MC1173103 High
Secure Boot certificate deployment guide and tools
Summary AI-generated
Update expiring Secure Boot certificates to 2023 CAs using new guides and tools; 2011 CAs start expiring June 2026, with 2023 CAs rolling out via Windows updates from October 2025.
Suggested actions AI-generated
- Review deployment playbook and new tools
- Monitor and update Secure Boot CAs to 2023 versions
- Opt in for Microsoft-managed updates if desired
- Manually deploy CAs if not using Microsoft updates
Written by Azure OpenAI (gpt-4.1) from the text of the post below. It can be incomplete or wrong; the original post is authoritative.
Similar posts
Search for more like this- MC1185931 Secure Boot playbook for certificates expiring in 2026
- MC1237599 Windows Server Secure Boot playbook for certificates expiring in 2026
- MC1230373 Secure Boot certificate updates: actions required ahead of June 2026 expiration
- MC1403212 Best practices for deploying Secure Boot certificate updates
- MC1262523 New resources to help organizations prepare for Secure Boot certificate expirations
- MC1193371 How to use Microsoft Intune to update expiring Secure Boot certificates
Original post from Microsoft
Use the newly published guide and tools to start updating your organization’s expiring Secure Boot certificates. As the 2011 certificate authorities (CAs) start expiring in June 2026, 2023 CAs are required. Updated CAs allow Secure Boot to continue preventing malware early in the startup sequence. New resources are available for you to start monitoring, deploying, and troubleshooting Secure Boot CAs. These include the deployment playbook, new registry keys, Windows Event Log, and Windows Configuration System (WinCS) APIs.
When will this happen:
- The deployment guide, new registry keys, and WinCS are available today.
- The 2023 Secure Boot CAs are rolling out gradually as part of Windows monthly updates starting with the October 2025 security update.
- Additional tools will be available soon.
- The 2011 CAs start expiring beginning in June 2026.
How this will affect your organization:
Devices manufactured before 2012 and those that don’t already have new certificates need to be updated with the 2023 CAs. We recommend taking measures well before the 2011 CAs start expiring.
What you need to do to prepare:
If your organization sends diagnostic data and lets Microsoft manage your updates, your devices will automatically get updated CAs with the monthly Windows updates. You can also opt in to let Microsoft determine high-confidence devices that will get these CAs first.
If you prefer to deploy these CAs yourself, follow the deployment playbook to monitor, deploy, and troubleshoot Secure Boot updates. You can use new registry keys, Windows Event Log, and WinCS to do so.
Additional information:
- Find the deployment playbook in the updated Secure Boot certificate updates: Guidance for IT professionals and organizations.
- Learn how to use new registry keys to monitor, deploy, and troubleshoot Secure Boot CAs.
- Learn how to use new Windows Configuration System (WinCS) APIs to deploy Secure Boot CAs.
- Learn how to use Windows Event Log to monitor Secure Boot CA updates.
- Bookmark Windows Secure Boot certificate expiration and CA updates as the landing page to the most up-to-date information.