Event details
It's time for our third Ask Microsoft Anything (AMA) about updating Secure Boot certificates on your Windows devices before they expire in June of 2026. If you've already bookmarked Secure Boot playbook, but need more details or have a specific question, join us to get the answers you need to prepare for this milestone. No question is too big or too small. Update scenarios, inventorying your estate, formulating the right deployment plan for your organization -- we're here to help!
How do I participate?
Registration is not required. Simply select Add to calendar then sign in to the Tech Community and select Attend to receive reminders. Post your questions in advance, or any time during the live broadcast
Get started with these helpful resources
281 Comments
- Churros_FragobarCopper Contributor
Let's say I have a 2024 HP ProBook Laptop with 2026 latest BIOS update, AD DS joined, with Windows Update activated with basic GPO settings (drivers and quality included).
No telemetry , no diagnostics sent to MS, no Intune.
If I let things go without interfering, when does this laptop will get certificates update from Windows Update ?
Will the update sent from Windows Update will create the scheduled task and run it every 12h ?
Thanks
- mihiIron Contributor
It will get the certificate with a monthly cumulative update, assuming the device type reaches the high confidence list. Probably it already has.
The scheduled task is already there for a long time (it has been also used to apply DBX updates, for example) and it will run every 12 hours, but just do nothing as long as there is nothing to do.
- mikemagarelliCopper Contributor
Arden_White
Can you please let us know when the Intune Error Code 65000 issue is expected to be fixed? I've seen this still across multiple tenants but there's been no update to guidance around resolution date. If there's been a delay, can you please let us know? The official doc says "this issue will be resolved for all devices by February 27, 2026." Thanks!
- Arden_White
Microsoft
Hi mikemagarelli,
we discovered a new issue where the 65000 error occurs, and it seems to only occur on Windows 11 23H2. A fix for this is coming in the April release. Is that the version of Windows where you are seeing the error or have you been seeing it elsewhere?Arden
- mikemagarelliCopper Contributor
Arden_White We are seeing it in an environment with only Win 11 25H2 & 24H2, we not have 23H2.
- IT_SystemEngineerIron Contributor
Will Microsoft and/or Broadcom provide a solution to automatically update ESXi VMs with missing KEK/PK?
The solution from the article https://knowledge.broadcom.com/external/article/421593/missing-microsoft-corporation-kek-ca-202.html is unfortunately no longer available (upgrading the hardware version and deleting/renaming the .nvram file).
This article https://knowledge.broadcom.com/external/article?articleNumber=423893 states:
"There is no automated resolution available at this time. In coordination with Microsoft, Broadcom Engineering Team is actively working towards implementing an automated solution in a future release to update the Platform Key (PK) on the affected VMs, which will facilitate the certificate rollout as outlined in the Microsoft Guideline."- Prabhakar_MSFT
Microsoft
Hello IT_SystemEngineer , As you mentioned, we are coordinating with Broadcom to bring support in Windows to update KEK on the ESXI VMs. If new VMs are created on latest versions on ESXI, VMs get created with new certificates. For pre-existing VMs, Microsoft is coordinating with Broadcom and will be enabled in the future update.
- Ian_B1066Copper Contributor
What happens if you set the registry settings on a device that is still using Legacy BIOS? Is the update process smart enough to ignore those devices?
- Pearl-Angeles
Community Manager
Thanks for your question! It was answered at around 0:46 during the live AMA.
- antfrCopper Contributor
The device is not updated (since there is no Secure Boot to update) and the scheduled task Secure-Boot-Update will write a 1801 error event.
- gmartin_3434Copper Contributor
My company has around 2000 servers on VMWare that we need to make sure that get updated. We don't want to rely on Microsoft to eventually roll out these updates. I know the February AMA discussed that there might be some tools coming out in March that might help with automating some of this.
I just spent about 2 hours or so with our server team just going through this process to update these machines manually. I mean this is asking a lot to have us touch each server, coordinate with folks on their production servers so that we can shut them off, update the NVRAM file, then reboot them about 2 additional times before we get the 1808 event ID that tells us all is well and good.
I also have a script that supposedly audits our servers and tells us if the certs are active. I just looked at a few machines where it says the certs are active and it gives it a "pass" on the report, but when I go to the registry under secure boot, the status is set to "not started", there are also no event IDs present for TPM/WMI. I mean maybe things updated a while ago, but shouldn't I see "updated" in the registry and not "not started". Can someone verify what we should see in the registry w/ regards to this just for verification purposes?
