Microsoft’s latest reassurance on the Windows 11 Secure Boot certificate transition is significant precisely because it removes the most alarming interpretation of the June 2026 expiration dates: a PC that has not yet received the newer 2023 certificates is not suddenly destined to fail at startup. In the July 14 cumulative update, KB5101650, Microsoft said devices still waiting for the newer certificates will continue to boot and receive ordinary Windows updates, while certificate deployment continues “in the coming months.” The same update brought Windows 11 versions 25H2 and 24H2 to builds 26200.8875 and 26100.8875, respectively. Microsoft’s KB5101650 release notes
That is welcome news for home users, small businesses, and IT teams dealing with a rollout that has been more complicated than a normal Windows servicing update. It does not, however, mean the new certificates are optional forever. The practical distinction is straightforward: an unremediated machine should keep functioning today, but it may gradually lose the ability to receive future protections for the most sensitive stage of the Windows startup chain.
For Windows enthusiasts, the right response is neither panic nor complacency. Check the status, make sure Windows and firmware updates are current, and let the staged process proceed unless Windows specifically identifies a firmware-related problem.
Secure Boot is a security feature built into UEFI firmware, the modern replacement for legacy PC BIOS. Before Windows begins loading, UEFI checks whether boot software is signed by a trusted authority. If a bootloader, firmware component, or other pre-operating-system code fails that trust check, Secure Boot can stop it from executing. Microsoft’s Secure Boot certificate overview
That early position in the startup process is what makes Secure Boot valuable. Conventional antivirus tools begin working only after the operating system has already started. A bootkit or rootkit that runs before Windows can potentially hide from protections that operate later in the boot process.
Microsoft’s current effort is about replacing the certificate authorities that have underpinned the Windows Secure Boot ecosystem since 2011. Those certificates were designed for a different era of hardware, threat intelligence, and cryptographic lifecycle management. Fifteen years is a long deployment horizon for any trust anchor, especially one used across billions of devices.
The certificates serve different functions within the Secure Boot trust chain:
These dates understandably created concern, but expiration does not operate like a timed self-destruct mechanism for an already working Windows installation. Existing systems can continue to boot because the relevant software and trust relationships were already established. The more important long-term concern is that Microsoft’s ability to deliver newly signed updates to boot-level trust data becomes constrained when an old signing authority has expired.
Microsoft explicitly says affected devices may continue to start normally and install standard Windows updates. The limitation is that they may no longer receive future protections for early boot components, including Windows Boot Manager changes, Secure Boot database updates, revocation-list updates, and mitigations for newly discovered boot-level vulnerabilities. Microsoft’s Windows client remediation guidance
That makes the situation less dramatic than a sudden mass boot failure, but more consequential than a harmless informational alert.
This reflects an important operational reality: Secure Boot updates touch firmware-resident variables, boot files, revocation databases, and recovery-sensitive configurations such as BitLocker. Microsoft cannot safely treat every Windows PC as identical.
Instead, the company is using a phased, data-driven rollout. Its Windows 10 servicing documentation describes “high confidence” device targeting data intended to expand coverage of PCs that have demonstrated sufficient successful-update signals. That is a sensible engineering strategy, even if it is frustrating for enthusiasts who expect a fully patched PC to receive every security-related update immediately. Microsoft’s Windows 10 May update documentation
For typical consumer devices, the message is clear:
Multiple restarts therefore do not automatically indicate that something has gone wrong. They are a logical consequence of changing security material that Windows cannot fully apply while the operating system is running.
Microsoft also began adding a
The interface turns a complicated firmware and certificate issue into a practical visual indicator.
For most users, this is the ideal end state. The 2023 trust chain is present, and Windows can continue servicing relevant boot components under the new signing infrastructure.
Yellow is not an instruction to start changing firmware settings. In many cases, the correct action is simply to remain current on Windows updates and wait for Microsoft’s rollout logic to establish that the device is eligible.
That restraint is a strength of the design. A forced firmware update is far more disruptive than a routine Windows patch, so Microsoft’s caution protects users from an avoidable boot or recovery incident.
The first place to look is the PC manufacturer’s support site for a BIOS or UEFI firmware update specifically applicable to the exact model. Firmware packages should never be downloaded from random driver sites, forums, or unofficial mirrors.
