Missed Windows 11 Secure Boot? Don’t panic, Microsoft is still pushing it in the coming months

July 29, 2026

Microsoft recently took to its Patch Tuesday changelog on July 14 to provide clarity to Windows 11 and Windows 10 users regarding the Secure Boot 2023 certificates. The tech giant reassured users that even if their PCs have not yet received the new certificates, they will continue to boot normally and receive regular updates. The rollout of these certificates is expected to continue over the upcoming months.

The initial Secure Boot certificate expired on June 24, 2026, and Microsoft has been actively replacing the older 2011 certificates since 2024. The latest confirmation was included in the KB5101650 update, which transitioned Windows 11 to OS builds 26200.8875 and 26100.8875 for versions 25H2 and 24H2, respectively.

Microsoft confirms new Secure Boot 2023 certificates will keep coming for months

In the release notes for KB5101650, Microsoft stated: “Devices that haven’t received the newer certificates will continue to start, and standard Windows updates will continue to install. We will continue to install the newer certificates via Windows updates in the coming months.” This means that users who have yet to receive the new Secure Boot certificates can rest assured that their systems will function as usual and may receive the updates with future Patch Tuesday releases, provided their devices are eligible.

Why does your PC need Secure Boot in the first place?

Secure Boot is a UEFI firmware feature designed to verify the digital signature of every piece of software attempting to load before Windows boots. This pre-boot check is crucial for protecting against stealthy malware, such as rootkits and bootkits, which can evade detection by antivirus tools by loading before the operating system. If a bootloader’s signature does not match the trusted signatures in Secure Boot, the firmware will refuse to execute it.

Reason to replace old Secure Boot certificates

The trustworthiness of Secure Boot relies on cryptographic certificates, which have been in place since Windows 8 and were issued in 2011. To prevent potential exploitation by attackers, these certificates come with expiration dates, and 15 years is a considerable duration for any cryptographic key to remain in service. Consequently, the 2011 certificates are being phased out in three stages:

  1. Microsoft Corporation KEK CA 2011 expired June 24, 2026
  2. Microsoft UEFI CA 2011 expired June 27
  3. Microsoft Windows Production PCA 2011 expires October 19, 2026

What do the 2023 Secure Boot certificates do?

The 2023 certificates replace the aforementioned three certificates with modern cryptographic standards. Once a device receives these new certificates, its boot manager will automatically switch over, allowing Microsoft to continue delivering DBX revocation updates—essentially a blacklist of compromised bootloaders—without interruption. Devices still using the 2011 KEK can only receive DBX updates signed with that key, which ceased to be valid after June 24.

For instance, the BlackLotus UEFI bootkit, discovered in 2023, exploited vulnerabilities in older bootloaders to bypass Secure Boot on fully patched Windows 11 systems until Microsoft revoked the compromised signatures. Without DBX updates, devices are at risk of losing protection against future threats.

Microsoft has to continue to install the newer certificates even after expiry

Over the past two years, Microsoft has been diligently rolling out the 2023 certificates. The June 2026 update elevated most supported PCs into what Microsoft refers to as the high confidence category, where the certificate applies automatically. However, a significant number of devices remained in a yellow or red status when the June deadline arrived, prompting Microsoft to include this reassurance in the July update changelog.

How to check your Secure Boot 2023 status right now

To verify your Secure Boot status, navigate to Windows Security > Device Security and scroll to the Secure Boot section. A green checkmark indicates that the certificates have been successfully applied.

<figure id="attachment88542″ aria-describedby=”caption-attachment-88542″ class=”wp-caption aligncenter”><figcaption id="caption-attachment88542″ class=”wp-caption-text”>The Secure Boot section showing the “fully updated” status with a green checkmark icon.

If you see a yellow warning, it means Windows requires additional compatibility data about your firmware before proceeding.

<figure id="attachment88543″ aria-describedby=”caption-attachment-88543″ class=”wp-caption aligncenter”><figcaption id="caption-attachment88543″ class=”wp-caption-text”>The Secure Boot section showing the “Not yet updated” status with a yellow warning icon.

A red alert indicates a firmware incompatibility blocking the update, necessitating a BIOS update from your manufacturer.

<figure id="attachment88544″ aria-describedby=”caption-attachment-88544″ class=”wp-caption aligncenter”><figcaption id="caption-attachment88544″ class=”wp-caption-text”>The Secure Boot section showing the “Requires action” status with a red stop icon.

If the Secure Boot section is absent, it may be due to Secure Boot being disabled in firmware, the system running in Legacy BIOS mode, or the use of a registry bypass on unsupported hardware.

Every Secure Boot update so far from Microsoft

The Windows Security app began displaying Secure Boot status following the April 2026 update. Microsoft confirmed that multiple reboots would be necessary after installing monthly updates, as writing new certificates to firmware, applying the updated boot manager, and booting with the new chain each require a separate restart. Additionally, a new SecureBoot folder appeared under C:Windows on eligible devices, containing PowerShell scripts for IT administrators.

The June 2026 Patch Tuesday update (KB5094126) expanded the high confidence category, pushing certificates to all eligible devices just hours before the June 24 KEK expiry.

IT admins are the ones dealing with Secure Boot headaches

Following the June 24 deadline, Microsoft hosted two Ask Microsoft Anything sessions for IT administrators, clarifying that the date was not a hard stop. All previously signed update payloads, including those using the manual registry key method, remain functional. What ceased was Microsoft’s ability to sign new revocation updates with the expired key.

By the end of June, major PC manufacturers, including ASUS, Dell, HP, Lenovo, MSI, Acer, Samsung, and LG, had released OEM Secure Boot transition guides detailing which models were covered. However, as highlighted in Windows Latest’s investigation, many Secure Boot 2023 updates encountered failures across various PCs due to inconsistent firmware handling industry-wide.

HP later acknowledged that a batch of its BIOS updates from April 2026 had caused Windows 11 PCs to become unresponsive, trapping commercial laptops and workstations in BitLocker recovery loops. Microsoft has since identified specific device and firmware combinations causing issues and has paused the rollout for those configurations.

To further assist IT admins, Microsoft organized an OEM Secure Boot Office Hours event on July 15, providing a platform for engineers from Microsoft and OEMs to address questions regarding confidence ratings, the AvailableUpdates registry key, and BitLocker recovery.

These PCs won’t get the Secure Boot 2023 certificates at all

OEMs have established firmware cutoffs based on device age. For instance, Dell is not providing BIOS updates for platforms that reached the end of their service life before January 1, 2026. HP’s commercial cutoff excludes PCs manufactured in 2018 or earlier, while Lenovo has similar rules for its oldest hardware. PCs operating in Legacy BIOS mode or with Secure Boot manually disabled will also not receive updates, as Microsoft’s process cannot apply certificates to firmware that is not running proper UEFI Secure Boot.

Furthermore, Windows 11 installations on unsupported hardware via registry bypass typically fall into this category, as Secure Boot is usually disabled or misconfigured by default on such setups. While these older PCs will continue to boot, they will not receive future DBX revocation updates.

Windows 10 gets Secure Boot 2023 update too, but only with ESU

Although Windows 10 has surpassed its support lifecycle, Microsoft continues to deliver Secure Boot certificate updates using the same code as Windows 11. The May 2026 update, KB5087544, introduced the same status indicators to the Windows Security app on Windows 10. However, enrollment in Extended Security Updates (ESU) is required to receive these updates. PCs not enrolled in ESU will not receive the 2023 certificates, regardless of their hardware age. Microsoft’s recent decision to extend Windows 10 ESU until October 2027 may provide additional motivation for users to enroll.

Windows 11 Secure Boot certificates will keep rolling out, here’s what to do

For most users, unless you are an IT administrator managing a large fleet of devices awaiting Secure Boot updates, there is no immediate concern regarding your PC. A simple check of your status through Windows Security > Device Security > Secure Boot is sufficient. Take action only if you encounter a red alert accompanied by a BIOS update available on your manufacturer’s website. For everyone else, it is advisable to allow Windows Update to run its course and complete the rollout in the coming months.

Winsage
Missed Windows 11 Secure Boot? Don't panic, Microsoft is still pushing it in the coming months