Event details
It's time for our second Ask Microsoft Anything (AMA) about updating Secure Boot certificates on your Windows devices before they expire in June of 2026. If you've already bookmarked Secure Boot playbook, but need more details or have a specific question, join us to get the answers you need to prepare for this milestone. No question is too big or too small. Update scenarios, inventorying your estate, formulating the right deployment plan for your organization -- we're here to help!
On the panel: Arden White; Scott Shell; Richard Powell, Kevin Sullivan
How do I participate?
Registration is not required. Simply select Add to calendar then sign in to the Tech Community and select Attend to receive reminders. Post your questions in advance, or any time during the live broadcast.
Get started with these helpful resources
327 Comments
- kev403Copper Contributor
Are the cert updates available through SCCM for endpoints that don't have access to Windows Update?
- MattCasperCopper Contributor
We see the Secure Boot report in Intune for all of our devices even though they are not all enrolled in Autopatch. Is this expected and would this be accurate?
Also, the report shows a certificate status as one value, but when you export the report to a CSV, all the values are different (all changed to 'Not applicable'. Has anyone else reported this? - Philippe_Ngo
Microsoft
customer reported question : experiencing difficulties to apply secureboot certificate updates
From a Microsoft security perspective, what is the less worst risk exposition to secureboot exploit between all these below configurations
1. A system with Secure Boot enabled :
a. Expired certificates in DB, and KEK (2011) and boot manager signed by 2011 certificate (nothing is uptodate)
b. 2023 certificate are in DB, boot manager signed by 2023 certificate but only KEK 2011 certificate version (Update procedure fails to update kek) (partial update)
2. A system running UEFI but Secure Boot disabled
3. A system running in Legacy BIOS (non-UEFI) modeIs a system in scenario (1a and 1b) considered more exposed, less exposed, or equivalent in risk compared to scenarios (2) and (3)?
- mihiCopper Contributor
1B is best, 1A slightly worse (bugfixes in Boot Manager not present), 2 and 3 are equally insecure.
You could also reach 1C by revoking 2011 DB certificate and applying SVN update to the 1B configuration, which would give another boost against BlackLotus & co.
- NicolasKuntz
Microsoft
It seems that new certificate's expiration is on May 15th 2026 :
Issuer : CN=Windows UEFI CA 2023, O=Microsoft Corporation, C=US
NotAfter : 15/05/2026 21:23:59
Could you explain the process that will be ongoing after been updated to CA 2023 ?
- stevensgroiCopper Contributor
So how do you install the CFR on your managed servers that connect to WSUS?
- DMannekeOccasional Reader
Can you please further document actions to undertake when a system doesn't boot after enabling secure boot from the BIOS, like precising all the mandatory settings to implement for it to work and possibly bringing the host back to a secure baseline which allows it to boot with the setting enabled, this aspect isn't documented properly and or I'm missing where to look at
KR- Pearl-Angeles
Community Manager
Thanks for your participation in this AMA! Panelists covered your question around 44:22.
- Shyama_SasidharanOccasional Reader
Should I enable the Secure Boot settings in Intune even if some devices are reporting error Error Code 65000, and is it safe to use both Intune Secure Boot policies and manual remediation together, or could doing both cause issues
- Got_the_manOccasional Reader
For the third-party antivirus it will have any affect if the certificate doesn't update ?
- Pearl-Angeles
Community Manager
Thanks for your question! This was covered at around 43:39 during the live AMA.
- Daniele De Angelis
Microsoft
I'm doing test in my lab, and i have successfully completed the update of the Secure boot via RegKey, but i have noticed that the boot loader is updated with the new certificate that will expire to May 2026, this will be update automatically during the normal patching process???
- Pearl-Angeles
Community Manager
Thanks for your participation! Your question was addressed at 46:08 during the live AMA.
- KenShaCopper Contributor
If a computer has been properly updated, how often will Event ID 1808 appear in the event log?