Microsoft’s original Windows Secure Boot certificates, issued in 2011 and embedded across years of PCs, begin expiring in June 2026, forcing Microsoft, OEMs, administrators, and some users to move devices to newer 2023 certificate authorities before boot-level security protections fall behind...
Microsoft will begin running into the first expirations of its original 2011 Secure Boot certificate chain in June 2026, forcing Windows PCs, servers, recovery media, and firmware ecosystems to move to newer 2023 certificates through a staged Windows Update process. The practical sign for many...
The first Microsoft Secure Boot certificate from the Windows 8 era expires on June 24, 2026, beginning a staged retirement of 2011 trust anchors that still underpin boot security on many Windows PCs, servers, and embedded systems. The immediate danger is not a wave of unbootable laptops. It is...
bitlocker
enterprise it
firmware security
it administration
it management
secure boot
uefi certificates
uefifirmwareuefi trust chain
windows 10
windows 10 and 11
windows 11 security
windows security
windows update
Microsoft is replacing the original 2011 Secure Boot certificate chain across Windows PCs and servers before certificates begin expiring in June 2026 and continue expiring into October, affecting supported Windows 10, Windows 11, and Windows Server systems that still trust those aging boot...
bitlocker
enterprise it
firmware security
it admin checklist
it administration
it management
it security
it security management
kb5089592
kb5092765
kb5096160
kb5096160 update
safe os dynamic update
secure boot
secure boot certificates
setup dynamic update
uefi certificates
uefifirmwareuefi trust chain
windows 10
windows 10 and 11
windows 11
windows 11 24h2
windows 11 26h1
windows 11 security
windows 11 servicing
windows recovery environment
windows security
windows servicing
windows update
winre recovery
winre update
wsus
Microsoft’s May 2026 Windows update begins a broad Secure Boot certificate transition for most Windows devices ahead of June 2026 expirations, adding new deployment machinery and, on Windows 11, a visible SecureBoot folder that has startled users who were not expecting it. This is not a cosmetic...
Microsoft’s June 2026 Secure Boot certificate deadline affects most Windows devices that still depend on Microsoft’s 2011-era boot trust certificates, and the immediate fix is installing current Windows updates, allowing the machine to restart, and leaving the new Secure Boot remediation files...
Microsoft’s Secure Boot certificate rollover is reaching ordinary Windows PCs in May 2026, with some devices getting a one-time extra restart as Windows Update installs replacement boot-trust certificates before the first 2011-era certificates begin expiring in June. The restart is the visible...
Microsoft has confirmed that some Windows 11 PCs may restart more than once while installing recent and upcoming updates in spring 2026 because Windows is applying Secure Boot 2023 certificate changes before older 2011 certificates begin expiring in June 2026. That is the plain answer to the...
Background
Microsoft’s Secure Boot certificate transition is not a simple “flip the switch” update. It is a staged trust-chain renewal for the UEFI Secure Boot ecosystem, replacing older 2011-era certificates with 2023 certificates so Windows devices can keep receiving future boot-chain...
enterprise compliance
exposure management
it security
microsoft defender
microsoft intune
secure boot
uefi certificates
uefifirmware
windows 10 esu
windows update
There is a strong case for treating BIOS and UEFI maintenance as a priority task in 2026, and the reason is not just vague “best practice” advice. Microsoft has confirmed that the original Secure Boot certificates introduced in 2011 begin expiring in June 2026, and devices that do not receive...
Microsoft’s Secure Boot certificate deadline is real, but the dramatic framing circulating online needs a little correction: this is not a sudden emergency that will break Windows in eight weeks, and it is not a blanket “security upgrade” every user must manually install. What Microsoft has...
Microsoft is using the Windows Security app to surface a deadline that has been quietly building for years: the original Secure Boot certificates issued in 2011 are now approaching expiration, and some devices will begin losing the ability to receive new boot-chain protections as early as June...
Microsoft’s new Secure Boot status alerts in Windows 11 are a small UI change with outsized security implications. By surfacing certificate health inside the Windows Security app, the company is trying to turn a nearly invisible firmware maintenance deadline into something ordinary users and IT...
Microsoft has done something small on the surface but important in practice: it is giving Windows users a clearer heads-up about the Secure Boot certificate transition that has been looming since the company first warned about it in 2024. The new Windows Security indicators are meant to tell...
certificate rollover
it admin alerts
it admins
secure boot
secure boot alerts
secure boot certificates
uefi certificates
uefifirmware
windows 10 esu
windows 11
windows 11 security
windows security
windows security app
windows update
Windows 11’s Secure Boot certificate transition is proving to be far more than a routine trust refresh. What began as a planned migration from Microsoft’s aging 2011 signing roots to the newer CA 2023 family has turned into a stress test for the entire PC firmware stack, exposing how unevenly...
Microsoft’s Secure Boot certificate deadline is no longer a distant infrastructure footnote. The company has confirmed that the 2011-era Secure Boot certificates used across Windows devices begin expiring in June 2026, and it is warning that systems which fail to receive the newer 2023...
Keeping firmware current is not optional for Windows 11 fleets — it’s a foundational maintenance task that affects security, compatibility and long‑term supportability. In practice that means understanding the difference between legacy BIOS and modern UEFI firmware, choosing the safest update...
Microsoft has issued a coordinated warning: the original Secure Boot certificates that have underpinned Windows platform integrity since 2011 are reaching the end of their lifecycle, and a deliberate, ecosystem-wide refresh is required before mid‑2026 to avoid a progressive loss of...
Microsoft has quietly begun a coordinated refresh of the Secure Boot certificate chain that underpins modern Windows platform security, rolling new 2023-era certificate authorities into firmware and Windows updates so devices running Windows 10 and Windows 11 can continue to trust and receive...
IT administrators now have practical, fleet-scale ways to check whether Windows devices are carrying the updated Secure Boot certificate chain and whether they’re ready to accept the upcoming Secure Boot updates — a crucial capability as Microsoft and OEMs rotate the platform’s cryptographic...