Event details
Hi kMor,
Depending on exactly what you've configured, it may take some time. The default update process is only initiated on devices that have been added to the high confidence compatibility list/DB to ensure that we maximize success. In an enterprise environment, we do strongly encourage orgs to enable the update explicitly on representative device in their environment though to ensure that compatibility and success information is fed back to us so that we can update the high confidence db.
Thank you for the response!
Would you suggest we do anything other than apply the profile? I'm hearing we just need to be patient with the process.
- Jason_SandysMay 21, 2026
Microsoft
If left alone, correct, patience with the process. As noted though, in an enterprise environment, you should be setting the Enable Secureboot Certificate Updates setting to force the update on representative devices to ensure these device types are accounted for and tested even before making it to the high confidence database. See Microsoft Intune method of Secure Boot for Windows devices with IT-managed updates - Microsoft Support for a lot more details on this setting and the others.