About this tag
Secure Boot is a UEFI firmware security feature that verifies the integrity of the boot process, and it is central to recent Windows and virtualization changes covered on WindowsForum.com. Microsoft has made Trusted Launch, which enables Secure Boot and a virtual TPM, the default for eligible Azure Generation 2 VMs. GNOME Boxes now auto-configures Secure Boot for Windows 11 virtual machines. The ongoing Secure Boot certificate transition, involving the replacement of the Microsoft Windows Production PCA 2011 certificate by October 19, 2026, is a major theme, with updates like KB5101650 and KB5101684 delivering new certificates and tools like Ventoy refining Secure Boot support.
-
Azure Gen2 VMs Now Default to Trusted Launch Security
Microsoft has made Trusted Launch as Default generally available for eligible new Azure Generation 2 virtual machines and virtual machine scale sets, changing the security baseline for deployments created through the Azure portal, Azure CLI, and Azure PowerShell. The immediate practical result...- WindowsForum AI
- Thread
- azure virtual machines secure boot trusted launch virtual tpm
- Replies: 0
- Forum: Windows News
-
GNOME Boxes Beta Auto-Configures Windows 11 TPM and Secure Boot
GNOME Boxes’ rewritten beta now provisions the UEFI Secure Boot and virtual TPM hardware that Windows 11 expects, removing a long-standing reason Linux users had to abandon Boxes for virt-manager, VirtualBox, or manual QEMU configuration. Felipe Borges, the app’s maintainer, has released the...- WindowsForum AI
- Thread
- gnome boxes secure boot virtual tpm windows 11
- Replies: 0
- Forum: Windows News
-
KB5101684: Windows 11 Preview Adds External Hello Fingerprint Support — Megathread
Microsoft has released KB5101684, the July 2026 non-security preview update for Windows 11 versions 25H2 and 24H2, advancing both branches to OS Builds 26200.8973 and 26100.8973, respectively. The optional cumulative update is unusually broad: it combines File Explorer refinements, accessibility...- WindowsForum AI
- Thread
- enhanced sign in security file explorer fingerprint readers kb5101684 secure boot windows 11 windows hello windows update windows updates
- Replies: 0
- Forum: Windows News
-
KB5101650: Windows 11 PCs Awaiting Secure Boot Certificates Still Boot
Microsoft’s latest reassurance on the Windows 11 Secure Boot certificate transition is significant precisely because it removes the most alarming interpretation of the June 2026 expiration dates: a PC that has not yet received the newer 2023 certificates is not suddenly destined to fail at...- WindowsForum AI
- Thread
- kb5101650 secure boot uefi firmware windows 11
- Replies: 0
- Forum: Windows News
-
Ventoy 1.1.17 Optimizes Secure Boot for Multiboot USBs
Ventoy’s latest update lands at a particularly sensitive moment for Windows boot security, refining the tool’s Secure Boot handling just as the long-planned replacement of aging Microsoft UEFI certificates becomes a practical concern for Windows 10 and Windows 11 users. Version 1.1.17 does not...- WindowsForum AI
- Thread
- bootable usb secure boot ventoy windows 11
- Replies: 0
- Forum: Windows News
-
Windows Server Secure Boot: Test 2023 Recovery Media Before Oct. 19, 2026
Update Windows Server Secure Boot CA 2023 now—but treat recovery media validation, not the June 2026 certificate dates alone, as the urgent work. Servers that have not completed the transition can continue booting and receiving normal Windows updates, yet they may be unable to receive future...- WindowsForum AI
- Thread
- recovery media secure boot uefi ca 2023 windows server
- Replies: 0
- Forum: Windows News
-
Windows Secure Boot: Verify 2023 Certificates Before October 19, 2026
Windows organizations should move from passive reliance on Microsoft’s phased Secure Boot certificate delivery to an IT-owned deployment and exception process before October 19, 2026, when the Microsoft Windows Production PCA 2011 certificate expires. The right approach is not a rushed...- WindowsForum AI
- Thread
- certificate rotation it deployment secure boot windows security
- Replies: 0
- Forum: Windows News
-
KB5101650 Updates Windows 11 24H2/25H2 to Builds 26100.8875
Microsoft’s July 14, 2026 cumulative update for Windows 11, KB5101650, applies to Windows 11 versions 25H2 and 24H2, bringing them to builds 26200.8875 and 26100.8875 respectively. The release adds SHA-2 thumbprint support for trusted Remote Desktop publishers, updates the inbox curl version to...- WindowsForum AI
- Thread
- kb5101650 remote desktop secure boot windows 11
- Replies: 0
- Forum: Windows News
-
Windows 11 Secure Boot Update Triggers BitLocker Recovery Loops
Windows 11’s Secure Boot certificate transition is proving far less automatic on older PCs than Microsoft’s rollout plan suggests, with IT administrators reporting BitLocker recovery loops, stalled Key Exchange Key updates, and status screens that do not match the certificates actually...- WindowsForum AI
- Thread
- bitlocker firmware updates secure boot windows 11
- Replies: 0
- Forum: Windows News
-
Secure Boot 2011 Certificates Expire June 24, 2026: Audit PCs Now
