Event details
It's time for our second Ask Microsoft Anything (AMA) about updating Secure Boot certificates on your Windows devices before they expire in June of 2026. If you've already bookmarked Secure Boot play...
Heather_Poulsen
Updated Feb 12, 2026
Id_Jamie
Feb 05, 2026Copper Contributor
can we use older ESXi like version 7 seeing issue where its not applying the KEK and giving error. solution is to renaming the nvram which is not really ideal for large enterprise.
- Id_JamieFeb 05, 2026Copper Contributor
will the patch in march cover old ESXi versions ?
- mihiFeb 05, 2026Copper Contributor
The march patch is applied to the Hyper-V host and will not cover third-party products.
When you have KEK update issues, most likely the platform key is not submitted to Microsoft or it is even a locally generated one (you can check with Powershell in a VM hosted there). In that case, there is nothing Microsoft can do to push the updates, so you'd have to manually enroll the KEK or live with it not being patched.