P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Windows Update certificates expire 17 May and 19 June 2027; Server 2016 support ends 125 days before

Microsoft says a set of Windows Update certificates expires on 17 May and 19 June 2027 and that unsupported Windows will lose Windows Update. Its own lifecycle page ends Server 2016 support on 12 January 2027, 125 days before the first date, and the notice never mentions ESU.

By Parminder Kumar Sharma · · 23 min read

An old beige computer tower, switched off, stands beside a graphite laptop with a blank pale-blue screen, under a wall calendar with an empty grid and two cells ringed in red. Text on the left reads: Windows Update certificates expire 17 May, 19 June 2027. 125 days: Server 2016 support ends this long before 17 May.

Microsoft asks Server 2016 owners to act 125 days after Server 2016 support ends

Microsoft's lifecycle page ends extended support for Windows Server 2016 on 12 January 2027. Microsoft's notice of 8 October 2026, Prepare for Windows Update certificate rotation in 2027, lists Server 2016 among the versions that must install the July 2026 security update or later before 17 May 2027. That is 125 days after extended support ends (derived). The notice sets a second date, 19 June 2027, 33 days later (derived), for every other version it names. Counted from Friday 9 October 2026, the first date is 220 days away and the second is 253 (derived).

The arithmetic establishes less than it seems to. It does not show that a Server 2016 machine loses Windows Update on 17 May. Microsoft's Windows Server ESU page says Server 2016 Extended Security Updates start on 12 January 2027, with Azure Arc as the route Microsoft's blog names, and the notice never mentions ESU. So the Server 2016 row can only be meaningful for a machine that is still receiving updates after 12 January, which means one under ESU (inference), and the notice does not say which machines it is addressed to. It does not say how many devices are affected. It does not say whether the dates will move. And it does not say what happens, on either date, to a device on a version that has already ended but holds the replacement certificates.

What it does show is that "supported" is a moving label. On Microsoft's own dates, Windows 11 24H2 Home and Pro, Windows 11 23H2 Enterprise and Education, Windows Server 2016 and Windows 10 Enterprise LTSC 2021 all leave ordinary support before the first certificate date, and only some can be kept on a support footing by buying ESU. And the check that costs least, whether a device has the July 2026 update, has already been due for some time: the NCSC's 7 days for operating system updates ended on 21 July 2026, 80 days ago (derived from the 14 July release).

Method: every figure is read from a Microsoft page unless it is marked derived (arithmetic on Microsoft's dates), inference (this briefing's reading) or UK source. BleepingComputer's report of 9 October 2026 is the pointer to Microsoft's notice and matches it. Microsoft sells Extended Security Updates and Windows licences, and the notice tells owners of old Windows to upgrade.

What the table says, counted

Microsoft publishes the same table twice: as a bullet list in the Windows message centre and as a table in the blog post. The action is always the same: a named monthly security update, or later, before a date. The notice gives no KB numbers; the build numbers that match each month are in the section on finding the estate.

Microsoft's action table for the Windows Update certificate rotation, as printed in the Windows IT Pro Blog on 8 October 2026

Windows version, as Microsoft names itAction Microsoft statesBefore
Windows 11, version 25H2 and laterNoneNo date
Windows 11, version 24H2 and Windows Server 2025Install the September 2025 security update or later19 June 2027
Other Windows 11 versions in support and Windows Server 2022Install the July 2026 security update or later19 June 2027
Windows 10 versions in supportInstall the July 2026 security update or later19 June 2027
Windows 10 Enterprise 2019 LTSC, Windows Server 2019, Windows Server 2016Install the July 2026 security update or later17 May 2027
Other Windows versionsUpgrade to a supported version of Windows client or serverNo date: "they'll lose access to Windows Update services"

Counted, the table has six rows and names nine product groups in four buckets: one needs nothing (Windows 11 25H2 and later), two must reach the September 2025 update by 19 June 2027, three the July 2026 update by 19 June 2027, and three the July 2026 update by 17 May 2027 (derived count). The sixth row, "Other Windows versions", is open: it names no version and gives no date.

On Microsoft's Windows 11 release page, "version 25H2 and later" covers three versions today: 25H2, 26H1 and 26H2, the last generally available since 29 September 2026. The same page says 26H1 is "not designed as a feature update for existing devices", so a fleet on 24H2 reaches the "no action" row through 25H2 or 26H2, not 26H1.

Microsoft names no version as "other". The table below sets the end dates on Microsoft's Windows client, Windows Server and lifecycle pages against the open row and against the versions that end first. Placing a version in "other" is this briefing's reading, not Microsoft's.

