Event details

It's time for our fourth Ask Microsoft Anything (AMA) about updating Secure Boot certificates on your Windows devices before they expire in June of 2026. If you've already bookmarked Secure Boot playbook, but need more details or have a specific question, join us to get the answers you need to prepare for this milestone. No question is too big or too small. Update scenarios, inventorying your estate, formulating the right deployment plan for your organization -- we're here to help!

How do I participate?

Registration is not required. Simply select Add to calendar then sign in to the Tech Community and select Attend to receive reminders. Post your questions in advance, or any time during the live broadcast

Get started with these helpful resources

Pearl-Angeles
Updated Apr 15, 2026

198 Comments

  • Are there any Updates regarding my Question: "Will Microsoft and/or Broadcom provide a solution to automatically update ESXi VMs with missing KEK/PK?"

    The last Answer from PrabhakarMSFT was: "...we are coordinating with Broadcom to bring support in Windows to update KEK on the ESXI VMs.   If new VMs are created on latest versions on ESXI, VMs get created with new certificates. For pre-existing VMs, Microsoft is coordinating with Broadcom and will be enabled in the future update."

  • seandowd's avatar
    seandowd
    Copper Contributor

    Intune's "Secure Boot Status" report has six columns. Five columns are sortable. The one column that can NOT be sorted is "Certificate Status". That seems like the most important column. I understand that we can export the data and sort within Excel, but it would be nice if we could sort by "Certificate Status" directly in Intune. 

    • Paul_Woodward's avatar
      Paul_Woodward
      Iron Contributor

      yes, at min sortable, preference would be also option to filter.

  • VinceNoir's avatar
    VinceNoir
    Copper Contributor

    I have a large number of devices in storage, which are unlikely to be powered on before the end of June 2026. Once the devices are back on line after June 2026, will we still be able to update the certs after the appropriate bios and windows updates are installed?

    • mihi's avatar
      mihi
      Brass Contributor

      Yes, the secure boot certificates will be updated when you (or the new device owner) install the next cumulative updates, or re-install a Windows version that has the updates included.

       

      See The Secure Boot FAQ: https://support.microsoft.com/en-us/topic/frequently-asked-questions-about-the-secure-boot-update-process-b34bf675-b03a-4d34-b689-98ec117c7818

      Section 1 Q1: What happens if my device doesn’t get the new Secure Boot certificates before the old ones expire?

      Section 2 Q8: If the Secure Boot certificates on my device are already expired, can I still receive updated certificates?

       

  • dwqdda's avatar
    dwqdda
    Copper Contributor

    We have several devices without 2023 cert in default db where we expect to reset secure boot and reinstall past June 2026. I understand it's possible to install 2023 cert post June 2026, but will Windows Update automatically install 2023 cert past June 2026 since you won't get security updates for boot manager and secure boot via Windows Update past that date?

    • mihi's avatar
      mihi
      Brass Contributor

      When performing the reinstall, make sure that you use an ISO that still uses the old boot manager (or it won't boot). As of now, all publicly available ISOs do that, so it depends on how many months/years after June 2026 it will be. As a result, the installed Windows version will also use the old boot manager, but will boot and get LCU without issues.

      Once you have done so, the machine will not be different from a machine that has been installed in the past and has not been booted for months/years. So, the next available LCU update will run the Secure Boot scheduled task again and apply the certs. (Just like it will apply any pending Secure Boot DBX updates even if the updates came out mid-2025 and you did the reinstall in 2026)