Event details
It's time for our third Ask Microsoft Anything (AMA) about updating Secure Boot certificates on your Windows devices before they expire in June of 2026. If you've already bookmarked Secure Boot playb...
Pearl-Angeles
Updated Mar 11, 2026
Jay Murphy
Mar 12, 2026Occasional Reader
If my device doesn't have UEFICA2023 cert and can no longer PXE, what would be the process to update that machine if the device is not bootable.
- mihiMar 13, 2026Brass Contributor
Have your PXE server push securebootrecovery.efi as the boot binary for just that device (e.g. by mac address).
Otherwise I am unsure what you mean by "device is not bootable". Anything signed with the old 2011 cert will still boot fine. So put securebootrecovery.efi on a bootable device and boot from it. Done.