
Windows 11 auto-replaces expiring Secure Boot certificates to preserve boot integrity
Microsoft is automatically updating expiring Secure Boot certificates on eligible Windows 11 24H2/25H2 devices via quality updates, with a phased rollout to high-confidence machines; admins can also deploy certificates manually via registry, WinCS, or Group Policy. To avoid boot issues, devices must receive the updates before the June 2026 expiry, or risk losing Windows Boot Manager and Secure Boot protections; administrators should inventory devices, verify Secure Boot status, update firmware, then apply the certificate updates.
