Secure Boot update - Operational update

Tounou, Fernand 20 Reputation points
2026-07-20T08:34:09.63+00:00

Hello,

Microsfot published recently an artice about Secure Boot update.

We woul like to confirm the Operational impacts if we don't have Secure Boot update in our servers.

Thank you

Windows for business | Windows Server | Devices and deployment | Install Windows updates, features, or roles
0 comments No comments

Answer accepted by question author

Chen Tran 12,750 Reputation points Independent Advisor
2026-07-20T09:48:39.13+00:00

Hello Fernand,

Thank you for posting question on Microsoft Windows Forum!

Well! The plausible explanation to your query is that based on the best available information, not installing the Secure Boot update on your servers will lead to a degraded security posture over time. While your servers will continue to boot normally in the short term, they will lose the ability to receive critical future protections against boot-level threats.

The potential operational impacts for not updating is the loss of Future Boot-Level Security Updates. The servers will not be able to receive future updates to the Secure Boot database, revocation lists (DBX), or the Windows Boot Manager. This means that if new vulnerabilities or bootkits are discovered after the old certificates expire, your servers will remain unprotected against them. On the other hand, any new, properly signed pre-boot components (like firmware drivers or OS loaders) may not be trusted by your server's firmware if it lacks the new 2023 certificates. This could lead to compatibility issues, especially during future OS upgrades or when applying third-party signed firmware. In addition to that, since the update is primarily a security hardening measure. Without it, the server remains protected only by the older Secure Boot trust chain. It cannot benefit from Microsoft's newer boot security improvements and remains exposed to attack scenarios involving compromised or outdated bootloaders that Microsoft is actively revoking.

The best practice is to verify that server hardware and hypervisors have up-to-date UEFI firmware capable of handling the 2023 certificate rotation. Also performing a pilot deployment by staggering updates through Windows Update or managed deployment policies across pilot server cohorts ( or test the update process on a small group of servers representing your different hardware platforms to identify and resolve any vendor-specific quirks) rather than applying changes all at once. Ensure your BitLocker recovery keys are securely escrowed or backed up and accessible before deploying any updates known to impact Secure Boot. This will help you recover swiftly if a server triggers a recovery prompt on reboot

You are strongly encouraged to consult the following link for more information about Secure Boot Certificate updates guidance.

Hope the above information is helpful! If it is. Free feel to hit "Accepted" for benefitting others in community having the same query too.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Most helpful
  1. HARDCORE GAMES™ 350 Reputation points
    2026-07-20T18:37:35.5433333+00:00

    You are asking for trouble not using secure boot. Everything from rootkits and up.

    Make sure updates are also all installed.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.