Secure Boot Certificate Expiration - Legacy BIOS

Paguirigan, Christian 20 Reputation points
2026-07-15T15:20:28.6266667+00:00

Hi,

I've noticed that some Windows KB release notes include a notice about the Windows Secure Boot certificate expiration. I'd like to confirm in writing whether this affects our environment and whether we need to install the Secure Boot patch that Microsoft has made available.

Our environment is running Windows Server 2019 configured in Legacy BIOS mode, where Secure Boot is not supported.

Based on this configuration, can you please confirm whether the Secure Boot certificate expiration impacts our systems and whether any action or patch installation is required?

Thank you!

Windows for business | Windows Server | Devices and deployment | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. VPHAN 42,480 Reputation points Independent Advisor
    2026-07-15T16:02:05.6066667+00:00

    Hi Paguirigan, Christian,

    In your case, operating Windows Server 2019 under the Legacy BIOS architecture dictates that this platform entirely lacks the integration of a cryptographic signature database, as well as the firmware communication functions required to activate the Secure Boot feature.

    To verify this on your server, the Windows operating system manages the state of the Secure Boot feature through the registry key located at the path HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\State. On a Legacy BIOS system, the UEFISecureBootEnabled value at this directory will be either unavailable or unreadable, because the underlying hardware lacks an NVRAM chip to store such certificates. Strictly due to this architectural framework, when Windows updates related to Secure Boot certificates are executed on your server, the system will automatically detect the hardware incompatibility and bypass the procedure. It avoids forcing an installation that would otherwise generate boot denial error codes or update failures (such as error code 0x800f0922, commonly observed on misconfigured UEFI machines).

    The expiration of the Secure Boot certificate presents no physical or logical vectors of impact on your current server environment. Therefore, your system is completely immune to this issue, and the deployment of the Secure Boot certificate update patch is unnecessary.

    Hope this answer has brought you some useful information. If it did, please hit “accept answer”. Should you have any questions, feel free to leave a comment.

    VPHAN

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.