How to Update the Windows Boot Manager Certificate Before October 19, 2026
Microsoft is transitioning Windows devices away from older Secure Boot certificates issued in 2011. One of the most important dates for IT teams is October 19, 2026, when the Microsoft Windows Production PCA 2011 certificate expires. This certificate is associated with signing the Windows boot loader, and Microsoft has introduced the Windows UEFI CA 2023 certificate as its replacement.
For businesses managing dozens, hundreds, or thousands of Windows endpoints, this should not be treated as simply another Windows Update task. The challenge is determining which devices have already received the required Secure Boot certificate updates, which devices are blocked, whether firmware needs to be updated, and whether BitLocker or other security controls could complicate remediation.
Microsoft says most devices receive Secure Boot certificate updates automatically, but some systems may require additional action, including OEM firmware updates. Microsoft recommends reviewing the device estate, updating firmware where necessary, piloting changes, and then deploying through supported enterprise management methods such as Intune, Group Policy, Registry or Windows CSP.
For organizations that rely on Microsoft 365, Intune, Windows 11, BitLocker, Entra ID and managed endpoints, the practical objective is simple:
Identify affected devices → validate their Secure Boot state → update prerequisites → deploy the new certificates → verify remediation → document exceptions.
Need help identifying affected Windows devices?
Get a Windows Secure Boot & Endpoint Security Assessment
Let Synergy IT review your Windows environment, identify certificate-update risks, assess endpoint readiness, and help your IT team build a remediation plan before the October 19, 2026 deadline. Request a Business IT Security Assessment.
Why Is the Windows Boot Manager Certificate Expiring on October 19, 2026?
The expiration is part of Microsoft’s broader transition from 2011 Secure Boot certificates to newer 2023 certificates.
Secure Boot is designed to establish trust before Windows loads. During startup, UEFI firmware validates boot software against trusted certificates and databases. This helps prevent unauthorized or malicious software from executing before the operating system starts.
Microsoft’s certificate transition affects several components:
| Older Certificate | Expiration | Replacement | Purpose |
|---|---|---|---|
| Microsoft Corporation KEK CA 2011 | June 24, 2026 | Microsoft Corporation KEK 2K CA 2023 | Signs DB/DBX updates |
| Microsoft Windows Production PCA 2011 | October 19, 2026 | Windows UEFI CA 2023 | Windows boot loader signing |
| Microsoft UEFI CA 2011 | June 27, 2026 | Microsoft UEFI CA 2023 | Third-party bootloaders/EFI applications |
| Microsoft UEFI CA 2011 | June 27, 2026 | Microsoft Option ROM UEFI CA 2023 | Option ROM signing |
The important business distinction is that certificate expiration does not necessarily mean every affected PC will suddenly stop booting on October 19.
Microsoft states that affected devices can continue starting Windows and receiving standard Windows updates. The bigger issue is that they may no longer be able to receive future security protections for early-boot components, including Windows Boot Manager updates, Secure Boot database/revocation updates and fixes for newly discovered boot-level vulnerabilities.
That makes this a security-maintenance and endpoint-management problem, rather than simply a “Windows won’t start” problem.
Not sure whether your business endpoints are affected?
Don’t wait for the expiration date to find out.
Have your Windows fleet assessed for Secure Boot certificate status, firmware readiness and remediation requirements. Check Your Windows Security Readiness.
What Happens If Your Business Does Not Update the Windows Boot Manager Certificate?
The biggest misconception is that every PC with an outdated certificate will immediately become unbootable.That’s not what Microsoft currently describes.
Instead, an affected device may continue operating normally while gradually losing protection for the early boot chain. Microsoft explains that standard Windows updates can continue, but future updates involving Windows Boot Manager, Secure Boot databases, revocation lists and other boot-level protections may not be available to devices that have not transitioned appropriately.
For an individual computer, that may initially seem like a minor concern.
For an organization, however, the risk becomes much larger.
