Event details
It's time for our second Ask Microsoft Anything (AMA) about updating Secure Boot certificates on your Windows devices before they expire in June of 2026. If you've already bookmarked Secure Boot playbook, but need more details or have a specific question, join us to get the answers you need to prepare for this milestone. No question is too big or too small. Update scenarios, inventorying your estate, formulating the right deployment plan for your organization -- we're here to help!
On the panel: Arden White; Scott Shell; Richard Powell, Kevin Sullivan
How do I participate?
Registration is not required. Simply select Add to calendar then sign in to the Tech Community and select Attend to receive reminders. Post your questions in advance, or any time during the live broadcast.
Get started with these helpful resources
327 Comments
- laytonm21Copper Contributor
You might have already covered this, but is there a way to update the wks if the deadline to update the certificate on host is missed?
- knmcelhaneyCopper Contributor
If a device's firmware is not updated before the expiration date, will we still be able to update the BIOS to get the new certificate?
- FSS421077Occasional Reader
Will the registry ever auto update to 0x5944? It currently is not an automatic update.
- Derek89Occasional Reader
Do i Understand this correctly. Event ID 1801 means that my device has the new Certs, but only at the OS level. So that technically means my device has and is using the new Certs?
BUT if i want the EXTRA peace of mind and avoidance of accidentally losing those certs due to someone changing something in BIOS, i need to fully bake them into BIOS via a Firmware update. And that would give me an 1808 ID?
So both IDs mean i have, and am using, the new Certs. But one is more robust than the other? - Dharani21Occasional Reader
Is it mandatory to get the BIOS updated to latest version on HPs we maintain? Will the policy still act on those devices though it has n-1 or lower version than the latest?
https://support.hp.com/us-en/document/ish_13070353-13070429-16 - TobiABrass Contributor
Is there an option to update to the new the Secureboot certificate before imaging a device manually (in WinPE), if its not yet there? Or do we have to image the device and wait for LCU to do the update?
- kumarshai88hotmailcoCopper Contributor
Why system event ID 1808 getting generated every time while rebooting the servers if the CA 2023 applied to firmware already ? is this excepted behavior ?
- Mabel_Gomes
Microsoft
Event 1808 is an informational event that indicates that the device has the required new Secure Boot certificates applied to the device’s firmware. You should expect to see this event after a successful certificate update. No other steps required for that device. We will update this article to make event logs clearer: Secure Boot Certificate updates: Guidance for IT professionals and organizations - Microsoft Support> Monitoring Event Logs. Thank you for your question.
- Joe_FriedelBrass Contributor
If I only set Configure Microsoft Update Managed Opt In to Enabled, is that enough for my managed devices to install the cert updates when Microsoft deems it safe to do or do I also need to set Enable Secure Boot Certificate Updates to Enabled simultaneously? It seems like the Enable Secure Boot Certificate Updates setting will start the process immediately.
- Joerg1Occasional Reader
can you give instruction on the boot medium, that boot with 2011 keys and can upgrade the new boot manager in the case that windows does not start anymore, because the new keys in db are reset to 2011?
- mihiCopper Contributor
It needs to have
"C:\Windows\Boot\EFI\SecureBootRecovery.efi"
copied as
\EFI\Boot\Bootx64.efi
on it. Apart from that, it needs to be FAT formatted like every UEFI boot medium.
See https://support.microsoft.com/en-au/topic/how-to-manage-the-windows-boot-manager-revocations-for-secure-boot-changes-associated-with-cve-2023-24932-41a975df-beb2-40c1-99a3-b3ff139f832d for more detailed instructions.
- mikemagarelliCopper Contributor
Follow up question: I thought I heard someone say that Server OS shouldn't be expected to receive updates via CFR. Did I hear that correctly? If yes, can you elaborate?
- Pearl-Angeles
Community Manager
Thanks for participating in this AMA! Panelists answered this question at 27:22.