{"id":25067,"date":"2026-08-13T08:45:00","date_gmt":"2026-08-13T15:45:00","guid":{"rendered":"https:\/\/research.codeghost.online\/insidetrack\/blog\/?p=25067"},"modified":"2026-08-12T17:21:17","modified_gmt":"2026-08-13T00:21:17","slug":"keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft","status":"publish","type":"post","link":"https:\/\/research.codeghost.online\/insidetrack\/blog\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\/","title":{"rendered":"Keeping the enterprise secure by default: Secure Boot certificate updates at Microsoft"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">At Microsoft, we manage around 500,000 Windows client devices worldwide, from employee laptops to servers to meeting room systems. In an environment that large, it\u2019s complex and challenging to maintain end-to-end security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Every one of those devices relies on Secure Boot, a Windows security capability that verifies firmware, boot loaders, and operating system components before startup. This system helps ensure all our Windows devices run only trusted software and protects us against threats that target the boot process.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When three Microsoft-issued Secure Boot certificates approached expiration in 2026, our team in Microsoft Digital, the company\u2019s IT organization, knew we needed to take action early and get ahead of the update. By partnering with the Microsoft Office of the CISO and several of our product teams, we developed an approach that ensured secure-by-default devices from the firmware up.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Updating the foundation of device trust<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Secure Boot sits at the foundation of Windows security. Without updated certificates, devices would lose the ability to receive future Secure Boot protections and other boot-level security improvements.<\/p>\n\n\n\n<figure class=\"wp-block-image alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Luis-Quintana.png\" alt=\"A photo of Quintana.\" class=\"wp-image-25070\" style=\"width:150px\" srcset=\"https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Luis-Quintana.png 500w, https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Luis-Quintana-300x300.png 300w, https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Luis-Quintana-150x150.png 150w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">&#8220;We manage a diverse fleet of devices and usage scenarios, so we needed an approach that could scale safely, provide visibility into our progress, and maintain confidence in device security.&#8221;<\/p>\n<cite>Luis Quintana, principal engineering group manager, Endpoint Security<\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">To maintain protection, we needed to replace three legacy certificates with four new ones across a diverse device fleet. Replacing the certificates was straightforward. The real work was validating the update across thousands of device models and deployment scenarios.<\/p>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-624db1de wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:var(--wp--preset--spacing--spacing-16);padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:var(--wp--preset--spacing--spacing-16)\">\n<h3 class=\"wp-block-heading\">Secure Boot certificates needing replacement<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>KEK:<\/strong> Microsoft Corporation KEK CA 2011 \u2192 Microsoft Corporation KEK 2K CA 2023<br><em>Covers: Database updates (DB and DBX)<\/em><\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>UEFI CA:<\/strong> Microsoft Corporation UEFI CA 2011 \u2192 Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023<br><em>Covers: Third-party UEFI modules, bootloaders, and option ROMs<\/em><\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Windows Boot chain:<\/strong> Microsoft Windows Production PCA 2011 \u2192 Windows UEFI CA 2023 <br><em>Covers: Windows Boot Manager and boot components<\/em><\/li>\n<\/ul>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">We started early so we could test, validate, and gradually deploy the updates before the certificate expiration dates arrived. That approach helped us strengthen the security posture of our devices while minimizing disruption to employees and business-critical systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Updating hundreds of thousands of devices without disrupting people and business operations is no small task,&#8221; says Luis Quintana, principal engineering group manager for Endpoint Security. &#8220;We manage a diverse fleet of devices and usage scenarios, so we needed an approach that could scale safely, provide visibility into our progress, and maintain confidence in device security.&#8221;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Leading the update across a complex device estate<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We first began this work in 2024 by partnering with the Windows Servicing and Delivery team, which helped us identify device models the certificate renewal might affect. We tested those models end to end in our Client Test Lab, then deployed the update to a pilot group of around 35,000 devices using a controlled firmware release (CFR). That pilot achieved a 95% success rate, which gave us the confidence to scale up.