Uploaded March 2026 | Updated September 2026, 12 hours ago
It's time for our third Ask Microsoft Anything (AMA) about updating Secure Boot certificates on your Windows devices before they expire in June of 2026. If you've already bookmarked Secure Boot playbook, but need more details or have a specific question, join us to get the answers you need to prepare for this milestone. No question is too big or too small. Update scenarios, inventorying your estate, formulating the right deployment plan for your organization -- we're here to help!
0:00 – Welcome & introductions
0:46 – Question – What happens if you set the registry settings on a device that is still using Legacy BIOS? Is the update process smart enough to ignore those devices?
1:59 – Question – Our company does not allow us to use Intune. Are there any helpful tools or scripts to Inventory?
3:24 – Question – During the February AMA, you en-phased that enterprises should leverage Intune and build their own dashboard to monitor secure boot states. The guide requires Enterprises licenses. As an MSP that manages thousands of devices with Business Premium Plan...
6:03 – Question – Could you confirm that the Secure-Boot-Update scheduled task expects Microsoft's Owner GUID on Microsoft's signatures in Secure Boot? We customize the Secure Boot content ....
9:20 – Question – "The KEK update (needs to be signed by the OEM because they own the PK) is required before June 2026." I remember Scott in the December AMA saying that the various (existing) key/cert updates continued to work past 2026...
10:38 – Question – If I ignore this and do nothing, will devices with (or without) secure boot enabled continue to boot?
12:05 – Question – What is the timeline of assisted Controlled Feature Update? Are you planning to roll out the Secure Boot Cert. Update to 100% of devices before June 2026? Or should we already prepare the alternative ways to update the devices (registry, GPO or Intune policy)?
14:29 – Question – Seeing some devices running on Hyper V with the March 2026 updates applied, some Server 2019 servers show updated...
16:02 – Question – What would be the impact of blanketly applying this policy setting? Enable Secureboot Certificate Updates
17:12 – Question – Are these updates Bitlocker aware? Do we need to suspend bitlocker for 2-3 reboots during this process?
18:25 – Question – We've successfully updated some of our devices with the 2023 cert, and tested how PXE boot in SCCM would work....
22:35 – Question – How can we get a compliance report if we do not use AutoPatch?
Question – What is the timeframe for the cert to upgrade if we leave the LCU to do the job based on a high confidence level compared to enabling the CFR settings?
26:48 – Question – How important is it that the system already boots trusting the 2023 cert instead of the 2011 cert? Is it okay for the system to continue booting using the 2011 cert as long as the 2023 KEK and DB certificates install?
29:37 – Question – I have deployed the secure boot remediation through Intune and I see event ID 1801 that says the certificates are available but not applied and the BucketConfidenceLevel shows Need more data. Do i need to take any action on that ?
33:02 – Question – Looks like there have been reports online of users receiving driver updates that are requiring bitlocker keys to be entered after reboot...
35:24 – Question – I noticed that some of my clients (around 5% so far) updated only two of three Secure Boot Certificates. Intune Remediation script shows the following output: Microsoft UEFI CA 2023 = False, Microsoft Corporation UEFI CA 2011 = True...
38:23 – Question – Will Microsoft release an OS upgrade that requires the EFI partition to be signed with the 2023 certificate? If so, is this expected in Windows 11 26H2, and has Microsoft announced anything about this?
42:14 – Question – Can Secure Boot certificates be updated when Secure Boot is disabled?
Question – Does Server 2025 automagically comply? Both fresh install & Server 2022 update? – answered at 47:15.
49:00 – Question – Will devices that have 2023 cert already require a boot.wim that has 2023 cert once June 2026 has passed?
50:47 – Question – How long will the 2023 certs last? Will this process need to be repeated when that happens?
52:59 – Question – I manually updated the registry on a device, set it to 22852, and forced the Scheduled Task to start, waited 30 seconds and forced a reboot, and the server (server 2019 VM in hyperv with the latest march patches)...
55:27 – Question – In the March 2026 release notes it says this: “With this update, Windows quality updates include additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot...
57:36 – Question – How will Windows Update behavior change post-expiration on devices that haven't trusted the 2023 keys....
