{"id":14189,"date":"2025-12-09T07:01:11","date_gmt":"2025-12-08T22:01:11","guid":{"rendered":"https:\/\/m365jp.net\/?p=14189"},"modified":"2025-12-09T07:06:09","modified_gmt":"2025-12-08T22:06:09","slug":"mc1193371-how-to-use-microsoft-intune-to-update-expiring-secure-boot-certificates","status":"publish","type":"post","link":"https:\/\/m365jp.net\/index.php\/2025-12-09-mc1193371-how-to-use-microsoft-intune-to-update-expiring-secure-boot-certificates","title":{"rendered":"MC1193371 | How to use Microsoft Intune to update expiring Secure Boot certificates"},"content":{"rendered":"<div class=\"postie-post\">\n<div>\n<hr>\n<table id=\"section\">\n<tbody>\n<tr>\n<th width=\"95%\">MC1193371 | How to use Microsoft Intune to update expiring Secure Boot certificates<\/th>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr>\n<table id=\"data\">\n<tbody>\n<tr>\n<th>Classification<\/th>\n<td>stayInformed<\/td>\n<\/tr>\n<tr>\n<th>Last Updated<\/th>\n<td>12\/08\/2025 21:59:20<\/td>\n<\/tr>\n<tr>\n<th>Start Time<\/th>\n<td>12\/08\/2025 21:59:19<\/td>\n<\/tr>\n<tr>\n<th>End Time<\/th>\n<td>12\/08\/2026 21:59:19<\/td>\n<\/tr>\n<tr>\n<th>Message Content<\/th>\n<td>\n<div>You can now&nbsp;deploy, manage, and monitor Secure Boot certificate updates.&nbsp;This method represents an alternative to&nbsp;setting&nbsp;registry keys and using Group Policy.&nbsp;You can&nbsp;use Intune to&nbsp;deploy&nbsp;on&nbsp;all domain-joined Windows clients, opt out of high-confidence   buckets, and opt in&nbsp;to Microsoft managing these updates.&nbsp;<\/div>\n<div>&nbsp;<\/div>\n<div><b>When will this happen:<\/b>&nbsp;<\/div>\n<div>The&nbsp;following&nbsp;settings are&nbsp;now&nbsp;available&nbsp;in&nbsp;the&nbsp;Intune&nbsp;settings&nbsp;catalog:&nbsp;<\/div>\n<ul>\n<li>Configure Microsoft Update Managed Opt-In&nbsp;<\/li>\n<li>Configure High-Confidence Opt-Out&nbsp;<\/li>\n<li>Enable&nbsp;SecureBoot&nbsp;Certificate Updates&nbsp;<\/li>\n<\/ul>\n<div>&nbsp;<\/div>\n<div><b>How this will affect your organization:<\/b>&nbsp;<\/div>\n<div>As the 2011&nbsp;Secure Boot certificates&nbsp;will&nbsp;start expiring in June 2026,&nbsp;it&nbsp;is&nbsp;essential that organizations start planning for and updating to 2023 certificates.&nbsp;You can now use Microsoft Intune, in addition to registry keys and Group Policy, to&nbsp;deploy,   manage, and&nbsp;monitor&nbsp;this update process.&nbsp;The three&nbsp;new&nbsp;settings are&nbsp;disabled by default.&nbsp;Enable them to start taking advantage of the desired&nbsp;capabilities.&nbsp;<\/div>\n<div>&nbsp;<\/div>\n<div><b>What you need to do to prepare:<\/b>&nbsp;<\/div>\n<div>To manage Secure Boot certificate updates in Intune, enable the new settings&nbsp;by navigating to the&nbsp;Microsoft Intune&nbsp;admin&nbsp;center:&nbsp;<\/div>\n<ol>\n<li>Under\u202f<b>Devices\u202f<\/b>&gt;\u202f<b>Manage devices<\/b>,\u202fselect\u202f<b>Configuration<\/b>.&nbsp;<\/li>\n<li>Select\u202f<b>Create\u202f<\/b>and select\u202f<b>New Policy.<\/b>&nbsp;<\/li>\n<li>Select&nbsp;<b>Create a profile<\/b>\u202fin the right-hand pane.&nbsp;<\/li>\n<li>Fill in\u202f<b>Platform\u202f<\/b>with\u202f<b>Windows 10 and later<\/b>.&nbsp;<\/li>\n<li>Select the\u202f<b>Settings Catalog<\/b>\u202funder the\u202f<b>Profile Type<\/b>.\u202f\u200b\u200b\u200b\u200b\u200b&nbsp;<\/li>\n<li>Begin creating&nbsp;a profile by giving the profile a name. Press\u202f<b>Next<\/b>.\u200b\u200b\u200b\u200b\u200b\u200b&nbsp;<\/li>\n<li>Under\u202f<b>Configuration settings<\/b>, select\u202f<b>Add settings<\/b>.\u202fIn&nbsp;the Settings picker,&nbsp;search&nbsp;for Secure Boot<em>.<\/em>\u202fThere should be&nbsp;three settings in the Secure Boot category.