OEMs Discuss Secure Boot Challenges
Last week, Microsoft invited enterprise IT administrators to a technical community exchange. They discussed the complex UEFI CA 2023 certificate update. Representatives from major hardware manufacturers attended the event. Acer, ASUS, Dell, HP, Lenovo, and Microsoft’s Surface team answered crucial Secure Boot questions. However, feedback from these IT professionals reveals significant problems. The current certificate migration process is causing widespread frustration.
The Expiration of UEFI CA 2011
The UEFI CA 2011 certificate expired in June 2026. Consequently, Microsoft started pushing the new UEFI CA 2023 certificate earlier this year. Microsoft delivers this certificate directly through standard system updates for personal devices. Therefore, some computers upgrade smoothly without any extra steps.
Enterprise IT Faces Migration Hurdles
Conversely, enterprise environments require IT administrators to update these certificates manually. A delayed update will not immediately break the device. However, ignoring the update will block future cumulative updates. Furthermore, it might prevent systems from upgrading to newer Windows 11 versions. As a result, IT teams in strict enterprise environments are rushing to update. They want to avoid missing critical security patches.
Hardware Compatibility Limitations
Many IT administrators shared their migration struggles during the forum. Some users asked if certain devices would remain stuck on the 2011 certificate forever. The Microsoft Surface team provided a clear answer. Eligible Surface devices will definitely receive the new update. However, older Windows 8 era models do not meet the hardware requirements. For example, the Surface Pro 3 and Surface 3 cannot receive the new certificate.
HP Identifies Firmware Boundaries
HP offered a very similar technical explanation. HP commercial devices from 2019 onward will automatically enable the 2023 certificate. Users must simply upgrade to the latest BIOS firmware first. Additionally, HP G8 and newer business laptops can get the certificate via BIOS updates. Ultimately, the manufacturer’s support cycle directly controls the migration success.
HP Equipment Triggers BitLocker Loops
The technical forum featured numerous complaints specifically regarding HP equipment. For instance, one administrator struggled to migrate an HP EliteBook 840 G6. Official documents listed BIOS version 01.33.00 as the minimum requirement. In reality, the update only worked on version 01.35.01. Worse still, the successful update immediately triggered a Microsoft BitLocker recovery loop.
NVRAM Space Causes Dropped Support
This administrator noted that HP previously promised support for 2018 models. Later, HP quietly removed several older devices from the compatibility list. Experts suspect insufficient NVRAM capacity caused this sudden change. Consequently, these older laptops lack official migration support. Another manager oversees 7,000 HP EliteBook and ZBook units. He warned that forcing the certificate update triggers BitLocker recovery screens constantly. Thus, a mass deployment would easily overwhelm any IT support team.
Microsoft and OEMs Must Fix the Process
Current feedback shows that many devices cannot transition smoothly. Microsoft has not revealed the exact number of failing personal computers. Still, IT administrators believe a massive number of consumer devices are failing to update. Consequently, these computers will miss future security updates. This failure will heavily weaken Windows 11 security.
The Need for Better BIOS Support
Ultimately, Microsoft and the OEMs must resolve these compatibility issues together. In theory, this certificate migration should happen automatically behind the scenes. In reality, hardware age and BIOS support create massive roadblocks. Therefore, IT administrators cannot execute large-scale migrations without reliable OEM firmware updates.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.