Event details
It's time for our third Ask Microsoft Anything (AMA) about updating Secure Boot certificates on your Windows devices before they expire in June of 2026. If you've already bookmarked Secure Boot playbook, but need more details or have a specific question, join us to get the answers you need to prepare for this milestone. No question is too big or too small. Update scenarios, inventorying your estate, formulating the right deployment plan for your organization -- we're here to help!
How do I participate?
Registration is not required. Simply select Add to calendar then sign in to the Tech Community and select Attend to receive reminders. Post your questions in advance, or any time during the live broadcast
Get started with these helpful resources
219 Comments
- JimAOccasional Reader
Does Server 2025 automagically comply?
Both fresh install & Server 2022 update?
- Pearl-Angeles
Community Manager
Your questions were also answered at 47:15 during the live AMA. For more info, go to aka.ms/SecureBootForServer
- Ashis_Chatterjee
Microsoft
No, Server 2025 does not automagically comply. They will need to be updated using the methods outlined Secure Boot guidance
- COLDESTJOHNCopper Contributor
Will Microsoft apply the new certs in newer GA releases? Cause when download a fresh image form the VLK repo this is still shipped with PCA 2011
- CTKMNCopper Contributor
VMware has not yet released an updated virtual hardware/BIOS package for this issue (only manual steps). Do we need to worry about the virtual hardware/Bios update offered by VMware if we’re already seeing the “Updated”/ WindowsUEFICA2023Capable =2 results we’re getting now within the registry? We also get the result of “True” using the verification command - ([System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).Bytes)) -match "Windows UEFI CA 2023". From a compliance perspective, does this mean we’re covered? For that matter, do we even need to rename the NVRAM File?
We’ve also noticed that on some of our Server 2025 systems, even when the certificates seemingly updates itself successfully, the Secure Boot scheduled task fails with a “file not found” error. Is there a way to correct this? We are not sure how to address this. It appears to be a built‑in, “solid‑state” task.
- Piyush3o5Occasional Reader
Hello, I have deployed the secure boot remediation through Intune and I see event ID 1801 that says the certificates are available but not applied and the BucketConfidenceLevel shows Need more data. Do i need to take any action on that ?
- Pearl-Angeles
Community Manager
Thanks for participating in this AMA! Your question was answered at 29:37.
- Bryant_KintnerCopper Contributor
Can Secure Boot certificates be updated when Secure Boot is disabled? Microsoft’s AvailableUpdates process errors out unless Secure Boot is enabled. If a device won’t boot Windows with Secure Boot on, how can we bring it into compliance?
- Pearl-Angeles
Community Manager
Your question was answered during the live AMA at 42:14. Follow aka.ms/GetSecureBoot for the latest updates and new tools/guides.
- Ashis_Chatterjee
Microsoft
If Secure Boot is disabled, the device is compliant. Secure Boot certificate update compliance is applicable only to devices that have Secure Boot enabled
- e-idyCopper Contributor
Looks like there have been reports online of users receiving driver updates that are requiring bitlocker keys to be entered after reboot. Is this expected behavior? If the certs were already installed via policy still get prompted from driver updates?
Is there a way to know what driver updates in Intune actually have the drivers that potentially can cause bitlocker keys to be entered? Naming conventions in Intune for drivers are a bit difficult to decipher.
- Pearl-Angeles
Community Manager
Thanks for your question! This topic was covered at 33:02 during the live AMA.
- Bryant_KintnerCopper Contributor
What happens in June when the current Secure Boot certificates expire? Will devices with Secure Boot still boot if their EFI partition is signed with the 2011 certificate? If so, how long past June will they continue to boot, and will they eventually stop?
- Ashis_Chatterjee
Microsoft
Yes, it will continue to boot. There is no specific date when it will stop booting.
- SCCM_TerrorCopper Contributor
I noticed that some of my clients (around 5% so far) updated only two of three Secure Boot Certificates.
Intune Remediation script shows the following output: Microsoft UEFI CA 2023 = False, Microsoft Corporation UEFI CA 2011 = True.Two other certificates are showing "2023" data string.
Is it expected that not all the certificates are updated at the same time?
- Pearl-Angeles
Community Manager
For reference, this question was answered at 35:24 during the live AMA.
- SCCM_TerrorCopper Contributor
Thanks for the answer. The script returns the following output for the other two certificates:
Windows UEFI CA 2023 = TrueMicrosoft Corporation KEK 2K CA 2023 = True
- DRWaldenOccasional Reader
Is there any update on KBKB5077181 being updated to address the boot loop issue?
- SebastianKITOccasional Reader
My current status regarding dbx is that the old certificates must be moved there so that the SecureBoot certificate update can be completed successfully (managed IT environment with Windows 11 Enterprise licenses). Will there also be instructions or a PowerShell script that performs or explains this process?
Thank you for your time.- Jason_Sandys
Microsoft
Hi SebastianKIT,
DBX is for explicit revocations in case of compromise or similar. That is not the case here and is part of this process. Adding the old certs to DBX would cause all current boot critical components to become untrusted making the system unbootable. We would need to update every boot critical component to re-sign it on all in market OS versions which would be an even greater logistic nightmare and would add not true value. Ultimately, both certs of certs will remain trusted and there isn't an explicit reason to ever change this (unless a cert is compromised as noted).
- Bryant_KintnerCopper Contributor
Will Microsoft release an OS upgrade that requires the EFI partition to be signed with the 2023 certificate? If so, is this expected in Windows 11 26H2, and has Microsoft announced anything about this? We want to avoid upgrading devices if it will re-sign the EFI partition before the new certificates are installed.
- Pearl-Angeles
Community Manager
Your question was answered at 38:23 during the live AMA.