MC1230373 High Major change
Secure Boot certificate updates: actions required ahead of June 2026 expiration
Summary AI-generated
Secure Boot certificates issued in 2011 will start expiring in June 2026; admins should plan for certificate updates to ensure continued secure Windows startup.
Suggested actions AI-generated
- Review the Secure Boot playbook for expiring certificates
- Plan certificate updates for Windows environments
- Bookmark provided guidance links
Written by Azure OpenAI (gpt-4.1) from the text of the post below. It can be incomplete or wrong; the original post is authoritative.
Similar posts
Search for more like this- MC1185931 Secure Boot playbook for certificates expiring in 2026
- MC1262523 New resources to help organizations prepare for Secure Boot certificate expirations
- MC1237599 Windows Server Secure Boot playbook for certificates expiring in 2026
- MC1403212 Best practices for deploying Secure Boot certificate updates
- MC1173103 Secure Boot certificate deployment guide and tools
- MC1193371 How to use Microsoft Intune to update expiring Secure Boot certificates
Original post from Microsoft
Secure Boot is a foundational Windows security feature that runs at startup, before Windows load, and helps ensure that only trusted, digitally signed software can execute. After more than 15 years of continuous service, the original Secure Boot certificates are reaching the end of their planned lifecycle and begin expiring in late June 2026.
To learn more about Microsoft’s effort to update these certificates, see the blog post Refreshing the root of trust: industry collaboration on Secure Boot certificate updates. To prevent disruption and maintain secure startup across Windows environments, plan for these certificates update following the guidance in the Secure Boot playbook.
When this will happen:
The 2011 Secure Boot certificates begin expiring in June 2026.
What you need to do to prepare:
Review the Secure Boot playbook for certificates expiring in 2026 to understand requirements, timelines, and supported scenarios. Additionally, bookmark https://aka.ms/GetSecureBoot for more information about this change, OEMs guidance, and answers to frequently asked questions.
Additional technical resources:
- If you use Microsoft Intune, read Microsoft Intune method of Secure Boot for Windows devices with IT-managed updates.
- Compare this method to Registry key updates for Secure Boot: Windows devices with IT-managed updates.
- Check out the option Group Policy Objects (GPO) method of Secure Boot for Windows devices with IT-managed updates.
- See how these methods work together in Secure Boot playbook for certificates expiring in 2026.