Imagine an environment with:
- 50 Windows laptops
- 200 Windows workstations
- 500 remote employees
- Multiple hardware manufacturers
- Different BIOS/UEFI versions
- BitLocker-enabled devices
- Intune-managed endpoints
- Legacy systems that cannot immediately receive firmware updates
The IT team cannot realistically assume that one Windows Update action has successfully remediated every device.
The real business risk is unknown endpoint status.
An organization could have devices that are:
- Successfully updated
- Waiting for a reboot
- Missing required firmware
- Incompatible with the update
- Offline
- No longer actively managed
- Using older hardware
- Reporting remediation failures
- Outside the organization’s normal management platform
That is why Microsoft recommends reviewing the device estate, identifying devices using older certificates, updating firmware where required and piloting the remediation before broader deployment.
Have unmanaged or unknown Windows devices?
Synergy IT can help inventory, assess and prioritize your Windows endpoint environment so your IT team knows which systems require action before the deadline.Get a Windows Endpoint Risk Review.
How to Check Your Windows Secure Boot Certificate Status
Before deploying anything across a business environment, establish the current state of your endpoints. Microsoft added Secure Boot certificate status information to the Windows Security application in 2026. On supported systems, users can navigate to:
Windows Security → Device Security → Secure Boot
The Windows Security interface can show information about the Secure Boot certificate update status and whether action is needed. Microsoft states that this functionality applies to Windows 11 and supported Windows versions including Windows Server 2025, Windows Server 2022 and Windows Server 2019.
For IT administrators, however, checking individual machines manually is not a scalable enterprise process.
A business should instead build an inventory that can answer:
- Is Secure Boot enabled?
- Which Secure Boot certificates are currently trusted?
- Has the 2023 certificate transition been completed?
- Is the device running supported firmware?
- Does the device require an OEM BIOS/UEFI update?
- Is the endpoint managed by Intune, Group Policy or another platform?
- Is BitLocker enabled?
- Has the device reported a Secure Boot remediation status?
- Does the device require manual intervention?
- Has the remediation been verified?
This distinction is important for large environments because certificate remediation is only successful when the organization can prove which endpoints were updated and which were not.
Need an enterprise-wide certificate inventory?
How to Update Windows Boot Manager and Secure Boot Certificates
For most supported devices, Microsoft is delivering the certificate transition through Windows servicing rather than requiring administrators to manually install a certificate on every computer. However, enterprise environments need a controlled process.
A practical business remediation workflow looks like this:
Step 1: Inventory the Windows Environment
Start by identifying every relevant Windows endpoint.
Include:
- Windows 10/11 endpoints where supported
- Windows Server systems
- Corporate laptops
- Desktop workstations
- Remote devices
- Shared computers
- Kiosk systems
- Specialized workstations
- Devices managed through Intune
- Devices managed through Group Policy
- Devices outside normal endpoint management
Do not assume that your endpoint management platform’s device count represents your complete hardware estate.
Step 2: Check Secure Boot Readiness
Determine whether Secure Boot is enabled and whether the system contains the required certificate transition.
Microsoft specifically recommends identifying devices that still use 2011 Secure Boot certificates.
Step 3: Verify OEM Firmware
Firmware is an important part of the remediation process.
Microsoft recommends checking for and deploying OEM firmware updates, particularly on older device models. Firmware updates can improve compatibility and reduce the likelihood of update failures.
This means your remediation plan should account for manufacturers such as:
- Dell
- HP
- Lenovo
- Microsoft Surface
- ASUS
- Acer
- Other OEM systems
The exact process can vary by manufacturer and hardware generation.
Step 4: Pilot Before Broad Deployment
Do not immediately push the remediation across every endpoint.
Microsoft recommends testing on representative pilot groups that include different OEMs and firmware versions and BitLocker-enabled systems. IT teams should verify successful certificate updates, boot behavior and unexpected BitLocker recovery prompts before expanding deployment.
