palmiq Speak to an expert

Secure Boot Certificate Expiration 2026: K-12 Guide

6 min read Microsoft

Secure Boot certificate expiration 2026 breaks nothing visibly. Here is the server, Hyper-V, firmware and imaging work school IT teams still need to scope.

A diverse team of business professionals working together in a modern office setting.

Secure Boot certificate expiration 2026 is the rare IT deadline that produces no help desk tickets. The June milestone has already passed. Nothing in your district or on your campus stopped booting, nobody called, and Windows updates kept installing.

That is exactly why it gets skipped — and why the October 2026 milestone is still ahead of a lot of school fleets with no owner assigned to it.

Here is what actually changed, what Windows Update handles for you, and what is still manual scoping work on servers, virtual machines, firmware, and imaging media.

What happens if Secure Boot certificates expire in 2026?

The device keeps working, and it quietly stops receiving one specific class of protection. Microsoft Support states that a device reaching the expiration date without the new certificates will still start and operate normally and will keep installing standard Windows updates — but it will no longer be able to receive new security protections for the early boot process.

No bricked laptops. No boot loops. That is the whole problem: there is no symptom to react to.

The early boot process is the part of startup Secure Boot exists to protect. The Key Exchange Key (KEK) is the credential that authorizes updates to a device’s Secure Boot allow list (DB) and deny list (DBX). Eclypsium, an independent firmware security vendor, describes the consequence plainly: devices that are not migrated retain their DB and DBX state indefinitely until an OEM firmware update embeds the new certificates, which means past revocations — including the ones issued for bootkits such as BlackLotus and BootHole — can no longer be extended.

In practice, a device with a frozen deny list is a device that cannot be told about the next bootkit.

Which Windows Secure Boot certificates expire in June and October 2026?

Three certificates originally issued in 2011, on a staggered schedule. Microsoft Corporation KEK CA 2011 and Microsoft Corporation UEFI CA 2011 expired in late June 2026. Microsoft Windows Production PCA 2011, which lives in the DB store, expires in October 2026.

Microsoft’s replacements include Windows UEFI CA 2023 and Microsoft Corporation KEK 2K CA 2023, per reporting from Malwarebytes. Microsoft Support notes that both the UEFI Secure Boot DB and the KEK need to be updated with the corresponding new 2023 versions — two stores, not one. Microsoft has described this as the first global large-scale certificate update to Secure Boot.

Sources differ on the exact day in June, so we are saying “late June 2026” rather than printing a date we cannot confirm against Microsoft’s own certificate documentation. For planning purposes, the month is what matters.

Does Windows Update install the new Secure Boot certificates automatically?

For many Windows 11 PCs, yes. 4sysops reports that Microsoft began automatically updating Secure Boot certificates on eligible Windows 11 systems with the January 2026 security update. Microsoft’s opt-in behavior is driven by the MicrosoftUpdateManagedOptIn registry key, and in a January 14, 2026 editor’s note Microsoft clarified that any non-zero value works.

“Eligible” is doing real work in that sentence. Devices that are unmanaged, not patching, or dependent on firmware their manufacturer never shipped do not get carried along automatically.

Newer hardware is largely pre-solved. Microsoft reports that many newer server hardware and VM versions built since 2024, and almost all released in 2025, already ship preconfigured with the 2023 Secure Boot certificates. Security Today reports that Windows PCs shipped since early 2024 already include the 2023 certificates preinstalled.

So the exposure concentrates in roughly 2012–2023 equipment. In K-12, that is most of the fleet outside the last two refresh cycles — plus the lab carts and library machines that quietly outlived their replacement plan.

Do Windows Servers and Generation 2 Hyper-V VMs get these updates automatically?

No, and this is the largest blind spot we see. 4sysops reports that unlike Windows 11, Windows Server does not receive these certificate updates automatically through Windows Update, and that administrators must manually deploy the 2023 replacement certificates to all applicable servers and Generation 2 virtual machines.

