Event details
Join us in May for our fourth Ask Microsoft Anything (AMA) about updating Secure Boot certificates on your Windows devices before they start expiring in June of 2026. If you've already bookmarked Sec...
Heather_Poulsen
Updated May 18, 2026
Dan H
May 18, 2026Copper Contributor
I noticed that on some devices, if I am receiving FALSE when running "[System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match 'Windows UEFI CA 2023', that if I download the UEFIv2 powershell module and run Get-UEFISecureBootCerts that then I can see the 2023 certs. I assume that the firmware on most of those devices should switch the certificate, and 90% chance that those devices need no action even though the default query does not show those certificates?