{"id":514664,"date":"2026-01-14T04:11:17","date_gmt":"2026-01-14T04:11:17","guid":{"rendered":"https:\/\/www.europesays.com\/us\/514664\/"},"modified":"2026-01-14T04:11:17","modified_gmt":"2026-01-14T04:11:17","slug":"new-windows-updates-replace-expiring-secure-boot-certificates","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/us\/514664\/","title":{"rendered":"New Windows updates replace expiring Secure Boot certificates"},"content":{"rendered":"<p style=\"text-align:center\"><img loading=\"lazy\" decoding=\"async\" alt=\"Windows\" height=\"900\" src=\"https:\/\/www.europesays.com\/us\/wp-content\/uploads\/2026\/01\/Windows-headpic.jpg\" width=\"1600\"\/><\/p>\n<p>Microsoft has started automatically replacing expiring Secure Boot certificates on eligible Windows 11 24H2 and 25H2 systems.<\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/tag\/Secure-Boot\/\" target=\"_blank\" rel=\"nofollow noopener\">Secure Boot<\/a> is a security feature that blocks malicious software (like rootkit malware)\u00a0from executing during the system startup sequence by ensuring that only trusted bootloaders can load on computers with\u00a0UEFI firmware.\u00a0This is done by checking the software&#8217;s digital signature against a set of trusted digital certificates that are stored in the device&#8217;s firmware.<\/p>\n<p>Today&#8217;s announcement comes after Microsoft <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/windows-itpro-blog\/secure-boot-playbook-for-certificates-expiring-in-2026\/4469235\" target=\"_blank\" rel=\"nofollow noopener\">warned IT admins<\/a> in November to update the\u00a0security certificates used to validate UEFI firmware before they expire.<\/p>\n<p> <a href=\"https:\/\/www.wiz.io\/lp\/securing-ai-agents-101?utm_source=bleepingcomputer&amp;utm_medium=display&amp;utm_campaign=FY26Q3_INB_FORM_Securing-AI-Agents-101&amp;sfcid=701Py00000RTEWMIA5&amp;utm_term=FY26Q4-bleepingcomputer-970x250&amp;utm_content=AIAgents101\" rel=\"nofollow noopener\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/us\/wp-content\/uploads\/2026\/01\/Securing-AI-Agents-970x250.png\" alt=\"Wiz\" style=\"margin-top: 0px;\"\/><\/a><\/p>\n<p>&#8220;Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. This might affect the ability of certain personal and business devices to boot securely if not updated in time,&#8221; <a href=\"https:\/\/x.com\/WindowsUpdate\/status\/2011140448274800881\" target=\"_blank\" rel=\"nofollow noopener\">Microsoft said<\/a>.<\/p>\n<p>&#8220;Starting with this update, Windows quality updates include a subset of high confidence device targeting data that identifies devices eligible to automatically receive new Secure Boot certificates. Devices will receive the new certificates only after demonstrating sufficient successful update signals, ensuring a safe and phased deployment,&#8221; it <a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/january-13-2026-kb5074109-os-builds-26200-7623-and-26100-7623-3ec427dd-6fc4-4c32-a471-83504dd081cb#:~:text=%5BSecure%20Boot%5D%C2%A0Starting%20with%20this%20update\" target=\"_blank\" rel=\"nofollow noopener\">added<\/a>.<\/p>\n<p>IT admins who want to maintain Secure Boot functionality and ensure their endpoints&#8217; security should install the new certificates before the old certificates expire this summer.<\/p>\n<p>Failing to do so could result in losing Windows Boot Manager\u00a0and Secure Boot protections, as security updates for pre-boot components will no longer be provided to Secure Boot-enabled devices.<\/p>\n<p>&#8220;Without updates, the Secure Boot-enabled Windows devices risk not receiving security updates or trusting new boot loaders which will compromise both serviceability and security,&#8221; Microsoft <a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/windows-secure-boot-certificate-expiration-and-ca-updates-7ff40d33-95dc-4c3c-8725-a9b95457578e\" target=\"_blank\" rel=\"nofollow noopener\">explains<\/a>.<\/p>\n<p>While Microsoft will automatically update high-confidence devices via Windows Update, organizations can also deploy Secure Boot certificates using registry keys, the Windows Configuration System (WinCS), and Group Policy settings.<\/p>\n<p>According to <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/windows-itpro-blog\/secure-boot-playbook-for-certificates-expiring-in-2026\/4469235\" target=\"_blank\" rel=\"nofollow noopener\">Microsoft&#8217;s Secure Boot playbook<\/a>, admins should first inventory their device fleets, verify Secure Boot status using PowerShell commands or registry keys, and then apply manufacturer firmware updates before installing Microsoft&#8217;s certificate updates.<\/p>\n<p>        <a href=\"https:\/\/www.wiz.io\/reports\/ciso-security-budget-benchmark-2026?utm_source=bleepingcomputer&amp;utm_medium=display&amp;utm_campaign=FY26Q3_INB_FORM_2026-CISO-Budget-Benchmark-Report&amp;sfcid=701Py00000TCR5YIAX&amp;utm_term=FY26Q4-bleepingcomputer-article-ad&amp;utm_content=2026-CISO-Budget\" target=\"_blank\" rel=\"noopener sponsored\"><br \/>\n            <img decoding=\"async\" src=\"https:\/\/www.europesays.com\/us\/wp-content\/uploads\/2025\/11\/2026-CISO-Spend_512x512.png\" alt=\"Wiz\"\/><\/a><\/p>\n<p>It&#8217;s budget season! Over 300 CISOs and security leaders have shared how they&#8217;re planning, spending, and prioritizing for the year ahead. This report compiles their insights, allowing readers to benchmark strategies, identify emerging trends, and compare their priorities as they head into 2026.<\/p>\n<p>Learn how top leaders are turning investment into measurable impact.<\/p>\n<p>        <a href=\"https:\/\/www.wiz.io\/reports\/ciso-security-budget-benchmark-2026?utm_source=bleepingcomputer&amp;utm_medium=display&amp;utm_campaign=FY26Q3_INB_FORM_2026-CISO-Budget-Benchmark-Report&amp;sfcid=701Py00000TCR5YIAX&amp;utm_term=FY26Q4-bleepingcomputer-article-ad&amp;utm_content=2026-CISO-Budget\" target=\"_blank\" rel=\"noopener sponsored\">Download Now<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"Microsoft has started automatically replacing expiring Secure Boot certificates on eligible Windows 11 24H2 and 25H2 systems. Secure&hellip;\n","protected":false},"author":3,"featured_media":514665,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[158,67,132,68],"class_list":{"0":"post-514664","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-technology","8":"tag-technology","9":"tag-united-states","10":"tag-unitedstates","11":"tag-us"},"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@us\/115891502222542945","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts\/514664","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/comments?post=514664"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts\/514664\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/media\/514665"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/media?parent=514664"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/categories?post=514664"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/tags?post=514664"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}