Event details
Ask Microsoft Anything (AMA) about updating Secure Boot certificates on your Windows devices before they expire in June of 2026. We recently published the first version of the Secure Boot playbook, o...
Heather_Poulsen
Updated Dec 09, 2025
David_Swenson
Dec 10, 2025Iron Contributor
I deployed the new Settings Catalog options via Intune as described here. The deployment failed with no conflicts just error devices in Intune.
Build 26200.7296
- Configure High Confidence Opt Out
- State = Disabled, Result = ✅ Succeeded
- Configure Microsoft Update Managed Opt In
- State = Enabled, Result = ❌ Failed
- Enable Secureboot Certificate Updates
- State = Enabled, Result = ❌ Failed
David_Swenson
Dec 10, 2025Iron Contributor
Is this not available yet?
- OvativeFyeDec 10, 2025Copper Contributor
Hey David, chiming in here as I had the same issue. Pretty sure those two settings for Opt in and Enable the certs is broken, see here for workarounds: https://evil365.com/intune/SecureBoot-Cert-Expiration/#option-3---self-managed-rollout-using-intune-policies
I personally used a detection/remediation script to do this.- David_SwensonDec 12, 2025Iron Contributor
Thanks OvativeFye! Would be great if Microsoft could actually respond to this...
- OvativeFyeDec 19, 2025Copper Contributor
No problem David_Swenson - They are really bad at stuff like that :)