Microsoft Outdated Windows Devices Stop Receiving Security Updates
Microsoft has announced that systems operating on outdated Windows versions will cease to receive security patches following the 2027 certificate rotation.
Announcement Details
Microsoft emphasized that devices running unsupported Windows iterations will no longer access Windows Update services after the expiration of current update certificates in May and June 2027. To maintain protection, administrators and users must transition to supported Windows versions prior to these deadlines. The update process hinges on the expiration of Windows Update certificates, which are standard security measures with defined lifespans. Once these certificates expire, devices on unsupported operating systems will lose access to critical security updates.
Microsoft clarified that replacement certificates have already been deployed to systems running current Windows versions, requiring no additional intervention for users who maintain up-to-date configurations. Detailed mitigation steps vary by Windows edition.
Mitigation Steps
For Windows 11, version 25H2 and later, no action is necessary. Users of Windows 11 24H2 and Windows Server 2025 must install the September 2025 security update or newer by June 19, 2027. Other supported Windows 11 variants, Windows Server 2022, and Windows 10 systems need the July 2026 security update or later installed before the same date. Windows 10 Enterprise 2019 Long-Term Servicing Channel (LTSC), Windows Server 2019, and Windows Server 2016 users must apply the July 2026 update or newer by May 17, 2027. All other unsupported Windows versions require migration to a supported operating system.
IT Team Guidance
Microsoft urged IT teams to audit their environments and identify devices running obsolete Windows versions ahead of the 2027 certificate expiration. Administrators are advised to ensure all supported systems receive monthly updates and to establish upgrade timelines for unsupported devices. The company highlighted that organizations still have sufficient time to address legacy systems, provided they review, update, and plan transitions before the May and June 2027 deadlines.
Additional Notes
This policy does not impact devices managed through Windows Server Update Services (WSUS), which continue to function independently of the certificate rotation. Additionally, Microsoft recently launched Windows 11 version 26H2, a minor update for eligible 24H2 and 25H2 systems. This enablement package, part of a phased rollout, replaces the need for a full operating system overhaul.
Conclusion
The announcement underscores the importance of proactive system management in mitigating vulnerabilities associated with end-of-support software. Organizations relying on outdated Windows versions face heightened risks of exploitation once certificate expiration occurs, necessitating immediate action to align with Microsoft’s security requirements.