Versions that Microsoft's own pages show as ended, or ending before 17 May 2027, and the gap to 17 May 2027 (days derived)

Version and editionEnd date on Microsoft pageDays before 17 May 2027
Windows Server 2012 and 2012 R2, extended support10 Oct 20231,315
Windows 11 22H2 Home and Pro8 Oct 2024951
Windows 10 22H2, without ESU14 Oct 2025580
Windows 11 22H2 Enterprise and Education14 Oct 2025580
Windows 11 23H2 Home and Pro11 Nov 2025552
Windows 11 24H2 Home and Pro13 Oct 2026216
Windows 10 Enterprise LTSB 2016; Server 2012 and 2012 R2 ESU year 313 Oct 2026216
Windows 11 23H2 Enterprise and Education10 Nov 2026188
Windows Server 2016; Windows 10 Enterprise LTSC 202112 Jan 2027125

Two rows need care. Windows 10 version 22H2 is shown as "End of updates" on the Windows 10 release page, yet ESU devices still receive updates: business ESU year two ends 12 October 2027 and year three 10 October 2028 per the ESU FAQ, and consumer ESU ends 12 October 2027 per Microsoft's consumer page. Read against those pages, "Windows 10 versions in support" can only mean 22H2 under ESU or an LTSC edition (inference); the notice does not say so. And Windows Server 2012 and 2012 R2 appear in no row of the notice, yet Microsoft's ESU table lists them until 13 October 2026.

What the notice states, and what it leaves out

The mechanism first. Microsoft says what the certificates are for, not what they are.

Microsoft's notice, the mechanism: what the message centre item and blog post state and do not state

QuestionStated by MicrosoftNot stated
Which certificates"Certificates used to establish trusted connections to Windows Update"; the blog adds that Windows Update uses certificate-based trust to confirm devices connect to authoritative Windows Update serversNames, subjects, thumbprints or issuers; whether they are roots, intermediates or others; what else they sign
How a device is protected"Devices must contain the replacement certificates to continue receiving updates after the applicable expiration date"; supported, updated versions "already have the necessary updated certificates"A way to check that a device holds them; in the pages read, the update level is the only proxy
Which update carries themNamed by month: September 2025 or July 2026, or laterAny mention in those updates' own release notes (see below)
17 May versus 19 JuneThree products by 17 May, the rest by 19 June; "A set of these certificates will expire on May 17, 2027 and June 19, 2027"Why the three older products are earlier; which set covers which version; what happens to Windows 11 between 17 May and 19 June
Unsupported versions"will lose access to Windows Update services and won't receive any updates as a result"; the advice is to upgradeAny fix for them (the page points to none); the date a given unsupported version loses access
What "access" coversAffected devices "will stop connecting and receiving all types of updates from Windows Update"Whether Defender updates, drivers, the Microsoft Store, Windows Update for Business or Autopatch are included; none is named
Extended Security UpdatesESU exists for Windows 10 22H2 (to 2027 or 2028), Windows 10 Enterprise LTSC 2021 (on sale from 1 Sep 2026) and Server 2016 (from 12 Jan 2027)Any mention of ESU in the notice, so whether ESU-covered devices are the "in support" rows is not stated
An ended version that holds the certificatesThe message centre tests the certificates ("without the replacement certificates"); the blog tests support statusWhich test governs, for example a Windows 11 24H2 Home device that took the September 2025 update and left support on 13 October 2026

The last row is the one that decides the most devices, and Microsoft answers it with two different sentences. The message centre item says devices "without the replacement certificates will lose access". The blog post says devices on unsupported versions "will lose access", "as a result" of getting no updates. If the first test governs, an ended version that already holds the certificates keeps access; if the second, it does not. Neither page says (inference: the first reading fits a mechanism, the second fits a policy).

The manual route is the Microsoft Update Catalog. The blog tells owners of supported but out-of-date devices to "use Microsoft Update Catalog to directly download and install required updates". Microsoft's Catalog page, last updated 28 September 2026, says the Catalog "offers updates for all operating systems that Microsoft currently supports". It says nothing about versions Microsoft does not support, and the notice does not say whether the Catalog stays open to them.

