Event details
Follow up on earlier SCCM boot.wim questions:
Can we continue using the boot.wim with 2011 cert past June 2026?
Will that work successfully with devices that only have 2011 cert?
Will devices that have 2023 cert already require a boot.wim that has 2023 cert once June 2026 has passed?
(We have thousands of devices in storage, and need to know sooner, rather than later, if they need to get updated pre-June 2026)
- Jason_SandysMar 12, 2026
Microsoft
Nothing changes instantly in June or when the certs expire. The boot critical components signed by these certs are still trusted and valid and devices will continue to boot fine as the certs themselves are still "trusted".
Answers
- Yes, the old certs are still trusted as noted.
- Yes, same reason.
- No, device will trust both old and new certs.
Note that a better path though is to begin your Intune and Autopilot journey.
- Pearl-AngelesMar 12, 2026
Community Manager
Your 3rd question was addressed at 49:00 during the live AMA.