Microsoft Is Racing to Update Windows 11 PCs Before a Major Secure Boot Deadline
Microsoft has once again expanded the rollout of new Secure Boot certificates for Windows 11, this time alongside the September 2026 Patch Tuesday updates.
With Windows 11 KB5124008, Microsoft added more “high confidence” devices to the group that can automatically receive the replacement Secure Boot certificates through Windows Update.
The company says the rollout will continue over the coming months, even though some certificates issued in 2011 have already reached their expiration dates.
Old Secure Boot certificates are expiring
Several Secure Boot certificates originally issued in 2011 expire throughout 2026. There is no single expiration date because Microsoft uses different certificates for different parts of the Secure Boot chain.
Two important deadlines have already passed. Microsoft Corporation KEK CA 2011 expired on June 24, 2026, while Microsoft UEFI CA 2011 expired on June 27.
The next major date is October 19, 2026, when Microsoft Windows Production PCA 2011 expires.
That certificate plays an especially important role because Microsoft uses it to sign the Windows boot loader.
Microsoft is opening the rollout to more Windows 11 PCs
Microsoft has gradually expanded automatic certificate deployment rather than pushing the replacements to every compatible PC at once.
KB5124008 extends that rollout to additional devices Microsoft considers sufficiently reliable, or “high confidence,” for automatic certificate servicing.
Users generally don’t need to install the certificates manually. Microsoft distributes them through Windows Update as systems become eligible.
PC owners should continue installing Windows 11 updates and any BIOS or firmware updates supplied by their device manufacturer. They can also check Windows Security > Device security > Secure Boot to confirm that Secure Boot remains enabled.
PCs won’t suddenly stop working after October 19
The certificate expiration dates do not mean Windows 11 PCs will suddenly stop booting once a deadline passes.
Microsoft says compatible devices can still move to the newer 2023 Secure Boot certificates after older certificates expire.
Systems that have not yet received the replacements should also continue booting normally and receiving standard Windows updates while Microsoft expands deployment.
The October 19 deadline still makes the ongoing rollout important, particularly as Microsoft works to move more Windows 11 devices away from certificates that have been in use since 2011.
In other news, September’s Patch Tuesday brought 966 security fixes, but even fully updated PCs remain vulnerable to the newly disclosed ShieldCrash zero-day exploit.
Via Windows Latest
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages