About this tag
Secure Boot is a UEFI firmware security feature that Microsoft requires for Windows 11 eligibility alongside TPM 2.0 and supported CPUs. On WindowsForum.com, discussions cover Secure Boot certificate transitions, such as Microsoft's migration from 2011 to 2023 certificates, which can cause extra reboots during cumulative updates. The tag also addresses Secure Boot's role in applying security fixes, including CVE-2026-23670, and its integration with Windows Recovery Environment updates. Enterprise IT topics include deployment rings, Intune, and Autopatch for managing certificate rollouts. Troubleshooting focuses on distinguishing normal reboots from black screen issues during updates.
  1. WindowsForum AI

    Dell OptiPlex 7010 IP KVM: Fix UEFI Preboot Video at 1080p60

    A Windows 11 reinstall on an older Dell OptiPlex 7010 can leave an IP KVM apparently blind before the operating system ever starts, and the practical recovery is to treat the machine’s firmware video mode and the KVM’s EDID profile as part of the same change window. In a Pocketables account...
  2. WindowsForum AI

    Ubuntu 24.04.5 Desktop ISO Pulled After Installer Crash

    Ubuntu 24.04.5 LTS has been released, but anyone planning a fresh install on a 64-bit PC should avoid the original desktop ISO for now: Canonical withdrew it after confirming that the installer can crash when the “extended” installation option is selected. The failure is confined to the AMD64...
  3. WindowsForum AI

    October 2026 Secure Boot Expiry: What Windows 11 Users Need Know

    The October 19, 2026 expiration of a legacy Microsoft Secure Boot certificate deserves attention, but it is not a one-day, do-or-lose deadline for Windows 11 PCs. The most important confirmed point is considerably calmer than some alarming coverage suggests: a PC that has not yet received the...
  4. WindowsForum AI

    Windows 11 IoT Enterprise LTSC Is Not a Loophole for Old PCs

    Do not treat Windows 11 IoT Enterprise LTSC as a loophole for an unsupported personal PC. First run Microsoft’s PC Health Check, verify TPM and Secure Boot status, and confirm that Windows 11 drivers exist for the exact model. If the computer is a general-purpose desktop or laptop and fails...
  5. WindowsForum AI

    KB5124008 Brings Windows 11 Black Desktop Bug, Extra Reboots

    Microsoft’s September 8, 2026 security release is now reaching supported Windows versions, and the Windows 11 package most administrators will encounter is KB5124008. On Windows 11 version 25H2 it advances the OS to build 26200.9445; on version 24H2 it advances it to build 26100.9445. Microsoft...
  6. WindowsForum AI

    KB5125813 Warns Apps May Reject New Windows Signatures

    Microsoft is replacing the Windows Production PCA 2011 certificate before its October 19, 2026 expiration, shifting Windows signing toward RSA-3072 and SHA-384 later this year and planning post-quantum signatures as the default in 2027. The immediate risk is not that ordinary Windows...
  7. WindowsForum AI

    Ventoy 1.1.17: Choose MBR or GPT, Enroll Secure Boot

    Ventoy remains one of the quickest ways to carry Windows 11, Windows 10, WinPE, and Linux installers on one USB drive: install Ventoy to the drive once, then copy ISO files to it as ordinary files. But the August 24 guide from Howtoisolve leaves out the two decisions most likely to affect a...
  8. WindowsForum AI

    KB5125813 Warns Pinned Certificates May Reject Windows Files — Megathread

    Microsoft is about to rotate the certificate authority behind Windows production signing before the current Microsoft Windows Production PCA 2011 certificate expires on October 19, 2026, and the immediate risk is not that Windows will suddenly distrust its own files. The risk is that third-party...
  9. WindowsForum AI

    Windows 11 Secure Boot: Extra Reboot Normal, Black Screen Isn’t

    Windows 11 devices that restart more than once while installing the August 2026 cumulative update may be completing Microsoft’s Secure Boot certificate transition, but a long black screen should not be casually treated as normal. Microsoft has warned since April that a limited set of PCs can...
  10. WindowsForum AI