If Windows Security says the device does not support the automated certificate update because of hardware or firmware limitations, Microsoft’s advice is to contact the manufacturer. Microsoft’s support guidance for unsupported automated updates
A device that continues on the older certificate chain may still run Windows, browse the web, launch applications, and receive normal cumulative updates. Yet it may be unable to receive future DBX updates. The DBX, or Disallowed Signature Database, is Secure Boot’s revocation list: it blocks bootloaders and related components that have been identified as untrustworthy or vulnerable. Microsoft’s explanation of DB, DBX, and KEK roles
This is especially relevant because boot-level threats are not theoretical. The BlackLotus UEFI bootkit demonstrated how attackers could abuse known vulnerabilities in signed boot components to undermine Secure Boot protections on patched Windows systems until vulnerable signatures were revoked. The lesson is not that every older PC is currently infected; it is that keeping revocation capability current matters when attackers find a way around an existing trusted component.
Microsoft’s current guidance summarizes the risk accurately: old-certificate devices may retain normal functionality but lose access to future boot-manager, database, revocation-list, and early-boot vulnerability mitigations. Microsoft’s Windows client Secure Boot update guidance
For Windows 11 enthusiasts, that distinction should shape priorities. There is no need to treat a yellow badge as an emergency, but a red message tied to firmware limitations should not be dismissed indefinitely.
That creates a dependency chain:
Microsoft’s Windows client troubleshooting material specifically identifies older firmware as a higher-risk factor. It recommends installing OEM firmware updates, testing representative device groups before broad deployment, and monitoring for Boot Manager errors, startup hangs, BitLocker recovery prompts, and even boot failures in affected environments. Microsoft’s enterprise remediation recommendations
That is not a reason to avoid all firmware updates. It is a reason to treat them as firmware updates: confirm the recovery-key process first, use manufacturer-supported packages, ensure stable AC power on laptops, and avoid interrupting the flashing process.
For organizations, Microsoft’s advice to pilot certificate updates across different OEMs, BIOS versions, and BitLocker configurations is not bureaucratic caution. It is a practical defense against turning a security improvement into an unexpected recovery event across a large fleet. Microsoft’s pilot-deployment guidance
A useful registry indicator is:
When the process is complete, Microsoft documents
In the System event log, the important event IDs include:
The broader lesson is that an organization should not equate “Windows is patched” with “Secure Boot transition is complete.” Inventory must account for firmware model, firmware revision, certificate state, boot configuration, and BitLocker recovery readiness.
The complication is support status. A Windows 10 PC that is no longer receiving monthly updates cannot rely on routine servicing to deliver the Secure Boot transition. For systems covered by Extended Security Updates, the normal Windows Update path remains relevant; for unsupported systems outside that update channel, the practical options narrow considerably.
That does not mean every older Windows 10 PC will immediately stop working. Microsoft’s position remains that devices without the new certificates can continue to boot and receive ordinary updates where such updates are still available. Microsoft’s Secure Boot certificate expiration guidance
Still, this is another reason not to regard the Secure Boot issue in isolation. Windows lifecycle support, firmware support, and boot-chain security are now closely connected.
The remaining risk is not an immediate Windows 11 apocalypse. It is a slower erosion of early-boot defenses on PCs that cannot move beyond the 2011 trust chain. Keeping Windows current, applying appropriate manufacturer firmware updates, and responding thoughtfully to a red Secure Boot warning remains the most reliable route to preserving both normal operation and the security protections Secure Boot was designed to provide.
That is welcome news for home users, small businesses, and IT teams dealing with a rollout that has been more complicated than a normal Windows servicing update. It does not, however, mean the new certificates are optional forever. The practical distinction is straightforward: an unremediated machine should keep functioning today, but it may gradually lose the ability to receive future protections for the most sensitive stage of the Windows startup chain.
For Windows enthusiasts, the right response is neither panic nor complacency. Check the status, make sure Windows and firmware updates are current, and let the staged process proceed unless Windows specifically identifies a firmware-related problem.
Why This Secure Boot Update Matters
Secure Boot is a security feature built into UEFI firmware, the modern replacement for legacy PC BIOS. Before Windows begins loading, UEFI checks whether boot software is signed by a trusted authority. If a bootloader, firmware component, or other pre-operating-system code fails that trust check, Secure Boot can stop it from executing. Microsoft’s Secure Boot certificate overviewThat early position in the startup process is what makes Secure Boot valuable. Conventional antivirus tools begin working only after the operating system has already started. A bootkit or rootkit that runs before Windows can potentially hide from protections that operate later in the boot process.
Microsoft’s current effort is about replacing the certificate authorities that have underpinned the Windows Secure Boot ecosystem since 2011. Those certificates were designed for a different era of hardware, threat intelligence, and cryptographic lifecycle management. Fifteen years is a long deployment horizon for any trust anchor, especially one used across billions of devices.
The certificates serve different functions within the Secure Boot trust chain:
- Microsoft Corporation KEK CA 2011 is a Key Enrollment Key authority used to authorize updates to the Secure Boot signature databases.
- Microsoft Windows Production PCA 2011 signs the Windows bootloader.
- Microsoft UEFI CA 2011 is used for third-party bootloaders and EFI applications.
- The newer 2023 certificates split some responsibilities more finely, including separating third-party bootloader trust from option-ROM trust. Microsoft’s certificate table and terminology
The June and October deadlines explained
The most immediate expiration was for Microsoft Corporation KEK CA 2011, which expired on June 24, 2026. Microsoft UEFI CA 2011 followed on June 27, 2026, while the Microsoft Windows Production PCA 2011 certificate is due to expire on October 19, 2026. Microsoft’s Azure Stack certificate guidance lists the precise dates and replacement certificatesThese dates understandably created concern, but expiration does not operate like a timed self-destruct mechanism for an already working Windows installation. Existing systems can continue to boot because the relevant software and trust relationships were already established. The more important long-term concern is that Microsoft’s ability to deliver newly signed updates to boot-level trust data becomes constrained when an old signing authority has expired.
Microsoft explicitly says affected devices may continue to start normally and install standard Windows updates. The limitation is that they may no longer receive future protections for early boot components, including Windows Boot Manager changes, Secure Boot database updates, revocation-list updates, and mitigations for newly discovered boot-level vulnerabilities. Microsoft’s Windows client remediation guidance
That makes the situation less dramatic than a sudden mass boot failure, but more consequential than a harmless informational alert.
What Microsoft Has Actually Promised
The key development is Microsoft’s continuing commitment to the deployment process. In KB5101650, the company again stated that PCs which have not received the newer certificates will still start, will still receive normal Windows updates, and will continue to receive the 2023 certificate package through Windows Update over the coming months. Microsoft’s July 14 Windows 11 update notesThis reflects an important operational reality: Secure Boot updates touch firmware-resident variables, boot files, revocation databases, and recovery-sensitive configurations such as BitLocker. Microsoft cannot safely treat every Windows PC as identical.
Instead, the company is using a phased, data-driven rollout. Its Windows 10 servicing documentation describes “high confidence” device targeting data intended to expand coverage of PCs that have demonstrated sufficient successful-update signals. That is a sensible engineering strategy, even if it is frustrating for enthusiasts who expect a fully patched PC to receive every security-related update immediately. Microsoft’s Windows 10 May update documentation
For typical consumer devices, the message is clear:
- Keep Windows Update enabled.
- Install ordinary monthly cumulative updates.
- Restart when requested.
- Keep the PC connected to the internet.
- Update BIOS or UEFI firmware if the manufacturer provides an applicable release.
Why several restarts may be normal
Secure Boot certificate deployment can require more than one reboot. The update process may need to write new firmware variables, update the Windows boot manager, and then validate startup under the updated trust chain.Multiple restarts therefore do not automatically indicate that something has gone wrong. They are a logical consequence of changing security material that Windows cannot fully apply while the operating system is running.
Microsoft also began adding a
C:\Windows\SecureBoot folder on eligible systems. The company describes the contents as example scripts intended to help organizations detect certificate status and automate a safe enterprise rollout; it is not evidence of malware or an accidental system folder. Microsoft’s documentation for KB5087544How to Check Secure Boot Certificate Status in Windows 11
Microsoft’s best consumer-facing improvement may be the status display built into Windows Security. Starting in April 2026, Windows Security began showing Secure Boot certificate information under Device security > Secure Boot. Microsoft’s Windows Security status guideThe interface turns a complicated firmware and certificate issue into a practical visual indicator.
