How to use Microsoft Intune to update expiring Secure Boot certificates
You can now deploy, manage, and monitor Secure Boot certificate updates. This method represents an alternative to setting registry keys and using Group Policy. You can use Intune to deploy on all domain-joined Windows clients, opt out of high-confidence buckets, and opt in to Microsoft managing these updates. When will this happen: The following settings are now available in the Intune settings catalog: Configure Microsoft Update Managed Opt-In Configure High-Confidence Opt-Out Enable SecureBoot Certificate Updates How this will affect your organization: As the 2011 Secure Boot certificates will start expiring in June 2026, it is essential that organizations start planning for and updating to 2023 certificates. You can now use Microsoft Intune, in addition to registry keys and Group Policy, to deploy, manage, and monitor this update process. The three new settings are disabled by default. Enable them to start taking advantage of the desired capabilities. What you need to do to prepare: To manage Secure Boot certificate updates in Intune, enable the new settings by navigating to the Microsoft Intune admin center: Under Devices > Manage devices, select Configuration. Select Create and select New Policy. Select Create a profile in the right-hand pane. Fill in Platform with Windows 10 and later. Select the Settings Catalog under the Profile Type. ​​​​​ Begin creating a profile by giving the profile a name. Press Next.​​​​​​ Under Configuration settings, select Add settings. In the Settings picker, search for Secure Boot. There should be three settings in the Secure Boot category. Select the desired settings for your organization: Configure Microsoft Update Managed Opt-In, Configure High-Confidence Opt-Out, and Enable SecureBoot Certificate Updates (preselected for you). Finish the profile for the devices that will use these settings. Additional information: Read complete guidance at Microsoft Intune method of Secure Boot for Windows devices with IT-managed updates. Compare this method to Registry key updates for Secure Boot: Windows devices with IT-managed updates. Compare this method to Group Policy Objects (GPO) method of Secure Boot for Windows devices with IT-managed updates. See how these methods work together in Secure Boot playbook for certificates expiring in 2026. Message ID: MC1193371
The post How to use Microsoft Intune to update expiring Secure Boot certificates appeared first on M365 Admin.
Published on:
Learn moreWe can help you with How to use Microsoft Intune to update expiring Secure Boot certificates
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
External messaging limits for onmicrosoft.com-only organizations in Microsoft Teams
Microsoft Teams will impose outbound external messaging limits starting mid-September 2026 for organizations using only the default onmicrosof...
Microsoft Teams: Enable agents for existing applications in your organization
For third-party applications already being used in your organization, admins can now discover and enable the corresponding Teams agents from w...
Microsoft Viva: Campaigns Hub in Engage and Engage in Teams mobile
The Campaigns Hub in Viva Engage provides a centralized mobile destination where employees can discover and participate in organizational camp...
Planner: Conditional Coloring
Conditional Coloring highlight tasks based on selected criteria, making priorities, status, and important task details easier to spot. Product...
Outlook: Offline settings “Days of email to save” admin policy
Tenant admins will be able to define the default value for “Days of email to save” in Offline settings and designate whether end u...
Microsoft Copilot Studio: Agent Sharing amongst makers
Enables sharing of agents with other makers in the new GHCP harness. Makers can grant other makers Agent Viewer (view analytics/evaluations on...
OneDrive Photos on Windows: admin controls and policy support
OneDrive Photos, integrated into the OneDrive sync app for Windows 10/11, is currently available only for personal Microsoft accounts, with wo...
Admin app retiring in Teams, Outlook and Microsoft365.com
The Admin app for very small businesses in Teams, Outlook, and Microsoft365.com will retire by October 2026, with rollout starting August 2026...
Calls popout into a new window on the browser to support multi-tasking and collaboration during a meeting
Microsoft Teams for Web will introduce a Picture-in-Picture Call Monitor in October 2026, allowing users to manage meeting controls in a separ...
Microsoft Windows Autopatch: September 2026 Windows security update requires a restart for hotpatch-enabled devices
The September 2026 Windows security update requires a restart for hotpatch-enabled devices because it is a standard update. Devices will remai...