on October 14, 2025, the Extended Security Updates (ESU) program offers a paid subscription lifeline for critical and important patches. Microsoft documentation outlines specific technical prerequisites for deploying these ESU keys, particularly in cloud and virtual desktop infrastructure (VDI) environments.

Enabling ESU on physical or virtual Windows 10 version 22H2 endpoints requires installing update KB5066791 followed by the ESU Licensing Preparation Package (KB5072653). Nonpersistent VDI deployments demand a precise provisioning sequence to avoid burning through activation keys. Admins must install version 22H2, apply and activate the ESU key, install the latest updates, execute a product key removal command via slmgr.vbs /upk using specific activation IDs, and run sysprep to generate a clean golden image.

Conversely, Microsoft-hosted Azure virtual machines automatically inherit ESU coverage without manual key injection. Similarly, local Windows 10 endpoints accessing Windows 365 Enterprise or Flex Cloud PCs in dedicated mode receive automatic ESU entitlement, provided the physical hardware is Microsoft Entra joined or hybrid joined.

User Hesitation and Recent Patch Stability Concerns

For enterprise administrators and retail users alike, the mandate to apply patches introduces a frustrating operational dilemma. Technical fatigue is running high. Users have grown increasingly skeptical of mandatory update rollouts given a persistent string of quality control failures.

Recent update history justifies that caution. The August 2026 Patch Tuesday deployment triggered widespread crashes and random reboots across multiple high-profile titles, including Arc Raiders, Marvel Tokon: Fighting Souls, and The Finals. A parallel regression surfaced with update KB50124010, which disrupted Javelin-protected games like Battlefield 6 and Wardogs.

Over the past year alone, cumulative updates for Windows 11 have broken OneDrive synchronization, incapacitated the Recycle Bin, throttled Nvidia GPU performance, and forced Microsoft to yank installation packages due to severe deployment errors. These recurring stability slips forced the company to pivot engineering resources toward core OS stabilization rather than feature bloat.

Sysadmins now face a difficult calculus. Delaying patches to preserve system stability risks running headfirst into the hard 2027 certificate expiration wall, which turns a temporary deferral into a permanent severance from security updates.

Photo of author

Sophie Lin - Technology Editor

Sophie is a tech innovator and acclaimed tech writer recognized by the Online News Association. She translates the fast-paced world of technology, AI, and digital trends into compelling stories for readers of all backgrounds.

New Brain Study Identifies Five Distinct Profiles of Depression