Resource icon

Check the 2026 Secure Boot certificate transition without risky firmware changes

Some devices still have Secure Boot certificates issued in 2011 that expire in June 2026. Microsoft says such PCs may continue booting and receiving ordinary Windows updates, yet could miss future protections for early boot components. That is different from an immediate blanket failure. A cautious user should keep Windows and OEM firmware current, identify actual status and protect BitLocker recovery access before changing UEFI. Managed fleets need staged deployment rather than a blind command copied from a forum.

Before you start​

Back up files and locate the 48-digit BitLocker or Device Encryption recovery key. Confirm the key works for the device account without exposing it in a screenshot. Record Windows build, PC model and firmware version. If the device belongs to an organization, ask IT for its certificate rollout plan; do not apply a consumer workaround to a fleet machine.

Do it step by step​

  1. Open Windows Security > Device security and System Information to confirm Secure Boot is enabled and the machine uses UEFI, then note any warnings without changing switches.
  2. Install current Windows updates and restart until no pending restart remains. Check the PC maker's official firmware page for a model-specific update and its prerequisites.
  3. Read Microsoft's current Secure Boot certificate guidance. For a managed device, check the documented status signals, including relevant system events such as 1801, with the administrator's inventory process.
  4. Do not manually clear Secure Boot keys, disable Secure Boot or import arbitrary certificates from a download. Those operations can cause recovery prompts or reduce protection.
  5. If an approved firmware or certificate update is scheduled, have the recovery key and a working bootable recovery route available; use the vendor's power and battery requirements.
  6. After the update, check boot, encryption status and Microsoft's reported certificate state. Record any Event Viewer warning and seek vendor or IT help for repeated failures.

Check the result​

The PC boots normally, Secure Boot remains enabled, encryption can be recovered and official status signals show a successful update or a documented pending state.

If something goes wrong​

Event 1795 or 1801 can indicate rollout issues; capture the full event and device details before changing anything. An unexpected BitLocker prompt requires the correct recovery key, not a TPM reset. Follow Microsoft and OEM remediation guidance for that model.

Know the limit​

The 2026 expiry does not mean every Windows 11 PC stopped booting in June. Certificate deployment varies by firmware, Windows servicing and management policy. This is an update-and-verification task, not a reason to bypass Secure Boot. Microsoft Secure Boot certificate guidance BitLocker overview

Decision checkpoint​

The device's update state and OEM firmware support matter more than its age alone. Inventory whether it is personal or managed before running any certificate procedure. A system event is an investigation lead, not an instruction to edit registry keys from a search result. If the device is already in a BitLocker recovery loop, prioritize data access with the correct key and vendor support before another firmware flash. Keep the repair notes with the device record.

Aftercare​

Review update status again after the next firmware or Windows servicing cycle. A pending certificate rollout can become complete without a manual intervention.
Posted by
Jack
Views
1
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack