Event details
It's time for our second Ask Microsoft Anything (AMA) about updating Secure Boot certificates on your Windows devices before they expire in June of 2026. If you've already bookmarked Secure Boot play...
Heather_Poulsen
Updated Feb 19, 2026
Arden_White
Microsoft
Mar 02, 2026Some things to look at:
- Check the registry keys UEFICA2023Status, UEFICA2023Error, and UEFICA2023ErrorEvent
- Look for events in the System log with event source TPM-WMI.
- Ensure that the Secure-Boot-Update exists and that it has active triggers (on startup and ever 12 hours)
sysadmin315
Mar 02, 2026Copper Contributor
Registry keys
System log
Task scheduler
- Arden_WhiteMar 02, 2026
Microsoft
Hi,
it appears that the firmware returned an error (ERROR_WRITE_PROTECT) when a certificate update was attempted. Would you be willing to share the text of the event 1795? This event will include the error code, what operation was attempted, and some details about the device.
Arden- sysadmin315Mar 02, 2026Copper Contributor
1801
1795
- mihiMar 02, 2026Brass Contributor
Updating KEK on Hyper-V VMs is known to not working right now, to get it working you will have to install March cumulative update on the Hyper-V host (once available).