Secure boot certificate renewal method in case of updates are being managed by SCCM

Shailendra kumar 6 Reputation points
2025-08-01T02:30:52.98+00:00

I've recently become aware of the article below which suggests that we will need to update Windows secure boot certificates on devices before June 2026;

We use SCCM to deploy the updates, so will updates be available to deploy to all Servers/client OS that contain the updated secure boot certificates, is there any additional action required to deploy such updates from SCCM ?

Windows for business | Windows Client for IT Pros | Devices and deployment | Other
0 comments No comments
{count} vote

1 answer

Sort by: Most helpful
  1. Romin_007 225 Reputation points
    2025-11-25T12:57:24.2433333+00:00

    Yes — updates will be available and you can deploy them via SCCM (or your Windows Update pipeline). But yes, there are additional steps required* beyond just “deploy patch”. You need to make sure firmware, Secure Boot state, diagnostic data & policy/registry settings are all aligned. If you skip those, you risk devices that:

    don’t get updated certificates

    can’t receive Secure Boot security updates after expiry

    potentially fail boot integrity checks


    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.