<\/p>\n\n\n\n<figure class=\"wp-block-image alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Kubilay-Dagdelen.png\" alt=\"A photo of Dagdelen\" class=\"wp-image-25071\" style=\"width:150px\" srcset=\"https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Kubilay-Dagdelen.png 500w, https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Kubilay-Dagdelen-300x300.png 300w, https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Kubilay-Dagdelen-150x150.png 150w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">\u201cIntune was the glue that brought the process together, turning a collection of settings and instructions into something we could orchestrate. It helped us create a repeatable playbook that covered everything from reporting and targeting to rollout.\u201d<\/p>\n<cite>Kubilay Dagdelen, senior service engineer, Microsoft Intune<\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">In February 2026, we kicked off the broader effort across our entire Windows 11 device ecosystem. Reporting and telemetry formed our essential starting point.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft Digital partnered with the Windows Autopatch, Intune, and Microsoft Defender for Endpoint teams to identify which devices already included the latest certificates because they were released after 2025, which devices needed the update, and which failed. In support of these efforts, the Autopatch team built fleet-wide reporting of Secure Boot status directly into Intune, turning raw telemetry into a live compliance dashboard.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cIntune was the glue that brought the process together, turning a collection of settings and instructions into something we could orchestrate,&#8221; says Kubilay Dagdelen, a senior service engineer on the Microsoft Intune team. \u201cIt helped us create a repeatable playbook that covered everything from reporting and targeting to rollout.\u201d<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">A ringed approach across a range of devices<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We started small, using telemetry signals to identify device cohorts based on their risk of failure. Starting from the simplest devices to update, we gradually scaled across models that carried more complexity, keeping backups and loaner machines ready to support global operations in case of disruption. After just 70 days, we had achieved 86% compliance across all our devices.<\/p>\n\n\n\n<figure class=\"wp-block-image alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Pandurang-Kamath-Savagur.png\" alt=\"A photo of Savagur.\" class=\"wp-image-25072\" style=\"width:150px\" srcset=\"https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Pandurang-Kamath-Savagur.png 500w, https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Pandurang-Kamath-Savagur-300x300.png 300w, https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Pandurang-Kamath-Savagur-150x150.png 150w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">&#8220;This has been an opportunity to strengthen our security foundation. It&#8217;s about going from reactive security to a secure-by-default baseline aligned with Zero Trust principles.&#8221;<\/p>\n<cite>Pandurang Savagur, senior product manager, Microsoft Digital<\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">But we don\u2019t just maintain employee devices. Our hardware estate spans meeting rooms, secure admin workstations, digital signage, and executive devices. These different device types demanded different Secure Boot approaches.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To tackle this challenge we established a virtual team, with members responsible for each of these surfaces holding weekly syncs and leadership updates. For example, our 15,000 meeting room devices run a custom Windows 11 image, so we partnered with OEMs to release firmware for them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Meanwhile, cloud PCs on Azure infrastructure needed scheduled reboots to update, so we let employees choose when to restart. For our server cohort, where telemetry gaps made progress hard, Microsoft Defender for Endpoint delivered the independent visibility we needed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;This has been an opportunity to strengthen our security foundation,&#8221; says Pandurang Savagur, a senior product manager on the Device Lifecycle team in Microsoft Digital. &#8220;It&#8217;s about going from reactive security to a secure-by-default baseline aligned with Zero Trust principles.&#8221;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Our Customer Zero experience: Expertise and process pathfinding<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Our role as <a href=\"https:\/\/research.codeghost.online\/insidetrack\/blog\/customer-zero\/\">Customer Zero<\/a> shaped how we approached this process. As both the creators and users of Microsoft technology, we have direct access to product teams as well as intimate knowledge of our tools\u2019 capabilities.