Windows 11 auto-replaces expiring Secure Boot certificates to preserve boot integrity

1 min read
Source: BleepingComputer
Windows 11 auto-replaces expiring Secure Boot certificates to preserve boot integrity
Photo: BleepingComputer
TL;DR Summary

Microsoft is automatically updating expiring Secure Boot certificates on eligible Windows 11 24H2/25H2 devices via quality updates, with a phased rollout to high-confidence machines; admins can also deploy certificates manually via registry, WinCS, or Group Policy. To avoid boot issues, devices must receive the updates before the June 2026 expiry, or risk losing Windows Boot Manager and Secure Boot protections; administrators should inventory devices, verify Secure Boot status, update firmware, then apply the certificate updates.

Share this article

Reading Insights

Total Reads

0

Unique Readers

4

Time Saved

3 min

vs 4 min read

Condensed

88%

63675 words

Want the full story? Read the original article

Read on BleepingComputer