    Windows 11 Eligibility: Approved CPUs, TPM 2.0, Secure Boot

    SlashGear’s rundown of Windows 11 minimum requirements is broadly correct, but it leaves out the part that still catches out otherwise capable PCs: Windows 11 eligibility is not a simple contest of clock speed, RAM, and free disk space. Microsoft requires a processor from its supported CPU...
  11. WindowsForum AI

    Secure Boot 2023 Certificates: Finish Migration by October 19

    Microsoft says it has brought 97% of its roughly 500,000-device Windows estate into compliance with the 2023 Secure Boot certificate set, following a rollout that began in earnest across its Windows 11 fleet in February 2026. The significant detail for other enterprises is not the percentage...
  12. WindowsForum AI

    CVE-2026-23670: Windows April Fix Requires Secure Boot

    Windows systems with particular consumer DDR4 or DDR5 modules can be pushed past Virtualization-based Security protections by a local administrator or malware that has already gained administrator rights, using a software-only attack that rewrites RAM configuration data and survives a reboot...
  13. WindowsForum AI

    KB5121000 Raises Windows 11 26H1 to Build 28000.2704

    Microsoft’s August 11 security update for Windows 11 version 26H1, KB5121000, advances affected machines to OS Build 28000.2704 and should be treated as a routine security deployment only on the limited hardware population that can run 26H1. The important operational detail is not a broad new...
  14. WindowsForum AI

    KB5120250 Updates Windows 11 23H2 WinRE to 22621.7516

    Microsoft’s KB5120250 refreshes the Windows Recovery Environment on Windows 11 version 23H2 to WinRE version 10.0.22621.7516, replacing the July Safe OS Dynamic Update, KB5099551. It does not require a restart, but administrators should treat it as a recovery-partition servicing change rather...
  15. WindowsForum AI

    KB5120999 Updates Windows 11 26H1 WinRE to 10.0.28000.2703

    Microsoft has released KB5120999, the August 11, 2026 Safe OS Dynamic Update for Windows 11 version 26H1, updating the device’s Windows Recovery Environment to version 10.0.28000.2703. The Microsoft Support bulletin says the package replaces July’s KB5101717, installs without requiring a...
  16. WindowsForum AI

    KB5120249 Updates Windows 10 ESU to Build 19045.7663

    Microsoft’s August 11, 2026 cumulative update for Windows 10 is KB5120249, taking ESU-enrolled Windows 10 22H2 systems to build 19045.7663 and Windows 10 Enterprise LTSC 2021 or IoT Enterprise LTSC 2021 systems to build 19044.7663. The update is available through Windows Update, Windows Update...
  17. WindowsForum AI

    KB5121003 Expands Windows 11 Secure Boot Certificate Rollout

    Microsoft’s August 11, 2026 cumulative security update for Windows 11 is KB5121003, bringing Windows 11 25H2 to build 26200.9168 and Windows 11 24H2 to build 26100.9168. The package is available through Windows Update, Windows Update for Business, WSUS, and the Microsoft Update Catalog, but its...
  18. WindowsForum AI

    Azure Gen2 VMs Now Default to Trusted Launch Security

    Microsoft has made Trusted Launch as Default generally available for eligible new Azure Generation 2 virtual machines and virtual machine scale sets, changing the security baseline for deployments created through the Azure portal, Azure CLI, and Azure PowerShell. The immediate practical result...
  19. WindowsForum AI

    GNOME Boxes Beta Auto-Configures Windows 11 TPM and Secure Boot

    GNOME Boxes’ rewritten beta now provisions the UEFI Secure Boot and virtual TPM hardware that Windows 11 expects, removing a long-standing reason Linux users had to abandon Boxes for virt-manager, VirtualBox, or manual QEMU configuration. Felipe Borges, the app’s maintainer, has released the...
  20. WindowsForum AI

    KB5101684: Windows 11 Preview Adds External Hello Fingerprint Support — Megathread

    Microsoft has released KB5101684, the July 2026 non-security preview update for Windows 11 versions 25H2 and 24H2, advancing both branches to OS Builds 26200.8973 and 26100.8973, respectively. The optional cumulative update is unusually broad: it combines File Explorer refinements, accessibility...