Solved garlin's PowerShell scripts for updating Secure Boot CA 2023


Hello,
Just out of curiosity:
Following Microsoft's latest update yesterday, the Secure Boot status message changed from "more data needed" to "High Confidence."
I wonder how this is possible, given that the last available BIOS update for my old Dell XPS 13 9360 was released in 2021, and i needed performed the update using @garlin's scripts, even having to set the BIOS to "Custom Mode," and leave it that way as the PC wouldn't boot otherwise.
I'm updated thanks to @garlin but how would Microsoft have performed the update if I required manual BIOS intervention to carry it out?

Best regards ;-)
 

My Computer My Computer

At a glance

Windows 11 Pro 25H2Intel(R) Core(TM) i7-7500U CPU @ 2.70GHz8 GB
OS
Windows 11 Pro 25H2
Computer type
Laptop
Manufacturer/Model
Dell XPS 13 9360
CPU
Intel(R) Core(TM) i7-7500U CPU @ 2.70GHz
Memory
8 GB
Your BIOS has all of the CA 2023 certs installed, but CA 2011 has not been revoked (it's still optional for now). This PC is good for now.

Someone mentioned that a recent Beelink BIOS update added CA 2023 support. So it's always important to check for recent BIOS updates, in case your OEM has already added the CA 2023 certs into the firmware.
Very appreciative of your review and details .
 

My Computers My Computers

  • At a glance

    25H2 > to 10.0.26200 26200.8894AMD Ryzen 7 8845HSDDR5-5600 / PC5-44800 DDR5 SDRAM SO-DIMM32GAMD Radeon 780M
    OS
    25H2 > to 10.0.26200 26200.8894
    Computer type
    PC/Desktop
    Manufacturer/Model
    Beelink SER8 Mini
    CPU
    AMD Ryzen 7 8845HS
    Motherboard
    AZW SER8 AMD Promontory/Bixby FCH
    Memory
    DDR5-5600 / PC5-44800 DDR5 SDRAM SO-DIMM32G
    Graphics Card(s)
    AMD Radeon 780M
    Sound Card
    AMD Zen - Audio Processor - HD Audio Controller
    Monitor(s) Displays
    1 LG HDR 32"
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Crucial NVMe
    2TB Crucial NVME
    WD 1TB SSD SATA to USB3
    1 Seagate BUP Slim 2TB SATA to USB3
    1 Seagate BUP Slim 4TB SATA to USB3
    Samsung SSD 1TB SATA to USB3
    Samsung 500G SATA to USB3
    500G Crucial SSD to USB3
    PSU
    Beelink Proprietary
    Case
    Beelink Proprietary
    Cooling
    Beelink Proprietary
    Keyboard
    Logitech Backlit USB
    Mouse
    Logitech M510
    Internet Speed
    T-Mobile 5G 500 T-Mobile Home Internet -Asus ZenWifi AX Mesh
    Browser
    Edge, Firefox, Chrome
    Antivirus
    Microsoft Security 1.451.235.0 version created 6-2-2026
    Other Info
    Macrium X Build 10.0.8843
    Minitool Pro Ultimate 13.6
    Aomie Partition Assistant Pro 10.11.0
    REVO Pro 5.5.0.0 Portable
    JAM Treesize 9.7.2.2203 Perpetual Outdated.
    JAM Ultrasearch Pro 4.9.1.1204 Perpetual Outdated.
    Malwarebytes Pro 5.5.7.255 Update 1.0.110434 Component 157.0.5633
    Screenpresso Pro 2.2.12.3 beta (.Net 4.8) 2026-5-026
    Hamrick Vue Scan Pro 9.8.51.13
    Visio 2021 Pro 2021 MSO (Version 2605 Build 16.0.20026.20076) 64-bit
    Droid Transfer-Android 26.2.26.0
    Thunderbird 151.0.1
    em Client 10.4.5326
    Affinity Suite 3.2.1
    Microsoft 365 MSO (Version 2605 Build 16.0.20026.20076) 64-bit
    Adobe Creative cloud Version 6911 Apps 6.9.0.618 CCLibrary 4.16.2 (Photo subscription)
    HXD Hex Editor Version 2.5.0.0
    DAW Software Reaper-Izotope Plugins
    TGRMN Software ViceVersa Pro Build 6015 and VVEngine 3 Build 3000
    ISOBuster Pro 5.8.0.0
    Microsoft Visio Pro 2021 Version 2605 Build 16.0.20026.20076
    Many Other free and paid applications
    WYSIWYG Web Builder 21.07
    Filezilla 3.70.5
    Putty .83 and Putty Gen .83
    System Informer 4.0.26144.416 Stable
    O&O Regedit Version12 Build 2172
    WINRAR 7.22
    Lockhunter 3.4.3.146. x64
    Advanced IP Scanner 2.5.1
    Epson Eco Tank Printers and Epson Scanners.
    Bluestacks for Ring Cameras
    PEAK DCA Transistor Graphical USB Interface for Viewing Transistor Operational Curves. Win 10 Version and has functioneded on Win11 perfectly. Version 1.1.1963.
    Games - Card Games -Microsoft FSX "Pro Gold Flight Sim with add ons. Still works perfectly.
    Still run a few older onese successfully on win11 as well with no graphic issue.
  • At a glance

    Win11 Pro OEM 25H2 OS Build 26200.7019AMD Ryzen 7 8845HSDDR5 32GBeelink SER7
    Operating System
    Win11 Pro OEM 25H2 OS Build 26200.7019
    Computer type
    PC/Desktop
    Manufacturer/Model
    Beelink
    CPU
    AMD Ryzen 7 8845HS
    Motherboard
    AMD
    Memory
    DDR5 32G
    Graphics card(s)
    Beelink SER7
    Sound Card
    Beelink SER7
    Monitor(s) Displays
    Dell
    Screen Resolution
    Native
    Hard Drives
    1TB Crucial NVMe SSD 2G SATA
    PSU
    Beelink Proprietary
    Case
    Beelink Proprietary
    Cooling
    Beelink Proprietary
    Keyboard
    gaming keyboard
    Mouse
    MS
    Internet Speed
    T-Mobile 5G
    Antivirus
    Defender Malwarebytes
    Other Info
    Microsoft 365 Family Office
    Macrium X Subscription1 Version 10
    Mini-Tool Ultimate 13.0 Lifetime
    Malwarebytes Premium w/VPN 5
    Revo Pro Portable Pro 5
    Roboform 9.7.7.
    Others. (All legit)
Following Microsoft's latest update yesterday, the Secure Boot status message changed from "more data needed" to "High Confidence."
I wonder how this is possible, given that the last available BIOS update for my old Dell XPS 13 9360 was released in 2021, and i needed performed the update using @garlin's scripts, even having to set the BIOS to "Custom Mode," and leave it that way as the PC wouldn't boot otherwise.
I'm updated thanks to @garlin but how would Microsoft have performed the update if I required manual BIOS intervention to carry it out?
MS could have changed the status on their end, if they were informed either a newer BIOS was released (less likely on a 2021 PC), or Dell submitted a signed KEK instead of a BIOS update (more likely).

A BIOS update is always preferred, since any factory reset means you still have the CA 2023 certs installed. But a signed KEK file effectively does the same thing, and the update process can be repeated.

But honestly the whole Confidence Bucket thing is a black box, because MS refuses to divulge any statistics on their collected data. Other than sharing a giant list of unique combinations of PC motherboards & BIOS versions they've observed in the wild. And they won't inform you why they suddenly decided your PC is now in High Confidence after months of being in More Data Needed.

IMO it's better just to update a PC using whatever means works, and if the vendor catches up later... great.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
To prevent attackers from rolling back to an earlier file version, Windows has two different checks:

SVN -> Windows boot manager's SVN
SkuSiPolicy.p7b -> winload.efi's file version

If you have a SkuSiPolicy file deployed, this means you will have to rebuild your WinRE-based boot media (again). This is the price of keeping up with Windows boot security.

Hi Garlin, after installing this month's WU and then running the Check UEFI CA2023 script - verbose, I got "SkuSiPolicy.p7b Version: 3.0.0.15 and that was not matching. So, I ran the update script and got this below and it changed it to 3.0.0.16. Now all is good.

Is this what you mean when saying "we" will be required to rebuild the WinRE-based boot media "ourselves"? And that this will need to be done with each WU, (if the SkuSiPolicy.p7b Version changes)? Microsoft, in the future, will not do this automatically? 🤷‍♂️

Thanks...


EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\\.\HarddiskVolume1\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.352, SVN 9.0

Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.

SkuSiPolicy.p7b is CURRENT.
\\.\HarddiskVolume1\EFI\Microsoft\Boot\SkuSiPolicy.p7b
Version: 3.0.0.16
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.8894Intel® Core™ Ultra 7 265 1.8GHz to 5.3GHz (Ar...SK Hynix 32GB DDR5 5600 Desktop RAM UDIMM Non...Dell NVIDIA® GeForce RTX™ 4060 8GB GDDR6 & (i...
    OS
    Windows 11 Pro 25H2 26200.8894
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Tower Plus EBT2250, DOB: 06/15/2025
    CPU
    Intel® Core™ Ultra 7 265 1.8GHz to 5.3GHz (Arrow Lake)
    Motherboard
    Dell Inc. 02D3NT A00 (U3E1)
    Memory
    SK Hynix 32GB DDR5 5600 Desktop RAM UDIMM Non-ECC PC5-5600B
    Graphics Card(s)
    Dell NVIDIA® GeForce RTX™ 4060 8GB GDDR6 & (iGPU) Integrated Intel® UHD Graphics
    Sound Card
    Chipset Realtek High-Definition Audio with Dolby Atmos
    Monitor(s) Displays
    Dell Ultra Sharp U2515H 25-Inch Screen LED-Lit
    Screen Resolution
    2560 X 1440
    Hard Drives
    Samsung (NVMe PM9C1a 1024GB) M.2 PCIe NVMe Solid State Drive (OS), with Samsung Piccolo (S4LY022) 6-Core 4 Channel Controller.

    Samsung T7 500GB SSD, USB-C External Drive
    PSU
    Dell 460W
    Case
    Dell Tower Plus EBT 2250
    Cooling
    Fan
    Keyboard
    Dell Wired Keyboard - KB216
    Mouse
    Logitech M510
    Internet Speed
    Intel Killer E3100G 2.5 Gigabit Ethernet Controller
    Browser
    Microsoft Edge
    Antivirus
    Microsoft Windows Security
    Other Info
    The Samsung NVMe PM9C1a 1024GB SSD does not use a Phison NAND controller. Instead, it uses Samsung's in-house developed Piccolo (S4LY022) 6-Core 4 Channel Controller. The PM9C1a utilizes a controller built using Samsung's 5-nanometer process and seventh-generation V-NAND technology. 🤔
  • At a glance

    Windows 11 Pro 25H2 26200.889410th Generation Intel Core i7-10510U Processo...16GB DDR4 RAMNVIDIA® GeForce® MX250 with 2GB GDDR5 graphic...
    Operating System
    Windows 11 Pro 25H2 26200.8894
    Computer type
    Laptop
    Manufacturer/Model
    Dell Inspiron 15 7000 (7591) 2-in-1, DOB: 11/30/2019
    CPU
    10th Generation Intel Core i7-10510U Processor (8MB Cache, up to 4.9 GHz) Comet Lake
    Motherboard
    Dell 0NNW5N
    Memory
    16GB DDR4 RAM
    Graphics card(s)
    NVIDIA® GeForce® MX250 with 2GB GDDR5 graphics memory
    Sound Card
    Chipset Realtek ALC3254 🤔
    Monitor(s) Displays
    Dell 15.6-inch UHD Truelife Touch Narrow Border WVA Display with Active Pen support
    Screen Resolution
    3840 x 2160
    Hard Drives
    Intel NVME 512GB SSD with 32GB Intel Optane Memory, M.2 80mm PCIe 3.0 RAID

    SanDisk 256GB Extreme microSDXC UHS-I Memory Card
    PSU
    Dell 4-Cell Battery, 68 Whr (Integrated), 90 Watt AC Adapter
    Case
    Dell Inspiron 15 7000 2-in-1 (7591)
    Cooling
    Standard Dell Case Fan & Havit HV-F2056 USB Powered (3 Fans) Laptop Cooling Pad.
    Keyboard
    Dell
    Mouse
    Logitech Wireless Mouse M650L
    Internet Speed
    Wireless/Wired connectivity (WiFi 6 - 802.11 ax)
    Browser
    Microsoft Edge
    Antivirus
    Microsoft Windows Security
    Other Info
    From Dell: 512GB NVME Solid State Drive accelerated by 32GB Intel Optane Memory are the fastest as compared to NAND SSDs. Intel Optane H10 with SSD offers speedy storage and accelerates opening your programs.
Hi Garlin, after installing this month's WU and then running the Check UEFI CA2023 script - verbose, I got "SkuSiPolicy.p7b Version: 3.0.0.15 and that was not matching. So, I ran the update script and got this below and it changed it to 3.0.0.16. Now all is good.
I don't know if the Secure Boot task has responsibility for pushing a new SkuSiPolicy, whenever a new version appears. There's a hidden AvailableUpdates value (0x20) that manually controls that behavior, but Windows may not do this update automatically.

