How to check if your Secure Boot certs are updated. (three methods)


You shouldn't be required to type "powershell -ep bypass -f script.ps1" from inside a PS 7 window. That's lame.

That's why I had to go back, and retest everything so it worked on both PowerShell's.


That's why I made you, Method Three... in post #3 of this thread. :-)
See posts 1 and 3 in this topic. I edited them.

Personally, I like Method One in this topic.
 
Last edited:

My Computers My Computers

  • At a glance

    Win 11 Home ♦♦♦26200.8875 ♦♦♦♦♦♦♦25H2AMD Ryzen 7 3700XG.Skill (F4-3200C14D-16GTZKW)EVGA RTX 2070 (08G-P4-2171-KR)
    OS
    Win 11 Home ♦♦♦26200.8875 ♦♦♦♦♦♦♦25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® [May 2020]
    CPU
    AMD Ryzen 7 3700X
    Motherboard
    Asus Pro WS X570-ACE (BIOS 5302)
    Memory
    G.Skill (F4-3200C14D-16GTZKW)
    Graphics Card(s)
    EVGA RTX 2070 (08G-P4-2171-KR)
    Sound Card
    Realtek ALC1220P / ALC S1220A
    Monitor(s) Displays
    Dell U3011 30"
    Screen Resolution
    2560 x 1600
    Hard Drives
    2x Samsung 860 EVO 500GB,
    WD 4TB Black FZBX - SATA III,
    WD 8TB Black FZBX - SATA III,
    DRW-24B1ST CD/DVD Burner
    PSU
    PC Power & Cooling 750W Quad EPS12V
    Case
    Cooler Master ATCS 840 Tower
    Cooling
    CM Hyper 212 EVO (push/pull)
    Keyboard
    Ducky DK9008 Shine II Blue LED
    Mouse
    Logitech Optical M-100
    Internet Speed
    300/300
    Browser
    Firefox (latest)
    Antivirus
    Bitdefender Total Security
    Other Info
    Speakers: Klipsch Pro Media 2.1
  • At a glance

    Windows XP Pro 32bit w/SP3AMD Athlon 64 X2 5000+ (OC'd @ 3.2Ghz)TWIN2X2048-6400C4DHX (2 x 1GB, DDR2 800)EVGA 256-P2-N758-TR GeForce 8600GT SSC
    Operating System
    Windows XP Pro 32bit w/SP3
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® (not in use)
    CPU
    AMD Athlon 64 X2 5000+ (OC'd @ 3.2Ghz)
    Motherboard
    ASUS M2N32-SLI Deluxe Wireless Edition
    Memory
    TWIN2X2048-6400C4DHX (2 x 1GB, DDR2 800)
    Graphics card(s)
    EVGA 256-P2-N758-TR GeForce 8600GT SSC
    Sound Card
    Onboard
    Monitor(s) Displays
    ViewSonic G90FB Black 19" Professional (CRT)
    Screen Resolution
    up to 2048 x 1536
    Hard Drives
    WD 36GB 10,000rpm Raptor SATA
    Seagate 80GB 7200rpm SATA
    Lite-On LTR-52246S CD/RW
    Lite-On LH-18A1P CD/DVD Burner
    PSU
    PC Power & Cooling Silencer 750 Quad EPS12V
    Case
    Generic Beige case, 80mm fans
    Cooling
    ZALMAN 9500A 92mm CPU Cooler
    Keyboard
    Logitech Classic Keybooard 200
    Mouse
    Logitech Optical M-BT96a
    Internet Speed
    300/300
    Browser
    Firefox 3.x ??
    Antivirus
    Symantec (Norton)
    Other Info
    Still assembled, still runs. Haven't turned it on for 15 years?
You shouldn't be required to type "powershell -ep bypass -f script.ps1" from inside a PS 7 window. That's lame.

That's why I had to go back, and retest everything so it worked on both PowerShell's.
I for one appreciate all the work you've put into this, thanks for all the effort to make this painless! :crossed
 

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2, Build 26200.8894Intel Core i5 1450064GB DDR4GeForce RTX 4060
    OS
    Win 11 Pro 25H2, Build 26200.8894
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Brew
    CPU
    Intel Core i5 14500
    Motherboard
    Gigabyte B760M G P WIFI
    Memory
    64GB DDR4
    Graphics Card(s)
    GeForce RTX 4060
    Sound Card
    Chipset Realtek
    Monitor(s) Displays
    LG 45" Ultragear, Acer 24" 1080p
    Screen Resolution
    5120x1440, 1920x1080
    Hard Drives
    Crucial P310 2TB 2280 PCIe Gen4 3D NAND NVMe M.2 SSD (O/S)
    Silicon Power 2TB US75 NVMe PCIe Gen4 M.2 2280 SSD (backup)
    Crucial BX500 2TB 3D NAND (2nd backup)
    Seagate 4TB Ironwolf, rotating HDD archive files
    External off-line backup Drives: 2 NVMe 4TB drives in external enclosures
    PSU
    Thermaltake Toughpower GF3 750W
    Case
    LIAN LI LANCOOL 216 E-ATX PC Case
    Cooling
    Lots of fans!
    Keyboard
    Microsoft Comfort Curve 2000
    Mouse
    Logitech G305
    Internet Speed
    Verizon FiOS 1GB
    Browser
    Firefox
    Antivirus
    Malware Bytes & Windows Defender Security
  • At a glance

    Win 11 Pro 25H2, Build 26200.8894Intel Core i5 1440032GB DDR5Intel 700 Embedded GPU
    Operating System
    Win 11 Pro 25H2, Build 26200.8894
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Brew
    CPU
    Intel Core i5 14400
    Motherboard
    Gigabyte B760M DS3H AX
    Memory
    32GB DDR5
    Graphics card(s)
    Intel 700 Embedded GPU
    Sound Card
    Realtek Embedded
    Monitor(s) Displays
    27" HP 1080p
    Screen Resolution
    1920x1080
    Hard Drives
    Crucial P310 2TB 2280 PCIe Gen4 eD NAND PCIe SSD
    Samsung EVO 990 2TB NVMe Gen4 SSD
    Samsung 2TB SATA SSD
    PSU
    Thermaltake Smart BM3 650W
    Case
    Okinos Micro ATX Case
    Cooling
    Fans
    Keyboard
    Microsoft Comfort Curve 2000
    Mouse
    Logitech G305
    Internet Speed
    Verizon FiOS 1GB
    Browser
    Firefox
    Antivirus
    Malware Bytes & Windows Defender Security
  • Nimo N171 17" Laptop, (Intel i3-1215U, 16GB RAM, 2TB NVMe, Win11 Pro)
    Acemagic Vista Mini PC V1 (Intel N150, 16GB RAM, 1TB NVMe, Win11 Pro)
    HP ENVY h8-1540t, (24GB RAM, 2TB SSD, 2TB HDD, Win11 Pro)
I for one appreciate all the work you've put into this, thanks for all the effort to make this painless!
I got 2 out of three machines updated using these scripts, just 1 doorstop to contend with.
 

My Computers My Computers

  • At a glance

    Windows 11 Enterprise 25H2 26200 7462Intel XEON E5-2699 v364GB Teamgroup UD4-3600NVIDIA GeForce GTX 1080 Ti
    OS
    Windows 11 Enterprise 25H2 26200 7462
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom Build
    CPU
    Intel XEON E5-2699 v3
    Motherboard
    ASUS X99-A
    Memory
    64GB Teamgroup UD4-3600
    Graphics Card(s)
    NVIDIA GeForce GTX 1080 Ti
    Sound Card
    Integrated
    Monitor(s) Displays
    ACER X34 Predator
    Screen Resolution
    3440 x 1440
    Hard Drives
    Crucial CT1000P 3P SSD8 1TB
    Crucial CT1000 BX500 SSD 1TB
    PSU
    GameMax Pro
    Case
    Fractal Design
    Cooling
    Corsair H110iGT + 6 140mm Fans
    Keyboard
    Corsair K4
    Mouse
    G-Skill G502
    Internet Speed
    300MBs
    Browser
    Chrome
    Antivirus
    OEM
    Other Info
    ASUS RT-AC87U Router
  • At a glance

