Ask Microsoft Anything: Secure Boot - December 2025 @WindowsAtWork
Ask Microsoft Anything: Secure Boot - December 2025  @WindowsAtWork
Uploaded December 2025 | Updated September 2026, 1 hour ago
Visit https://aka.ms/AMA/SecureBoot to Ask Microsoft Anything (AMA) about updating Secure Boot certificates on your Windows devices before they expire in June of 2026. Get to know the tools and steps you can take today to proactively plan and prepare for this milestone. Get answers and insights about update scenarios, inventorying your estate, and formulating the right deployment plan for your organization.


0:00 – Welcome and intros

1:31 – Question – We have diagnostic data turned on in our Intune environment, but I'm not seeing the registry key "MicrosoftUpdateManagedOptIn". Should I be worried about this? If this key does not exist, MS will not push the certificates down, correct?

4:28 – Question – If we apply the 0x5944 registry value on updateable systems, are we still able to network boot them with our existing WinPE to image them with SCCM?

6:01 – Question – When you say "future security updates cannot be applied," do you mean monthly cumulative updates will fail to install entirely, or will just the potentially bundled updates to Secure Boot / Boot Manager be skipped?

7:42 – Question – Will the Windows Install process update the Certs if the Windows Install source media has been updated and the device has not?

10:10 – Question – Is it true that Hyper-V Gen 1 VMs are not affected by this issue?

11:10 – Question – What is the easiest way to tell if our devices will need to be updated?

12:50 – Question – Does this have any relation with Defender ASR rule 'Block rebooting machine in Safe Mode'?

13:31 – Question – Am I right to say if the "HighConfidenceOptOut" registry key does not exist, this means we have opted in?

18:16 – Question – If we miss the June 2026 deadline, how would we go about bringing a device back to a compliant state?

20:26 – Question – We have 70k Win11 23H2 devices patched using Autopatch every month. All managed by Intune. Is the right behavior to simply put the registry down to the device and they will update certs via the schedule task on the box and then we are fine? We don’t have to think of it anymore?

25:36 – Question – Towards the bottom of the guidance at aka.ms/GetSecureBoot, it states that the WindowsUEFICA2023Capable is not recommended for general use. However, can it be used to query devices in my environment to get an accurate picture of how many devices have the certificate in the DB already?

27:06 – Question – How about Azure VMs? Do we have to take action on them as well?

29:14 – Question – You mentioned “assists” – how do we access those? Are they a service we need to sign up for?
• To stay up to date on additional help mechanisms, go to https://aka.ms/GetSecureBoot

31:27 – Question – Does the rollout from MSFT include adding the old cert to the Exclusion DB (dbX)?

34:45 – Question – When I look at my environment, even brand-new devices are showing that registry the UEFICA2023Status regkey is NotStarted. Even on brand new devices we've deployed. Does NotStarted also mean the device may not need it? Or was I querying the wrong registry key?

36:00 – Question – When will the certificates come down with Windows Updates? Is there an expected month they will be delivered?

39:39 – Question – If I have devices in Autopatch & diagnostics being sent. Do I need to implement any other configuration policies or registry keys or is it all automatically completed? Or do we need a settings catalog policy as well?

42:25 – Question – How will the WinPE boot image (from the ADK) be affected by these changes? If it will be updated, will it continue to work on systems that have not yet installed the updated certificates?

44:37 – Question – How are you working with OEMs to ensure that they are updating their firmware in advance?

45:58 – Question – If the key "WindowsUEFICA2023Capable" is set to 1 instead of 2, this means the device is still not in a "secure state". The key needs to be set to 2?

47:33 – Question – Does applying the 0x5944 registry key apply the Secure Boot revocations or does this only apply the new cert, but leaves the old cert in place? And is Microsoft planning on revoking the old cert at some point in the future?

49:04 – Question – What about my device at home? Do I need to take steps there as well?

50:21 – Closing tips & tricks
Ask Microsoft Anything: Secure Boot - December 2025From panic to productive: point-in-time restore in WindowsAMA: Intune device inventory and analytics - Tech Community LiveAMA: Windows 365 - June 2025Transitioning to post-quantum cryptographyWindows settings backup and restore: Faster PC setup and recoveryAMA: The future of AI with Windows 11 and Copilot+ PCsLets talk Windows and Intune: 2026 editionAMA: Copilot/agentic-centered endpoint managementAMA: Windows and AI experiencesI want to be a cloud-first enterprise. How do I get there? - Tackling Tech
Windows At Work |

Ask Microsoft Anything: Secure Boot - December 2025

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER