← Back
How to use Microsoft Intune to update expiring Secure Boot certificates
MC1193371 · build prod-20251231-200323
Category
stayInformed
Severity
normal
Major change
False
Last modified
2025-12-08 21:59:20
Summary source
Azure OpenAI (gpt-4.1)
Action by (Graph)
Action by (AI)
Services
Windows
Tags
Admin impact
Master tags
Security
Roadmap IDs

One-line summary

Admins can now use Intune to deploy, manage, and monitor Secure Boot certificate updates on Windows clients, with new settings available for streamlined management.

Similar updates

More like this
MC1185931 Secure Boot playbook for certificates expiring in 2026
Secure Boot playbook for certificates expiring in 2026 Secure Boot certificates on many Windows devices will expire in June 2026; admins should monitor, prepare, and update certificates to ensure continued protection. Soon, you’ll be able to use scalable MDM solutions, such as Microsoft Intune. Secure Boot certificates on many Windows devices.
MC1139443 Secure Boot certificate expiration: What Windows IT admins need to know now
Secure Boot certificate expiration: What Windows IT admins need to know now Microsoft is updating Secure Boot certificates before current ones expire in 2026; IT admins must ensure systems accept new certificates to maintain security and updates. Secure Boot protects Windows systems by validating firmware and boot components using trusted.
MC1104112 (Updated) Act now: Secure Boot certificates expire in June 2026
(Updated) Act now: Secure Boot certificates expire in June 2026 Microsoft will roll out updated Secure Boot certificates for Windows systems; current certificates start expiring June 2026, requiring firmware and policy updates to maintain security. Allow Microsoft to manage Secure Boot-related updates for your devices by setting the following.
MC1173103 Secure Boot certificate deployment guide and tools
Secure Boot certificate deployment guide and tools Update expiring Secure Boot certificates to 2023 CAs using new guides and tools; 2011 CAs start expiring June 2026, with 2023 CAs rolling out via Windows updates from October 2025. Use the newly published guide and tools to start updating your organization’s expiring Secure Boot certificates. As.
MC1183612 Action Required to Enable Extended Security Update for local devices accessing Windows 365
Action Required to Enable Extended Security Update for local devices accessing Windows 365 Admins must deploy a custom policy via Intune or MDM to enable Windows 10 ESU for Windows 365 Cloud PCs before November 11, 2025, to receive the November security update. Windows 10 devices accessing Windows 365 Enterprise Clo... IT administrators must.
MC1192217 Secure Boot AMA: Ask Microsoft Anything on December 10
Secure Boot AMA: Ask Microsoft Anything on December 10 Join a live AMA on December 10, 2025, for guidance on updating Secure Boot certificates on Windows devices before their June 2026 expiration; get expert advice and post questions in advance. Join us December 10, 2025, at 8:00 AM PST for a live Ask Microsoft Anything (AMA) session focused on.

Details

Body (from Message Center)

You can now deploy, manage, and monitor Secure Boot certificate updates. This method represents an alternative to setting registry keys and using Group Policy. You can use Intune to deploy on all domain-joined Windows clients, opt out of high-confidence buckets, and opt in to Microsoft managing these updates. 
 
When will this happen: 
The following settings are now available in the Intune settings catalog: 
  • Configure Microsoft Update Managed Opt-In 
  • Configure High-Confidence Opt-Out 
  • Enable SecureBoot Certificate Updates 
 
How this will affect your organization: 
As the 2011 Secure Boot certificates will start expiring in June 2026, it is essential that organizations start planning for and updating to 2023 certificates. You can now use Microsoft Intune, in addition to registry keys and Group Policy, to deploy, manage, and monitor this update process. The three new settings are disabled by default. Enable them to start taking advantage of the desired capabilities. 
 
What you need to do to prepare: 
To manage Secure Boot certificate updates in Intune, enable the new settings by navigating to the Microsoft Intune admin center: 
  1. Under Devices > Manage devices, select Configuration
  2. Select Create and select New Policy. 
  3. Select Create a profile in the right-hand pane. 
  4. Fill in Platform with Windows 10 and later
  5. Select the Settings Catalog under the Profile Type. ​​​​​ 
  6. Begin creating a profile by giving the profile a name. Press Next.​​​​​​ 
  7. Under Configuration settings, select Add settings. In the Settings picker, search for Secure Boot. There should be three settings in the Secure Boot category. 
  8. Select the desired settings for your organization: Configure Microsoft Update Managed Opt-In, Configure High-Confidence Opt-Out, and Enable SecureBoot Certificate Updates (preselected for you). 
  9. Finish the profile for the devices that will use these settings. 
 
Additional information: 

Raw JSON (for debugging)

Expand/collapse the full payload below.
Show/hide raw
{
  "snapshot_item": {
    "action_required_by": null,
    "ai_action_required_by": null,
    "ai_actions": [
      "Enable new Secure Boot settings in Intune",
      "Create and assign configuration profiles for Windows devices",
      "Plan migration to 2023 Secure Boot certificates"
    ],
    "ai_master_tags": [
      "Security"
    ],
    "ai_model": "gpt-4.1",
    "ai_summary": "Admins can now use Intune to deploy, manage, and monitor Secure Boot certificate updates on Windows clients, with new settings available for streamlined management.",
    "ai_topics": [
      "Windows",
      "Intune"
    ],
    "category": "stayInformed",
    "details_map": {},
    "id": "MC1193371",
    "importance": 0,
    "is_major_change": false,
    "last_modified": "2025-12-08T21:59:20Z",
    "ms_products": [
      "Windows"
    ],
    "platforms": null,
    "roadmap_ids": [],
    "services": [
      "Windows"
    ],
    "severity": "normal",
    "tags": [
      "Admin impact"
    ],
    "title": "How to use Microsoft Intune to update expiring Secure Boot certificates"
  }
}