Windows 11 auto-replaces expiring Secure Boot certificates to preserve boot integrity

TL;DR
Microsoft is automatically updating expiring Secure Boot certificates on eligible Windows 11 24H2/25H2 devices via quality updates, with a phased rollout to high-confidence machines; admins can also deploy certificates manually via registry, WinCS, or Group Policy. To avoid boot issues, devices must receive the updates before the June 2026 expiry, or risk losing Windows Boot Manager and Secure Boot protections; administrators should inventory devices, verify Secure Boot status, update firmware, then apply the certificate updates.
New Windows updates replace expiring Secure Boot certificates BleepingComputer
Want the full story? Read the original reporting
Read on BleepingComputer