I have a couple of success stories to share.
AceMagic S1, Windows 11 Pro. Hardest part on this one was removing and re-adding the Hello PIN. Had to use the Forgot My PIN option.
check-uefi -verbose -audit
Windows PowerShell
Copyright (C) Microsoft Corporation. All rights reserved.
Windows 11 26H2 (26340.9233)
Secure Boot: ON
Virtualization Based Security: ON
BitLocker on (C:) OFF
BIOS Firmware
-------------
Default string Default string
Version: 5.26
Date: 2023-09-26
Factory Default UEFI PK Cert
----------------------------
DO NOT TRUST - AMI Test PK
UEFI PK Cert
------------
Windows OEM Devices PK
Factory Default UEFI KEK Certs
------------------------------
Microsoft Corporation KEK CA 2011
UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023
Factory Default UEFI DB Certs
-----------------------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023
Factory Default UEFI DBX Certs
------------------------------
(NONE)
EFI_CERT_SHA256_GUID Signatures: 217
UEFI DBX Certs
--------------
(NONE)
Windows BootMgr SVN is MISSING.
EFI_CERT_SHA256_GUID Signatures: 443
UEFI Variables
--------------
Credential Guard: ON
EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\\.\HarddiskVolume1\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.355, SVN 9.0
Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.
[OPTIONAL] SkuSiPolicy.p7b (for VBS) is MISSING.
AUDIT REPORT
============
1. Cannot confirm if W11 26H2 (26340.9233) has the latest files
2. [Production PCA 2011] is missing from UEFI DBX
3. DBX Updates are missing from UEFI DBX
4. Windows BootMgr SVN is missing from UEFI DBX
[OPTIONAL] SkuSiPolicy.p7b (for VBS) is missing from EFI
REQUIRED ACTION
===============
To REVOKE the [PCA 2011] cert, run the commands:
reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x282 /f
powershell Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"
Panasonic 3E tablet, Windows 10 (x86). Nearly gave up on this one. Check-UEFI got stuck with the error that you'd discovered from others running the 32-bit version of PowerShell and there are no 64-bit options. Put it in Setup mode and ran Update anyway. CA2023 KEK was delivered but enabling SB produced violation error. There are 3 options at the bottom of BIOS SB page, Authenticate Signatures, Delete Signatures, and View Signature Info. Authenticate allowed me to turn SB back on.
check-uefi -verbose -audit
Windows PowerShell
Copyright (C) Microsoft Corporation. All rights reserved.
Try the new cross-platform PowerShell
Meet Katmai's fishing giants
Windows 10 22H2 (19045.7663)
Secure Boot: ON
Virtualization Based Security: OFF (Audit Report runs as ON)
BitLocker on (C:) OFF
BIOS Firmware
-------------
3E Education PC by 3E
Version: PHBYT10A.86A.0031.2014.1216.1446
Date: 2014-12-15
Factory Default UEFI PK Cert
----------------------------
ECS
UEFI PK Cert
------------
Windows OEM Devices PK
Factory Default UEFI KEK Certs
------------------------------
Microsoft Corporation KEK CA 2011
ECS
UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023
ECS
Factory Default UEFI DB Certs
-----------------------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
ECS
UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023
ECS
Factory Default UEFI DBX Certs
------------------------------
(NONE)
EFI_CERT_SHA256_GUID Signatures: 0
UEFI DBX Certs
--------------
(NONE)
Windows BootMgr SVN is MISSING.
EFI_CERT_SHA256_GUID Signatures: 94
UEFI Variables
--------------
SBAT (Linux only): sbat,1,2024010900 / shim,4 / grub,3 / grub.debian,4
EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\\.\HarddiskVolume1\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.342, SVN 9.0
Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.
[OPTIONAL] SkuSiPolicy.p7b (for VBS) is MISSING.
& : The term 'C:\WINDOWS\SysNative\bcdedit' is not recognized as the name of a cmdlet, function, script file, or
operable program. Check the spelling of the name, or if a path was included, verify that the path is correct and try
again.
At C:\DownLoad\SecureBoot-CA-2023-Updates.v2026.08.21\Check_UEFI-CA2023.ps1:1640 char:20
+ if ((& "$env:SystemRoot\SysNative\bcdedit" | Select-Strin ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : ObjectNotFound: (C:\WINDOWS\SysNative\bcdedit:String) [], CommandNotFoundException
+ FullyQualifiedErrorId : CommandNotFoundException
DBX update file "C:\WINDOWS\SysNative\SecureBootUpdates\dbxupdate.bin" not found.check-uefi -verbose -audit
Windows PowerShell
Copyright (C) Microsoft Corporation. All rights reserved.
Try the new cross-platform PowerShell
Meet Katmai's fishing giants
Windows 10 22H2 (19045.7663)
Secure Boot: ON
Virtualization Based Security: OFF (Audit Report runs as ON)
BitLocker on (C:) OFF
BIOS Firmware
-------------
3E Education PC by 3E
Version: PHBYT10A.86A.0031.2014.1216.1446
Date: 2014-12-15
Factory Default UEFI PK Cert
----------------------------
ECS
UEFI PK Cert
------------
Windows OEM Devices PK
Factory Default UEFI KEK Certs
------------------------------
Microsoft Corporation KEK CA 2011
ECS
UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023
ECS
Factory Default UEFI DB Certs
-----------------------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
ECS
UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023
ECS
Factory Default UEFI DBX Certs
------------------------------
(NONE)
EFI_CERT_SHA256_GUID Signatures: 0
UEFI DBX Certs
--------------
(NONE)
Windows BootMgr SVN is MISSING.
EFI_CERT_SHA256_GUID Signatures: 94
UEFI Variables
--------------
SBAT (Linux only): sbat,1,2024010900 / shim,4 / grub,3 / grub.debian,4
EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\\.\HarddiskVolume1\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.342, SVN 9.0
Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.
[OPTIONAL] SkuSiPolicy.p7b (for VBS) is MISSING.
& : The term 'C:\WINDOWS\SysNative\bcdedit' is not recognized as the name of a cmdlet, function, script file, or
operable program. Check the spelling of the name, or if a path was included, verify that the path is correct and try
again.
At C:\DownLoad\SecureBoot-CA-2023-Updates.v2026.08.21\Check_UEFI-CA2023.ps1:1640 char:20
+ if ((& "$env:SystemRoot\SysNative\bcdedit" | Select-Strin ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : ObjectNotFound: (C:\WINDOWS\SysNative\bcdedit:String) [], CommandNotFoundException
+ FullyQualifiedErrorId : CommandNotFoundException
DBX update file "C:\WINDOWS\SysNative\SecureBootUpdates\dbxupdate.bin" not found.
Thanks, and I hope this is useful info for someone else.