Green: fully updated
A green check mark means the device has received the necessary Secure Boot certificate updates and the updated boot manager is installed. No additional action should be required. Microsoft’s explanation of the green Secure Boot stateFor most users, this is the ideal end state. The 2023 trust chain is present, and Windows can continue servicing relevant boot components under the new signing infrastructure.
Yellow: not yet updated or awaiting compatibility data
A yellow warning generally means Windows is still using an older trust configuration, needs additional validation, or has not yet delivered the update automatically. It can also appear when the rollout has been paused for a known device-specific issue. Microsoft’s status-message tableYellow is not an instruction to start changing firmware settings. In many cases, the correct action is simply to remain current on Windows updates and wait for Microsoft’s rollout logic to establish that the device is eligible.
That restraint is a strength of the design. A forced firmware update is far more disruptive than a routine Windows patch, so Microsoft’s caution protects users from an avoidable boot or recovery incident.
Red: action is required
A red status is more serious. Microsoft uses it for devices that cannot receive a necessary Windows boot-experience security update under their current configuration, particularly after a relevant vulnerability requires protection that cannot be delivered through the older certificate chain. Microsoft’s red “Requires action” guidanceThe first place to look is the PC manufacturer’s support site for a BIOS or UEFI firmware update specifically applicable to the exact model. Firmware packages should never be downloaded from random driver sites, forums, or unofficial mirrors.
If Windows Security says the device does not support the automated certificate update because of hardware or firmware limitations, Microsoft’s advice is to contact the manufacturer. Microsoft’s support guidance for unsupported automated updates
The Security Cost of Staying on the 2011 Chain
The most important nuance in this story is that booting normally is not the same as remaining fully protected.A device that continues on the older certificate chain may still run Windows, browse the web, launch applications, and receive normal cumulative updates. Yet it may be unable to receive future DBX updates. The DBX, or Disallowed Signature Database, is Secure Boot’s revocation list: it blocks bootloaders and related components that have been identified as untrustworthy or vulnerable. Microsoft’s explanation of DB, DBX, and KEK roles
This is especially relevant because boot-level threats are not theoretical. The BlackLotus UEFI bootkit demonstrated how attackers could abuse known vulnerabilities in signed boot components to undermine Secure Boot protections on patched Windows systems until vulnerable signatures were revoked. The lesson is not that every older PC is currently infected; it is that keeping revocation capability current matters when attackers find a way around an existing trusted component.
Microsoft’s current guidance summarizes the risk accurately: old-certificate devices may retain normal functionality but lose access to future boot-manager, database, revocation-list, and early-boot vulnerability mitigations. Microsoft’s Windows client Secure Boot update guidance
For Windows 11 enthusiasts, that distinction should shape priorities. There is no need to treat a yellow badge as an emergency, but a red message tied to firmware limitations should not be dismissed indefinitely.
Why OEM Firmware Is the Hard Part
Windows Update can deploy software, but it cannot override every quirk of years of PC firmware implementations. Secure Boot keys and databases live in UEFI firmware, where motherboard vendors and device manufacturers retain substantial control over storage, behavior, and compatibility.That creates a dependency chain:
- Microsoft prepares new certificate material and updated boot components.
- Windows Update identifies eligible devices.
- The firmware must correctly accept and preserve the new keys.
- The device must successfully reboot into the revised trust configuration.
- BitLocker and other recovery-sensitive components must recognize the expected boot state.
Microsoft’s Windows client troubleshooting material specifically identifies older firmware as a higher-risk factor. It recommends installing OEM firmware updates, testing representative device groups before broad deployment, and monitoring for Boot Manager errors, startup hangs, BitLocker recovery prompts, and even boot failures in affected environments. Microsoft’s enterprise remediation recommendations
BitLocker deserves special attention
Firmware and Secure Boot changes can affect the measurements BitLocker uses to decide whether a system’s startup environment remains trusted. In a well-managed rollout, recovery keys should already be available through the Microsoft account, Entra ID, Active Directory, or the organization’s escrow process.That is not a reason to avoid all firmware updates. It is a reason to treat them as firmware updates: confirm the recovery-key process first, use manufacturer-supported packages, ensure stable AC power on laptops, and avoid interrupting the flashing process.
