Home / Companies / Fleet / Blog / Post Details
Content Deep Dive

Microsoft is rotating every Windows PC's Secure Boot keys. Is your fleet ready?

Blog post from Fleet

Post Details
Company
Date Published
Author
Harry Ravazzolo
Word Count
1,221
Company Posts That Month
13
Language
-
Hacker News Points
-
Post removed?
No
Summary

Windows PCs built since 2012 contain Secure Boot certificates that will start expiring in June 2026, affecting their ability to receive new signed boot updates and security features. Although devices will continue operating normally, they will lose the capacity to update vulnerable components and anti-bootkit lists. Microsoft's gradual rollout of replacement certificates is based on telemetry feedback, leaving some devices in limbo without clear updates. The process can stall if Secure Boot is disabled, if OEMs haven't shipped necessary updates, or if known firmware issues block the updates. Administrators can use tools like Microsoft Intune or registry modifications to manage the upgrade, ideally through a configuration profile for managed fleets. By deploying the secureboot_cert_update osquery extension, administrators can assess their devices' status, identify those needing action, and apply fixes before the expiration deadline.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.