Nothing in the updates' own release notes describes the change. This briefing searched the full text of seven Microsoft pages, the July 2026 updates for Windows 11 24H2 and 25H2 (KB5101650), Windows 10 22H2 and LTSC 2021 (KB5099539), Server 2016 (KB5099535), Server 2019 and Windows 10 LTSC 2019 (KB5099538), Server 2022 (KB5099540) and Server 2025 (KB5099536), and the September 2025 update for Windows 11 24H2 (KB5065426), for "rotation", "Windows Update certificate", "May 17, 2027" and "June 19, 2027". None appears. The certificate text in those pages is chiefly about Secure Boot, which Microsoft says was "set to expire starting in June 2026", a separate certificate problem with separate dates that the Windows Update notice does not mention. A headline that says "Windows certificates are expiring" covers at least two unrelated Microsoft changes.

"In support" is doing five jobs in that table

The notice says most devices need no action if they run "an in-support version of Windows" and are current. On Microsoft's own pages the phrase covers five different things, and they do not all stay true until the certificate dates:

  • Windows 11 24H2: Home and Pro "will reach end of updates on October 13, 2026" (KB5101650); Enterprise and Education run to 12 October 2027.
  • Windows 10 22H2: "End of updates" since 14 October 2025 on the release page, with ESU to 12 October 2027 (consumer, and business year two) or 10 October 2028 (business year three).
  • Windows 10 Enterprise LTSC 2021: ends 12 January 2027, with its own ESU on sale from 1 September 2026, $61 USD per device for year one or $45 with Intune or Autopatch (Microsoft's planning post). IoT Enterprise LTSC 2021 is outside that offer and runs to 13 January 2032. The enable ESU page says LTSB and LTSC releases "are NOT covered via the Windows 10 ESU program", which is the 22H2 programme.
  • Windows Server 2016: extended support ends 12 January 2027, and ESU starts the same day, through Azure Arc and for three more years in Azure (Windows Server blog, ESU page). The ESU FAQ table lists Windows 10 and Windows Server 2012 and 2012 R2 and not Server 2016, so Microsoft's own pages differ.
  • Windows 10 Enterprise 2019 LTSC, Windows 10 IoT Enterprise LTSC 2019 and Windows Server 2019: extended support to 9 January 2029.

So "in support" on 8 October 2026 and "in support" on 17 May 2027 are different sets of devices (derived from the dates above). The friendly label is not a control: the question for each device is which row it will be in on the date, and whether it holds the update by then.

The WSUS exception says less than it appears to

Microsoft's wording is one sentence in the message centre item and the blog post: the change "does not apply to devices receiving updates from Windows Server Update Services (WSUS)". Configuration Manager is not mentioned in either. Three things on Microsoft's other pages bear on it:

  • A WSUS server "connects to Microsoft Update to download updates", which Microsoft calls synchronisation, and "at least one WSUS server on your network must be able to connect to Microsoft Update" (WSUS plan, WSUS overview).
  • Configuration Manager's software updates synchronisation "connects to Microsoft Update to retrieve software updates metadata", unless it is pointed at another WSUS server (Configuration Manager).
  • WSUS "is deprecated and is no longer adding new features", but "continues to be supported for production deployments" (WSUS overview, page last updated 5 May 2025).

What the notice does not say is whether WSUS-managed devices need the same update, where a WSUS client gets its trust, or whether the upstream server's own synchronisation with Microsoft Update is covered by the rotation. Two readings are open (inference). One: the exception is about clients, which take content from your server and do not test Windows Update's certificates. Two: the upstream server still connects to Microsoft's service, so its operating system and update level are what matter, and the WSUS role runs on Windows Server, which Microsoft's WSUS overview says it applies to as Server 2016, 2019, 2022 and 2025. The second reading would put a Server 2016 or Server 2019 WSUS server in the 17 May row. Microsoft's pages support neither reading, so the safe course is to treat the upstream server as in scope until Microsoft says otherwise.

A client "receiving updates from WSUS" may not receive all of them from WSUS. Microsoft's WSUS deployment page warns that a policy blocking Windows Update internet locations "can break Windows Store connectivity", which suggests some traffic of a managed client still goes to Microsoft's service (inference). The exception does not define "receiving updates from" for mixed or dual-scan clients.