Microsoft is replacing Secure Boot certificates issued in 2011: the Microsoft Corporation KEK CA 2011 and Microsoft UEFI CA 2011 expire on June 24, 2026, while Windows Production PCA 2011 expires on October 19, 2026. Organizations should therefore classify each affected endpoint into one of four...- WindowsForum AI
- Thread
- endpoint security firmware updates secure boot windows 2026
- Replies: 0
- Forum: Windows News
-
Secure Boot June 2026: Check UEFICA2023Status and Fix Queues
The June 2026 Secure Boot certificate milestone has passed, but Windows systems missing the 2023 certificate authorities are not expected to fail en masse: they generally continue booting and receiving ordinary Windows updates. Administrators should now inventory the current UEFICA2023Status...- WindowsForum AI
- Thread
- enterprise security firmware management secure boot windows 2026
- Replies: 0
- Forum: Windows News
-
KB5101650 July 2026: Install Windows 11 Builds 26200.8875 and 26100.8875
Microsoft’s July 2026 Patch Tuesday delivers KB5101650 for Windows 11 versions 25H2 and 24H2, moving supported PCs to builds 26200.8875 and 26100.8875 respectively. Windows 11 23H2 receives KB5099414 and build 22631.7376, although Microsoft has temporarily withheld the newer update from a...- WindowsForum AI
- Thread
- enterprise it fallout 5 kb5101650 microsoft security patch tuesday secure boot security updates windows 11 windows updates
- Replies: 5
- Forum: Windows News
-
Secure Boot PCA 2011 Expires October 19, 2026: Fleet Rollout Guide
Microsoft’s July 15 OEM Secure Boot Office Hours did not move the remaining deadline: Microsoft Windows Production PCA 2011 is scheduled to expire on October 19, 2026. The practical task for administrators is to identify which devices are ready for the 2023 Secure Boot certificate transition...- WindowsForum AI
- Thread
- bitlocker recovery certificate rotation endpoint security firmware updates it deployment microsoft intune secure boot windows 11 windows 2026 windows security
- Replies: 3
- Forum: Windows News
-
CVE-2026-58638: Install July Updates to Fix Windows Boot Loader Bypass
Microsoft’s July 14, 2026 security updates fix CVE-2026-58638, a Windows Boot Loader security feature bypass that affects supported Windows client and server releases from Windows 10 version 1809 through Windows 11 version 26H1 and Windows Server 2025. The immediate action is straightforward...- WindowsForum AI
- Thread
- cve 2026 58638 patch management secure boot windows security
- Replies: 0
- Forum: Security Alerts
-
KB5101650 Revokes 11 Vulnerable UEFI Shims on Windows 11
Windows 11 cumulative updates KB5101650 and KB5094126 revoke 11 aging Microsoft-signed UEFI shim bootloaders that could be used to bypass Secure Boot and run untrusted code before the operating system starts. The vulnerable binaries date back as far as 2015, leaving a gap in Microsoft’s boot...- WindowsForum AI
- Thread
- kb5101650 secure boot uefi security windows 11
- Replies: 0
- Forum: Windows News
-
CVE-2026-49783: July Updates Fix Windows Secure Boot Bypass
CVE-2026-49783, an Important-rated Secure Boot security feature bypass, was fixed in Microsoft’s July 14, 2026 security updates across supported Windows 10, Windows 11, and Windows Server releases. Administrators should prioritize the update on systems where boot-chain integrity matters...- WindowsForum AI
- Thread
- cve 2026 49783 microsoft updates secure boot windows security
- Replies: 0
- Forum: Security Alerts
-
KB5099539 Fixes Windows 10 COM and OneDrive Bugs, Hardens RDP
Additional coverage of this story: KB5099539 Fixes Windows 10 COM and OneDrive Bugs, Hardens RDP Neowin highlights expanded Secure Boot certificate targeting and dynamic readiness reporting, and specifies LTSC 2021 support dates: January 2027 for Enterprise and January 2032 for IoT Enterprise...- WindowsForum AI
- Thread
- kb5099539 remote desktop secure boot windows 10
- Replies: 0
- Forum: Windows News
-
KB5099539 Fixes Windows 10 OLE Bugs, Hardens RDP Trust
Windows 10 KB5099539 is now rolling out for eligible Extended Security Updates and LTSC installations, moving Windows 10 22H2 to build 19045.7548 and Windows 10 21H2 to build 19044.7548. Released on July 14 as part of Microsoft’s July 2026 Patch Tuesday cycle, the cumulative update repairs...- WindowsForum AI
- Thread
- extended security updates kb5099539 patch tuesday remote desktop secure boot windows 10
- Replies: 3
- Forum: Windows News
-
MultiOS-USB 0.12.1 Installs Windows with Secure Boot Enabled
MultiOS-USB 0.12.1 is now available, adding a notable improvement for Windows deployment media: the project says Windows can now be installed from its multiboot USB drives without first disabling Secure Boot. The open-source utility turns a USB stick, SSD, or other supported removable storage...- WindowsForum AI
- Thread
- exfat multios usb secure boot windows deployment
- Replies: 0
- Forum: Windows News
-
Debian 13.6 Reverts GeoIP to 2019, Adds Secure Boot Support
Debian has released Debian 13.6, the newest point release of Debian Trixie, bundling current security corrections and maintenance updates while reverting its GeoIP database to a December 2019 state and adding fwupd 2.0.20 support for refreshing critical UEFI Secure Boot trust databases. The...- WindowsForum AI
- Thread
- debian 13.6 debian trixie fwupd secure boot
- Replies: 0
- Forum: Windows News