Windows Update: two certificates expire in 2027, Server 2019 first
On 8 October 2026 Microsoft put a date on the table in the Windows IT Pro Blog that is landing in IT departments right now. The certificates a device presents when it contacts Windows Update expire on 17 May 2027 and on 19 June 2027. The same day, message MC1491763 went out to every tenant admin in the Microsoft 365 Message Center, under the Windows service. Nothing changes for a machine on a monthly routine. For a system that hasn't seen a cumulative update in a year and a half, 2027 closes the entire update path.
What Microsoft is replacing here
Windows Update authenticates the other end of the connection with certificates. A device only accepts update content from servers that can present the matching certificate, because that is what makes a connection to a Windows Update server a trusted one. Those certificates carry an expiry date like any other certificate and get rotated on an interval. Microsoft delivers the replacements through the ordinary monthly security updates, which is why this concerns the trust path to the update service itself and nothing else. The chain is short: a device that misses the replacement certificates loses the Windows Update connection after the relevant deadline and loses all update types in one go.
The reporting trail from these past days is useful for anyone who processes tenant mail: blog post on 8 October, Message Center entry the same day, independent coverage on 9 October. MC1491763 can go straight to whoever owns the server round.
The deadlines by version
Microsoft sorts the Windows world into six groups. The replacement certificates sit in a different update per group, and the deadlines are a month apart.
| Windows version | Update required | Deadline |
|---|---|---|
| Windows 11 from version 25H2 | none, certificates already built in | none |
| Windows 11 24H2, Windows Server 2025 | September 2025 security update or later | 19 June 2027 |
| other supported Windows 11 editions, Windows Server 2022 | July 2026 security update or later | 19 June 2027 |
| supported Windows 10 editions | July 2026 security update or later | 19 June 2027 |
| Windows 10 Enterprise 2019 LTSC, Windows Server 2019, Windows Server 2016 | July 2026 security update or later | 17 May 2027 |
| all other Windows versions | upgrade to a supported version | before expiry |
The table mixes two maintenance worlds. The early mid-May deadline applies to Server 2016, Server 2019 and Windows 10 Enterprise 2019 LTSC, which is to say the systems still running for years in a lot of small server rooms and terminal server estates, because extended support runs until January 2029. Anyone who doesn't know which Windows versions are in their estate can answer that with an inventory sweep in minutes. Cleaning up afterwards takes considerably longer.
What happens after the deadline
Current devices on supported versions won't notice anything, their certificates were replaced long ago. Devices on a supported but outdated version stop seeing the update offer after the relevant date. The way out is stated in the same Microsoft message: the required update can be pulled from the Microsoft Update Catalog as a single package and deployed through the normal management path, after which access works again. Devices outside the support window lose update access with no substitute, and Microsoft's advice there is an upgrade to a supported client or server version.
For pure WSUS estates Microsoft makes an explicit exception: devices receiving updates through Windows Server Update Services are not affected by the change. The WSUS server is itself a Windows server though, and sits in one of those table rows. Its own patch level keeps counting, otherwise every client ends up nicely supplied while the supply line from the Microsoft cloud and the catalog runs dry.
Why this date belongs in the maintenance calendar now
The deadlines sound remote, the actual work is already months behind us. The July 2026 update is roughly three months old as of this writing, and anyone patching on the second Tuesday has long had the certificates in the building. Three reasons to schedule the check anyway.
First, lifecycle: Windows 10 Home and Pro left support on 14 October 2025, straight from the Microsoft lifecycle page. Those devices sit in the last row of the table, and for them there is no update to catch up on, only an upgrade or a planned ESU path. Second, how long the other group is planned to live: Windows Server 2019 and Windows 10 Enterprise LTSC 2019 run until 9 January 2029 according to the lifecycle page. Nobody is re-planning those machines, precisely because they are supported for years more, and for exactly those machines the date is now 17 May 2027. Third, proof: the moment an insurer, a customer or an audit asks for the patch state of your servers, "we should have that" stops being an answer.
