Loading...

Best practices for deploying Secure Boot certificate updates

Best practices for deploying Secure Boot certificate updates

Many individuals and organizations have already successfully updated certificates for client devices, servers, and virtual machines, with others close behind. However close you are, finishing Secure Boot certificate deployment remains important. If you’re still on this path, stay the course. Read about the proven best practices and the resources already available to you, as well as a few more opportunities to ask questions. Rollout schedule: June 24, 2026 – Secure Boot certificates start expiring, beginning with Microsoft Corporation KEK CA 2011 certificate. July 1 – Windows Server Secure Boot AMA July 8 – Secure Boot Office Hours for virtualized environments July 15 – OEM Secure Boot Office Hours Impact on your organization: If you are still in the process of updating Secure Boot certificates or validating updates in your organization, there are resources that can help. Focus on progress over perfection. Each step forward helps strengthen your environment’s platform root of trust. Devices with older certificates will continue to function and receive updates, giving you time to complete deployment. Completing this transition helps ensure that your devices stay current with evolving Secure Boot protections. Action required/recommendations: What we’ve seen consistently is that success comes from staying the course:  Keep your devices up to date with the latest Windows updates. Check that the latest firmware version is installed. You can visit your OEM’s support page or use their official support channels.  Continue with your phased rollout. Gradual deployment of certificates, boot managers, and updated OEM firmware, along with validation, remains the most reliable approach.  Use the tools available to you. Whether built into Windows, such as the Windows Security app, or designed for IT-managed environments, these tools help you monitor progress and make informed decisions. Read Best practices for deploying Secure Boot certificate updates for a list of resources to support your next steps. Compliance considerations: No compliance considerations are identified. Review as appropriate for your organization. Message ID: MC1403212

The post Best practices for deploying Secure Boot certificate updates appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Best practices for deploying Secure Boot certificate updates

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft Excel: Excel canvas

Excel canvas, a new Copilot feature in Microsoft Excel, creates dynamic reports with visualizations and insights that update automatically wit...

2 days ago

Dynamics 365 Contact Center – Use role-based enforcement for recording and transcription downloads

We are announcing the ability to use role-based enforcement for recording and transcription downloads in Dynamics 365 Contact Center. This fea...

2 days ago

Microsoft Outlook: Right-click to customize the classic ribbon

Microsoft Outlook now allows users to customize the classic ribbon by right-clicking on the Home or View tab to select commands and arrange th...

2 days ago

Microsoft Exchange Online: Exchange Web Services (EWS) enforcement update for EWSAllowedAppIDs

Starting October 10, 2026, Exchange Online tenants must configure EWSAllowedAppIDs to allow Exchange Web Services (EWS) access; EWSEnabled=Tru...

2 days ago

Microsoft Entra App Gallery: Self-service onboarding for new applications

Microsoft Entra App Gallery introduces self-service onboarding for new applications, allowing ISVs to validate SSO and provisioning integratio...

2 days ago

Upgraded call history in Teams Calls app

Teams Calls app call history is upgraded to consolidate missed calls and voicemails into single entries and expand history from 100 to 3,000 r...

2 days ago

Power Automate – Enable Process Intelligence Studio in object-centric process mining

We are announcing the availability of Process Intelligence Studio in object-centric process mining in Power Automate Process Mining. This feat...

2 days ago

Dynamics 365 Contact Center – Use after conversation presence status for wrap-up activities

We are announcing the ability to use after conversation presence status for wrap-up activities in Dynamics 365 Contact Center. This feature wi...

2 days ago

Dynamics 365 Finance and Operations cross-app: Migrate finance and operations environments from Lifecycle Services to Power Platform admin center

The self-service environment migration feature moves management of an existing finance and operations apps environment from Microsoft Dynamics...

2 days ago

Microsoft Teams: Start side conversations during meetings

Keep collaboration moving without disrupting the main discussion. Start and continue one-to-one or small-group conversations directly from a m...

2 days ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.