Step 5: Deploy Through Your Management Platform
Depending on the environment and Microsoft’s supported deployment guidance, organizations can use mechanisms such as:
- Microsoft Intune
- Windows Configuration Service Provider
- Group Policy
- Registry-based deployment
- Windows Update
- OEM firmware management
Microsoft specifically lists Intune, Registry, Windows CSP and Group Policy among supported deployment options in its administrator guidance.
Step 6: Verify Remediation
Deployment is not the end.
Your IT team should confirm:
- Certificate status
- Secure Boot status
- Firmware version
- Windows version
- Boot success
- BitLocker status
- Management status
- Error conditions
- Devices still requiring remediation
The final output should be an exception report, not simply a deployment report.
Need help deploying the update safely?
What Should IT Teams Do About BitLocker?
BitLocker deserves special attention during Secure Boot-related maintenance because changes to the boot environment can interact with device protection and recovery mechanisms. Microsoft explicitly recommends including BitLocker-enabled devices in pilot testing and checking for unexpected BitLocker recovery prompts.
Before making broad changes, IT teams should know:
- Which devices use BitLocker
- Whether recovery keys are properly escrowed
- Whether devices are managed through Entra ID/Intune
- Whether recovery information is accessible to authorized administrators
- Whether firmware updates are pending
- Whether Secure Boot configuration changes could trigger recovery
This is one reason businesses should avoid treating the October 19 deadline as a simple “click Windows Update” exercise.A controlled rollout should include backup, recovery-key validation, pilot testing and post-deployment verification.
Worried about BitLocker recovery issues?
How Businesses Can Manage the Windows Secure Boot Update Through Intune
For organizations using Microsoft Intune, the biggest advantage is centralized endpoint visibility and deployment control. Instead of asking every employee to manually check Windows Security, IT administrators can develop a controlled remediation process around device inventory, compliance status and deployment groups.
A practical approach is:
Discover → Categorize → Pilot → Remediate → Verify → Report
Create groups based on:
- Hardware manufacturer
- Hardware model
- Windows version
- Firmware version
- Secure Boot status
- BitLocker status
- Remote vs office device
- Criticality
- Update readiness
- Remediation failure
Then begin with a representative pilot.
This is especially important for businesses with mixed hardware fleets because the Secure Boot transition can involve both Windows servicing and OEM firmware considerations. Microsoft recommends firmware readiness checks and representative testing before broad deployment.
Managing hundreds or thousands of Intune devices?
What If the Secure Boot Certificate Update Is Not Working?
Not every endpoint will necessarily transition smoothly.
Microsoft has published specific guidance for devices that are prevented from updating Secure Boot certificates. The guidance notes that most devices receive updates automatically, but some systems can be blocked from updating and may require additional troubleshooting or action.
Common areas to investigate include:
Outdated firmware: The device may require an OEM BIOS/UEFI update before certificate remediation can proceed.
Device management restrictions: Enterprise policies or configuration settings may interfere with the update process.
Unsupported or legacy hardware: Older devices may require special handling or replacement planning.
Secure Boot configuration: The existing UEFI configuration may need to be reviewed before remediation.
BitLocker considerations: Changes to boot-related configuration can require recovery readiness checks.
Devices that are offline:Remote or rarely connected devices can remain outside the remediation window.
Failed remediation: Some systems may report an unsuccessful update and require targeted troubleshooting.
The important lesson is to create an exception-management process rather than repeatedly deploying the same update and hoping the problem disappears.
Have Windows devices failing Secure Boot remediation?
Windows Boot Manager Certificate Deadline: What Businesses Should Do Now
With the October 19, 2026 expiration approaching, businesses should not wait until the final week.
