Event details
It's time for our second Ask Microsoft Anything (AMA) about updating Secure Boot certificates on your Windows devices before they expire in June of 2026. If you've already bookmarked Secure Boot play...
Heather_Poulsen
Updated Feb 12, 2026
Matthew_Stevenson
Feb 03, 2026Brass Contributor
Hello!
We are currently testing the cert update in our VMWare ESXi 8 environment for server OS. Testing 2016, 2019, 2022, and 2025. All VMs are fully patched and have latest VMWare tools installed.
After setting the GPO "Enable Secure Boot Certificate Deployment":
2016 updates all certs, EventID 1808 is written.
2019 and 2022, most certs are updated however the KEK is not, giving the Event error 1796.
2025 does not update any certs, nor does it start the update process at all.
- Anyone else having issues with VMWare guests and KEK update for 2019 and 2022?
- Any clue as to why 2025 is not even starting the update process?
Thanks!
Arden_White
Microsoft
Feb 04, 2026I found these two articles on the Broadcom site that might be helpful.
https://knowledge.broadcom.com/external/article/423893/secure-boot-certificate-expirations-and.html
https://knowledge.broadcom.com/external/article/423919
Arden - Microsoft