As I've highlighted before, forcing a new SkuSiPolicy before you're ready has bad consequences

Is this what you mean when saying "we" will be required to rebuild the WinRE-based boot media "ourselves"? And that this will need to be done with each WU, (if the SkuSiPolicy.p7b Version changes)? Microsoft, in the future, will not do this automatically? 🤷‍♂️
Why would MS update your boot media? It's not something created by MS, nor would it be expected that your boot drives are always plugged in. Also you could have an USB drive that's intended for another PC, which hasn't been updated in the same way.

Does updating your drives suck? Yes. But I've said this many times, Macrium and Hasleo (plus whoever else) has to get off their butts and adapt to the new world order. Rufus is already aware of SVN and SkuSiPolicy.

The backup vendors need to update their products to check once a day (in case you've just installed a new Monthly Update), and confirm if the SVN or SkuSiPolicy has changed since the last time you created a recovery drive. If either of them have changed, they should provide a courtesy notification to make a new recovery drive. And after you've recreated the drive, reset the check until the next time either one gets updated again.

None of this is MS's problem. The only major MS app that creates a bootable USB is MCT.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
I'm sorry - I did a poor posting of what I am wondering about. I got "my" boot media part all straighten out, and that is not a problem for me. I check and do that easily enough when needed.

I guess what I was trying to ask about is the SkuSiPolicy version changing with this month's WU and then displaying as not being current in the -Verbose output I ran after the WU, requiring me to run the update SkuSiPolicy script once again to make the WU version match what is on my system after the WU update. This what I am not clear on. Will I need to update the policy version myself with each WU from now on out, that is my question. Thanks.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.8894Intel® Core™ Ultra 7 265 1.8GHz to 5.3GHz (Ar...SK Hynix 32GB DDR5 5600 Desktop RAM UDIMM Non...Dell NVIDIA® GeForce RTX™ 4060 8GB GDDR6 & (i...
    OS
    Windows 11 Pro 25H2 26200.8894
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Tower Plus EBT2250, DOB: 06/15/2025
    CPU
    Intel® Core™ Ultra 7 265 1.8GHz to 5.3GHz (Arrow Lake)
    Motherboard
    Dell Inc. 02D3NT A00 (U3E1)
    Memory
    SK Hynix 32GB DDR5 5600 Desktop RAM UDIMM Non-ECC PC5-5600B
    Graphics Card(s)
    Dell NVIDIA® GeForce RTX™ 4060 8GB GDDR6 & (iGPU) Integrated Intel® UHD Graphics
    Sound Card
    Chipset Realtek High-Definition Audio with Dolby Atmos
    Monitor(s) Displays
    Dell Ultra Sharp U2515H 25-Inch Screen LED-Lit
    Screen Resolution
    2560 X 1440
    Hard Drives
    Samsung (NVMe PM9C1a 1024GB) M.2 PCIe NVMe Solid State Drive (OS), with Samsung Piccolo (S4LY022) 6-Core 4 Channel Controller.

    Samsung T7 500GB SSD, USB-C External Drive
    PSU
    Dell 460W
    Case
    Dell Tower Plus EBT 2250
    Cooling
    Fan
    Keyboard
    Dell Wired Keyboard - KB216
    Mouse
    Logitech M510
    Internet Speed
    Intel Killer E3100G 2.5 Gigabit Ethernet Controller
    Browser
    Microsoft Edge
    Antivirus
    Microsoft Windows Security
    Other Info
    The Samsung NVMe PM9C1a 1024GB SSD does not use a Phison NAND controller. Instead, it uses Samsung's in-house developed Piccolo (S4LY022) 6-Core 4 Channel Controller. The PM9C1a utilizes a controller built using Samsung's 5-nanometer process and seventh-generation V-NAND technology. 🤔
  • At a glance