<\/p>\n\n\n\n<figure class=\"wp-block-image alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Yulia-Evgrafova.png\" alt=\"A photo of the Evgrafova.\" class=\"wp-image-25073\" style=\"width:150px\" srcset=\"https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Yulia-Evgrafova.png 500w, https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Yulia-Evgrafova-300x300.png 300w, https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Yulia-Evgrafova-150x150.png 150w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">&#8220;Technology and culture matter equally here, and our Microsoft culture means we know what&#8217;s coming and can act proactively through direct access to our engineering groups.&#8221;<\/p>\n<cite>Yulia Evgrafova, principal security service engineer, Office of the CISO<\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Intune served as our execution engine, orchestrating policies and remediation scripts across more than 90% of our devices with precision. Autopatch and Defender added speed through visibility.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Thanks to the lessons we learned throughout our update journey, we\u2019re in the process of incorporating capabilities we developed internally into each solution for public release. We\u2019ve also established steps that can help you manage your own Secure Boot certificate updates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Technology and culture matter equally here, and our Microsoft culture means we know what&#8217;s coming and can act proactively through direct access to our engineering groups,&#8221; says Yulia Evgrafova, a principal security service engineer for our Office of the CISO. &#8220;On the technology side, we have the expertise to experiment and the privilege of reaching engineering teams directly.&#8221;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Secure by default and ready for what&#8217;s next<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Thanks to thorough telemetry and a measured approach to rolling out the update, we\u2019ve now reached 97% compliance globally, all while keeping our failure rate under one percent and our support burden low. Our devices now validate trusted firmware and boot components by default, keeping the list of trusted components current and closing gaps that attackers could exploit at startup.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This work continues as we collect logs on devices that need attention and remediate the stragglers, including meeting rooms and virtual machines. That long tail is the hard part, but it\u2019s a natural component of any effort at this scale.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What we built here reaches well beyond one certificate update. Telemetry gave us the visibility to protect devices without disrupting people, and that aspect of this rollout will guide get compliant and stay compliant in the future.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;This effort serves as a playbook for many different initiatives that we&#8217;ll take on in the future,&#8221; Quintana says. &#8220;One of the biggest lessons is how we can balance experience and protection between Microsoft Digital and our security teams.&#8221;<strong><\/strong><\/p>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-37425b6a wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--rd-xs);padding-right:var(--wp--preset--spacing--rd-xs);padding-bottom:var(--wp--preset--spacing--rd-xs);padding-left:var(--wp--preset--spacing--rd-xs)\">\n<h3 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Key takeaways<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">As you update your own Secure Boot certificates, keep the lessons we learned internally during this process in mind:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Start early and validate with pilots.<\/strong> Give yourself enough runway to test on representative hardware, because certificate updates touch the firmware layer and you don\u2019t want surprises at scale.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Make telemetry your foundation.<\/strong> Reliable, fleet-wide visibility tells you which devices need updates, which have already succeeded, and where the real risks are before you deploy anything.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Deploy in phased rings.<\/strong> Start with low-risk devices and progress toward high-risk and older hardware, using guardrails at each stage to avoid boot failures and contain any issues.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Plan extra time for difficult device types.<\/strong> Older hardware, meeting room systems, servers, and end-of-support devices present the biggest hurdles, so identify them upfront and budget the effort they demand.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Build a virtual team culture.<\/strong> Bringing every stakeholder together, from security to leadership, gives each group a chance to shape the plan while also securing the budget and support that the effort requires.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Treat secure-by-default as the new standard.