There is so much confusion over what we need to do. We've spent probably too much time looking at Microsoft documentation on this trying to figure out what to do. My boss doesn't want to wait things out and risk critical servers to have issues with booting at some point. Also, going through 2000 servers with a team of about 5 of us is also a lot to ask to make sure certificates are installed and active. There has to be an easier way to do this.
- Prabhakar_MSFT
Microsoft
Hello gmartin_3434 , We have published detection script that helps with collecting data on certificate deployment status in the system. The link to the script is published at Sample Secure Boot Inventory Data Collection script - Microsoft Support . Copy the script and save it and execute on server where you want to verify status. The script exits with code 0 if certs are updated else it exits with 1 indicating one or more certs are not updated. Script also prints data points which provides data points about overall secureboot status, any errors with applying the updates.
- rparmar50
Microsoft
The status registry will show "updated" only when all required certs + bootmgr is updated. If it is showing "not started" that means that device is not fully updated (either some certs or bootmgr is old) and there is no in-progress update.
- njewettCopper Contributor
Our company does not allow us to use Intune.
Are there any helpful tools or scripts to Inventory?- Pearl-Angeles
Community Manager
In addition to Ashis's response below, the panelists covered your question during the live AMA at 1:59.
- Ashis_Chatterjee
Microsoft
Yes, the Inventory Powershell script in: aka.ms/getsecureboot->IT Managed guide on left Nav has a section on Inventory which can be used as a sample.
Sample Secure Boot Inventory Data Collection script
Copy and paste this sample script and modify as needed for your environment: The Sample Secure Boot Inventory Data Collection script.
- fmartelBrass Contributor
During the February AMA, you en-phased that enterprises should leverage intune and build their own dashboard to monitor secure boot states. The guide require Enterprises licences. As an MSP that manage thousand of devices with Business Premium Plan for multiple customer with Intune and Lighthouse it doesn't make sense.
Is there a plan to monitor those states via a compliance policy instead?
And also.. regarding the secured boot compliance policy that will happen to devices that will still have an old certificate, will they continue to show as compliant with the 2011 certificate?- Pearl-Angeles
Community Manager
Thanks for participating in today's AMA! Your question was answered at around 3:24.
- HeyHey16KSteel Contributor
Hi guys 👋, thank you for hosting another AMA, and for fixing the Intune Secure Boot report 🙏.
It was advised the 65000 error on the Intune report would be fixed by now, but it's still showing on every device we apply the policy to:
When will this issue be resolved please?
Thank you 🙂- Jason_Sandys
Microsoft
Hi HeyHey16K,
The issue is caused by a licensing issue on our end. The service was updated a 2 or three weeks ago to correct the issue and requires devices update their licensing online. This automatically happens every 28 days I believe but can also be forced. See the Known Issues section at Microsoft Intune method of Secure Boot for Windows devices with IT-managed updates - Microsoft Support for information on this. If you have devices still experiencing the issue, please open a support case for deeper investigation as there are no other known, widespread issues at this time but something else may be going on that requires this investigation.
- HeyHey16KSteel Contributor
Hi Jason, thank you for your reply. We already have a case open for this but received no response yet from Microsoft support. We have already run the commands referenced in the Known Issues to force the licence refresh but no joy - local Event Logs are still full of endless 827 "policy rejected by licensing" errors as per my post on yesterday's Secure Boot AMA at
Ask Microsoft Anything: Secure Boot - March 12, 2026 - Windows Tech Community
- antfrCopper Contributor
Could you confirm that the Secure-Boot-Update scheduled task expects Microsoft's Owner GUID on Microsoft's signatures in Secure Boot? We customize the Secure Boot content and it seems that a different GUID causes the task to break the behavior of GetFirmwareEnvironmentVariableA() (used by BitLocker in other things).
Could you also confirm that updating the firmware SVN (4th step of the revocations) only consists in adding SVNs to the DBX? And that for testing purposes, resetting the DBX is enough to cancel the rollback prevention?
- Pearl-Angeles
Community Manager
Your question was covered by panelists during the live AMA at 6:03.
- JamesEppIron Contributor
I must have a thousand questions. I'm making one comment per question as that seems reasonable. Posted in no particular order. As of 2026-02-26 I have 22 questions.
I typed up all these questions not knowing there was a February AMA. I'll have to watch that later to see if any of my questions are answered there.
---
When do the 2023 keys expire? See you again in ten years? Or will all you brainiacs be retired by then? :)
- antfrCopper Contributor
You can download the certificates and check their expiration dates. For Microsoft Corporation KEK 2K CA 2023 it's valid until 2038-03-02, after that date Microsoft won't be able to sign Secure Boot updates to the DB and DBX with this certificate