    Windows 11 Pro 25H2 26200.889410th Generation Intel Core i7-10510U Processo...16GB DDR4 RAMNVIDIA® GeForce® MX250 with 2GB GDDR5 graphic...
    Operating System
    Windows 11 Pro 25H2 26200.8894
    Computer type
    Laptop
    Manufacturer/Model
    Dell Inspiron 15 7000 (7591) 2-in-1, DOB: 11/30/2019
    CPU
    10th Generation Intel Core i7-10510U Processor (8MB Cache, up to 4.9 GHz) Comet Lake
    Motherboard
    Dell 0NNW5N
    Memory
    16GB DDR4 RAM
    Graphics card(s)
    NVIDIA® GeForce® MX250 with 2GB GDDR5 graphics memory
    Sound Card
    Chipset Realtek ALC3254 🤔
    Monitor(s) Displays
    Dell 15.6-inch UHD Truelife Touch Narrow Border WVA Display with Active Pen support
    Screen Resolution
    3840 x 2160
    Hard Drives
    Intel NVME 512GB SSD with 32GB Intel Optane Memory, M.2 80mm PCIe 3.0 RAID

    SanDisk 256GB Extreme microSDXC UHS-I Memory Card
    PSU
    Dell 4-Cell Battery, 68 Whr (Integrated), 90 Watt AC Adapter
    Case
    Dell Inspiron 15 7000 2-in-1 (7591)
    Cooling
    Standard Dell Case Fan & Havit HV-F2056 USB Powered (3 Fans) Laptop Cooling Pad.
    Keyboard
    Dell
    Mouse
    Logitech Wireless Mouse M650L
    Internet Speed
    Wireless/Wired connectivity (WiFi 6 - 802.11 ax)
    Browser
    Microsoft Edge
    Antivirus
    Microsoft Windows Security
    Other Info
    From Dell: 512GB NVME Solid State Drive accelerated by 32GB Intel Optane Memory are the fastest as compared to NAND SSDs. Intel Optane H10 with SSD offers speedy storage and accelerates opening your programs.
I believe the Secure Boot task is cautious, and doesn't automatically push the newer file unless you use a specific AvailableUpdate value of 0x20.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
That might explain it, I missed that warning from the Dec 2025 release notes. Sigh, why can't a MS-written tool do this?

It's also interesting that MS's example tries to create a "\EFI\Microsoft\Boot" folder if needed. That would imply the original bcdboot action to provision the active EFI volume failed, or something clobbered it.

So you would have a worse problem on your hands than just have no (updated) SkuSiPolicy in place.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7

My Computers My Computers

  • At a glance

    Win11 25H2 26200.7623Intel XEON W-2245 8c/16t128GB DDR4-2933 ECCNvidia Quadro K4200
    OS
    Win11 25H2 26200.7623
    Computer type
    PC/Desktop
    Manufacturer/Model
    Lenovo P520
    CPU
    Intel XEON W-2245 8c/16t
    Memory
    128GB DDR4-2933 ECC
    Graphics Card(s)
    Nvidia Quadro K4200
    Sound Card
    Bultin
    Monitor(s) Displays
    LCD 24in
    Screen Resolution
    1920x1200
    Hard Drives
    1TB SSD system, 16TB data 3.5in HDD, 16TB backup 3.5in HDD
    PSU
    900W
    Cooling
    Air
    Internet Speed
    1Gb
    Browser
    Firefox & Chrome
    Antivirus
    MalwareBytes
  • At a glance

    Win10 22H2Intel Core i7-3520m16GBintegrated CPU graphics
    Operating System
    Win10 22H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo T530
    CPU
    Intel Core i7-3520m
    Memory
    16GB
    Graphics card(s)
    integrated CPU graphics
    Hard Drives
    1TB SSD
    Internet Speed
    1Gb
    Browser
    Fiefox & Chrome
    Antivirus
    Malwarebytes
Not strictly on topic, but interesting given the subject matter of this thread ...
The UEFI Forum (an industry group) has designated MS one of their "keepers of the DBX list", where MS hosts the reference copy on their Secure Boot Objects GitHub. Other industry players are supposed to consult this list when creating an updated BIOS image.

There's several aspects to this problem:

1. Someone has to decide which boot files are banned, based on previous security reports. MS appears to work with some of the leading Linux folks (hughsie for example) to co-ordinate the list's contents. MS is primarily responsible for maintaining it's own list of banned Windows boot files, and originally added 151 examples after the Black Lotus rootkit was exposed.