Offline, virtual and embedded estates

Microsoft's notice, estates and routes: what it states and does not state

EstateWhat Microsoft states elsewhereNot stated in the notice
Offline or air-gapped devicesWSUS servers in a network isolated from the internet can be fed by exporting update metadata and content from a connected server to media and importing it ([WSUS plan](https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/plan/plan-your-wsus-deployment))Any mention of offline devices, or whether imported content is affected
Virtual machines and imagesESU for Windows 10 is free on Windows 365, Azure Virtual Desktop and Azure virtual machines ([ESU](https://learn.microsoft.com/en-us/windows/whats-new/extended-security-updates))Any mention of images or cloud services. An image built before July 2026 lacks the update (inference)
IoT and embeddedDates: IoT Enterprise LTSC 2019 to 9 Jan 2029; LTSC 2021 to 12 Jan 2027, extended to 13 Jan 2032; Windows 11 IoT Enterprise LTSC 2024 to 10 Oct 2034Whether IoT editions sit in the same rows as their Enterprise twins
Windows 11 Enterprise LTSC 2024Same build line as 24H2 (26100); support to 9 Oct 2029 ([release page](https://learn.microsoft.com/en-us/windows/release-health/windows11-release-information))Which row it is in: 24H2 (September 2025) or "other in-support" (July 2026)

Where the notice is silent, the test in Microsoft's own sentence still works: "Devices must contain the replacement certificates." For an offline device or a template that is never updated, the notice's test is the update level, not whether the device is online. An air-gapped server that never touches Windows Update is not affected by losing it, but it also never gets the new certificates, so the day it is first connected after the dates is the day the question arises (inference).

What "lose access" covers, and what stays open

The blog says affected devices stop receiving "all types of updates from Windows Update". It names none of them. Microsoft's Defender update page lists Windows Update as one of several ways to install security intelligence and engine updates, alongside WSUS, a software update point, a file server and the Windows Security app, and says platform updates can also come from the Windows Update Catalog. It also says cloud-delivered protection "is always on and requires an active connection to the internet". The notice says nothing about whether Defender's own update channel is affected, and this briefing cannot establish it.

The NCSC's obsolete products guidance states the general risk: anti-malware products "may not be updated when running on an unsupported operating system". That is a general statement, not a finding about Microsoft Defender after 17 May or 19 June.

What the UK sources say

Cyber Essentials sets a clock that UK suppliers are assessed against. The Requirements for IT Infrastructure v3.3 (April 2026, read from the NCSC PDF) define "licensed and supported software" as software "a vendor has committed to support by providing regular vulnerability fixes", where the vendor "must provide the future date when they will stop providing these". Section 3, Security Update Management, then requires all in-scope software to be licensed and supported and to be "removed from devices when it becomes unsupported", or removed from scope "by using a defined sub-set that prevents all traffic to or from the internet". Critical or high-risk fixes must be installed within 14 days.

By that definition, Server 2016's vendor date is 12 January 2027: from 13 January a Server 2016 machine in scope has to be removed, isolated or covered by something that makes it supported (inference from the definition). The PDF does not mention Extended Security Updates, so how an assessor treats ESU is not in the document read.

UK sources read for this briefing, and what each does and does not say about the rotation

SourceWhat it saysWhat it does not say
Cyber Essentials requirements v3.3, April 2026 (NCSC PDF)Supported means a vendor date for the end of fixes; unsupported software removed or isolated; 14 days for critical and high fixesAnything about Windows Update, certificates or ESU
NCSC, "Put in place a policy to update by default", v2.1, reviewed 1 May 2026Update completed within 5 days for internet-facing software, 7 days for operating systems and applications, 14 days for internal or air-gapped softwareAny vendor-specific date; the 7 days apply to updates "published", so the July 2026 update was due by 21 July (derived)
NCSC, "Obsolete products", v2.1, reviewed 13 May 2025"The only fully effective way to mitigate this risk is to stop using the obsolete product"; if not, treat devices as untrusted, block email and browsing, zone the networkAny statement about Windows Update access after support ends
NHS England, "Windows 10 end of support October 2025", last edited 26 June 2025All trusts and ICBs "must transition to Windows 11"Anything after October 2025, including ESU and certificates
NHS England, DSPT Data Security Standard 8, edited 8 October 2025 (2023-24 standard)"No unsupported operating systems, software or internet browsers are used within the IT estate"; accepts that not all can be upgradedAnything about the Windows Update rotation

No UK source read here mentions the rotation. Cyber Essentials and the NCSC treat "supported" as a vendor commitment with a date, so the notice's real effect on a UK assessment is indirect: it moves forward the day a device with no update path becomes a finding, and it makes the question "which devices are on which row" an assessment question. The same arithmetic on another vendor's support dates is in brief 241, and the 14-day clock applied to an advisory is in brief 272. This briefing found no NHS England statement after October 2025 on Windows 10 devices still in use; none is claimed.

What an organisation has to decide before May 2027

For each device that is not on the no-action row, there are four choices, and Microsoft's pages say different things about each.

The four choices for a device on an ended or ending version, with what Microsoft's pages say

ChoiceWhat Microsoft statesWhat it does not say
Upgrade in place or reimageNo action once on Windows 11 25H2 or later; devices that do not meet Windows 11 requirements "might not be able to install Windows 11" ([lifecycle FAQ](https://learn.microsoft.com/en-us/lifecycle/faq/windows))How many of your devices fail the requirements
ReplaceMicrosoft names Windows 11 Enterprise LTSC 2024 as the move from LTSC 2021 ([planning post](https://techcommunity.microsoft.com/blog/windows-itpro-blog/plan-for-windows-10-enterprise-ltsc-2021-end-of-support/4539866)) and Windows Server 2025 or Azure for Server 2016 ([Windows Server blog](https://www.microsoft.com/en-us/windows-server/blog/2026/02/25/planning-ahead-for-windows-server-2016-end-of-support/))Lead times, or the build a new device ships at
Buy ESU, where it is soldWindows 10 22H2, business: $61 USD per device for year one, doubling each year for up to three years ([ESU](https://learn.microsoft.com/en-us/windows/whats-new/extended-security-updates), page last updated 17 Nov 2025); year ends 13 Oct 2026, 12 Oct 2027, 10 Oct 2028. Consumer to 12 Oct 2027 ([consumer page](https://www.microsoft.com/en-gb/windows/extended-security-updates)). LTSC 2021: separate offer, $61 or $45 with Intune or Autopatch, from 1 Sep 2026 ([planning post](https://techcommunity.microsoft.com/blog/windows-itpro-blog/plan-for-windows-10-enterprise-ltsc-2021-end-of-support/4539866)). Server 2016: from 12 Jan 2027, through Azure Arc and for three more years in Azure ([ESU page](https://www.microsoft.com/en-us/windows-server/extended-security-updates))Whether ESU devices count as "in support" for the notice; any Server 2016 ESU price (none read); any ESU for Windows 11 24H2 Home and Pro or for IoT LTSC 2021
IsolateNot discussed in the notice. The NCSC and Cyber Essentials describe isolation (UK section)Whether an isolated device that keeps working after the dates still needs the update

ESU is cumulative: Microsoft says a year-two purchase also needs year one. If a business enrolled for Windows 10 year one only, that coverage ends on 13 October 2026, four days from this briefing. Prices on Microsoft's pages are in US dollars and carry a date; this briefing makes no claim about UK prices it did not read.

Finding the estate: build numbers, update source, image age

Microsoft's own plan is three steps: identify devices on older or unsupported versions, keep supported devices current, and make an upgrade plan before May and June 2027. The first step needs a field most inventories already hold, the build number. The table below gives the build Microsoft lists for each month the notice names. A device on the same version with a higher revision number after the dot has the update or a later one, because Microsoft says the monthly releases are cumulative (inference for the comparison; the cumulative statement is Microsoft's, on the Windows 11 release page).

Build numbers of the updates the notice names, from Microsoft's release health pages (build is the number Microsoft lists for that update)

ProductJuly 2026 update (KB, build)September 2025 update (KB, build)
Windows 11 24H2 and 25H2KB5101650, 26100.8875 and 26200.8875KB5065426, 26100.6584 (24H2)
Windows 11 23H2KB5099414, 22631.7376Not needed
Windows 10 22H2 and LTSC 2021KB5099539, 19045.7548 and 19044.7548Not needed
Windows 10 LTSC 2019 and Server 2019KB5099538, 17763.9020Not needed
Windows Server 2016KB5099535, 14393.9339Not needed
Windows Server 2022KB5099540, 20348.5386Not needed
Windows Server 2025KB5099536, 26100.33158KB5065426, 26100.6584

Add three fields the build number does not give. The update source: WSUS, Configuration Manager, Windows Update or Windows Update for Business, because the notice treats them differently. The image age: any golden image or template built before July 2026 (or, for 24H2 and Server 2025, before September 2025) lacks the update. And the last time each device was online, because an offline device that has never installed the update has the same exposure as a neglected one. Microsoft offers no method for checking that a device holds the replacement certificates, so the update level is the only evidence.

A dated plan, to scale

The diagram draws Microsoft's two dates and the end dates of the versions near its list on one axis, to scale. The gap between 12 January and 17 May is the stretch in which Server 2016 and Windows 10 Enterprise LTSC 2021 are out of support but the notice still asks for an update.

