Windows Devices For Home Users Businesses And Schools With Microsoft Managed Updates 29bfd847 5855 49f1 Bb94 E18497fe2315
Note In this article, we also refer to Windows devices as Windows systems or PCs.
To help keep your Windows device secure, Microsoft is updating the certificates used by Secure Boot—a security feature that helps protect your devices from malware during startup. These certificates, originally issued in 2011, are set to expire starting in June 2026. To stay protected, your operating system (OS) needs to receive a new set of certificates before then.
Secure Boot helps ensure that your device only runs trusted software when it starts up. If the Secure Boot certificates expire, your device will no longer receive future security fixes related to Windows boot manager updates or Secure Boot, which compromises the security of the device.
That is why Microsoft is rolling out new certificates now, well ahead of the June 2026 expiration date.
If you use a Windows 10 or Windows 11 device that runs , Pro or Education edition, and you get updates automatically from Microsoft (like most people do), then yes—this is applicable for your device.
The good news is that the new 2023 certificates will be delivered to your device through regular Windows Update channels. For most users on supported Windows systems, no action is needed.
The new certificate updates will continue gradually through June 2026. Microsoft is starting with and Pro edition systems first to ensure a smooth and safe transition.
On supported Windows systems, in many cases, no action is needed. Just make sure that:
Your device is running a supported version of Windows 10 or Windows 11
Windows updates are not paused.
Secure Boot is enabled (it usually is by default on newer systems).
To check if Secure Boot is turned on:
If Secure Boot is currently disabled, please consult your device manufacturer for information when your device firmware will be updated to include the latest Secure Boot configuration from Microsoft. We recommend checking this before making any changes to your Secure Boot settings. For more information, please see Windows 11 and Secure Boot .
Unfortunately, in a few cases, your device might not start, or you might experience a BitLocker recovery situation when receiving the new certificates. We can help you recover from these situations.
Secure Boot helps to make sure that your device starts (boots) using only firmware that is trusted by the manufacturer. You can usually disable Secure Boot through the device firmware (BIOS) menus, but the way you disable it varies by device manufacturer.
Note If you have trouble disabling Secure Boot, we recommend that you your device manufacturer for help.
The following are general steps to disable Secure Boot:
Open the System BIOS by doing one of the following:
Find the Secure Boot setting in the BIOS . If possible, set it to Disabled . This option is usually in either the Security tab, the Boot tab, or the Authentication tab.
Save changes and then exit. The device should restart.
For more information, see Disable Secure Boot .
To recovery from this situation, enter the BitLocker Recovery Key. On the BitLocker recovery screen, type the 48-digit recovery key (hyphens are optional). If correct, your device will start into Windows.
For more information, see the following resources:
BitLocker recovery overview
BitLocker recovery process
Find your BitLocker recovery key
Get recovery key for Windows
How to fix BitLocker recovery key if device is not linked to MS account
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
