Microsoft Updates Secure Boot Certificates on Over Half a Million Devices
Microsoft manages around 500,000 Windows client devices worldwide, from employee laptops to servers and meeting room systems. To maintain end-to-end security in such a complex environment, Secure Boot is used to verify firmware, boot loaders, and operating system components before startup.
When three Microsoft-issued Secure Boot certificates approached expiration in 2026, the company's IT organization knew it needed to take action early to get ahead of the update. By partnering with various product teams, they developed an approach that ensured secure-by-default devices from firmware up.
The team replaced three legacy certificates with four new ones across a diverse device fleet. The real work was validating the update across thousands of device models and deployment scenarios. They started early to test, validate, and gradually deploy the updates before the certificate expiration dates arrived.