Event details
It's time for our fourth Ask Microsoft Anything (AMA) about updating Secure Boot certificates on your Windows devices before they expire in June of 2026. If you've already bookmarked Secure Boot play...
Pearl-Angeles
Updated Apr 15, 2026
AdamDunleavy
Apr 23, 2026Copper Contributor
Will pushing out BIOS updates at the same time as Secure Boot certificate updates from intune increase the risks of the device becoming bitlockered?
- mihiApr 23, 2026Brass Contributor
There are safeguards in place that prevent Secure Boot certificate updates if there is a firmware update pending. Also, unless you bind to PCR 0 or 2 in your TPM configuration, BIOS updates will not affect Bitlocker at all.
Still, there might be a minimal risk that these processes interfere, especially since firmware update process heavily depends on how the manufacturer implemented it.