kb5093574

About this tag
KB5093574 is a Microsoft update that adds a -Decoded parameter to the Get-SecureBootUEFI PowerShell cmdlet. This enhancement allows Windows administrators to read Secure Boot certificate databases—PK, KEK, DB, and DBX—in a human-readable format. The update supports the ongoing migration from the original 2011 Secure Boot certificates to the 2023 certificate chain, making it easier to diagnose and manage Secure Boot configurations in enterprise environments.
  1. Get-SecureBootUEFI -Decoded (KB5093574): Read PK KEK DB DBX Certificates in PowerShell

    Microsoft has quietly given Windows administrators a badly needed diagnostic upgrade for the Secure Boot certificate transition: a new -Decoded parameter for the Get-SecureBootUEFI PowerShell cmdlet. Published under KB5093574 on April 28, 2026, the change turns Secure Boot’s normally opaque...