<\/strong> Secure Boot is no longer an opt-in position, so communicate early and enforce consistently. Remember that people need to know the change is coming and that you\u2019re doing everything possible to make it happen smoothly.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Try it out<\/h3>\n\n\n\n<ul class=\"wp-block-list is-style-list-no-bullets\">\n<li class=\"wp-block-list-item\">See what our approach to Zero Trust can accomplish for your organization. <a href=\"https:\/\/signup.microsoft.com\/get-started\/signup?offerid=71fe267c-1b50-4ac5-b278-28a2e4b6b7d1&amp;ali=1&amp;products=71fe267c-1b50-4ac5-b278-28a2e4b6b7d1&amp;bpr=1?OCID=InsideTrack_Product_10910\" target=\"_blank\" rel=\"noreferrer noopener\">Try Microsoft Intune for free.<\/a><\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Related links<\/h3>\n\n\n\n<ul style=\"margin-top:var(--wp--preset--spacing--spacing-20)\" class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/research.codeghost.online\/insidetrack\/blog\/transforming-security-and-compliance-at-microsoft-with-windows-hotpatch\/\">Read how we\u2019re transforming security and compliance at Microsoft with Windows Hotpatch.<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/research.codeghost.online\/insidetrack\/blog\/deploying-microsoft-baseline-security-mode-at-microsoft-our-virtuous-learning-cycle\/\">Discover the virtuous learning cycle behind our deployment of Microsoft Baseline Security Mode.<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/research.codeghost.online\/insidetrack\/blog\/simplifying-device-registration-at-microsoft-with-an-agentic-ai-assistant\/\">Learn how we\u2019re simplifying device registration at Microsoft with an agentic AI assistant.<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/research.codeghost.online\/insidetrack\/blog\/unpacking-microsofts-internal-deployment-of-the-first-major-update-to-windows-11\/\">Unpack Microsoft\u2019s internal deployment of the first major update to Windows 11.<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/research.codeghost.online\/insidetrack\/blog\/keeping-our-in-house-optical-network-safe-with-a-zero-trust-mentality\/\">Find out how we\u2019re keeping our in-house optical network safe with a Zero Trust mentality.<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/research.codeghost.online\/insidetrack\/blog\/how-we-approach-cybersecurity-risk-management-at-microsoft\/\">Explore our approach to cybersecurity risk management at Microsoft.<\/a><\/li>\n<\/ul>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>At Microsoft, we manage around 500,000 Windows client devices worldwide, from employee laptops to servers to meeting room systems. In an environment that large, it\u2019s complex and challenging to maintain end-to-end security. Every one of those devices relies on Secure Boot, a Windows security capability that verifies firmware, boot loaders, and operating system components before [&hellip;]<\/p>\n","protected":false},"author":115,"featured_media":25068,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_hide_featured_on_single":false,"_show_featured_caption_on_single":true,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[904,820,927,903,937,419],"coauthors":[622],"class_list":["post-25067","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-digital","tag-customer-zero","tag-device-management","tag-modern-work","tag-security","tag-security-and-governance","tag-zero-trust","m-blog-post"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Keeping the enterprise secure by default: Secure Boot certificate updates at Microsoft - Inside Track Blog<\/title>\n<meta name=\"description\" content=\"Discover our process for updating boot certificates to ensure secure boot and support Zero Trust at Microsoft.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/research.codeghost.online\/insidetrack\/blog\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Keeping the enterprise secure by default: Secure Boot certificate updates at Microsoft - Inside Track Blog\" \/>\n<meta property=\"og:description\" content=\"Discover our process for updating boot certificates to ensure secure boot and support Zero Trust at Microsoft.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/research.codeghost.online\/insidetrack\/blog\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\/\" \/>\n<meta property=\"og:site_name\" content=\"Inside Track Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-13T15:45:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/10910-Hero_image.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2300\" \/>\n\t<meta property=\"og:image:height\" content=\"1293\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Alex Fleck\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alex Fleck\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\\\/\"},\"author\":{\"name\":\"Alex Fleck\",\"@id\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/b623d895338189d1c487d4a0b93d4764\"},\"headline\":\"Keeping the enterprise secure by default: Secure Boot certificate updates at Microsoft\",\"datePublished\":\"2026-08-13T15:45:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\\\/\"},\"wordCount\":1628,\"image\":{\"@id\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2026\\\/08\\\/10910-Hero_image.jpg\",\"keywords\":[\"Customer Zero\",\"Device management\",\"Modern work\",\"Security\",\"Security and governance\",\"Zero Trust\"],\"articleSection\":[\"Microsoft Digital\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\\\/\",\"url\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\\\/\",\"name\":\"Keeping the enterprise secure by default: Secure Boot certificate updates at Microsoft - Inside Track Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2026\\\/08\\\/10910-Hero_image.jpg\",\"datePublished\":\"2026-08-13T15:45:00+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/b623d895338189d1c487d4a0b93d4764\"},\"description\":\"Discover our process for updating boot certificates to ensure secure boot and support Zero Trust at Microsoft.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\\\/#primaryimage\",\"url\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2026\\\/08\\\/10910-Hero_image.jpg\",\"contentUrl\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2026\\\/08\\\/10910-Hero_image.jpg\",\"width\":2300,\"height\":1293,\"caption\":\"To ensure secure-by-default devices at Microsoft, we\u2019ve taken a proactive approach to updating the Secure Boot certificates on our devices and learned valuable lessons you can use to protect your organization.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Keeping the enterprise secure by default: Secure Boot certificate updates at Microsoft\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/\",\"name\":\"Inside Track Blog\",\"description\":\"How Microsoft does IT\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/b623d895338189d1c487d4a0b93d4764\",\"name\":\"Alex Fleck\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/340114d229a43eb2e869170b958db0ecd4394144a36e326e2b188d4937b1989d?s=96&d=mm&r=g4cfaccedbee32e457bda8cf3019f258b\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/340114d229a43eb2e869170b958db0ecd4394144a36e326e2b188d4937b1989d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/340114d229a43eb2e869170b958db0ecd4394144a36e326e2b188d4937b1989d?s=96&d=mm&r=g\",\"caption\":\"Alex Fleck\"},\"description\":\"I\u2019ve always had a passion for story, whether I find it in a novel, a medieval epic, a movie, or a game. Now, I\u2019m helping tell stories about the people and teams at Microsoft who build the technology that moves our world. When I\u2019m not reading, writing, translating, or gaming, you\u2019ll find me on a backcountry trek in Canada\u2019s woods and mountains.\",\"url\":\"https:\\\/\\\/research.codeghost.online\\\/insidetrack\\\/blog\\\/author\\\/alexfleck\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Keeping the enterprise secure by default: Secure Boot certificate updates at Microsoft - Inside Track Blog","description":"Discover our process for updating boot certificates to ensure secure boot and support Zero Trust at Microsoft.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/research.codeghost.online\/insidetrack\/blog\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\/","og_locale":"en_US","og_type":"article","og_title":"Keeping the enterprise secure by default: Secure Boot certificate updates at Microsoft - Inside Track Blog","og_description":"Discover our process for updating boot certificates to ensure secure boot and support Zero Trust at Microsoft.","og_url":"https:\/\/research.codeghost.online\/insidetrack\/blog\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\/","og_site_name":"Inside Track Blog","article_published_time":"2026-08-13T15:45:00+00:00","og_image":[{"width":2300,"height":1293,"url":"https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/10910-Hero_image.jpg","type":"image\/jpeg"}],"author":"Alex Fleck","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Alex Fleck","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/research.codeghost.online\/insidetrack\/blog\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\/#article","isPartOf":{"@id":"https:\/\/research.codeghost.online\/insidetrack\/blog\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\/"},"author":{"name":"Alex Fleck","@id":"https:\/\/research.codeghost.online\/insidetrack\/blog\/#\/schema\/person\/b623d895338189d1c487d4a0b93d4764"},"headline":"Keeping the enterprise secure by default: Secure Boot certificate updates at Microsoft","datePublished":"2026-08-13T15:45:00+00:00","mainEntityOfPage":{"@id":"https:\/\/research.codeghost.online\/insidetrack\/blog\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\/"},"wordCount":1628,"image":{"@id":"https:\/\/research.codeghost.online\/insidetrack\/blog\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\/#primaryimage"},"thumbnailUrl":"https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/10910-Hero_image.jpg","keywords":["Customer Zero","Device management","Modern work","Security","Security and governance","Zero Trust"],"articleSection":["Microsoft Digital"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/research.codeghost.online\/insidetrack\/blog\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\/","url":"https:\/\/research.codeghost.online\/insidetrack\/blog\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\/","name":"Keeping the enterprise secure by default: Secure Boot certificate updates at Microsoft - Inside Track Blog","isPartOf":{"@id":"https:\/\/research.codeghost.online\/insidetrack\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/research.codeghost.online\/insidetrack\/blog\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\/#primaryimage"},"image":{"@id":"https:\/\/research.codeghost.online\/insidetrack\/blog\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\/#primaryimage"},"thumbnailUrl":"https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/10910-Hero_image.jpg","datePublished":"2026-08-13T15:45:00+00:00","author":{"@id":"https:\/\/research.codeghost.online\/insidetrack\/blog\/#\/schema\/person\/b623d895338189d1c487d4a0b93d4764"},"description":"Discover our process for updating boot certificates to ensure secure boot and support Zero Trust at Microsoft.","breadcrumb":{"@id":"https:\/\/research.codeghost.online\/insidetrack\/blog\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/research.codeghost.online\/insidetrack\/blog\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/research.codeghost.online\/insidetrack\/blog\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\/#primaryimage","url":"https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/10910-Hero_image.jpg","contentUrl":"https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/10910-Hero_image.jpg","width":2300,"height":1293,"caption":"To ensure secure-by-default devices at Microsoft, we\u2019ve taken a proactive approach to updating the Secure Boot certificates on our devices and learned valuable lessons you can use to protect your organization."},{"@type":"BreadcrumbList","@id":"https:\/\/research.codeghost.online\/insidetrack\/blog\/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/research.codeghost.online\/insidetrack\/blog\/"},{"@type":"ListItem","position":2,"name":"Keeping the enterprise secure by default: Secure Boot certificate updates at Microsoft"}]},{"@type":"WebSite","@id":"https:\/\/research.codeghost.online\/insidetrack\/blog\/#website","url":"https:\/\/research.codeghost.online\/insidetrack\/blog\/","name":"Inside Track Blog","description":"How Microsoft does IT","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/research.codeghost.online\/insidetrack\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/research.codeghost.online\/insidetrack\/blog\/#\/schema\/person\/b623d895338189d1c487d4a0b93d4764","name":"Alex Fleck","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/340114d229a43eb2e869170b958db0ecd4394144a36e326e2b188d4937b1989d?s=96&d=mm&r=g4cfaccedbee32e457bda8cf3019f258b","url":"https:\/\/secure.gravatar.com\/avatar\/340114d229a43eb2e869170b958db0ecd4394144a36e326e2b188d4937b1989d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/340114d229a43eb2e869170b958db0ecd4394144a36e326e2b188d4937b1989d?s=96&d=mm&r=g","caption":"Alex Fleck"},"description":"I\u2019ve always had a passion for story, whether I find it in a novel, a medieval epic, a movie, or a game. Now, I\u2019m helping tell stories about the people and teams at Microsoft who build the technology that moves our world. When I\u2019m not reading, writing, translating, or gaming, you\u2019ll find me on a backcountry trek in Canada\u2019s woods and mountains.","url":"https:\/\/research.codeghost.online\/insidetrack\/blog\/author\/alexfleck\/"}]}},"jetpack_featured_media_url":"https:\/\/research.codeghost.online\/insidetrack\/blog\/uploads\/prod\/2026\/08\/10910-Hero_image.jpg","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9hcZA-6wj","_links":{"self":[{"href":"https:\/\/research.codeghost.online\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/25067","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/research.codeghost.online\/insidetrack\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/research.codeghost.online\/insidetrack\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/research.codeghost.online\/insidetrack\/blog\/wp-json\/wp\/v2\/users\/115"}],"replies":[{"embeddable":true,"href":"https:\/\/research.codeghost.online\/insidetrack\/blog\/wp-json\/wp\/v2\/comments?post=25067"}],"version-history":[{"count":3,"href":"https:\/\/research.codeghost.online\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/25067\/revisions"}],"predecessor-version":[{"id":25091,"href":"https:\/\/research.codeghost.online\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/25067\/revisions\/25091"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/research.codeghost.online\/insidetrack\/blog\/wp-json\/wp\/v2\/media\/25068"}],"wp:attachment":[{"href":"https:\/\/research.codeghost.online\/insidetrack\/blog\/wp-json\/wp\/v2\/media?parent=25067"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/research.codeghost.online\/insidetrack\/blog\/wp-json\/wp\/v2\/categories?post=25067"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/research.codeghost.online\/insidetrack\/blog\/wp-json\/wp\/v2\/tags?post=25067"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/research.codeghost.online\/insidetrack\/blog\/wp-json\/wp\/v2\/coauthors?post=25067"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}