To ensure secure-by-default devices at Microsoft, we’ve taken a proactive approach to updating the Secure Boot certificates on our devices and learned valuable lessons you can use to protect your organization.

Keeping the enterprise secure by default: Secure Boot certificate updates at Microsoft

At Microsoft, we manage around 500,000 Windows client devices worldwide, from employee laptops to servers to meeting room systems. In an environment that large, it’s complex and challenging to maintain end-to-end security.

Every one of those devices relies on Secure Boot, a Windows security capability that verifies firmware, boot loaders, and operating system components before startup. This system helps ensure all our Windows devices run only trusted software and protects us against threats that target the boot process.

When three Microsoft-issued Secure Boot certificates approached expiration in 2026, our team in Microsoft Digital, the company’s IT organization, knew we needed to take action early and get ahead of the update. By partnering with the Microsoft Office of the CISO and several of our product teams, we developed an approach that ensured secure-by-default devices from the firmware up.

Updating the foundation of device trust

Secure Boot sits at the foundation of Windows security. Without updated certificates, devices would lose the ability to receive future Secure Boot protections and other boot-level security improvements.

A photo of Quintana.

“We manage a diverse fleet of devices and usage scenarios, so we needed an approach that could scale safely, provide visibility into our progress, and maintain confidence in device security.”

Luis Quintana, principal engineering group manager, Endpoint Security

To maintain protection, we needed to replace three legacy certificates with four new ones across a diverse device fleet. Replacing the certificates was straightforward. The real work was validating the update across thousands of device models and deployment scenarios.

Secure Boot certificates needing replacement

  • KEK: Microsoft Corporation KEK CA 2011 → Microsoft Corporation KEK 2K CA 2023
    Covers: Database updates (DB and DBX)
  • UEFI CA: Microsoft Corporation UEFI CA 2011 → Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023
    Covers: Third-party UEFI modules, bootloaders, and option ROMs
  • Windows Boot chain: Microsoft Windows Production PCA 2011 → Windows UEFI CA 2023
    Covers: Windows Boot Manager and boot components

We started early so we could test, validate, and gradually deploy the updates before the certificate expiration dates arrived. That approach helped us strengthen the security posture of our devices while minimizing disruption to employees and business-critical systems.

“Updating hundreds of thousands of devices without disrupting people and business operations is no small task,” says Luis Quintana, principal engineering group manager for Endpoint Security. “We manage a diverse fleet of devices and usage scenarios, so we needed an approach that could scale safely, provide visibility into our progress, and maintain confidence in device security.”

Leading the update across a complex device estate

We first began this work in 2024 by partnering with the Windows Servicing and Delivery team, which helped us identify device models the certificate renewal might affect. We tested those models end to end in our Client Test Lab, then deployed the update to a pilot group of around 35,000 devices using a controlled firmware release (CFR). That pilot achieved a 95% success rate, which gave us the confidence to scale up.

A photo of Dagdelen

“Intune was the glue that brought the process together, turning a collection of settings and instructions into something we could orchestrate. It helped us create a repeatable playbook that covered everything from reporting and targeting to rollout.”

Kubilay Dagdelen, senior service engineer, Microsoft Intune

In February 2026, we kicked off the broader effort across our entire Windows 11 device ecosystem. Reporting and telemetry formed our essential starting point.

Microsoft Digital partnered with the Windows Autopatch, Intune, and Microsoft Defender for Endpoint teams to identify which devices already included the latest certificates because they were released after 2025, which devices needed the update, and which failed. In support of these efforts, the Autopatch team built fleet-wide reporting of Secure Boot status directly into Intune, turning raw telemetry into a live compliance dashboard.

“Intune was the glue that brought the process together, turning a collection of settings and instructions into something we could orchestrate,” says Kubilay Dagdelen, a senior service engineer on the Microsoft Intune team. “It helped us create a repeatable playbook that covered everything from reporting and targeting to rollout.”

A ringed approach across a range of devices

We started small, using telemetry signals to identify device cohorts based on their risk of failure. Starting from the simplest devices to update, we gradually scaled across models that carried more complexity, keeping backups and loaner machines ready to support global operations in case of disruption. After just 70 days, we had achieved 86% compliance across all our devices.

