Event details
Hello Swartz99
Good Morning.. Are you referring to the DBXUpdate that got delivered in July Security update released on Tuesday? This is Security fix to revoke vulnerable third party boot loaders to protect windows from exploitation. This update does not follow high confidence based rollout and applied to all Secure Boot enabled systems immediately.
This default DBXUpdate had always been applied to all Windows systems immediately. So this is not new.
However, DBXUpdate2024.bin and DBXUpdateSVN.bin are not applied automatically and require enteprises to take action to apply this update as this impacts recovery media and network boot scenarios. So we have published detailed guidance to customers on how to safely apply these two DBX Updates. Guidance can be found at How to manage the Windows Boot Manager revocations for Secure Boot changes associated with CVE-2023-24932 | Microsoft Support
Let us know if you have more questions
Actually, i am talking about our chat from the OEM Secure Boot Office hours! I understood that only HC devices and devices with the Intune/GPO policy would get updated however we did not use the Policy and have 49% of our updated devices (49% of 30,000) updated and do not have High Conf listed.
- Prabhakar_MSFTJul 16, 2026
Microsoft
Hi Swartz99
If you organization have enabled Diagnostics data and opted in for Microsoft Managed Secure Boot updates, we do push automatic updates in controlled manner via Controlled Feature Rollout (CFR) mechanism.
More details are here
Microsoft Intune method of Secure Boot for Windows devices with IT-managed updates | Microsoft Support (Refer to section "Confugure Microsoft Update Managed Opt In")
Group Policy Objects (GPO) method of Secure Boot for Windows devices with IT-managed updates | Microsoft Support (Refer to section Certificate Deployment via Controlled Feature Rollout)
- Swartz99Jul 16, 2026Tin Contributor
We did not opt in to this. I just checked again.