Our own estate: 100 hosts in the ESET channel, 97 with a Windows tag
On 11 October 2026 we pulled what we actually know about our Windows fleet out of the SIEM. The ESET channel shows 12,728 events from 100 distinct hostnames inside the 7 to 11 September window. 97 of those hosts carry a Windows identifier in the operating system field: 65 Windows 11 Pro, 20 Windows Server 2019 Datacenter, four Windows 10 Enterprise LTSC, three each of Windows 10 Enterprise 2016 LTSB and Windows 11 Home, plus one Windows 11 IoT Enterprise LTSC and one Windows Embedded Standard. Two Ubuntu hosts and one macOS host report through the same channel.
Two caveats belong right next to that number, otherwise it sounds more precise than it is. First, 8,918 of the 12,728 events carry no operating system field at all, so 97 hosts is a lower bound rather than a census. Second, the field does not distinguish Windows 10 Enterprise LTSC 2019 from LTSC 2021, even though only the 2019 release appears in the early table row. Anyone who needs those two apart requires a real inventory, not this channel. Sorted by event count, Server 2019 is the largest block among the identified systems: 3,067 events against 556 from Windows 11 Pro. The critical group from the table isn't a fringe topic here, it sits in the middle of the estate.
The same measurement exposes the uncomfortable side too: neither our SIEM nor our CVE watcher says anything about the patch level of the Windows hosts. Whether the July 2026 update is present on our Server 2019 machines is a question no tool in the house answers. We also haven't measured whether a WSUS stands anywhere in our path at all. That check runs through Get-HotFix or Win32_QuickFixEngineering against the server list, or through the update compliance report of whatever management tool is already deployed. The measurement is still outstanding, and the task list below applies to us exactly as it does to a customer estate.
The checklist for the autumn round
- Record the Windows versions in the estate and sort them into the table rows. The critical group first: Windows Server 2016 and 2019, Windows 10 Enterprise 2019 LTSC, deadline 17 May 2027.
- On that group, verify the install state of the July 2026 update and pull missing packages.
- End-of-life devices are a planning question, not an update question: Windows 10 Home and Pro has been out since 14 October 2025, so upgrade to Windows 11 or Server, or document an ESU path.
- Bring the WSUS server itself (if there is one) up to a supported version and a current patch state.
- Put 17 May and 19 June 2027 in the maintenance year as a check date, six months ahead. How a rollout runs cleanly without SCCM is in our post Patch management for SMEs.
Further reading
- Windows IT Pro Blog: Prepare for Windows Update certificate rotation in 2027, 8 October 2026, with the six-row table and the WSUS exception
- Microsoft 365 Message Center, MC1491763 of 8 October 2026, behind tenant login, full text as an archive copy
- Microsoft Lifecycle: Windows Server 2019, Windows 10 Enterprise LTSC 2019 and Windows 10 Home and Pro
- BleepingComputer: Microsoft: Outdated Windows devices will stop receiving security updates, 9 October 2026, quoting the Microsoft guidance row by row
Does my Windows 11 desktop have to do anything too?+
Windows 11 from 25H2 already carries the new certificates, so nothing to do there. Windows 11 24H2 needs the September 2025 security update or any later one, every other supported Windows 11 release needs the July 2026 security update or newer. Anyone patching monthly has discharged that duty already. The deadlines themselves are not until 2027.
What applies when I patch through WSUS?+
Microsoft expressly excludes devices that receive their updates from Windows Server Update Services. The WSUS server itself remains a Windows server and sits in one of the table rows. Its own patch level still counts. A WSUS left behind is not a sheltered zone.
What exactly stops working after 17 May and 19 June 2027?+
The device can no longer reach Windows Update, so it stops receiving every kind of update through that path, security updates included. Recovery exists: pull the missing update from the Microsoft Update Catalog as a single package, install it, and the path works again. Out of support devices don't have that escape route, their row in the Microsoft table only offers an upgrade.
senn-tech