Drooid Logo
Back to story perspectives

Full Breakdown

Microsoft to Expire Secure Boot Certificates on Most PCs in June 2026

5/27/2026, 12:09:20 AM

Core Event: Microsoft Begins Expiring Secure Boot Certificates

Microsoft announced that, starting in June 2026, it will expire Secure Boot certificates on the majority of PCs. The change will be delivered through the April-May 2026 security updates and will require users to restart their machines several times to complete the firmware and bootloader updates.

Background & Context: Secure Boot Certificate Lifecycle

Secure Boot, introduced in 2011, uses cryptographic certificates to verify the integrity of a PC’s boot process. Most PCs manufactured before 2023 still rely on certificates issued in 2011. After fifteen years, Microsoft is revoking these legacy certificates and issuing new ones to maintain the security architecture.

Key Entities & Groups

  • Microsoft – Developer of Windows and orchestrator of the certificate rollout.
  • Windows Security App – Updated tool that reports the status of Secure Boot updates.
  • Windows 11 PCs – Primary target for the new certificates.
  • Windows 10 PCs – Must be enrolled in Extended Security Updates (ESU) to receive the new certificates.
  • Federal Bureau of Investigation (FBI) – Cited in related coverage warning of potential account-access attacks if Secure Boot is compromised.

Timeline of the Expiration Process

  • 2011 – Initial issuance of Secure Boot certificates.
  • Pre-2023 – Majority of PCs receive certificates dated to 2011.
  • April-May 2026 – Deployment of security updates that embed new certificates.
  • June 2026 – Official expiration of legacy certificates; multiple reboots required to finalize the transition.

Data & Statistics

  • 15 years elapsed since the original certificates were issued.
  • Most PCs (unspecified exact share) will receive the update.
  • The update sequence typically involves three reboots: one to push data into firmware, a second to load the newly signed bootloader, and a third for the firmware to apply the changes; additional reboots may occur as needed.

Official Statements & Responses

Microsoft described the rollout as a “controlled process” that gathers signals from PCs to determine update eligibility and order. The company emphasized that the Windows Security App now displays amber or critical red warnings, guiding users to verify that Secure Boot status is “fine.” Microsoft also advised Windows 10 owners to confirm enrollment in ESU to receive the new certificates.

Criticism & Opposition

Security analysts have warned that PCs failing to install the updates will experience permanent degradation of system security, as Microsoft will cease delivering boot-critical updates and malware blacklist (DBX revocation) lists. The requirement for multiple restarts has been noted as potentially disruptive for users and enterprises with large fleets of devices.

Verbatim Quotes

  • “restart multiple times” — Microsoft guidance
  • “pushes data into the firmware,” — Microsoft technical description
  • “to load the newly signed bootloader,” — Microsoft technical description
  • “for the firmware to apply them.” — Microsoft technical description
  • “The clock is ticking on one of the most fundamental security architectures inside your PC,” — Windows Latest commentary
  • “your system security will permanently degrade because Microsoft will stop sending boot-critical updates and malware blacklists (DBX revocation lists).” — Windows Latest commentary

Why It Matters / Impact

Expiring legacy certificates restores the integrity of the Secure Boot chain, preventing attackers from exploiting outdated signatures. Without the update, PCs will no longer receive critical protections against boot-level malware, increasing exposure to sophisticated threats.

Conflicting Reports & Gaps

Sources differ on the exact number of required reboots; while Microsoft cites three primary restarts, the article notes that “there may be more than three” depending on download and installation conditions. Precise adoption rates for Windows 10 ESU enrollment are not provided.

What’s Next

Microsoft will continue monitoring update progress via the Windows Security App and will issue further guidance as the June deadline approaches. Users are urged to verify Secure Boot status and, for Windows 10 devices, to confirm ESU enrollment to avoid security gaps.