Secure Boot certificate expiration: What Windows IT admins need to know now
Secure Boot protects Windows systems by validating firmware and boot components using trusted certificates. Microsoft-issued certificates used in Secure Boot are expiring in 2026. In the coming months, Microsoft will be rolling out updated Secure Boot certificates needed to ensure a secure startup environment of Windows. IT-managed environments must take action to ensure their systems remain secure and serviceable. This post outlines what enterprise IT admins need to know and do. Secure Boot protects Windows systems by validating firmware and boot components using trusted certificates. Microsoft-issued certificates used in Secure Boot are expiring in 2026. In the coming months, Microsoft will be rolling out updated Secure Boot certificates needed to ensure a secure startup environment of Windows. IT-managed environments must take action to ensure their systems remain secure and serviceable. This post outlines what enterprise IT admins need to know and do. When will this happen: Microsoft UEFI CA 2011 and Microsoft KEK CA 2011 expire in June 2026. Microsoft Windows Production PCA 2011 expires in October 2026. Microsoft is rolling out updated certificates now via Windows Update to home users, businesses, and schools with devices that have updates managed by Microsoft. How this will affect your organization: Without updated certificates, Secure Boot-enabled systems may: Fail to receive future security updates. Be unable to validate new boot components. Face increased risk from boot-level vulnerabilities. What you need to do to prepare: Check with your OEM for the latest available firmware updates. These updates ensure your device’s Secure Boot configuration can accept new certificates. Review the KB articles and blog post listed below. Get familiar with the update paths available: Opt in to Microsoft-managed updates by enabling diagnostic data and setting the registry key MicrosoftUpdateManagedOptIn. Follow manual update steps for DB and KEK using published Microsoft guidance. Plan for future partially automated solutions that Microsoft will release to support self-service deployments. Additional information: Read Act now: Secure Boot certificates expire in June 2026. Bookmark the Secure Boot certificate rollout landing page. Consult guidance for Windows devices for businesses and organizations with IT-managed updates. For unmanaged scenarios, see Windows devices for home users, businesses, and schools with Microsoft-managed updates. Follow guidance in Windows 11 and Secure Boot to check if it’s enabled. Check OEM guidance in Windows Secure […]
The post Secure Boot certificate expiration: What Windows IT admins need to know now appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Secure Boot certificate expiration: What Windows IT admins need to know now
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Microsoft Copilot Studio: Introducing an App- and Intent-First Agent Creation Experience
Copilot Studio is evolving to an app-first agent creation experience. Makers start with the application their agent will work with and configu...
Microsoft Teams: Admins can control profanity filtering in meeting transcripts
Teams administrators will be able to use a meeting policy to control whether profane words are masked in live transcription and saved meeting ...
Microsoft Copilot Studio: Deliver rich interactive app experiences in Copilot Studio agents
Copilot Studio agents can now render rich, interactive UI inline using MCP Apps, an extension of the Model Context Protocol. When an agent cal...
Microsoft 365: Entra ID Backup & Recovery
Enable extended 30-day backup and recovery for a tenant’s Entra objects via the Microsoft 365 Backup native app or M365 Backup Storage p...
Microsoft Viva: Viva Insights and Copilot Analytics in GCC-High
Microsoft Viva Insights and Copilot Analytics are coming to Microsoft 365 Government Community Cloud High (GCC High), providing eligible organ...
Microsoft Copilot Studio: Streamlining experiences from Copilot Studio Agents in Microsoft 365 Copilot
This update is meant to bridge the experience of using Copilot Studio agents in M365 Copilot with the Copilot Chat experience. With these upda...
Microsoft Copilot Studio: Enabling makers to require human approval for tool calls
Copilot Studio now let’s makers require human approval before an agent runs specific tools. With a per-tool, per-agent toggle, any gated tool ...
Updates available for Microsoft 365 Apps for Current Channel
We’ve released updates to the following update channel for Microsoft 365 Apps: Current Channel When this will happen: We’ll be gra...
General Availability of Power BI developer mode
Power BI developer mode and the PBIP file format are generally available, making PBIR the default report format in Power BI Desktop and servic...
Microsoft Teams: Users can temporarily pause all notifications
Microsoft Teams will let users temporarily pause notifications for a chosen time to reduce interruptions and improve focus. This feature, avai...