Explore Our MECM / SCCM Training →
The expiration date for many Secure Boot certificates is fast approaching (June 2026). In this article, we walk through the steps for IT admins to identify affected devices within their SCCM environment, deploy Microsoft Secure Boot certificate updates using SCCM, and test these updates before a broad deployment.
Identifying Affected Devices
Use the SCCM hardware inventory to list all devices that require updated Secure Boot certificates. Inventory classes such as Microsoft_Windows_Security-CSPs and Microsoft-Windows-Pki-Cryptography contain relevant information.
Applying Updates via SCCM
Deploy the Secure Boot certificate updates using the Software Updates feature in SCCM. Create a new software update group and import the latest Microsoft Security Bulletins (MSRC) for the required certificates.
Testing Before Broad Deployment
Before deploying to all devices, test the updates on a pilot collection first. Check that the boot health remains intact post-update and verify that PXE boot and OS deployment are not affected.
Explore Our MECM / SCCM Training →
Written by Mohammed Akhter
Founder of ITP Training. 50,000+ students trained across 30+ countries in Microsoft endpoint and cloud security. Learn more →
