Microsoft is changing how Windows PCs verify their identity with update servers, a shift that will cut off internet updates for unpatched machines in mid-2027. This infrastructure overhaul affects every Windows device that has not installed the latest security patches, creating a hard deadline for system administrators and home users alike. Computers that fail to receive the necessary certificate updates will lose access to Windows Update, security patches, and feature updates after the expiration dates. This change matters because it forces a mandatory maintenance window for all supported Windows versions to ensure continued connectivity to Microsoft's update services.
Mandatory patches required for Windows 10 and Server systems
The update applies to a wide range of operating systems, including Windows 11 25H2 and later, Windows 11 24H2, Windows 10, Windows 10 Enterprise 2019 LTSC, Windows Server 2019, and Windows Server 2016. Windows 11 25H2 and later versions ship with the new certificates pre-installed, requiring no action from the user. Windows 11 24H2 requires the September 2025 security update or later to function correctly after the certificate rotation. Supported releases of Windows 11 and Windows 10 require the July 2026 security update or newer to maintain update access.
The core technical change involves rotating certificates used by Windows PCs to verify communication with Windows Update servers. Current certificates expire on May 17 and June 19, 2027, marking the end of the validity period for the old verification keys. Devices running unsupported Windows versions will lose Windows Update access entirely unless they upgrade to a supported release. This expiration is a hard stop, meaning the old certificates will no longer be accepted by Microsoft's servers after the specified dates.
Windows 10 Enterprise 2019 LTSC, Windows Server 2019, and Windows Server 2016 have a specific deadline of May 17, 2027, for this transition. Business PCs managed via WSUS are not affected by this change, allowing enterprise environments to maintain their current update workflows. The change ensures that only devices with valid, current certificates can communicate with Windows Update servers, enhancing the security of the update process. Microsoft confirmed this schedule through the Windows message center and the Windows IT Pro Blog.
Source: Windows Update, NotebookCheck




Discussion
0 comments