Loading...

How to use Microsoft Intune to update expiring Secure Boot certificates

How to use Microsoft Intune to update expiring Secure Boot certificates

You can now deploy, manage, and monitor Secure Boot certificate updates. This method represents an alternative to setting registry keys and using Group Policy. You can use Intune to deploy on all domain-joined Windows clients, opt out of high-confidence buckets, and opt in to Microsoft managing these updates.    When will this happen:  The following settings are now available in the Intune settings catalog:  Configure Microsoft Update Managed Opt-In  Configure High-Confidence Opt-Out  Enable SecureBoot Certificate Updates    How this will affect your organization:  As the 2011 Secure Boot certificates will start expiring in June 2026, it is essential that organizations start planning for and updating to 2023 certificates. You can now use Microsoft Intune, in addition to registry keys and Group Policy, to deploy, manage, and monitor this update process. The three new settings are disabled by default. Enable them to start taking advantage of the desired capabilities.    What you need to do to prepare:  To manage Secure Boot certificate updates in Intune, enable the new settings by navigating to the Microsoft Intune admin center:  Under Devices > Manage devices, select Configuration.  Select Create and select New Policy.  Select Create a profile in the right-hand pane.  Fill in Platform with Windows 10 and later.  Select the Settings Catalog under the Profile Type. ​​​​​  Begin creating a profile by giving the profile a name. Press Next.​​​​​​  Under Configuration settings, select Add settings. In the Settings picker, search for Secure Boot. There should be three settings in the Secure Boot category.  Select the desired settings for your organization: Configure Microsoft Update Managed Opt-In, Configure High-Confidence Opt-Out, and Enable SecureBoot Certificate Updates (preselected for you).  Finish the profile for the devices that will use these settings.    Additional information:  Read complete guidance at Microsoft Intune method of Secure Boot for Windows devices with IT-managed updates.  Compare this method to Registry key updates for Secure Boot: Windows devices with IT-managed updates.   Compare this method to Group Policy Objects (GPO) method of Secure Boot for Windows devices with IT-managed updates.  See how these methods work together in Secure Boot playbook for certificates expiring in 2026. Message ID: MC1193371

The post How to use Microsoft Intune to update expiring Secure Boot certificates appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with How to use Microsoft Intune to update expiring Secure Boot certificates

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft Excel: Excel canvas

Excel canvas, a new Copilot feature in Microsoft Excel, creates dynamic reports with visualizations and insights that update automatically wit...

2 days ago

Dynamics 365 Contact Center – Use role-based enforcement for recording and transcription downloads

We are announcing the ability to use role-based enforcement for recording and transcription downloads in Dynamics 365 Contact Center. This fea...

2 days ago

Microsoft Outlook: Right-click to customize the classic ribbon

Microsoft Outlook now allows users to customize the classic ribbon by right-clicking on the Home or View tab to select commands and arrange th...

2 days ago

Microsoft Exchange Online: Exchange Web Services (EWS) enforcement update for EWSAllowedAppIDs

Starting October 10, 2026, Exchange Online tenants must configure EWSAllowedAppIDs to allow Exchange Web Services (EWS) access; EWSEnabled=Tru...

2 days ago

Microsoft Entra App Gallery: Self-service onboarding for new applications

Microsoft Entra App Gallery introduces self-service onboarding for new applications, allowing ISVs to validate SSO and provisioning integratio...

2 days ago

Upgraded call history in Teams Calls app

Teams Calls app call history is upgraded to consolidate missed calls and voicemails into single entries and expand history from 100 to 3,000 r...

2 days ago

Power Automate – Enable Process Intelligence Studio in object-centric process mining

We are announcing the availability of Process Intelligence Studio in object-centric process mining in Power Automate Process Mining. This feat...

2 days ago

Dynamics 365 Contact Center – Use after conversation presence status for wrap-up activities

We are announcing the ability to use after conversation presence status for wrap-up activities in Dynamics 365 Contact Center. This feature wi...

2 days ago

Dynamics 365 Finance and Operations cross-app: Migrate finance and operations environments from Lifecycle Services to Power Platform admin center

The self-service environment migration feature moves management of an existing finance and operations apps environment from Microsoft Dynamics...

2 days ago

Microsoft Teams: Start side conversations during meetings

Keep collaboration moving without disrupting the main discussion. Start and continue one-to-one or small-group conversations directly from a m...

2 days ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.