Microsoft published a separate Windows Server Secure Boot playbook in February 2026 for exactly this reason. Scope matters when you build a checklist: Microsoft states the playbook does not apply to Azure Local hosts, Windows PCs, or Generation 1 Hyper-V VMs, and notes that Generation 1 Hyper-V VMs do not support Secure Boot at all.

For a district running a student information system, a print server, and a handful of Generation 2 Hyper-V guests on aging hosts, that is a short but very real list of machines nobody has touched this year.

Do I need a BIOS or firmware update for the 2026 Secure Boot change?

Some devices will need one. Microsoft Support notes that while most devices receive the update automatically, some systems require additional firmware updates. Microsoft’s guidance describes close collaboration with the OEMs who provide Secure Boot firmware updates as essential.

Translated for a school environment with hardware from three or four manufacturers plus whatever arrived on a grant: this is per-vendor firmware tracking, not a single Microsoft patch. And Security Today reports that older hardware lacking OEM firmware support may never receive the update — which means part of the audit output is not a remediation plan, it is a refresh list.

Why doesn’t reimaging a device fix it?

Because the certificates do not live where your image lives. 4sysops notes that the Secure Boot databases — PK, KEK, DB, and DBX — are stored in non-volatile UEFI firmware variables on the motherboard, not on the OS disk.

Three practical consequences for a summer imaging cycle:

  • Reimaging a laptop does not update its Secure Boot certificates.
  • A motherboard replacement under warranty can reset a device you already fixed, so RMA returns need re-verification.
  • Firmware and BIOS updating is a separate workstream from OS patching, with its own tooling, approvals, and reboot windows.

Boot and imaging media deserve their own line item. Microsoft states that unprepared physical devices and VMs lose the ability to install Secure Boot security updates after June 2026 and will not trust third-party software signed with new certificates after June 2026.

What is UEFICA2023Status, and what should it say?

It is the registry value that tells you whether a device made the transition, and it should read “updated.” Security Today and Microsoft’s Windows IT Pro blog both point to it, and Microsoft publishes PowerShell inventory commands at aka.ms/GetSecureBoot for checking Secure Boot certificate status across Windows 11 and server estates.

Registry and PowerShell guidance here is version-sensitive. Validate anything you script against Microsoft’s current published guidance and run it through a pilot ring before touching the whole fleet.

If you use an outside IT provider, two deliverables tell you where you stand: a per-device report of UEFICA2023Status across servers, VMs, and endpoints, and a written list of devices whose manufacturer has not shipped supporting firmware.

What should a school IT team do with the remaining window?

Inventory first, remediate second, document third. The June milestone has passed, the October 2026 milestone has not, and no device in your building is going to raise its hand.

A workable scoping order:

  1. Managed Windows 11 endpoints — confirm the automatic path actually landed instead of assuming it did.
  2. Windows Server hosts and Generation 2 Hyper-V VMs — manual deployment, per Microsoft’s playbook.
  3. Firmware-dependent devices — tracked by manufacturer, with a hard stop where support has ended.
  4. Imaging and boot media — rebuilt and re-signed as needed.
  5. Devices that can never be remediated in place — moved into the refresh conversation with a documented reason.

On how long this buys you: Malwarebytes reported from a March 2026 Microsoft AMA that the new certificates are valid until 2038, with a separate post-quantum transition planned around 2030 for future hardware. Treat 2026 as a once-a-decade cleanup, not recurring overhead.

palmiq is a Microsoft Gold partner, and we run this as an audit-and-remediate engagement: inventory the fleet, apply the update where the platform and firmware support it, and hand back a documented list of what cannot be fixed in place. That last list is usually the most useful part of the report.

Most of this work depends on how clearly you can see and act on your endpoint fleet. If that visibility is the gap, join our session on managing your endpoints with Microsoft Intune.

Want this handled for you?

We run managed IT, security and backup for organizations that would rather not read another article about it.

Speak to an expert

or call 703-336-9700