Windows Secure Boot Certificate Update
ADCS | Compliance
SaaS | Enterprise | Community Edition
How to update Windows Secure Boot Certificate
About Secure Boot
Secure Boot enforces a chain of trust by checking signatures against certificates stored in firmware (DB/KEK/PK). The 2011 Microsoft UEFI CA certificates begin expiring in June 2026; systems that do not receive the replacement certificates will enter a degraded security state and may lose future boot‑time protections
What Microsoft is doing and timeline
Microsoft published guidance and began a phased rollout of...