How to Check and Handle Secure Boot Update Issues on Windows 11 Laptops

Learn how Secure Boot certificate updates affect some Windows 11 laptops, which models are impacted, and what steps to take to ensure your device stays protected.

How to Check and Handle Secure Boot Update Issues on Windows 11 Laptops
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

Why Secure Boot Updates Matter for Windows 11 Users

Secure Boot is a crucial security feature designed to prevent unauthorized or malicious boot software from loading when starting your Windows 11 laptop. It verifies that only trusted software signed with a valid certificate can execute during the boot process. However, the Secure Boot certificates themselves expire over time and require periodic updates to maintain protection against emerging threats.

Microsoft recently rolled out an update to renew these certificates from those issued in 2011 to new ones issued in 2023. This update is vital because expired certificates can gradually reduce your device’s firmware-level protection and expose it to certain advanced boot-level vulnerabilities.

For users of Windows 11 laptops, understanding how this update works and whether your device is properly equipped to receive it is important for maintaining your system's security integrity over the long term.

Which Devices Are Affected by Secure Boot Update Problems?

Microsoft confirms Secure Boot update failing on some Windows 11 PCs,  blocks update due to known issues
Microsoft confirms Secure Boot update failing on some Windows 11 PCs, blocks update due to known issues

While the Secure Boot certificate update is broadly distributed via Windows Update, some laptops—particularly older models or those that no longer receive firmware updates from their Original Equipment Manufacturers (OEMs)—are facing challenges installing the new certificate. Issues stem from firmware incompatibilities that cause failures during the update process.

Microsoft has paused the rollout for affected devices to prevent boot failures or other problems. This pause means that on many older or unsupported laptops, the latest Secure Boot protections cannot be applied until OEMs release firmware patches or updates resolving these issues.

It’s important to note that this is not an immediate security risk or system failure for affected users. Current Secure Boot functionality remains operational, but the inability to update means your device's protection against future vulnerabilities might diminish gradually.

How to Check If Your Windows 11 Laptop Supports the Latest Secure Boot Certificate

It helps to proactively verify your device’s Secure Boot status to avoid surprises and ensure you are prepared for any firmware updates. Follow these steps:

  1. Open the Windows Security app via the Start menu search.
  2. Select "Device Security" from the sidebar to access the Device Security dashboard.
  3. Locate the Secure Boot section and review the status message shown:
  • "Secure Boot is on" – This means Secure Boot is enabled but does not confirm if the latest certificate is installed. To see detailed status, ensure all Windows Updates are installed, as Microsoft is rolling out updates that report certificate version.
  • "Devices in this group are affected by a known issue" – Your device cannot complete the update currently but may receive a firmware patch from your OEM soon. Check your laptop manufacturer's support page for BIOS or firmware updates.
  • "Secure Boot is on, but your device does not support the automated Secure Boot certificate update due to hardware or firmware limitations" – This indicates your laptop likely has ended official OEM support for firmware updates. Your device will retain current protections but won't get future certificate updates unless a manual workaround is provided.

What Windows 11 Laptop Users Should Do Next

Watch out Windows users, a Secure Boot update has been blocked on Windows 11  PCs due to failing on some devices — here's how to check if you're affected  | TechRadar
Watch out Windows users, a Secure Boot update has been blocked on Windows 11 PCs due to failing on some devices — here's how to check if you're affected | TechRadar

If you discover your device is impacted, here’s what you can do:

  • Check your laptop manufacturer’s support site regularly for BIOS or UEFI firmware updates that enable the latest Secure Boot certificates.
  • Keep Windows Update current to receive the latest security patches and utility updates that enhance Secure Boot reporting and protection.
  • Maintain standard security best practices including running antivirus software, enabling firewall protection, and avoiding suspicious downloads, since many protections rely on the OS beyond Secure Boot.
  • Consider hardware upgrade options if your device no longer receives firmware updates and security features are critical for your use case.

By addressing the Secure Boot update status now, Windows 11 laptop users can ensure continued defense against boot-time malware techniques that could compromise your system at a fundamental level.

Secure Boot Certificate Update: Key Takeaway for Windows 11 Laptop Users

Secure Boot remains an essential security layer on Windows 11 laptops, but its effectiveness hinges on timely certificate updates. Many laptops, especially older or unsupported models, face hurdles updating to the latest 2023 certificates due to firmware limitations.

This situation does not pose an immediate threat but signals a gradual reduction in system-level security resilience over time. Windows 11 users should verify their Secure Boot status via the Windows Security app, stay informed on OEM firmware updates, and continue following all standard protection practices. For devices without OEM support, planning toward future hardware upgrades could be necessary to maintain robust security defenses.

React to this story

Related Posts