    25H2 26200.50748GB
    Operating System
    25H2 26200.5074
    Computer type
    Laptop
    Manufacturer/Model
    ASUS X555LA
    Memory
    8GB
    Browser
    Chrome
    Antivirus
    OEM
Why under UEFI DBX Certs does the first line say (NONE)?NONE.webp
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2i7-8565U16GBIntel UHD Graphics 620
    OS
    Windows 11 Pro 25H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo T490 (2020 Hardware)
    CPU
    i7-8565U
    Motherboard
    20N20028US
    Memory
    16GB
    Graphics Card(s)
    Intel UHD Graphics 620
    Sound Card
    Realtec Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 970 PRO 512GB NVMe
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Supported hardware, upgraded from Windows 10 Pro to Windows 11 Pro version 24H2 on 06/01/2025 using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/07/2025. Secure boot enabled. Secure Boot CA 2023 updated.
  • At a glance

    Windows 11 Pro 25H2i7-4770 (with SSE4.2, and POPCNT)16GBIntel HD Graphics 4600
    Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Lenovo ThinkCentre M83 (2014 Hardware)
    CPU
    i7-4770 (with SSE4.2, and POPCNT)
    Motherboard
    10AL000GUS
    Memory
    16GB
    Graphics card(s)
    Intel HD Graphics 4600
    Sound Card
    Realtec High Definition Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 860 PRO 1TB SATA
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Unsupported hardware, upgraded from Windows 10 Pro (TPM 1.2 & unsupported CPU, but does have SSE4.2, and POPCNT) to Windows 11 Pro version 24H2 on 06/15/2025. Added Registry Key HKEY_LOCAL_MACHINE\SYSTEM\Setup\MoSetup – AllowUpgradesWithUnsupportedTPMOrCPU=1 to allow installation using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/08/2025. Secure boot enabled. Secure Boot CA 2023 updated.
"(NONE)" means you don't have the CA 2011 cert revoked.

I choose to print "(NONE)" so it's more obvious that nothing's installed, rather than someone trying to figure a reason why there are no certs listed for that variable.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
"(NONE)" means you don't have the CA 2011 cert revoked.

I choose to print "(NONE)" so it's more obvious that nothing's installed, rather than someone trying to figure a reason why there are no certs listed for that variable.
Gotcha. Thanks.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2i7-8565U16GBIntel UHD Graphics 620
    OS
    Windows 11 Pro 25H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo T490 (2020 Hardware)
    CPU
    i7-8565U
    Motherboard
    20N20028US
    Memory
    16GB
    Graphics Card(s)
    Intel UHD Graphics 620
    Sound Card
    Realtec Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 970 PRO 512GB NVMe
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Supported hardware, upgraded from Windows 10 Pro to Windows 11 Pro version 24H2 on 06/01/2025 using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/07/2025. Secure boot enabled. Secure Boot CA 2023 updated.
  • At a glance

    Windows 11 Pro 25H2i7-4770 (with SSE4.2, and POPCNT)16GBIntel HD Graphics 4600
    Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Lenovo ThinkCentre M83 (2014 Hardware)
    CPU
    i7-4770 (with SSE4.2, and POPCNT)
    Motherboard
    10AL000GUS
    Memory
    16GB
    Graphics card(s)
    Intel HD Graphics 4600
    Sound Card
    Realtec High Definition Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 860 PRO 1TB SATA
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Unsupported hardware, upgraded from Windows 10 Pro (TPM 1.2 & unsupported CPU, but does have SSE4.2, and POPCNT) to Windows 11 Pro version 24H2 on 06/15/2025. Added Registry Key HKEY_LOCAL_MACHINE\SYSTEM\Setup\MoSetup – AllowUpgradesWithUnsupportedTPMOrCPU=1 to allow installation using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/08/2025. Secure boot enabled. Secure Boot CA 2023 updated.
Hello could someone just check the results I posted a few days ago here and let me know what (if anything) I should do?