For organizations, Microsoft’s advice to pilot certificate updates across different OEMs, BIOS versions, and BitLocker configurations is not bureaucratic caution. It is a practical defense against turning a security improvement into an unexpected recovery event across a large fleet. Microsoft’s pilot-deployment guidance
What IT Administrators Should Monitor
The consumer-facing Windows Security display is useful, but enterprise administrators need stronger inventory and troubleshooting signals. Microsoft’s guidance points to registry state and Windows Event Viewer entries for determining whether a device has received the remediation.A useful registry indicator is:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBootWhen the process is complete, Microsoft documents
UEFICA2023Status = Updated as a success indicator. Administrators can also inspect the Secure Boot servicing area for error values. Microsoft’s troubleshooting documentationIn the System event log, the important event IDs include:
- 1808 — successful update.
- 1801 — incomplete update, often requiring a restart or further investigation.
- 1800 — restart required.
- 1803 — missing KEK.
- 1795 — firmware error during the update process. Microsoft’s Event Viewer reference
The broader lesson is that an organization should not equate “Windows is patched” with “Secure Boot transition is complete.” Inventory must account for firmware model, firmware revision, certificate state, boot configuration, and BitLocker recovery readiness.
Windows 10: The ESU Catch
Windows 10 is part of the same Secure Boot certificate transition, and Microsoft added Secure Boot status reporting to supported Windows 10 branches in 2026. Its May cumulative update described dynamic status reporting in Windows Security and expanded high-confidence targeting for devices eligible to receive the 2023 certificates. Microsoft’s Windows 10 KB5087544 release notesThe complication is support status. A Windows 10 PC that is no longer receiving monthly updates cannot rely on routine servicing to deliver the Secure Boot transition. For systems covered by Extended Security Updates, the normal Windows Update path remains relevant; for unsupported systems outside that update channel, the practical options narrow considerably.
That does not mean every older Windows 10 PC will immediately stop working. Microsoft’s position remains that devices without the new certificates can continue to boot and receive ordinary updates where such updates are still available. Microsoft’s Secure Boot certificate expiration guidance
Still, this is another reason not to regard the Secure Boot issue in isolation. Windows lifecycle support, firmware support, and boot-chain security are now closely connected.
The Sensible Next Steps for Windows 11 Users
For the overwhelming majority of Windows 11 users, the best approach is calm, routine maintenance rather than aggressive intervention.- Open Windows Security. Go to Device security > Secure Boot and read the current state.
- Install current Windows updates. The continuing rollout depends on Windows servicing, so pausing updates indefinitely is counterproductive.
- Restart when prompted. More than one restart can be part of the normal certificate and boot-manager transition.
- Check for an OEM BIOS or UEFI update. Do this particularly if Windows Security shows a red warning or identifies a firmware limitation.
- Save or confirm BitLocker recovery access before firmware work. Make sure the recovery key is accessible through the appropriate personal or organizational channel.
- Do not reset Secure Boot keys casually. Restoring firmware defaults or manually deleting keys can create complications for Windows, Linux, custom bootloaders, or device-specific firmware settings.
- Treat yellow as a monitoring state, not a crisis. Microsoft is deliberately continuing staged delivery for eligible devices.
The remaining risk is not an immediate Windows 11 apocalypse. It is a slower erosion of early-boot defenses on PCs that cannot move beyond the 2011 trust chain. Keeping Windows current, applying appropriate manufacturer firmware updates, and responding thoughtfully to a red Secure Boot warning remains the most reliable route to preserving both normal operation and the security protections Secure Boot was designed to provide.
References
- Primary source: Windows Latest
Published: 2026-07-28T19:17:15+00:00
Loading…
www.windowslatest.com - Official source: support.microsoft.com
Loading…
support.microsoft.com - Official source: learn.microsoft.com
Loading…
learn.microsoft.com - Official source: techcommunity.microsoft.com
Loading…
techcommunity.microsoft.com - Related coverage: neowin.net
Loading…
www.neowin.net - Related coverage: windowscentral.com
Microsoft blocks Windows 11 KB5101650 update for Dell PCs due to "unexpected shutdowns, poor performance, increased heat, and battery drain" | Windows Central
Microsoft has blocked the KB5101650 update after Dell informed the company that a recent change is causing some of its PCs to suffer from major instability issues.www.windowscentral.com