It's up the Linux community to submit non-MS files to the DBX list. MS takes their submissions and makes periodic updates, which are published on GitHub. The bulk of the DBX list is mostly non-Windows boot files of various types.

2. Due to concerns about the exhaustion of limited NVRAM space in older flash EEPROM's, it's preferred that individual file entries be avoided if it can be handled by the SVN (Windows) or SBAT (Linux) versioning methods. Using SVN or SBAT allows you to ban a whole series of (newer) boot files if they're written to obey the SVN or SBAT version rules.

But that doesn't cover all of the older boot files which were published before SVN or SBAT were popularized. This is where a vulnerable shim loader can get overlooked (because it was supposed to be banned before the repo was started in 2023), and nobody notices it's missing.

If you look at the GitHub commit activity, there's a lot of back and forth with outsiders making recommendations on what entries should be published and how the list is to be presented. MS is spending a lot of effort on trying to automate the submission process, and making more of the metadata available in parseable form. So other folks can write tools to compare the repo's entries against their own reference lists.

It's probably not perfect, but MS seems to be moving in the right direction. Albeit the GitHub review process runs at a snail's pace. :sleepy:
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Anyone that thinks any software as complex as Windows is totally "hack-proof" for all time is deluding themselves. It's inevitable that at some time someone will find a crack to wiggle through.
 

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2, Build 26200.8894Intel Core i5 1450064GB DDR4GeForce RTX 4060
    OS
    Win 11 Pro 25H2, Build 26200.8894
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Brew
    CPU
    Intel Core i5 14500
    Motherboard
    Gigabyte B760M G P WIFI
    Memory
    64GB DDR4
    Graphics Card(s)
    GeForce RTX 4060
    Sound Card
    Chipset Realtek
    Monitor(s) Displays
    LG 45" Ultragear, Acer 24" 1080p
    Screen Resolution
    5120x1440, 1920x1080
    Hard Drives
    Crucial P310 2TB 2280 PCIe Gen4 3D NAND NVMe M.2 SSD (O/S)
    Silicon Power 2TB US75 NVMe PCIe Gen4 M.2 2280 SSD (backup)
    Crucial BX500 2TB 3D NAND (2nd backup)
    Seagate 4TB Ironwolf, rotating HDD archive files
    External off-line backup Drives: 2 NVMe 4TB drives in external enclosures
    PSU
    Thermaltake Toughpower GF3 750W
    Case
    LIAN LI LANCOOL 216 E-ATX PC Case
    Cooling
    Lots of fans!
    Keyboard
    Microsoft Comfort Curve 2000
    Mouse
    Logitech G305
    Internet Speed
    Verizon FiOS 1GB
    Browser
    Firefox
    Antivirus
    Malware Bytes & Windows Defender Security
  • At a glance

    Win 11 Pro 25H2, Build 26200.8894Intel Core i5 1440032GB DDR5Intel 700 Embedded GPU
    Operating System
    Win 11 Pro 25H2, Build 26200.8894
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Brew
    CPU
    Intel Core i5 14400
    Motherboard
    Gigabyte B760M DS3H AX
    Memory
    32GB DDR5
    Graphics card(s)
    Intel 700 Embedded GPU
    Sound Card
    Realtek Embedded
    Monitor(s) Displays
    27" HP 1080p
    Screen Resolution
    1920x1080
    Hard Drives
    Crucial P310 2TB 2280 PCIe Gen4 eD NAND PCIe SSD
    Samsung EVO 990 2TB NVMe Gen4 SSD
    Samsung 2TB SATA SSD
    PSU
    Thermaltake Smart BM3 650W
    Case
    Okinos Micro ATX Case
    Cooling
    Fans
    Keyboard
    Microsoft Comfort Curve 2000
    Mouse
    Logitech G305
    Internet Speed
    Verizon FiOS 1GB
    Browser
    Firefox
    Antivirus
    Malware Bytes & Windows Defender Security
  • Nimo N171 17" Laptop, (Intel i3-1215U, 16GB RAM, 2TB NVMe, Win11 Pro)
    Acemagic Vista Mini PC V1 (Intel N150, 16GB RAM, 1TB NVMe, Win11 Pro)
    HP ENVY h8-1540t, (24GB RAM, 2TB SSD, 2TB HDD, Win11 Pro)
This wasn't a Windows problem. The DBX list is for all UEFI's, regardless of your OS. It can cover EFI tools that run without an OS, like a bootable BIOS updater or even something like Ventoy. If it boots directly from the EFI, then potentially it might need to banned.

