How to manage the Windows Boot Manager revocations for Secure Boot ...
This article describes the protection against the publicly disclosed Secure Boot security feature bypass that uses the BlackLotus UEFI bootkit tracked by CVE-2023-24932, how to enable the mitigations, and guidance on bootable media.
When Secure Boot certificates expire on Windows devices
Disabling Secure Boot significantly reduces device protection, removes safeguards against boot‑level malware, and can create new security and compliance risks. The recommended path is to ensure your device receives the updated 2023 Secure Boot certificates and any required OEM firmware updates.
Known issues and resolutions for Secure Boot certificates updates ...
For problems deploying Secure Boot certificates that are not caused by known issues in Windows or Microsoft Intune, please refer to the Secure Boot troubleshooting guide.
Windows 11 et Secure Boot - Support Microsoft
Découvrez comment modifier les paramètres afin dʼactiver le démarrage sécurisé si vous ne pouvez pas effectuer la mise à niveau vers Windows 11, et ce, parce que votre PC ne prend actuellement pas en charge le démarrage sécurisé.
Secure Boot DB and DBX variable update events - Microsoft Support
The DBX variable is used to untrust Secure Boot components and is typically used to block vulnerable or malicious Secure Boot components such as boot managers and certificates used to sign boot managers.
Sample Secure Boot E2E Automation Guide - Microsoft Support
The Secure Boot Certificate Rollout Automation is a PowerShell-based system that deploys Windows Secure Boot DB certificate updates to domain-joined machines in a controlled, graduated manner.
Group Policy Objects (GPO) method of Secure Boot for Windows devices ...
This method offers a straightforward Secure Boot Group Policy setting that domain administrators can set to deploy Secure Boot updates to all domain-joined Windows clients and servers.
Windows 11 and Secure Boot - Microsoft Support
Learn how to change settings to enable Secure Boot if you are not able to upgrade to Windows 11 because your PC is not currently Secure Boot capable.
Frequently asked questions about the Secure Boot update process ...
Devices with Secure Boot disabled will not receive the new Secure Boot certificates in firmware. As a result, they will remain vulnerable to boot-level malware, such as bootkits, because Secure Boot protections are not enforced.
Monitoring Secure Boot certificate status with Microsoft Intune ...
All Windows devices with Secure Boot enabled must be updated to the 2023 certificates before expiration to ensure continued security update support. This guide provides a monitoring-only approach using Microsoft Intune Remediations (Proactive Remediations).