Event details
It's time for our second Ask Microsoft Anything (AMA) about updating Secure Boot certificates on your Windows devices before they expire in June of 2026. If you've already bookmarked Secure Boot playbook, but need more details or have a specific question, join us to get the answers you need to prepare for this milestone. No question is too big or too small. Update scenarios, inventorying your estate, formulating the right deployment plan for your organization -- we're here to help!
On the panel: Arden White; Scott Shell; Richard Powell, Kevin Sullivan
This event has concluded. Follow https://aka.ms/securebootplaybook for announcements about future Secure Boot AMAs.
Get started with these helpful resources
327 Comments
- Id_JamieCopper Contributor
can we use older ESXi like version 7 seeing issue where its not applying the KEK and giving error. solution is to renaming the nvram which is not really ideal for large enterprise.
- Id_JamieCopper Contributor
will the patch in march cover old ESXi versions ?
- mihiCopper Contributor
The march patch is applied to the Hyper-V host and will not cover third-party products.
When you have KEK update issues, most likely the platform key is not submitted to Microsoft or it is even a locally generated one (you can check with Powershell in a VM hosted there). In that case, there is nothing Microsoft can do to push the updates, so you'd have to manually enroll the KEK or live with it not being patched.
- knmcelhaneyCopper Contributor
Can you elaborate on the differences between the active db and the default db? This seems to be a common point of confusion.
- Pearl-Angeles
Community Manager
Great question! Panelists covered this question at around 15:44 during the live AMA.
- lord_eddard_starkCopper Contributor
If diagnostic data/telemetry is disabled, what specifically stops working? Does it prevent Microsoft from delivering the secure boot update altogether, or does it mainly impact reporting and insights?
- Pearl-Angeles
Community Manager
Thanks for participating! Your question was addressed by panelists at 17:19 during the live AMA.
- HomagniOccasional Reader
how to monitor the secure certificate deployment? If we do the deployment from Intune. and choose MS patch to obtain it.
- Thomas MøllerCopper Contributor
If you select to push the certificate update through GPO / Intune, with the policy Enable Secure Boot certificate deployment / Enable SecureBoot Certificate Updates
How far does the process go?
As I understand it, there 4 steps
1. DB is updated with certificates
2. Boot manager is updated to use the new certificate
3. Old 2011 certificate is untrusted in DBX
4. SVN is updatedMy concern is step 3, because that causes the machine to no longer trust ones current pxe boot image, and it’s not ideal that happens at some random time.
Does the GPO / Intune setting go through all 4 steps in a matter of x reboots, or are the last steps something that happens in a windows update? - SlapjawCopper Contributor
The Intune policies that configure the secure boot cert updates - are those needed or will Microsoft automatically deploy the certs? Testing those policies in Intune are giving us a 65000 error - any idea why?
- Frank Rijt-vanBrass Contributor
what is the process to update devices with currently safeboot disabled.
- Pearl-Angeles
Community Manager
Panelists covered this topic at 19:09 during the live AMA!
- kumarshai88hotmailcoCopper Contributor
- Can we proceed with the firmware upgrades on the physical Hyper‑V servers with OEM Support before Microsoft releases the fix on March 10th?
- Do we need to wait for the automatic renewal process to begin, or should we initiate the manual renewal using the required registry key? As we have tough Deadline towards June,2026.
- We have several physical Hyper‑V host servers where Secure Boot is currently disabled at the Windows hypervisor level, while the guest virtual machines have Secure Boot enabled. Please confirm whether it is still necessary to update the compatible firmware on these Hyper‑V host servers.
- Is the presence of Event ID 1808 sufficient to validate the successful Secure Boot certificate renewal, or should we additionally verify the certificate expiry details?
- What is the expected downtime, how many reboot requires during the Secure Boot certificate renewal process, and how can we effectively manage this within the controlled patching window? Additionally, if we perform one reboot as part of the current monthly patching cycle and defer the second reboot to the next month’s patch schedule, would this cause any performance issues or operational risks on the affected servers?
- Is there any potential impact on installed applications following the renewal of Secure Boot certificates? Is there any rollback plan in case of any issues?
- When we will have Secure Boot certificate renew status reports in SCCM ?
- Pearl-Angeles
Community Manager
- mihiCopper Contributor
5. No extra reboots stricly required. When your device is eligible, the new certificates can be installed without a reboot. The switch to the new bootloaders will be deferred to after the next reboot to be sure that the new certificates work and are sticking.
6. If you have any "applications" that store key material in TPM and protect with PCR7, they might be unable to retrieve their keys and go through a recovery process. But that would be mostly third-party full disk encryption software, and which enterprise still uses them when they can get Bitlocker for free with Windows 10/11 Pro?
- KenShaCopper Contributor
Is there (or will there be) a tool or series of PowerShell commands that can be used to assess the current status of the computer and 2023 Certificate?
- Pearl-Angeles
Community Manager
Great question! Panelists answered this at 22:46 during the live AMA.
- 123442Occasional Reader
Hello, how to join this call now? There is no link available.
- Heather_Poulsen
Community Manager
There is no call. Simply refresh this page and the live stream will appear at the top. Post your questions here in the Comments for us to review. :)
- Pearl-Angeles
Community Manager
The AMA is streaming live above and will be available on demand after the live event is over. If you're having any issues loading the livestream, you can stream it from LinkedIn: Ask Microsoft Anything: Secure Boot.