Vertical timeline to scale, 9 October 2026 to 19 June 2027, 253 days. Support ends: 13 October 2026, Windows 11 24H2 Home and Pro; 10 November, Windows 11 23H2 Enterprise and Education; 12 January 2027, Windows Server 2016 and Windows 10 Enterprise LTSC 2021, 125 days before the first date. Microsoft's dates: 17 May 2027 for LTSC 2019, Server 2019 and Server 2016; 19 June for all others. Not stated: ESU, or what ended versions holding the certificates lose.
Drawn from Microsoft's message centre item of 8 October 2026, its Windows IT Pro Blog post, and the Windows release health and lifecycle pages, read on 9 October 2026. The axis is to scale; day counts are derived.

The plan, with dates. Patch Tuesday is the second Tuesday of the month, per Microsoft's Windows 11 release page.

  • Tuesday 13 October 2026: Patch Tuesday. Windows 11 24H2 Home and Pro, Windows 10 Enterprise LTSB 2016 and Server 2012 and 2012 R2 ESU year 3 end. Business ESU year 1 ends. Take the update and start the inventory.
  • Tuesday 10 November 2026: Windows 11 23H2 Enterprise and Education ends.
  • Tuesday 12 January 2027: Windows Server 2016 and Windows 10 Enterprise LTSC 2021 end. Any device still there is on a version with no path except isolation or ESU where sold.
  • Tuesday 11 May 2027: the last Patch Tuesday before 17 May, six days earlier (derived). Friday 14 May is the last working day before the date.
  • Monday 17 May 2027: first certificate date.
  • Tuesday 8 June 2027: the last Patch Tuesday before 19 June, 11 days earlier (derived).
  • Saturday 19 June 2027: second certificate date. Friday 18 June is the last working day before it.

What to do, in order

Take this with you

Defender actions, in the order worth doing

  • List every Windows device with edition, version, build number, update source, last-online date and image age. Microsoft names this as its first step.
  • Separate the devices at or above the July 2026 build in the build-number table (September 2025 for 24H2 and Server 2025) from those below it. Those below are already outside the NCSC 7-day clock.
  • Mark the devices whose version ends before 19 June 2027 on Microsoft's dates: Windows 11 24H2 Home and Pro, 23H2 Enterprise and Education, Server 2016 and Windows 10 Enterprise LTSC 2021.
  • For every Server 2016, Server 2019 and Windows 10 LTSC 2019 device, put 11 May 2027 in the plan as the last Patch Tuesday before the first date.
  • Treat the upstream WSUS server, and any server that synchronises with Microsoft Update, as in scope until Microsoft says the exception covers it.
  • Decide upgrade, replace, isolate or ESU per device and record it; for Cyber Essentials, record how each unsupported device is removed or kept out of scope.
  • Rebuild or patch golden images and templates to the July 2026 update, and check that cloned virtual machines inherit it.
  • Ask your Microsoft account team three questions in writing: whether an ended version holding the certificates keeps access, whether ESU devices are in the "in support" row, and what the WSUS exception covers.
  • Record 17 May and 19 June 2027 in the risk register with the owner of each device group, and re-read Microsoft's notice on each Patch Tuesday for changes.

What is not established, and what could not be read

Not established: how many devices are affected; whether Microsoft will move either date; the names and scope of the certificates; what Microsoft's own Defender platform does after the dates; what an ended version holding the replacement certificates loses; and how a Cyber Essentials assessor treats ESU. Not read: any Microsoft statement beyond the three forms of the 8 October notice and the pages they link, any Microsoft page on the certificates themselves (none was found in the pages read), and any UK public-sector statement after October 2025 on this change. The consumer ESU page, the lifecycle and release pages and the KB pages are as published on 9 October 2026 and change monthly.

The question this leaves

Microsoft has given 220 days to the first date. Which of your Windows devices are on a version that Microsoft's own lifecycle pages say will have ended before 19 June 2027, and could your inventory list them today, with the build number that shows whether each holds the July 2026 update?

