HomeNewsletterCommunityToolsArchiveBlogAboutQuick Links Subscribe free
← Back to Blog
Security Windows AutopatchSecure BootUEFIIntuneJune 2026

Autopatch Is Alerting on Expiring Secure Boot Certificates — Here's What to Do

IA
Imran Awan
26 June 2026

If you manage Windows 11 devices through Windows Autopatch, you may have noticed a new alert appearing in your tenant: Secure Boot — certificate update required. This is not cosmetic. The older Microsoft Secure Boot certificates that many devices are still using are set to expire in 2026, and devices that do not move to the 2023 UEFI certificates will progressively lose the ability to receive new Secure Boot security protections.

Action required: Devices flagged by this alert have Secure Boot enabled but are using Microsoft Secure Boot DB and KEK certificates that expire in 2026. Both must be updated to the 2023 versions before the expiry date.

What the alert says

The alert in the Autopatch Alerts and Remediations view reads:

Alert: Secure Boot — certificate update required
Devices have Secure Boot enabled but are using Microsoft Secure Boot certificates that expire in 2026. Devices must be updated with the latest UEFI Secure Boot DB and KEK certificates (2023 versions).

Why Secure Boot certificates matter

Secure Boot uses a chain of trust enforced by UEFI firmware. At the core of this chain are two certificate stores:

The older versions of these certificates are expiring. Once expired, Microsoft will no longer be able to issue new revocations through those certificates — meaning compromised boot components cannot be blocked on devices still using the old chain. New Secure Boot protections that Microsoft ships through the update process will also be blocked.

The new Secure Boot Status Report

Microsoft shipped a new Secure Boot Status Report in Windows Autopatch (GA — May 19, 2026). You can find it in:

Intune admin center → Reports → Windows Autopatch → Secure Boot Status

The report shows which of your managed devices are:

Which devices are affected

Any device where the UEFI firmware has not yet been updated to include the new 2023 Secure Boot DB and KEK certificates. This is typically driven by UEFI/BIOS firmware updates from your device manufacturer. Devices that have had a firmware update that includes the 2023 certificates are not affected.

Likely fine
  • ✓ Devices with recent UEFI firmware updates
  • ✓ New hardware purchased after mid-2024
  • ✓ Devices that show compliant in the Secure Boot Status Report
Check these
  • ✗ Older hardware with no UEFI updates since 2022
  • ✗ Devices where BIOS/UEFI updates are blocked or unmanaged
  • ✗ Devices flagged in the Autopatch alert report

How to remediate

The fix is a UEFI firmware update from your device manufacturer that includes the 2023 Secure Boot DB and KEK certificates. Steps:

  1. Open the Secure Boot Status Report in Intune to identify affected devices and their models
  2. Check your device manufacturer's support site for UEFI/BIOS firmware updates for those models — Dell, HP, Lenovo, and Microsoft Surface have all published firmware updates that include the 2023 certificates
  3. Deploy the firmware update via Intune (Dell Command Update, HP BIOS Configuration Utility, Lenovo System Update, or manufacturer-provided Win32 app packages)
  4. Verify the device moves to compliant in the Secure Boot Status Report after the firmware update and restart
Microsoft Secure Score impact: Microsoft Secure Score now includes the recommendation "Ensure devices are updated to Secure Boot 2023 certificates and boot manager" (added April 2026). Remediating this alert will improve your Secure Score.

Official Microsoft sources

Share this post
LinkedIn X / Twitter Reddit Bluesky

More from EndpointWeekly

Security
Windows 11 June 2026 Security Alert: Secure Boot Certificate…
KB5094126 delivers two urgent security items: automatic migration from expiring 2011…
Security
The Windows 11 25H2 Security Baseline Is in Intune — Here Is…
The Windows 11 25H2 security baseline is now in Intune. Your existing profiles will not…
Security
CVE-2026-41091: Microsoft Defender Elevation of Privilege…
CVE-2026-41091 is a CVSS 7.8 elevation of privilege vulnerability in Microsoft Defender…