Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Managing Secure Boot Certificate Expiration with NinjaOne

NinjaOne
05/31/2026
0
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


TL;DR

  • Microsoft's three critical Secure Boot certificates expire in June and October 2026, requiring proactive certificate rotation to maintain security protections for the early boot process.
  • NinjaOne's community script automates certificate status auditing, Windows Update opt-in configuration, and ongoing compliance monitoring across device fleets through custom fields and scheduled tasks.
  • Older devices without firmware support for 2023 certificate injection will continue booting but permanently lose the ability to receive new Secure Boot security updates, requiring hardware refresh planning.

Understanding the Secure Boot Certificate Challenge

Microsoft has scheduled the expiration of three critical certificates in the UEFI Secure Boot trust chain for 2026. The KEK CA-2011 and UEFI CA-2011 certificates expire in June 2026, while the Windows Production PCA-2011 certificate expires in October 2026. While devices won't stop booting after these expirations and standard Windows updates will continue, they will lose the ability to receive new Secure Boot security protections for the early boot process. This creates a significant security gap for organizations managing large device fleets, particularly for older hardware that may not support the certificate injection required for the 2023 replacement certificates.

Implementing Automated Monitoring and Remediation

NinjaOne addresses this challenge through a community-developed script that automates certificate status monitoring and remediation across entire device fleets. The solution involves creating custom fields to display certificate status, importing and configuring the audit script, and establishing automated weekly reporting to track compliance. The script can run in audit mode for read-only assessment or in active mode to enable Windows Update opt-in, configure registry keys, set telemetry levels, and trigger scheduled tasks. Organizations can create filtered reports to identify non-compliant devices and prioritize remediation efforts based on device make, model, and warranty status. The approach provides visibility into which devices require firmware updates to support the new certificates and which legacy devices may be permanently unable to receive future Secure Boot security updates due to manufacturer end-of-support.

Chapters

0:00 - Secure Boot Certificate Expiration Overview
1:10 - Creating Custom Fields in NinjaOne
2:10 - Assigning Custom Fields to Device Roles
2:37 - Importing the Community Script
3:06 - Running the Script and Viewing Results
5:15 - Real-World Examples and Firmware Considerations

Key Quotes

0:53 "Devices that miss these updates won't stop booting, and standard Windows updates will continue to install, but they will lose the ability to receive new Secure Boot security protections for the early boot process."
3:16 "This is a fully read-only run, so nothing is changed on the actual device."
5:53 "For the 2023 certificates to be written into the UEFI Secure Boot Database, the device firmware first needs to support the injection."
6:11 "The device will still boot after June 2026, and regular Windows updates will keep installing. But because the firmware can accept the replacement certificates, it will be permanently unable to receive new Secure Boot Security updates moving forward."

Categories:
  • » Cybersecurity » Endpoint Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Endpoint Management
  • Security Operations
  • Compliance & Governance
  • How-To
  • Technical Deep Dive
  • UEFI Secure Boot
  • Certificate Management
  • Windows Security
  • Firmware Updates
  • Compliance Monitoring
  • Automation Scripts
  • Device Lifecycle Management
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Managing Secure Boot Certificate Expiration with NinjaOne

              Upcoming Webinar Calendar

              • 06/02/2026
                01:00 PM
                06/02/2026
                Delving into Our Latest Investigations and the 2026 Threat Landscape
                https://www.truthinit.com/index.php/channel/1930/delving-into-our-latest-investigations-and-the-2026-threat-landscape/
              • 06/10/2026
                02:00 PM
                06/10/2026
                Understanding the True Costs of DIY Data Classification vs. Buying Solutions
                https://www.truthinit.com/index.php/channel/1985/understanding-the-true-costs-of-diy-data-classification-vs-buying-solutions/
              • 06/23/2026
                10:00 AM
                06/23/2026
                Keepit Product Insights for June 23
                https://www.truthinit.com/index.php/channel/1990/keepit-product-insights-for-june-23/

              Upcoming Events

              • Jun
                02

                Delving into Our Latest Investigations and the 2026 Threat Landscape

                06/02/202601:00 PM ET
                • Jun
                  10

                  Understanding the True Costs of DIY Data Classification vs. Buying Solutions

                  06/10/202602:00 PM ET
                  • Jun
                    23

                    Keepit Product Insights for June 23

                    06/23/202610:00 AM ET
                    More events
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version