Event details
It's time for our second Ask Microsoft Anything (AMA) about updating Secure Boot certificates on your Windows devices before they expire in June of 2026. If you've already bookmarked Secure Boot play...
Heather_Poulsen
Updated Feb 12, 2026
kumarshai88hotmailco
Feb 05, 2026Copper Contributor
- Can we proceed with the firmware upgrades on the physical Hyper‑V servers with OEM Support before Microsoft releases the fix on March 10th?
- Do we need to wait for the automatic renewal process to begin, or should we initiate the manual renewal using the required registry key? As we have tough Deadline towards June,2026.
- We have several physical Hyper‑V host servers where Secure Boot is currently disabled at the Windows hypervisor level, while the guest virtual machines have Secure Boot enabled. Please confirm whether it is still necessary to update the compatible firmware on these Hyper‑V host servers.
- Is the presence of Event ID 1808 sufficient to validate the successful Secure Boot certificate renewal, or should we additionally verify the certificate expiry details?
- What is the expected downtime, how many reboot requires during the Secure Boot certificate renewal process, and how can we effectively manage this within the controlled patching window? Additionally, if we perform one reboot as part of the current monthly patching cycle and defer the second reboot to the next month’s patch schedule, would this cause any performance issues or operational risks on the affected servers?
- Is there any potential impact on installed applications following the renewal of Secure Boot certificates? Is there any rollback plan in case of any issues?
- When we will have Secure Boot certificate renew status reports in SCCM ?
Pearl-Angeles
Community Manager
Feb 06, 2026Thanks for your questions! Panelists covered question #3 at around 21:32 and question #4 at 41:39 during the live AMA.