The short answer
Windows devices that are not current by mid-2027 will stop receiving any updates from Windows Update. The trust certificates behind the service expire on May 17, 2027 for Windows Server 2016, Windows Server 2019 and Windows 10 Enterprise 2019 LTSC, and on June 19, 2027 for everything else. A supported device with the July 2026 security update or later (September 2025 for Windows 11 24H2 and Server 2025) is ready. An unsupported one has to be upgraded.
The devices that miss this are rarely office laptops. They are build agents, test VMs, line-of-business servers and kiosks that someone pinned to an old image because an application depends on it. If your cloud and DevOps setup still runs Windows machines that are excluded from patching, this is the date to plan around.
What did Microsoft announce?
Windows Update checks certificates to confirm that a device is talking to Microsoft’s real update servers. Two sets of those certificates expire in 2027, and Microsoft has already shipped the replacements inside regular monthly updates. A device that installed the right update trusts the new certificates and carries on as before. A device that did not cannot set up the trusted connection once the old ones run out.
Microsoft’s guidance is short. Windows 11 25H2 and later need nothing. Windows 11 24H2 and Windows Server 2025 need the September 2025 security update or later. Other supported Windows 11 versions, Windows 10 and Windows Server 2022 need the July 2026 update or later. The long-term servicing releases, Windows 10 Enterprise 2019 LTSC, Windows Server 2019 and Windows Server 2016, need the same July 2026 update but face the earlier May 17 date. Unsupported versions get no fix: Microsoft says they lose Windows Update access and should be moved to a supported release.
Which Windows devices are at risk?
Any device that pulls updates directly from Windows Update and has fallen behind. That includes machines managed through tools that use Windows Update as their source. Microsoft says devices fed by WSUS are not affected, and that updates can still be installed by hand from the Microsoft Update Catalog.
In practice the risk sits in the corners of a fleet: Windows Server 2016 and 2019 hosts running old line-of-business apps, CI and build agents baked from golden images, test and staging VMs that are rebuilt rarely, kiosks, point-of-sale and lab PCs, and anything excluded from patching “because the vendor app breaks”. Techzine notes that systems kept off automatic updates for business-critical applications deserve the most attention. Windows Server 2016 also reaches the end of extended support on January 12, 2027, so for many of those hosts the real question is migration, not a single patch.
What it means for US & EU software teams
First, this is a cliff, not a slow decline. An unpatched server still runs after June 2027, but it can no longer receive the security fix that would close the next critical bug. That turns every frozen image into a permanent liability. Teams that delayed upgrades because “it still works” now have a hard date, and it lands within the next budget cycle.
Second, build and test infrastructure counts. Self-hosted Windows runners, signing machines and test VMs are often created once and patched never. If they lose Windows Update, they also drift away from the production patch level you test against. Rebuild images from a current baseline, or move the workloads to managed runners and cloud images that are refreshed for you. For Server 2016 and 2019 workloads that should leave on-premises hardware anyway, a planned Azure migration can solve the certificate date and the end-of-support date in one project.
Third, regulators will see it as a patch-management gap. Under NIS2, DORA, PCI DSS and SOC 2, systems that cannot receive security updates are a finding. A device that silently stopped updating in June 2027 is harder to defend in an audit than one with a documented upgrade plan made in 2026.
What should you do now?
- Inventory by build, not by name. Pull the OS version and latest installed update for every Windows device, including build agents, lab machines and appliances that run Windows inside.
- Check the update source. Separate devices that use Windows Update directly from WSUS-managed ones, and note anything that receives no updates at all.
- Patch the stragglers early. Install the July 2026 update or later on supported devices well before the deadline; for Server 2016, Server 2019 and 2019 LTSC, aim for the May 17 date.
- Plan the unsupported devices. Decide per machine: upgrade in place, rebuild on a supported release, move the workload to the cloud or retire it.
- Refresh images and pipelines. Update golden images and runner templates so that new machines start on a ready baseline, and add an alert for devices that stop reporting updates.
Frequently asked questions
When do the Windows Update certificates expire?
Microsoft says two sets of certificates used by Windows Update expire in 2027. The May 17, 2027 date applies to Windows 10 Enterprise 2019 LTSC, Windows Server 2019 and Windows Server 2016. The June 19, 2027 date applies to Windows 11, Windows 10 and Windows Server 2022 and 2025.
Which update do I need to keep receiving Windows updates?
Windows 11 version 25H2 and later need no action. Windows 11 version 24H2 and Windows Server 2025 need the September 2025 security update or later. Other supported Windows 11 versions, Windows 10, Windows Server 2022, Windows Server 2019, Windows Server 2016 and Windows 10 Enterprise 2019 LTSC need the July 2026 security update or later, installed before their deadline.
What happens to devices that are not ready?
After the certificates expire, a device that does not trust the new certificates can no longer connect to Windows Update and receives no updates of any type. Unsupported Windows versions lose Windows Update access and Microsoft recommends upgrading them to a supported release.
Are WSUS-managed devices affected?
Microsoft says the certificate rotation does not apply to devices that receive updates from Windows Server Update Services (WSUS). Updates can also be installed manually from the Microsoft Update Catalog.
Does Windows Server 2016 need special attention?
Yes. Windows Server 2016 is in the group with the earlier May 17, 2027 deadline, and it reaches the end of extended support on January 12, 2027. For many Server 2016 hosts the practical answer is an upgrade or migration plan rather than a single patch.
Sources
Microsoft Windows IT Pro Blog — Prepare for Windows Update certificate rotation in 2027
Microsoft Learn — Windows message center
BleepingComputer — Microsoft: Outdated Windows devices will stop receiving security updates
Techzine — Even supported Windows systems are at risk of missing updates in 2027