Microsoft is keeping Secure Boot alive with Windows updates

Feb 11, 2026 12:00 AM - 3 months ago 89210

Jess Weatherbed

is a news writer focused connected imaginative industries, computing, and net culture. Jess started her profession astatine TechRadar, covering news and hardware reviews.

Microsoft is automatically replacing boot-level information certificates connected Windows devices earlier they commencement expiring later this year. The caller Secure Boot certificates will beryllium rolled retired arsenic portion of the regular Windows level updates, according to Microsoft’s announcement blog, marking a “generational refresh” of the information standard.

Secure Boot was introduced successful 2011 to protect systems from immoderate unauthorized changes during the footwear process, later becoming 1 of Windows 11’s hardware requirements. After 15 years, those 2011 Secure Boot certificates are now group to expire betwixt June 2026 and October 2026. A caller batch of certificates was issued successful 2023 and already shipped pinch galore caller Windows-based devices sold since 2024, but older PC hardware will request to beryllium updated.

“As cryptographic information evolves, certificates and keys must beryllium periodically refreshed to support beardown protection,” Microsoft’s Nuno Costa said successful the announcement blog. “Retiring aged certificates and introducing caller ones is simply a modular manufacture believe that helps forestall aging credentials from becoming a anemic constituent and keeps platforms aligned pinch modern information expectations.”

Costa says that while PCs will “continue to usability normally” connected an expired certificate, they will participate into a “degraded information state” that could limit early boot-level information updates, and whitethorn acquisition compatibility issues pinch early hardware aliases software. New Secure Boot certificates started rolling retired pinch the Windows 11 KB5074109 update past month.

The caller certificates will beryllium installed automatically and require nary further action for the immense mostly of Windows 11 users. Microsoft says that immoderate specialized systems for illustration server aliases IoT devices whitethorn travel different update processes, and that a abstracted firmware update from third-party manufacturers whitethorn beryllium required for “a fraction of devices.” Check OEM support pages for much information. Windows 10 users will besides request to enroll successful Microsoft’s Extended Security Updates to person the caller certificates.

Follow topics and authors from this communicative to spot much for illustration this successful your personalized homepage provender and to person email updates.

More