A practical timeline is:
| Time | Business IT Action |
|---|---|
| Now | Inventory Windows devices across the business and identify systems that may require remediation. |
| Next | Identify Secure Boot status and determine whether the required boot manager certificate is installed and current. |
| Next | Check OEM firmware requirements, compatibility, and available updates before applying certificate-related remediation. |
| Pilot | Test the remediation process on representative devices covering different Windows versions, hardware models, and configurations. |
| Deploy | Roll out remediation in controlled groups to minimize business disruption and provide a clear rollback or recovery path. |
| Validate | Confirm the new certificate is properly applied and verify that Secure Boot remains enabled and functioning correctly. |
| Exception Handling | Troubleshoot devices that fail remediation, including incompatible firmware, certificate installation errors, or Secure Boot configuration issues. |
| Before Oct. 19 | Complete remediation across affected Windows devices and document unresolved exceptions, risks, and required follow-up actions. |
| After Deployment | Continue monitoring endpoint security, Secure Boot health, firmware status, and certificate validity to identify future issues early. |
The most important objective isn’t simply reaching 100% deployment.
It is knowing exactly:
Which devices are protected, which devices aren’t, why they aren’t, and what action is required.
Microsoft’s current guidance supports this approach: assess the device estate, update firmware where necessary, pilot across representative hardware, use supported deployment mechanisms and verify the results.
Don’t wait for the October 19 deadline:
Get a Windows Secure Boot Certificate Readiness Assessment from Synergy IT.
We can help your business identify affected devices, assess firmware and Secure Boot readiness, plan remediation, address exceptions and verify endpoint security after deployment. Start Your Windows Security Assessment :
FAQs :
Is the Windows Boot Manager certificate really expiring on October 19, 2026?
Yes. Microsoft lists Microsoft Windows Production PCA 2011 with an expiration date of October 19, 2026. It is used for signing the Windows boot loader, with Windows UEFI CA 2023 identified as the replacement. Need to know whether your Windows fleet has transitioned? Request a Secure Boot certificate assessment.
Will Windows stop booting after October 19, 2026?
Not necessarily. Microsoft says devices without the updated certificates can continue to start and receive standard Windows updates. However, they may no longer receive future security protections for early-boot components, including Windows Boot Manager and Secure Boot-related updates. Don’t wait for a boot-level security gap. Check your endpoint readiness now.
How do I update the Windows Boot Manager certificate?
For most supported systems, Microsoft is delivering Secure Boot certificate updates through Windows servicing. Some devices may require OEM firmware updates or additional remediation. Microsoft recommends inventorying devices, checking firmware, piloting the update and deploying through supported enterprise mechanisms. Need help with enterprise deployment? Talk with a Windows endpoint specialist.
How can I check whether my Windows PC has the new Secure Boot certificate?
Windows Security provides Secure Boot certificate update status under Device Security → Secure Boot on supported versions. IT administrators should use centralized inventory and management methods for larger environments.Managing multiple endpoints? Get an enterprise Secure Boot inventory review.
Does this affect Windows 11 businesses?
Yes, supported Windows client environments should be assessed for Secure Boot certificate status. Microsoft recommends identifying devices still using older certificates and ensuring firmware and certificate remediation are completed. Assess your Windows 11 security readiness.
Do I need a BIOS or firmware update?
Possibly. Microsoft specifically recommends checking and deploying OEM firmware updates where necessary, particularly for older device models. Unsure which devices need firmware updates? Let an IT expert assess your hardware fleet.
Does this affect BitLocker?
BitLocker-enabled systems should be included in pilot testing because changes involving Secure Boot and firmware can result in unexpected recovery prompts. Microsoft specifically recommends testing BitLocker-enabled devices before broad deployment. Validate BitLocker and Secure Boot readiness before deployment.
Can Microsoft Intune manage the Secure Boot certificate update?
Microsoft’s administrator guidance lists Microsoft Intune, Windows CSP, Group Policy and Registry-based mechanisms among supported deployment options, depending on the scenario. Get help designing an Intune-based remediation rollout.

Leave A Comment