Event details
We are doing IT Managed updates.
Q. If the dbDefault was successfully updated by the OEM BIOS firmware update, is it safe to assume that the active db can be updated safely via the "AvailableUpdates" registry key (0x5944)?
- mihiApr 28, 2026Brass Contributor
I'd say it is a very strong reason to believe so. But on the other hand, alone the fact that the vendor issued a firmware update in the timeframe the certificate updates have been running is a very strong argument that the update process is safe (does not lead to hangs or incompatibility issues).
OTOH, it is not a guarantee that it is successful (does not fail with a defined error code). There are cases (lost/replaced platform key) that cannot be remediated just by installing a firmware update, but only by following additional steps (e.g. suspending Bitlocker and resetting setup defaults). But I would expect the firmware vendor to clearly communicate those if they apply.