Thanks a lot.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
PC/Desktop

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
what am I suppose to do here I am lost
I had it set for Other OS just before had more green

** What is we use Macrium BCDEDIT Fix ? it will clear the bootloader and such, would that cause issues? on my old computer intel 8xxx I can use secure boot on the windows for some reason it says secure boot violention

this is with Windows Maximum security


1769172678440.webp
1769172976356.webp






This was just before with Other OS

1769172746578.webp







now after I did the Windows commands

it checkmark one more

1769173717453.webp
1769173797330.webp
 
Last edited:

My Computer My Computer

At a glance

Windows 117800x3DKINGSTONE DDR5ZOTAC 4090 AMP EXTREME
OS
Windows 11
Computer type
PC/Desktop
Manufacturer/Model
Intel
CPU
7800x3D
Motherboard
MSI X690E TOMHAWK
Memory
KINGSTONE DDR5
Graphics Card(s)
ZOTAC 4090 AMP EXTREME
Sound Card
Creative SXFI AMP
Monitor(s) Displays
Samsung S90C
Screen Resolution
3840x2160
Hard Drives
Nmve WD850N 1TB
SanDisk SDSSDXPS480G
Samsung SSD 840 PRO Series 256Gb
WDC Enterprise Gold 16TB 512MB
WDC Enterprise Gold 6TB 256MB
PSU
ThermalTake ToughPower 1650
Case
Obsidian Series™ 750D Airflow Edition Full Tower ATX Case
Cooling
Arctic Liquid Freezer II 360
Keyboard
SteelSeries APEX PRO
Mouse
SwitPoint Z2
Internet Speed
5000/500
Browser
CHROME
Antivirus
ESET Internet Security
You must create a recovery drive for computers that don't have a BIOS for 2023 certificates, and therefore the values may be reset to the Secure Boot defaults. The computer will no longer boot. Disabling Secure Boot will work, but you won't be able to update the 2023 certificates with or without scripts because there will be errors in the Event Viewer, such as a TPM/WMI error.

Create a recovery drive from a device where the July 8, 2025 update, or a later update, and the first mitigation step (updating the Secure Boot DB) have been applied. Type "recovery drive" in the Windows search bar to create it. Once finished, in a command prompt as administrator, type these lines (replace the drive letter with the one corresponding to your recovery drive):

Code:
md D:\EFI\BOOT

Code:
copy C:\windows\boot\efi\securebootrecovery.efi D:\efi\boot\bootx64.efi

You will boot from this USB recovery drive, and upon startup, you will see 4 to 5 lines indicating either that the certificate does not need to be reinstalled (it is already present) or that it has been reinstalled.

This recovery drive will be useful as long as you still have computers without BIOS support for 2023 certificates.

Once the 2023 certificate has been applied using this recovery drive, you will need to repeat the entire procedure to apply the other 2023 certificates and the SVN.

Microsoft calls this the recovery app, the file is securebootrecovery.efi.
If I remember correctly, it's version 1.0. Perhaps there will be other versions to reapply all certificates (even SVN) from this recovery drive in one go.

 

My Computer My Computer

At a glance

windows 11
OS
windows 11
Edit: If the response from the first command tells you something like "the path already exists," don't worry, just do the second one, it'll work.
 

My Computer My Computer

At a glance

windows 11
OS
windows 11
securebootrecovery.efi installs a temporary Production CA 2023 into the UEFI so you can continue booting up.

Normally the CA 2023 DB certs are signed by the KEK CA 2023 cert. This recovery Production CA 2023 is signed by a KEK CA 2011, ensuring your CA 2023 boot file is allowed without the presence of a KEK CA 2023.

But it's an emergency hack. It's not designed to do anything except to allow an emergency boot. But unless there's a BIOS password, you can always temporarily disable Secure Boot.

https://uefi.org/sites/default/file...ecure Boot Ecosystem_Flick and Sutherland.pdf
If Windows cannot detect the 2023 Certificates in DB_DEFAULT, Windows update will place a 2011 KEK signed SecureBootRecovery.efi application immediately after Bootmgfw.efi in the boot order carrying a 2011 KEK signed 2023 Production CA

•This ensures the system continues to boot windows if Secure Boot Keys are accidently cleared

Honestly, you should follow the process outlined:
1. Temporarily disable Secure Boot in BIOS​
2. Boot normally.​
3. Repeat the original Secure Boot update procedure.​
4. Re-enable Secure Boot in BIOS​

Because the recovery EFI doesn't restore the other missing certs (it's intended for an accident where you factory reset the UEFI and lose all the CA 2023 changes), it's better you follow the original steps for completeness. The point of this exercise is not just to refresh the certs to 2023, but also to properly ban UEFI exploits using the CA 2011-signed files.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
securebootrecovery.efi installs a temporary Production CA 2023 into the UEFI so you can continue booting up.

Normally the CA 2023 DB certs are signed by the KEK CA 2023 cert. This recovery Production CA 2023 is signed by a KEK CA 2011, ensuring your CA 2023 boot file is allowed without the presence of a KEK CA 2023.

But it's an emergency hack. It's not designed to do anything except to allow an emergency boot. But unless there's a BIOS password, you can always temporarily disable Secure Boot.

https://uefi.org/sites/default/files/resources/Evolving the Secure Boot Ecosystem_Flick and Sutherland.pdf


Honestly, you should follow the process outlined:
1. Temporarily disable Secure Boot in BIOS​
2. Boot normally.​
3. Repeat the original Secure Boot update procedure.​
4. Re-enable Secure Boot in BIOS​

Because the recovery EFI doesn't restore the other missing certs (it's intended for an accident where you factory reset the UEFI and lose all the CA 2023 changes), it's better you follow the original steps for completeness. The point of this exercise is not just to refresh the certs to 2023, but also to properly ban UEFI exploits using the CA 2011-signed files.
It's late... Yes, what you're saying is possible. I experimented with booting using the BIOS without a 2023 certificate. I could not boot without the 2023 certificate, I had to boot from the recovery disk. And I also tried updating the certificates without Secure Boot enabled. I got tpm-wmi errors because Secure Boot wasn't enabled.
 

My Computer My Computer

At a glance

windows 11
OS
windows 11
The existing MS docs are poor, which is why you have to read the UEFI slides. And it's still confusing.

Capture.webp
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
@garlin i wonder if this is of help updating the secure boot certs
just as a heads up and something you may wish to check please ..

within the Group Policy Editor
Computer Configuration > Administrative Templates > Windows Components

there is a 'Secure Boot' folder with these settings ..
1. Enable Secure Boot Certificate Deployment
2. Automatic Certificate Deployment via Update
3. Certificate Deployment via Controlled Feature Rollout

i have mine all set to 'Enabled'

would these settings/features be of any use to the average user.
best of luck Steve ..
 

My Computers My Computers

  • At a glance

    Windows 11 HomeRyzen 7 5825u64GB DDR4 3200Ryzen 7 5825u
    OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • At a glance

    Ubuntu 22.04.5 LTSi5 7200u16GB DDR4Intel
    Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
@garlin i wonder if this is of help updating the secure boot certs
just as a heads up and something you may wish to check please ..

within the Group Policy Editor
Computer Configuration > Administrative Templates > Windows Components

there is a 'Secure Boot' folder with these settings ..
1. Enable Secure Boot Certificate Deployment
2. Automatic Certificate Deployment via Update
3. Certificate Deployment via Controlled Feature Rollout

i have mine all set to 'Enabled'

would these settings/features be of any use to the average user.
best of luck Steve ..
Enabling them appears to prevent automatic updating.
 

