Microsoft Initiates Deployment of New UEFI Secure Boot Certificates for Eligible Windows 11 Devices
2026-01-15 / Read about 0 minute
Author:小编   

Commencing in January 2026, Microsoft will embark on a phased rollout of new UEFI Secure Boot certificates for qualifying devices operating on Windows 11 versions 24H2 and 25H2. These new certificates will supersede the existing ones, which are slated to reach their expiration date in June 2026. Secure Boot stands as a pivotal security mechanism for computers, guaranteeing that only verified boot loaders are initiated on systems utilizing UEFI firmware. This effectively thwarts malware, including rootkits, from executing during the system's startup sequence. The objective of this update is to ensure that devices retain their Secure Boot capabilities and continue to benefit from security enhancements even after the certificates' expiration. Microsoft will facilitate the automatic distribution of these new certificates via Windows Update. Additionally, it advises system administrators to finalize the deployment process prior to this summer to uphold the security integrity of their devices.