Key facts

Sources

  1. PrimaryItem 'Prepare for Windows Update certificate rotation in 2027', dated 2026-10-08 10:00 PT, read in full in a browser tab: the two dates, the five actions by version, the WSUS sentence. Microsoft sells ESU and Windows licences.Microsoft, Windows message centeraccessed 2026-10-09
  2. PrimaryThe full notice (version 2.0, 8 October 2026), read in full: the six-row table, the three outcome paragraphs, the Microsoft Update Catalog route, the action plan.Microsoft, Windows IT Pro Blogaccessed 2026-10-09
  3. PrimaryThe discussion post linked from the blog (8 October 2026), read in full: one paragraph and links to Autopatch, Windows Update for Business and Intune pages; no replies when read.Microsoft, Microsoft Community Hubaccessed 2026-10-09
  4. PrimarySupported versions of Windows client, last updated 2026-09-29: end-of-updates dates for Windows 11 24H2, 25H2, 26H1, 26H2 and Windows 10 22H2, LTSC 2019 and 2021, LTSB 2016.Microsoft, Windows release healthaccessed 2026-10-09
  5. PrimaryWindows Server release information: mainstream and extended end dates for Server 2016, 2019, 2022 and 2025 and the KB and build of each monthly update.Microsoft, Windows release healthaccessed 2026-10-09
  6. PrimaryWindows 11 release information: versions, builds, KB numbers, the second-Tuesday release cadence and the note that 26H1 is not designed as a feature update for existing devices.Microsoft, Windows release healthaccessed 2026-10-09
  7. PrimaryWindows 10 release information: 22H2 'End of updates', LTSC 2021 end date, LTSB 2016 extended end 2026-10-13, KB and build of the July 2026 update.Microsoft, Windows release healthaccessed 2026-10-09
  8. PrimaryWindows Server 2016 lifecycle: extended end date 12 January 2027.Microsoft, Microsoft Lifecycleaccessed 2026-10-09
  9. PrimaryWindows Server 2019 lifecycle: extended end date 9 January 2029.Microsoft, Microsoft Lifecycleaccessed 2026-10-09
  10. PrimaryWindows Server 2022 lifecycle: mainstream end 13 October 2026, extended end 14 October 2031.Microsoft, Microsoft Lifecycleaccessed 2026-10-09
  11. PrimaryWindows Server 2025 lifecycle: extended end 14 November 2034.Microsoft, Microsoft Lifecycleaccessed 2026-10-09
  12. PrimaryWindows Server 2012 R2 lifecycle: extended end 10 October 2023, ESU year 3 ends 13 October 2026.Microsoft, Microsoft Lifecycleaccessed 2026-10-09
  13. PrimaryWindows 10 Home and Pro lifecycle: 22H2 retired 14 October 2025.Microsoft, Microsoft Lifecycleaccessed 2026-10-09
  14. PrimaryWindows 10 Enterprise LTSC 2019 lifecycle: extended end 9 January 2029.Microsoft, Microsoft Lifecycleaccessed 2026-10-09
  15. PrimaryWindows 10 Enterprise LTSC 2021 lifecycle: mainstream end 12 January 2027.Microsoft, Microsoft Lifecycleaccessed 2026-10-09
  16. PrimaryWindows 10 IoT Enterprise LTSC 2021 lifecycle: mainstream end 12 January 2027, extended end 13 January 2032.Microsoft, Microsoft Lifecycleaccessed 2026-10-09
  17. PrimaryWindows 11 Home and Pro lifecycle: end dates by version, 24H2 13 October 2026, 23H2 11 November 2025, 22H2 8 October 2024.Microsoft, Microsoft Lifecycleaccessed 2026-10-09
  18. PrimaryWindows 11 Enterprise and Education lifecycle: 24H2 12 October 2027, 23H2 10 November 2026, 22H2 14 October 2025.Microsoft, Microsoft Lifecycleaccessed 2026-10-09
  19. PrimaryESU availability and end dates table: Windows 10 year ends 13 October 2026, 12 October 2027, 10 October 2028; Windows Server 2012 and 2012 R2 year 3 ends 13 October 2026.Microsoft, Microsoft Lifecycle FAQaccessed 2026-10-09
  20. PrimaryWindows 10 ESU programme page, last updated 17 November 2025: business price of 61 US dollars per device for year one, doubling yearly for up to three years; cumulative; free on Windows 365 and Azure.Microsoft, Microsoft Learnaccessed 2026-10-09
  21. PrimaryEnable Windows 10 ESU, last updated 22 April 2026: prerequisites KB5066791 and KB5072653; LTSB and LTSC releases are not covered via the Windows 10 ESU programme.Microsoft, Microsoft Learnaccessed 2026-10-09
  22. PrimaryWindows 10 Consumer ESU page: enrolment possible until the programme ends on 12 October 2027; no cost with settings sync, 1,000 Rewards points or a one-time 30 US dollars.Microsoft, Microsoft Windowsaccessed 2026-10-09
  23. PrimaryPlan for Windows 10 Enterprise LTSC 2021 end of support (5 August 2026): end 12 January 2027; separate ESU on sale from 1 September 2026 at 61 US dollars, 45 with Intune or Autopatch; not for IoT Enterprise LTSC.Microsoft, Windows IT Pro Blogaccessed 2026-10-09
  24. PrimaryExtended Security Updates for SQL Server and Windows Server: Windows Server 2016 extended support ends and its ESU starts on 12 January 2027; ESU enabled by Azure Arc; three more years in Azure.Microsoft, Windows Serveraccessed 2026-10-09
  25. PrimaryPlanning ahead for Windows Server 2016 end of support (25 February 2026): extended support ends 12 January 2027; ESU announced through Azure Arc.Microsoft, Windows Server Blogaccessed 2026-10-09
  26. PrimaryKB5101650, July 2026 update for Windows 11 24H2 and 25H2: full text searched for the rotation (not found); states 24H2 Home and Pro end of updates on 13 October 2026.Microsoft, Microsoft Supportaccessed 2026-10-09
  27. PrimaryKB5099539, July 2026 update for Windows 10 22H2 and LTSC 2021: full text searched (not found); Secure Boot certificate note; LTSC 2021 end date.Microsoft, Microsoft Supportaccessed 2026-10-09
  28. PrimaryKB5099535, July 2026 update for Windows Server 2016: full text searched (not found); end dates for LTSB 2016 and Server 2016.Microsoft, Microsoft Supportaccessed 2026-10-09
  29. PrimaryKB5099538, July 2026 update for Windows Server 2019 and Windows 10 LTSC 2019: full text searched (not found).Microsoft, Microsoft Supportaccessed 2026-10-09
  30. PrimaryKB5099540, July 2026 update for Windows Server 2022: full text searched (not found).Microsoft, Microsoft Supportaccessed 2026-10-09
  31. PrimaryKB5099536, July 2026 update for Windows Server 2025: full text searched (not found).Microsoft, Microsoft Supportaccessed 2026-10-09
  32. PrimaryKB5065426, September 2025 update for Windows 11 24H2: full text searched (not found).Microsoft, Microsoft Supportaccessed 2026-10-09
  33. PrimaryWSUS overview, last updated 5 May 2025: a WSUS server must be able to connect to Microsoft Update; WSUS is deprecated but supported.Microsoft, Microsoft Learnaccessed 2026-10-09
  34. PrimaryPlan your WSUS deployment, last updated 28 July 2026: synchronisation with Microsoft Update; the disconnected export and import option.Microsoft, Microsoft Learnaccessed 2026-10-09
  35. PrimaryConfiguration Manager software updates introduction, last updated 19 July 2026: synchronisation connects to Microsoft Update.Microsoft, Microsoft Learnaccessed 2026-10-09
  36. PrimaryDeploy updates using WSUS, last updated 17 June 2025: policy settings and the warning about Windows Store connectivity.Microsoft, Microsoft Learnaccessed 2026-10-09
  37. PrimaryMicrosoft Update Catalog how-to, last updated 28 September 2026: the Catalog offers updates for all operating systems that Microsoft currently supports.Microsoft, Microsoft Learnaccessed 2026-10-09
  38. PrimaryMicrosoft Defender Antivirus security intelligence and product updates, last updated 14 May 2026: the routes by which intelligence and platform updates are installed.Microsoft, Microsoft Learnaccessed 2026-10-09
  39. PrimaryLifecycle FAQ for Windows: monthly quality updates require a supported version; Windows 11 minimum system requirements.Microsoft, Microsoft Lifecycle FAQaccessed 2026-10-09
  40. PrimaryRequirements for IT Infrastructure v3.3, April 2026, read as the NCSC PDF: definition of licensed and supported software; security update management requirements; 14 days; sub-set definition.NCSC, Cyber Essentialsaccessed 2026-10-09
  41. Primary'Put in place a policy to update by default', version 2.1, published 12 February 2024, reviewed 1 May 2026: 5, 7 and 14 day timescales.NCSCaccessed 2026-10-09
  42. Primary'Obsolete products', version 2.1, published 29 June 2021, reviewed 13 May 2025: risks and mitigations for unsupported software; the antivirus caveat.NCSCaccessed 2026-10-09
  43. Primary'Windows 10 end of support October 2025', last edited 26 June 2025: trusts and ICBs must transition to Windows 11.NHS England Digitalaccessed 2026-10-09
  44. PrimaryData Security Standard 8, unsupported systems, last edited 8 October 2025, relating to the 2023-24 (version 6) standard.NHS England Digitalaccessed 2026-10-09
  45. Reported byNews report of 9 October 2026 that points to the message center item; used as the pointer only and checked line by line against Microsoft's pages.BleepingComputeraccessed 2026-10-09

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.