OEM

AppWizard
July 29, 2026
Purchasing a Samsung Galaxy Watch does not grant access to all its features unless paired with a Samsung Galaxy smartphone, despite owning a new Android device. The Samsung Health Monitor app, which includes critical health monitoring features like blood pressure, ECG, irregular heart rhythm, and sleep apnea monitoring, is only officially supported on Samsung smartphones. This app has been available since 2020 and is essential for detecting significant health indicators. Samsung's limitation on the app appears to be financially motivated, as it encourages users to buy Samsung smartphones. Other manufacturers do not impose similar restrictions, allowing their devices' full health features to work across different smartphone brands. Samsung could integrate Health Monitor features into the main Samsung Health app or make it available on the Play Store to increase accessibility, but it has not done so. Users of non-Samsung Android phones are unable to access these health features, which are critical for many individuals.
Winsage
July 29, 2026
Microsoft reassured Windows 11 and Windows 10 users that their PCs will continue to boot normally and receive updates even if they have not yet received the new Secure Boot 2023 certificates. The rollout of these certificates is expected to continue over the upcoming months. The initial Secure Boot certificate expired on June 24, 2026, and Microsoft has been replacing older 2011 certificates since 2024. The latest update, KB5101650, transitioned Windows 11 to OS builds 26200.8875 and 26100.8875 for versions 25H2 and 24H2, respectively. The 2023 certificates replace older certificates with modern cryptographic standards, allowing Microsoft to deliver DBX revocation updates without interruption. Devices using the 2011 KEK can only receive DBX updates signed with that key, which is no longer valid after June 24. Microsoft has been rolling out the 2023 certificates for the past two years, and many devices remained in a yellow or red status by the June deadline. To check Secure Boot status, users can navigate to Windows Security > Device Security. A green checkmark indicates successful application of the certificates, while yellow and red alerts indicate compatibility issues or firmware incompatibility. PCs that are older or operating in Legacy BIOS mode will not receive the updates. Windows 10 also receives Secure Boot updates, but enrollment in Extended Security Updates (ESU) is required.
Winsage
July 24, 2026
LG monitors were found to automatically install adware when connected to Windows PCs, leading to intrusive popups promoting applications like McAfee. In response to user backlash, Microsoft intervened and confirmed that LG has agreed to stop displaying McAfee ads in monitor popups. The adware was installed through a monitor app that downloaded automatically with the monitor connection, which previously included advertising popups. It is currently unclear if LG will permanently eliminate these ads.
Winsage
July 19, 2026
Microsoft held an OEM Secure Boot Office Hours event with manufacturers like Acer, Asus, Dell, and HP to discuss issues related to the Windows 11 Secure Boot 2023 certificate rollout. Many IT administrators left with unresolved concerns, particularly regarding Secure Boot certificate errors. Participants reported persistent problems, including failures of suggested solutions from official documentation to apply to their hardware configurations. Ed Tittel shared his experience with compliance issues related to CA-2023 certificates, noting that ASUS motherboards sometimes required Secure Boot to be disabled temporarily, while MSI models exhibited erratic behavior. ASRock systems needed manual key resets, and documentation was lacking. Devices from Dell, HP, and Lenovo performed better but still faced staggered rollouts and required multiple reboots for BIOS updates. Specific issues raised included HP's BitLocker recovery loop persisting even with the latest BIOS, challenges with legacy device support from HP, devices showing Secure Boot Status as Unknown, and failures in updating the KEK on HP EliteBooks. Some questions from IT administrators regarding Dell and HP went unanswered during the session. The experiences highlighted a trend of Secure Boot issues across multiple OEMs, not limited to a single vendor. IT administrators are advised to pilot updates on representative hardware, back up BitLocker recovery keys, and consult OEM-specific advisories. The unresolved issues reflect common challenges faced by users, indicating that problems with Secure Boot certificate deployments are widespread across various manufacturers.
