Event details

Get answers to your questions about adopting Windows 11 and managing Windows devices across your organization. Find out how to proactively implement and monitor Zero Trust practices. Get tips on keeping devices up to date. Learn how to move forward with cloud-native workloads, even if you have on-premises or hybrid needs.

Windows Office Hours is our continuing series of live Q&A for IT professionals here on Tech Community.

How does it work?

We will have a broad group of product experts, servicing experts, and engineers representing Windows, Microsoft Intune, Configuration Manager, Windows 365, Windows Autopilot, security, public sector, FastTrack, and more. They will be standing by here -- in chat -- to provide guidance, discuss strategies and tactics, and, of course, answer any specific questions you may have.

Post your questions in the Comments early and throughout the one-hour event.

Note: This is a chat-based event. There is no video or live meeting component. Questions and answers will appear in the Comments section below.

Heather_Poulsen
Updated Dec 18, 2025

39 Comments

Comments have been turned off for this event
  • HeyHey16K's avatar
    HeyHey16K
    Iron Contributor

    Hi Guys, and happy new year everyone 🎉,

    In the Secure Boot AMA (https://techcommunity.microsoft.com/event/windowsevents/ama-secure-boot/4472784) someone asked about the UEFICA2025Status Reg Key showing an unexpected status of "NotStarted". The Microsoft team advised they would investigate and advise what to do in this situation. We have this in our environment. When will we be told what to do/who can we speak to about this please?

     

    • EricMoe's avatar
      EricMoe
      Icon for Microsoft rankMicrosoft

      I reached out to the Secure Boot Certificate team and they shared the following:

      "Not Started" means that nothing has triggered the certificate updates. Possible triggers are:

      • We determine the device is high confidence - this will be ramping up over the next several months.
      • Customers have opted in to Controlled Feature Rollout and are providing telemetry
      • Customers trigger it themselves through Intune, GPO, registry key change

       

  • A colleague of mine installed an application at the end of the day on Friday and then shut down his computer. When he started it up today, the app wasn't working. Sure enough, the app required a restart, and apparently Fast Startup is still a thing that is enabled by default in Windows 11.

    The setting is not exposed anywhere in the modern Settings app; you have to go into the legacy Control Panel to turn it off. And apart from a couple mentions in the developer section, Microsoft's documentation doesn't acknowledge it at all. Every search result I found about how to turn it off is on a third-party web site. 

    If I'm not mistaken, it isn't even possible to disable Fast Startup with a standard GPO or an Intune configuration policy; you have to use a GPP or a script to set the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Power\HiberbootEnabled registry value to 0.

    And while I concede the feature had some benefit in the days of spinning rust, the speedup on SSD-based machines is so negligable as to be unnoticable.

    So, uh, what gives? 🙂

      • RyanSteele-CoV's avatar
        RyanSteele-CoV
        Iron Contributor

        Thanks EricMoe​. However, wouldn’t this disable the Hibernation feature entirely? Couldn’t that result in someone losing work if their laptop runs out of battery?

        I am interested to understand why Fast Startup still exists and is enabled by default. 

  • Can you clarify what is happening and what will need to be done regarding the Secure boot certificates. For the basic users of Windows does this affect the mainstream users both business and personal? I'm not sure I understand what is affected and links to documentation make things less clear rather than provide much in the way of an answer.