My Computer My Computer

At a glance

Windows 11 25H2Broadwell-e 6850K 4.5ghz @1.36v32GB Corsair LPM 3600 C16EVGA RTX 3080Ti FTW
OS
Windows 11 25H2
Computer type
PC/Desktop
Manufacturer/Model
EVGA home brew
CPU
Broadwell-e 6850K 4.5ghz @1.36v
Motherboard
EVGA X99 FTW K
Memory
32GB Corsair LPM 3600 C16
Graphics Card(s)
EVGA RTX 3080Ti FTW
Sound Card
Asus Centurion true 7.1 headset. (5 speakers in each earpeice)
Monitor(s) Displays
LG C4 55"
Screen Resolution
4K 144hz
Hard Drives
Various models of SSDs ~10TB No HDDs installed.
PSU
be quiet! BN516 Straight Power 12-1000w 80 Plus Platinum
Case
Corsair 780T modified to dual 200mm intake fans
Cooling
Corsair H110i
Keyboard
Corsair K95 Platinum
Mouse
Corsair M65 RGB Elite
Internet Speed
50Mbs
I opened up the SecureBoot.admx file, and it reveals:
Code:
    <policy name="SecureBoot_AvailableUpdatesPolicy"
        class="Machine"
        displayName="$(string.SecureBoot_AvailableUpdatesPolicy)"
        explainText="$(string.SecureBoot_AvailableUpdatesPolicy_Help)"
        key="SYSTEM\CurrentControlSet\Control\SecureBoot"
        valueName="AvailableUpdatesPolicy">
      <parentCategory ref="SecureBootCategory" />
      <supportedOn ref="windows:SUPPORTED_Windows8" />

      <enabledValue>
        <decimal value="22852" />
      </enabledValue>
      <disabledValue>
         <decimal value="0" />
      </disabledValue>
    </policy>

    <policy name="SecureBoot_HighConfidenceOptOut"
        class="Machine"
        displayName="$(string.SecureBoot_HighConfidenceOptOut)"
        explainText="$(string.SecureBoot_HighConfidenceOptOut_Help)"
        key="SYSTEM\CurrentControlSet\Control\SecureBoot"
        valueName="HighConfidenceOptOut">
      <parentCategory ref="SecureBootCategory" />
      <supportedOn ref="windows:SUPPORTED_Windows8" />

      <enabledValue>
        <decimal value="1" />
      </enabledValue>
      <disabledValue>
         <decimal value="0" />
      </disabledValue>
    </policy>

    <policy name="SecureBoot_MicrosoftUpdateManagedOptIn"
        class="Machine"
        displayName="$(string.SecureBoot_MicrosoftUpdateManagedOptIn)"
        explainText="$(string.SecureBoot_MicrosoftUpdateManagedOptIn_Help)"
        key="SYSTEM\CurrentControlSet\Control\SecureBoot"
        valueName="MicrosoftUpdateManagedOptIn">
      <parentCategory ref="SecureBootCategory" />
      <supportedOn ref="windows:SUPPORTED_Windows8" />

      <enabledValue>
        <decimal value="22852" />
      </enabledValue>
      <disabledValue>
         <decimal value="0" />
      </disabledValue>
    </policy>

So these reg values are already referenced here:
Registry key updates for Secure Boot: Windows devices with IT-managed updates

AvailableUpdates = 0x5944 (add CA 2023, but do not revoke CA 2011)

