Some devices still have Secure Boot certificates issued in 2011 that expire in June 2026. Microsoft says such PCs may continue booting and receiving ordinary Windows updates, yet could miss future protections for early boot components. That is different from an immediate blanket failure. A cautious user should keep Windows and OEM firmware current, identify actual status and protect BitLocker recovery access before changing UEFI. Managed fleets need staged deployment rather than a blind command copied from a forum.
Before you start
Back up files and locate the 48-digit BitLocker or Device Encryption recovery key. Confirm the key works for the device account without exposing it in a screenshot. Record Windows build, PC model and firmware version. If the device belongs to an organization, ask IT for its certificate rollout plan; do not apply a consumer workaround to a fleet machine.Do it step by step
- Open Windows Security > Device security and System Information to confirm Secure Boot is enabled and the machine uses UEFI, then note any warnings without changing switches.
- Install current Windows updates and restart until no pending restart remains. Check the PC maker's official firmware page for a model-specific update and its prerequisites.
- Read Microsoft's current Secure Boot certificate guidance. For a managed device, check the documented status signals, including relevant system events such as 1801, with the administrator's inventory process.
- Do not manually clear Secure Boot keys, disable Secure Boot or import arbitrary certificates from a download. Those operations can cause recovery prompts or reduce protection.
- If an approved firmware or certificate update is scheduled, have the recovery key and a working bootable recovery route available; use the vendor's power and battery requirements.
- After the update, check boot, encryption status and Microsoft's reported certificate state. Record any Event Viewer warning and seek vendor or IT help for repeated failures.