SCCM Secure Boot Certificate Expiry: What IT Admins Must Do Before June 2026

Explore Our MECM / SCCM Training →

The expiration date for many Secure Boot certificates is fast approaching (June 2026). In this article, we walk through the steps for IT admins to identify affected devices within their SCCM environment, deploy Microsoft Secure Boot certificate updates using SCCM, and test these updates before a broad deployment.

Identifying Affected Devices

Use the SCCM hardware inventory to list all devices that require updated Secure Boot certificates. Inventory classes such as Microsoft_Windows_Security-CSPs and Microsoft-Windows-Pki-Cryptography contain relevant information.

Applying Updates via SCCM

Deploy the Secure Boot certificate updates using the Software Updates feature in SCCM. Create a new software update group and import the latest Microsoft Security Bulletins (MSRC) for the required certificates.

Testing Before Broad Deployment

Before deploying to all devices, test the updates on a pilot collection first. Check that the boot health remains intact post-update and verify that PXE boot and OS deployment are not affected.

Explore Our MECM / SCCM Training →

Written by Mohammed Akhter

Founder of ITP Training. 50,000+ students trained across 30+ countries in Microsoft endpoint and cloud security. Learn more →