Winsage
July 18, 2026
Microsoft held its OEM Secure Boot Office Hours event on July 15, where engineers collaborated with OEM representatives from companies like Acer, Asus, Cisco, Dell, and HP. IT administrators were able to ask live questions about the Secure Boot 2023 rollout. The discussion thread became a detailed technical record, especially following the expiration of the first certificates three weeks prior. Concerns raised by IT admins included BitLocker recovery loops, stuck confidence ratings, and unhelpful Intune error codes. Key facts include: - Devices offline for long periods will still receive the 2023 certificates upon reconnecting to Windows Update. - Devices with existing 2023 certificates in firmware will switch to the new boot manager after the latest Windows patches are installed. - A new script, Detect-SecureBootCertUpdateStatus.ps1, is available in Windows for checking certificate status. - BIOS updates may reset a device’s confidence rating to unrated, which is normal and does not indicate certificate failure. - Admins should edit the AvailableUpdates registry key, not the AvailableUpdatesPolicy, which is managed by Intune and Group Policy. - A licensing bug affecting AvailableUpdatesPolicy on devices upgraded from Pro to Enterprise was resolved by Microsoft in 2026. - BitLocker recovery is not typically linked to the certificate update process but may relate to firmware or PCR issues. - Dell and HP provided guidance on which BIOS versions include the 2023 certificates for their newer models. - Older HP EliteBook 840 G5 units require a manual update package for the new certificates. - Eligible devices can still receive the 2023 certificates in the future, and Surface devices released from 2024 onward come pre-equipped with them. - Microsoft confirmed that devices running 2011 certificates will not lose the ability to receive the 2023 chain. - The Microsoft Corporation KEK CA 2011 and Microsoft UEFI CA 2011 certificates have expired, with the Microsoft Windows Production PCA 2011 set to expire on October 19, 2026.
Winsage
July 15, 2026
Microsoft has blocked the Windows 11 July 2026 update (KB5101650) on certain Dell PCs due to issues causing unexpected shutdowns, diminished performance, excessive heat, and battery drain. The problems are linked to the Intel Innovation Platform Framework Processor Participant driver, which affects power management. The complications stem from an optional June 2026 update (KB5095093) that introduced changes impacting the performance of some Dell PCs. Microsoft has not provided a list of affected models but is working with Dell to resolve the issue. The July update has been preemptively blocked from installation on incompatible devices, and a resolution is expected soon.
Winsage
July 13, 2026
Microsoft has blocked Secure Boot updates on certain Windows 11 devices due to complications in transitioning from the 2011 Secure Boot certificate to the 2023 certificate. The rollout of the 2023 certificate has faced challenges, particularly on devices with firmware issues. HP is issuing a BIOS update to help with the installation of the latest Secure Boot certificate, and Microsoft is providing an update for users to verify their Secure Boot status. Users are advised to check for pending Windows updates and consult their OEM’s Secure Boot support page for compatibility information.
Winsage
July 12, 2026
This weekend, discussions emerged reflecting user frustration with Windows 11 and Microsoft products, particularly regarding updates. A recent cumulative update introduced a customizable Start menu but also fixed a bug that was consuming users' storage. Microsoft has mandated that users cannot ignore these updates, contributing to dissatisfaction. Many users are opting for third-party applications like Files and Win11Debloat as alternatives to the native Explorer app. The latest version of Win11Debloat, released on July 11, 2026, includes features to prevent automatic installation of unwanted OEM apps with drivers, a reboot warning for certain functions, and various fixes and enhancements. Notable additions include support for WhatIf in Get.ps1, disabling Windows Notifications, and improvements in handling registry-backup load failures. The app is available on its official GitHub repository or through the Neowin software stories page.
Winsage
July 10, 2026
Microsoft has acknowledged that some Windows 11 PCs are facing issues with Secure Boot certificate updates, which may fail to install or be blocked. The company is working with PC manufacturers to develop a patch, while users may need to take proactive measures if their certificates are obstructed. Microsoft has temporarily halted the rollout of Secure Boot for certain devices due to complications, and affected users will receive detailed error messages in the Windows Security app regarding their Secure Boot certificates. Secure Boot certificates issued in 2011 have expired, and Microsoft is replacing them with new certificates issued in 2023. Most modern hardware is already utilizing the new certificates, but some devices may have disabled Secure Boot or faulty firmware. Users can check their Secure Boot status in the Windows Security app. HP has confirmed that Secure Boot updates are being blocked on some of its PCs due to a BitLocker issue, which prevents the installation of new certificates. Microsoft has paused Secure Boot certificate updates for devices affected by known issues while collaborating with manufacturers to identify specific devices or firmware complications. A firmware update will be necessary for affected devices, but it is not yet available. The majority of PCs have received the Secure Boot certificates via Windows Update, but compatibility issues may prevent some devices from receiving the update. Older devices or those not among the OEM’s top-selling models may not receive updates if the UEFI firmware is unsupported. Secure Boot is a security feature required for Windows 11, preventing unauthorized software from executing at boot. While an expired Secure Boot certificate does not stop a PC from functioning, it may limit long-term security protection. Microsoft advises users not to disable Secure Boot, as it would compromise security further.
Search