Skip to content
Track Secure Boot Certificate Expiry in MDE Security Console for Easy Device Tracking and Readiness

Track Secure Boot Certificate Expiry in MDE Security Console for Easy Device Tracking and Readiness

Written By Anoop C Nair
Last Updated July 2, 2026
Posted In Windows
SHARE

Key Takeaways

  • Microsoft Defender gives IT teams a single view of Secure Boot 2023 certificate readiness across all devices.
  • Devices are categorised as exposed, compliant, or not applicable to simplify tracking and prioritisation.
  • Access insights in the Defender portal under Exposure Management > Recommendations > Devices > Misconfigurations.
  • Exposed devices come with built-in guidance to help fix issues quickly.
  • Helps organisations get ready for the Secure Boot 2023 transition before certificate expiry.

Track Secure Boot Certificate Expiry in MDE Security Console for Easy Device Tracking and Readiness! Companies need to get ready for an important security update. The old Secure Boot certificates from 2011 will expire in June 2026, so they must be replaced with new 2023 certificates to keep devices safe. To help with this, Microsoft Defender has a tool that shows which devices are updated and which still need changes.

Table of Content

Track Secure Boot Certificate Expiry in MDE Security Console for Easy Device Tracking and Readiness

Microsoft Defender now offers a new recommendation that helps you make sure devices are updated to Secure Boot 2023 certificates and the latest boot manager. It gives you a simple, central view of your device security status across your organization.

You can easily use this tool in the Microsoft Defender portal by going to Exposure Management > Recommendations > Devices > Misconfigurations. It helps you quickly find devices that are not updated and gives clear steps to fix them.

  • Secure Boot 2023 Readiness Check in Microsoft Defender
    • The tool automatically groups devices into three types
      • Exposed devices (still using old certificates)
      • Compliant devices (updated and secure with 2023 certificates), and
      • Not applicable devices (where Secure Boot is turned off or not supported).
ActionDetails
Drill down into exposed devicesIdentify exactly which systems need attention
Filter and prioritizeUse OS platform and device details to focus on critical fixes
Export device dataShare insights with infrastructure and platform teams
Track progressMonitor rollout and updates across your organization
Integrate with workflowsAdd findings into your existing security and compliance processes
Track Secure Boot Certificate Expiry in MDE Security Console for Easy Device Tracking and Readiness – Table 1
Track Secure Boot Certificate Expiry in MDE Security Console for Easy Device Tracking and Readiness - Fig.1 - Creds to MS
Track Secure Boot Certificate Expiry in MDE Security Console for Easy Device Tracking and Readiness – Fig.1 – Creds to MS

Plan and Manage Your Secure Boot Updates

Use the Microsoft Defender tool to understand your current risk and take the right steps to secure your devices before the deadline. This helps you stay organised, involve the right teams, and ensure important systems are protected on time.

Patch My PC
  • Assess your exposure – Check how many devices need updates in your environment
  • Engage the right teams – Work with infrastructure and platform teams responsible for deployment
  • Prioritize critical devices – Focus first on high-value and sensitive systems
  • Track progress – Monitor updates and improve coverage before the June 2026 deadline
Track Secure Boot Certificate Expiry in MDE Security Console for Easy Device Tracking and Readiness - Fig.2
Track Secure Boot Certificate Expiry in MDE Security Console for Easy Device Tracking and Readiness – Fig.2

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, join the WhatsApp Community  and the Whatsapp channel to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair is a Workplace Technology solution architect with 25+ years of experience. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He is a blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, and Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Entra, and Microsoft Security.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws

Key Takeaways Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws! In the July 2026 Patch, Microsoft introduced new features designed to improve the overall Windows experience. The update adds enhancements to Windows Update for more flexible update management and introduces Point-in-Time Restore, providing an additional recovery option for […]

AC Anoop C Nair 9 min read
Intune

BitLocker Prompt Issue After June Patch KB5094126 Secure Boot UEFI 2023 Certificate Update

Key Takeaways BitLocker Prompt Issue After June Patch KB5094126 Secure Boot UEFI 2023 Certificate Update! After deploying the June 2026 Windows update (KB5094126), some HP EliteDesk 800 G6 devices began prompting for the BitLocker recovery key after every reboot. Based on our investigation, the Secure Boot UEFI 2023 certificate update does not appear to be […]

AC Anoop C Nair 5 min read
Microsoft Defender for Endpoint

Microsoft Defender for Endpoint EDR Updates are now Separate from Monthly Windows Security Updates for Faster Protection

Key Takeaways In this post, we are discussing how Microsoft Defender for Endpoint EDR Updates Will Be Delivered Through Microsoft Update. Microsoft has introduced a new update model for Microsoft Defender for Endpoint Detection and Response (EDR) security updates. Previously, these updates were included with the monthly Windows security updates. This change enables Microsoft to […]

AC Anoop C Nair 5 min read