Skip to content
MS Intune Secure Boot Certificate Status Report Now Shows Detailed Status for Each Certificate

MS Intune Secure Boot Certificate Status Report Now Shows Detailed Status for Each Certificate

Written By Anoop C Nair
Last Updated May 19, 2026
Posted In Intune
SHARE

Key Takeaways

  • The new Secure Boot status report in MSIntune provides a detailed flyout view for each certificate status.
  • Admins can quickly identify whether Secure Boot certificates are up to date, not up to date, Unknown, or not applicable.
  • The flyout helps track both Microsoft and non-Microsoft UEFI certificates on devices.
  • Devices using Microsoft-only Secure Boot trust settings may show non-Microsoft certificates as “Not applicable.”
  • This improvement makes troubleshooting Secure Boot certificates and compliance monitoring much easier for IT admins.

The new Secure Boot Certificate Status report in MS Intune now provides a detailed flyout view for every certificate status, making it easier for admins to understand the exact Secure Boot configuration of each device. The report clearly shows whether certificates are up to date, not up to date, Unknown, or not applicable, helping IT teams quickly identify devices that may require attention.

Table of Content

MSIntune Secure Boot Certificate Status Report Now Shows Detailed Status for Each Certificate

The flyout also displays Microsoft and non-Microsoft UEFI certificates separately, along with their current status. This provides administrators with better visibility into Secure Boot trust settings and simplifies troubleshooting, compliance checks, and device security monitoring across the organisation.

Certificate status
Devices with Microsoft-only Secure Boot trust setting do not support non-Microsoft UEFI components. Therefore for these devices, the status for non-Microsoft certificates is not applicable.
MS Intune Secure Boot Certificate Status Report Now Shows Detailed Status for Each Certificate – Table 1
MS Intune Secure Boot Certificate Status Report Now Shows Detailed Status for Each Certificate - Fig.1
MS Intune Secure Boot Certificate Status Report Now Shows Detailed Status for Each Certificate – Fig.1

Devices with Microsoft-Only Secure Boot Trust Setting

Devices configured with the Microsoft-only Secure Boot trust setting do not support non-Microsoft UEFI components. Because of this limitation, the status for non-Microsoft Secure Boot certificates is shown as Not applicable in the MSIntune Secure Boot Certificate Status report.

This helps administrators clearly understand why certain non-Microsoft certificates are not evaluated on those devices. The report also provides better visibility into Secure Boot configuration details, making security validation and troubleshooting easier.

Patch My PC
Secure Boot ConfigurationStatus
Secure Boot EnabledYes
Secure Boot Trust SettingMicrosoft Only
Non-Microsoft UEFI Components SupportedNo
Non-Microsoft Certificate StatusNot Applicable
MS Intune Secure Boot Certificate Status Report Now Shows Detailed Status for Each Certificate – Table 2
MS Intune Secure Boot Certificate Status Report Now Shows Detailed Status for Each Certificate - Fig.2
MS Intune Secure Boot Certificate Status Report Now Shows Detailed Status for Each Certificate – Fig.2

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, join the WhatsApp Community  and the Whatsapp channel to get the latest news on Microsoft Technologies. We are there on Reddit as well

Author

Anoop C Nair has been Microsoft MVP for 10 consecutive years from 2015 onwards. He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM,  Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read