It's time for our third Ask Microsoft Anything (AMA) about updating Secure Boot certificates on your Windows devices before they expire in June of 2026. If you've already bookmarked Secure Boot playbook, but need more details or have a specific question, join us to get the answers you need to prepare for this milestone. No question is too big or too small. Update scenarios, inventorying your estate, formulating the right deployment plan for your organization -- we're here to help!
0:00 – Welcome & introductions
0:46 – Question – What happens if you set the registry settings on a device that is still using Legacy BIOS? Is the update process smart enough to ignore those devices?
1:59 – Question – Our company does not allow us to use Intune. Are there any helpful tools or scripts to Inventory?
3:24 – Question – During the February AMA, you en-phased that enterprises should leverage Intune and build their own dashboard to monitor secure boot states. The guide requires Enterprises licenses. As an MSP that manages thousands of devices with Business Premium Plan...
6:03 – Question – Could you confirm that the Secure-Boot-Update scheduled task expects Microsoft's Owner GUID on Microsoft's signatures in Secure Boot? We customize the Secure Boot content ....
9:20 – Question – "The KEK update (needs to be signed by the OEM because they own the PK) is required before June 2026." I remember Scott in the December AMA saying that the various (existing) key/cert updates continued to work past 2026...
10:38 – Question – If I ignore this and do nothing, will devices with (or without) secure boot enabled continue to boot?
12:05 – Question – What is the timeline of assisted Controlled Feature Update? Are you planning to roll out the Secure Boot Cert. Update to 100% of devices before June 2026? Or should we already prepare the alternative ways to update the devices (registry, GPO or Intune policy)?
14:29 – Question – Seeing some devices running on Hyper V with the March 2026 updates applied, some Server 2019 servers show updated...
16:02 – Question – What would be the impact of blanketly applying this policy setting? Enable Secureboot Certificate Updates
17:12 – Question – Are these updates Bitlocker aware? Do we need to suspend bitlocker for 2-3 reboots during this process?
18:25 – Question – We've successfully updated some of our devices with the 2023 cert, and tested how PXE boot in SCCM would work....
22:35 – Question – How can we get a compliance report if we do not use AutoPatch?
Question – What is the timeframe for the cert to upgrade if we leave the LCU to do the job based on a high confidence level compared to enabling the CFR settings?
26:48 – Question – How important is it that the system already boots trusting the 2023 cert instead of the 2011 cert? Is it okay for the system to continue booting using the 2011 cert as long as the 2023 KEK and DB certificates install?
29:37 – Question – I have deployed the secure boot remediation through Intune and I see event ID 1801 that says the certificates are available but not applied and the BucketConfidenceLevel shows Need more data. Do i need to take any action on that ?
33:02 – Question – Looks like there have been reports online of users receiving driver updates that are requiring bitlocker keys to be entered after reboot...
35:24 – Question – I noticed that some of my clients (around 5% so far) updated only two of three Secure Boot Certificates. Intune Remediation script shows the following output: Microsoft UEFI CA 2023 = False, Microsoft Corporation UEFI CA 2011 = True...
38:23 – Question – Will Microsoft release an OS upgrade that requires the EFI partition to be signed with the 2023 certificate? If so, is this expected in Windows 11 26H2, and has Microsoft announced anything about this?
42:14 – Question – Can Secure Boot certificates be updated when Secure Boot is disabled?
Question – Does Server 2025 automagically comply? Both fresh install & Server 2022 update? – answered at 47:15.
49:00 – Question – Will devices that have 2023 cert already require a boot.wim that has 2023 cert once June 2026 has passed?
50:47 – Question – How long will the 2023 certs last? Will this process need to be repeated when that happens?
52:59 – Question – I manually updated the registry on a device, set it to 22852, and forced the Scheduled Task to start, waited 30 seconds and forced a reboot, and the server (server 2019 VM in hyperv with the latest march patches)...
55:27 – Question – In the March 2026 release notes it says this: “With this update, Windows quality updates include additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot...
57:36 – Question – How will Windows Update behavior change post-expiration on devices that haven't trusted the 2023 keys....