It doesn't sound like there's a formal round table that meets regularly, where selected UEFI Forum reps and folks from MS and Linux (remember there isn't "one" Linux, so who would you invite?) vote on adding DBX entries. And it's perfectly understandable that non-MS folks don't want MS to completely own the entire process end-to-end.

The reason MS probably gets to be a keeper of the DBX is they can afford to keep more staff assigned to Secure Boot issues, and their outsized influence on PC OEM's to enforce changes. This oversight in forgetting the banned shim was more of a (people) process gap.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
I believe the Secure Boot task is cautious, and doesn't automatically push the newer file
I don't get it, why introduce a newer SkuSiPolicy.p7b version and not automatically use it?:rolleyes:
I don't recall any poster mentioning an auto upgrade.

unless you use a specific AvailableUpdate value of 0x20.
Maybe it was really meant for enterprise use only, where IT depts manage it in their OS images.

It's got me thinking, the importance of naming future backups, maybe something like 10.0.26200.8875-SVN9-3.0.0.16
Seems older backups will become redundant with each version bump.
 

My Computer My Computer

At a glance

windows 11 pro
OS
windows 11 pro
Computer type
PC/Desktop
Manufacturer/Model
geekom a5 5800h 170W PSU
I don't get it, why introduce a newer SkuSiPolicy.p7b version and not automatically use it?:rolleyes:
I don't recall any poster mentioning an auto upgrade.
Probably because there isn't a Windows tool which checks whether a specific SkuSiPolicy.p7b file would ban the current winload.efi on your active EFI partition, or prevent a WinRE-based device from booting.

There's also the point of how would an user know there's a new SkuSiPolicy to begin with?

Maybe it was really meant for enterprise use only, where IT depts manage it in their OS images.
I'm sure. But MS doesn't clearly state that in their Secure Boot guidance. The current statements simply suggest users deploy SkuSiPolicy, without making any distinctions if you're in a work or home environment. It's one of those unanswered questions whether the threat level is high enough that normal users should follow the instructions.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Probably because there isn't a Windows tool which checks whether a specific SkuSiPolicy.p7b file would ban the current winload.efi on your active EFI partition, or prevent a WinRE-based device from booting.
winload.efi (osloader.exe) and winresume.efi (hiberrsm.exe) are located on the Windows partition, they're the first file loaded from this partition by the bootmanager.

I assume they're preparing for using more of the SkuSiPolicy.p7b- concept. Reagentc /info now gives the Winre.wim version number (no more need to mount it with DISM) and at least for Win11 25H2 it's now no longer some numbers behind, but got updated together with the July LCU:

1784274643520.webp

MS is working quite a lot on the SkuSiPolicy.p7b. Compare the 3.0.0.10 version to the latest version and there are quite some additions. Version 3.0.0.10 focused solely on winload.efi (osloader.exe) and winresume.efi (hiberrsm.exe), version 3.0.0.16 has in addition
cbproxy.exe (10 entries)
ffuloader.efi (10 entries)
hvloader.efi (2 entries)
memdiag.exe (10 entries)
mmosloader.efi (10 entries)
Mobilestartup (10 entries)
resetphone.efi (10 entries)
SecConfig.efi (10 entries)
SfhRecovery.efi (8 entries)

Since there's the sideloading option (like loading memtest.efi from a correctly signed bootmanager) where memtest.efi still can be signed with a revoked cert, I assume they're going to / have to focus on those files, too.

There's also the point of how would an user know there's a new SkuSiPolicy to begin with?
Well, you already scripted it, didn't you. But the next question would be what was changed. From 15 to 16 the part with the recognizable filenames didn't change, for example.
 

My Computer My Computer

At a glance

W10
OS
W10
Hi Garlin, how can i fix this??

x.webp
 

My Computer My Computer

At a glance

11 25H2
OS
11 25H2
i'm unable to launch the command 😵‍💫🤐 , can you guide me further??
What error are you getting? Are you running this from a CMD or PowerShell session?

If you're in PowerShell, you may need to add the full path to the batch file.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7

Latest Support Threads

Back
Top Bottom