Microsoft Secure Boot Certificate Updates: What Windows Users Need to Know

5 mins read

Updated on 2026-09-04 10:10:40 to Windows Fix

Microsoft Secure Boot certificate updates replace aging certificates issued in 2011 with newer 2023 certificates. The old certificates began expiring in June 2026, so Windows must refresh the trust data stored in UEFI firmware to keep receiving future protections for the boot process.

Most supported consumer PCs will receive the Secure Boot certificate updates automatically through Windows Update. Still, the update may not be complete even when Windows shows a reassuring status. This guide explains how to verify the update status and resolve any remaining issues.

1. What is the Secure Boot Certificate Update?

Secure Boot is a UEFI security feature that checks digital signatures before Windows starts. It allows trusted bootloaders, firmware drivers, and other pre-OS components to run while blocking code that is missing an approved signature or has been revoked.

The Secure Boot Certificate Update replaces Microsoft’s aging 2011 certificates stored in UEFI firmware with newer 2023 certificates. These certificates help Windows verify that bootloaders, firmware drivers, and other pre-OS components are trusted before the operating system starts.

secure boot certificate updates

The update does not change how Secure Boot works or normally affect the PC’s ability to start Windows. Instead, it refreshes the certificates and trust data required to receive future protections for Windows Boot Manager, Secure Boot databases, revocation lists, and newly discovered boot-level threats. Most supported consumer PCs receive the update automatically through Windows Update, although users may need to check whether the process has completed successfully.

2. Automatic Rollout Timeline for Microsoft Secure Boot Certificate Updates

April 2026: Status becomes visible

Starting in April 2026, Microsoft added Secure Boot certificate information to Windows Security. On supported devices, the path Windows Security > Device security > Secure Boot began showing whether the new certificates had arrived and whether the updated Boot Manager was present.

May 2026: More warnings and guidance

Beginning in May, Microsoft expanded the experience with clearer in-app guidance and notifications outside Windows Security. A yellow caution badge could appear when the automated deployment was blocked by a firmware or hardware limitation. Windows cumulative updates also continued expanding the pool of “high-confidence” devices eligible for automatic deployment.

As early as June 2026: action-required states

A red “Requires action” status may appear as early as June if the PC cannot receive a new boot security fix with its current configuration. Because Secure Boot databases are stored in firmware, Microsoft uses servicing and compatibility data to control the rollout. As a result, some PCs may receive the update later than others, even after installing the same monthly Windows update.

3. How to Check If the Secure Boot Certificate is Updated?

Use the Windows Security status page first. It gives home users the most direct answer and avoids unnecessary firmware changes.

  • Open Start, type Windows Security, and launch the app.

  • Select Device security. If shown, open the Secure Boot section.

  • Read the full message beneath the badge. “Fully updated” means the required certificate updates and updated Boot Manager are installed.

Note:

A green checkmark alone does not always prove that the certificate replacement is complete. Green may also mean that the device is currently protected or that Windows recommends no immediate action. The accompanying phrase, especially “Fully updated,” is the decisive signal.

4. What Should You Do for Each Secure Boot Status?

Meaning Typical action
Green Protected, fully updated, or no action currently recommended Read the text. If it says “Fully updated,” no action is needed.
Yellow Not yet updated, pending, or blocked by a limitation Install Windows and OEM firmware updates, restart, and recheck.
Red A required boot protection cannot be delivered to the current configuration Follow the displayed Microsoft guidance; contact the PC maker if firmware support is required.

If the status is green

Confirm that the message says “Fully updated” or updated Secure Boot certificates have been applied. Keep automatic Windows Update enabled and do not clear Secure Boot keys in UEFI. Clearing or replacing platform keys manually can break the trust chain and may trigger BitLocker recovery.

secure boot status is green

If the status is yellow or the update is pending

Install all available Windows updates, including optional firmware updates supplied by the PC manufacturer. Connect the laptop to power, suspend neither the update nor the restart, and check the manufacturer’s support page for a newer BIOS/UEFI release. A pending status is not proof of failure; phased deployment means two otherwise similar PCs may update at different times.

secure boot status is yellow

If the status is red or says action is required

Back up important files and save the BitLocker recovery key before changing firmware settings.

  • First, install all available Windows and firmware updates, restart the PC, and check the Secure Boot status again.

  • If Windows Security provides a specific link, follow its instructions rather than manually replacing the certificates.

  • If the update remains blocked because of hardware or firmware limitations, check the device manufacturer’s support page for a compatible BIOS/UEFI update or contact the manufacturer directly.

Do not disable Secure Boot or modify its certificates without official guidance. Organizations should test the recommended fix on representative device models before deploying it across the entire fleet.

secure boot status is red

⚡ Bonus Tip: Convert MBR to GPT for Secure Boot Compatibility

Secure Boot requires UEFI mode. An older PC may still boot in Legacy BIOS/CSM mode from an MBR system disk, which prevents Secure Boot from being enabled even if the firmware supports it. Converting the disk to GPT is therefore a preparation step. Back up critical files and verify that the motherboard supports UEFI before proceeding.

4DDiG Partition Manager can convert a Windows system disk from MBR to GPT without a conventional clean installation. A practical workflow is:

  • Download and install 4DDiG Partition Manager, then launch the program. From the left-hand menu, select Convert Disk and click Convert MBR to GPT.

    FREE DOWNLOAD

    Secure Download

    convert mbr to gpt
  • Choose the disk you want to convert and click Continue to enter the execution interface.

    select disk
  • If you are converting the system disk, the program will download the required PE components. After the download finishes, save any open files and make sure your computer is connected to a reliable power source. Click Sure when prompted. The computer will restart automatically and enter the PE environment.

    click sure
  • After 4DDiG Partition Manager launches in the PE environment, select Convert MBR to GPT.

    select mbr to gpt again
  • Select the disk you want to convert and click Continue. 4DDiG will begin converting the disk from MBR to GPT.

    select disk again to covert
  • When the conversion finishes, follow the on-screen instructions to boot your computer. Otherwise, Windows may not start properly.

    follow the steps to boot

Conclusion

Microsoft Secure Boot certificate updates preserve Windows’ ability to receive future boot-level protections after the 2011 certificates expire. Check Windows Security > Device security > Secure Boot, interpret the full status message rather than the badge alone, and let Windows Update handle the certificate rollout when possible.

For yellow or red states, install OEM firmware, retain your BitLocker recovery key, and follow Microsoft or manufacturer guidance. If Legacy BIOS and an MBR system disk are blocking Secure Boot, 4DDiG Partition Manager can help convert the disk to GPT before you switch the firmware to UEFI and enable Secure Boot.

FREE DOWNLOAD

Secure Download

William Bollson (senior editor)

William Bollson, the editor-in-chief of 4DDiG, devotes to providing the best solutions for Windows and Mac related issues, including data recovery, repair, error fixes.

(Click to rate this post)

You rated 4.5 ( participated)