A photo of Savagur.

“This has been an opportunity to strengthen our security foundation. It’s about going from reactive security to a secure-by-default baseline aligned with Zero Trust principles.”

Pandurang Savagur, senior product manager, Microsoft Digital

But we don’t just maintain employee devices. Our hardware estate spans meeting rooms, secure admin workstations, digital signage, and executive devices. These different device types demanded different Secure Boot approaches.

To tackle this challenge we established a virtual team, with members responsible for each of these surfaces holding weekly syncs and leadership updates. For example, our 15,000 meeting room devices run a custom Windows 11 image, so we partnered with OEMs to release firmware for them.

Meanwhile, cloud PCs on Azure infrastructure needed scheduled reboots to update, so we let employees choose when to restart. For our server cohort, where telemetry gaps made progress hard, Microsoft Defender for Endpoint delivered the independent visibility we needed.

“This has been an opportunity to strengthen our security foundation,” says Pandurang Savagur, a senior product manager on the Device Lifecycle team in Microsoft Digital. “It’s about going from reactive security to a secure-by-default baseline aligned with Zero Trust principles.”

Our Customer Zero experience: Expertise and process pathfinding

Our role as Customer Zero shaped how we approached this process. As both the creators and users of Microsoft technology, we have direct access to product teams as well as intimate knowledge of our tools’ capabilities.

A photo of the Evgrafova.

“Technology and culture matter equally here, and our Microsoft culture means we know what’s coming and can act proactively through direct access to our engineering groups.”

Yulia Evgrafova, principal security service engineer, Office of the CISO

Intune served as our execution engine, orchestrating policies and remediation scripts across more than 90% of our devices with precision. Autopatch and Defender added speed through visibility.

Thanks to the lessons we learned throughout our update journey, we’re in the process of incorporating capabilities we developed internally into each solution for public release. We’ve also established steps that can help you manage your own Secure Boot certificate updates.

“Technology and culture matter equally here, and our Microsoft culture means we know what’s coming and can act proactively through direct access to our engineering groups,” says Yulia Evgrafova, a principal security service engineer for our Office of the CISO. “On the technology side, we have the expertise to experiment and the privilege of reaching engineering teams directly.”

Secure by default and ready for what’s next

Thanks to thorough telemetry and a measured approach to rolling out the update, we’ve now reached 97% compliance globally, all while keeping our failure rate under one percent and our support burden low. Our devices now validate trusted firmware and boot components by default, keeping the list of trusted components current and closing gaps that attackers could exploit at startup.

This work continues as we collect logs on devices that need attention and remediate the stragglers, including meeting rooms and virtual machines. That long tail is the hard part, but it’s a natural component of any effort at this scale.

What we built here reaches well beyond one certificate update. Telemetry gave us the visibility to protect devices without disrupting people, and that aspect of this rollout will guide get compliant and stay compliant in the future.

“This effort serves as a playbook for many different initiatives that we’ll take on in the future,” Quintana says. “One of the biggest lessons is how we can balance experience and protection between Microsoft Digital and our security teams.”

Key takeaways

As you update your own Secure Boot certificates, keep the lessons we learned internally during this process in mind:

  • Start early and validate with pilots. Give yourself enough runway to test on representative hardware, because certificate updates touch the firmware layer and you don’t want surprises at scale.
  • Make telemetry your foundation. Reliable, fleet-wide visibility tells you which devices need updates, which have already succeeded, and where the real risks are before you deploy anything.
  • Deploy in phased rings. Start with low-risk devices and progress toward high-risk and older hardware, using guardrails at each stage to avoid boot failures and contain any issues.
  • Plan extra time for difficult device types. Older hardware, meeting room systems, servers, and end-of-support devices present the biggest hurdles, so identify them upfront and budget the effort they demand.
  • Build a virtual team culture. Bringing every stakeholder together, from security to leadership, gives each group a chance to shape the plan while also securing the budget and support that the effort requires.
  • Treat secure-by-default as the new standard. Secure Boot is no longer an opt-in position, so communicate early and enforce consistently. Remember that people need to know the change is coming and that you’re doing everything possible to make it happen smoothly.

Try it out

Related links