Enabling AvailableUpdatesPolicy does the same as the "reg add". Since the scheduled task runs periodically, it will invoke the "add CA 2023 certs" process in the background at some point. I don't see the advantage of using the GPO, unless someone is scared of copying & pasting commands from an online guide.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
I opened up the SecureBoot.admx file, and it reveals:
Code:
    <policy name="SecureBoot_AvailableUpdatesPolicy"
        class="Machine"
        displayName="$(string.SecureBoot_AvailableUpdatesPolicy)"
        explainText="$(string.SecureBoot_AvailableUpdatesPolicy_Help)"
        key="SYSTEM\CurrentControlSet\Control\SecureBoot"
        valueName="AvailableUpdatesPolicy">
      <parentCategory ref="SecureBootCategory" />
      <supportedOn ref="windows:SUPPORTED_Windows8" />

      <enabledValue>
        <decimal value="22852" />
      </enabledValue>
      <disabledValue>
         <decimal value="0" />
      </disabledValue>
    </policy>

    <policy name="SecureBoot_HighConfidenceOptOut"
        class="Machine"
        displayName="$(string.SecureBoot_HighConfidenceOptOut)"
        explainText="$(string.SecureBoot_HighConfidenceOptOut_Help)"
        key="SYSTEM\CurrentControlSet\Control\SecureBoot"
        valueName="HighConfidenceOptOut">
      <parentCategory ref="SecureBootCategory" />
      <supportedOn ref="windows:SUPPORTED_Windows8" />

      <enabledValue>
        <decimal value="1" />
      </enabledValue>
      <disabledValue>
         <decimal value="0" />
      </disabledValue>
    </policy>

    <policy name="SecureBoot_MicrosoftUpdateManagedOptIn"
        class="Machine"
        displayName="$(string.SecureBoot_MicrosoftUpdateManagedOptIn)"
        explainText="$(string.SecureBoot_MicrosoftUpdateManagedOptIn_Help)"
        key="SYSTEM\CurrentControlSet\Control\SecureBoot"
        valueName="MicrosoftUpdateManagedOptIn">
      <parentCategory ref="SecureBootCategory" />
      <supportedOn ref="windows:SUPPORTED_Windows8" />

      <enabledValue>
        <decimal value="22852" />
      </enabledValue>
      <disabledValue>
         <decimal value="0" />
      </disabledValue>
    </policy>

So these reg values are already referenced here:
Registry key updates for Secure Boot: Windows devices with IT-managed updates

AvailableUpdates = 0x5944 (add CA 2023, but do not revoke CA 2011)

Enabling AvailableUpdatesPolicy does the same as the "reg add". Since the scheduled task runs periodically, it will invoke the "add CA 2023 certs" process in the background at some point. I don't see the advantage of using the GPO, unless someone is scared of copying & pasting commands from an online guide.

i was enquiring because MS has made things regarding secure boot update as clear as mud for most people
so trying to find out exactly what these GPO secure entries do are somewhat vague.

but thank you for taking the time to look at them.
best of luck Steve ..
 

My Computers My Computers

  • At a glance

    Windows 11 HomeRyzen 7 5825u64GB DDR4 3200Ryzen 7 5825u
    OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • At a glance

    Ubuntu 22.04.5 LTSi5 7200u16GB DDR4Intel
    Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
i was enquiring because MS has made things regarding secure boot update as clear as mud for most people
so trying to find out exactly what these GPO secure entries do are somewhat vague.

but thank you for taking the time to look at them.
best of luck Steve ..
It's annoying that MS has now offered 4 different solutions for forcing updates (by order by release date):

1. Fiddling with AvailableUpdates reg value.
2. Intune policy for enterprises to give control of Secure Boot updates to MS (they push to your site based on telemetry)
3. GPO policy for enterprises (which is AvailableUpdates=0x5944, mirroring the current advice for option 1)
4. WinCSFlags.exe tool (which is even more cryptic about its flag values)

They probably all do the same thing: Allow "\Microsoft\Windows\PI\Secure-Boot-Update" to do the actual work.

The difference is how they feed AvailableUpdates in the background (directly or remotely triggered by some threshold).
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Back
Top Bottom