&nbsp;<\/li>\n<li>Select&nbsp;the&nbsp;desired&nbsp;settings&nbsp;for your organization:&nbsp;Configure Microsoft Update Managed Opt-In,&nbsp;Configure High-Confidence Opt-Out,&nbsp;and&nbsp;Enable&nbsp;SecureBoot&nbsp;Certificate Updates&nbsp;(preselected for you).&nbsp;<\/li>\n<li>Finish the profile for the devices that will&nbsp;use&nbsp;these settings.&nbsp;<\/li>\n<\/ol>\n<div>&nbsp;<\/div>\n<div><b>Additional&nbsp;information:<\/b>&nbsp;<\/div>\n<ul>\n<li>Read complete guidance at&nbsp;<a href=\"https:\/\/support.microsoft.com\/topic\/microsoft-intune-method-of-secure-boot-for-windows-devices-with-it-managed-updates-1c4cf9a3-8983-40c8-924f-44d9c959889d\" rel=\"noopener noreferrer\" target=\"_blank\">Microsoft Intune method   of Secure Boot for Windows devices with IT-managed updates.<\/a>&nbsp;<\/li>\n<li>Compare this&nbsp;method&nbsp;to&nbsp;<a href=\"https:\/\/support.microsoft.com\/kb\/5068202\" rel=\"noopener noreferrer\" target=\"_blank\">Registry key updates for Secure Boot: Windows devices with IT-managed updates<\/a>.&nbsp;&nbsp;<\/li>\n<li>Compare this method to&nbsp;<a href=\"https:\/\/support.microsoft.com\/kb\/5068198\" rel=\"noopener noreferrer\" target=\"_blank\">Group Policy Objects (GPO) method of Secure Boot for Windows devices with IT-managed updates<\/a>.&nbsp;<\/li>\n<li>See how these methods work together in&nbsp;<a href=\"https:\/\/techcommunity.microsoft.com\/blog\/windows-itpro-blog\/secure-boot-playbook-for-certificates-expiring-in-2026\/4469235\" rel=\"noopener noreferrer\" target=\"_blank\">Secure Boot playbook for certificates expiring   in 2026.<\/a><\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<th>Machine Translation<\/th>\n<td>\n<div>\u73fe\u5728&nbsp;\u3001Secure Boot\u8a3c\u660e\u66f8\u306e\u66f4\u65b0\u3092\u5c55\u958b\u3001\u7ba1\u7406\u3001\u76e3\u8996\u3067\u304d\u307e\u3059\u3002&nbsp;\u3053\u306e\u65b9\u6cd5\u306f\u30ec\u30b8\u30b9\u30c8\u30ea\u30ad\u30fc\u306e\u8a2d\u5b9a&nbsp;\u3084\u30b0\u30eb\u30fc\u30d7\u30dd\u30ea\u30b7\u30fc\u306e&nbsp;\u4ee3\u66ff\u624b\u6bb5\u3067\u3059\u3002&nbsp;Intune&nbsp;\u3092\u4f7f\u3063\u3066\u30c9\u30e1\u30a4\u30f3\u53c2\u52a0\u6e08\u307f\u306eWindows\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u3059\u3079\u3066\u306b&nbsp;\u30c7\u30d7\u30ed\u30a4&nbsp;\u3057\u3001\u9ad8\u4fe1\u983c\u5ea6\u30d0\u30b1\u30c3\u30c8\u304b\u3089\u30aa\u30d7\u30c8\u30a2\u30a6\u30c8\u3057\u3001&nbsp;Microsoft\u306b\u3053\u308c\u3089\u306e\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u3092\u7ba1\u7406\u3055\u305b\u308b\u3053\u3068\u304c\u53ef\u80fd\u3067\u3059&nbsp;\u3002&nbsp;<\/div>\n<div>&nbsp;<\/div>\n<div><b>\u3053\u308c\u306f\u3044\u3064\u5b9f\u73fe\u3057\u307e\u3059\u304b:<\/b>&nbsp;<\/div>\n<div>\u4ee5\u4e0b\u306e\u8a2d\u5b9a\u304c&nbsp;Intune&nbsp;&nbsp;&nbsp;\u306e\u8a2d\u5b9a\u30ab\u30bf\u30ed\u30b0\u3067&nbsp;&nbsp;\u5229\u7528&nbsp;\u53ef\u80fd\u306b\u306a\u308a\u307e\u3057\u305f:&nbsp;&nbsp;&nbsp;<\/div>\n<ul>\n<li>Microsoft Update \u7ba1\u7406\u30aa\u30d7\u30c8\u30a4\u30f3&nbsp;\u306e\u8a2d\u5b9a<\/li>\n<li>\u9ad8\u4fe1\u983c\u5ea6\u30aa\u30d7\u30c8\u30a2\u30a6\u30c8&nbsp;\u306e\u8a2d\u5b9a<\/li>\n<li>SecureBoot&nbsp;\u8a3c\u660e\u66f8\u306e\u66f4\u65b0&nbsp;\u3092\u6709\u52b9\u306b\u3059\u308b&nbsp;<\/li>\n<\/ul>\n<div>&nbsp;<\/div>\n<div><b>\u3053\u308c\u304c\u3042\u306a\u305f\u306e\u7d44\u7e54\u306b\u3069\u306e\u3088\u3046\u306a\u5f71\u97ff\u3092\u4e0e\u3048\u308b\u304b:<\/b>&nbsp;<\/div>\n<div>2011&nbsp;\u5e74\u306eSecure Boot\u8a3c\u660e\u66f8&nbsp;&nbsp;\u306f2026\u5e746\u6708\u306b\u671f\u9650\u5207\u308c\u3068\u306a\u308b\u305f\u3081\u3001&nbsp;&nbsp;&nbsp;\u7d44\u7e54\u306f2023\u5e74\u8a3c\u660e\u66f8\u306e\u8a08\u753b\u3068\u66f4\u65b0\u3092\u59cb\u3081\u308b\u3053\u3068\u304c\u4e0d\u53ef\u6b20\u3067\u3059\u3002&nbsp;Microsoft Intune\u306f\u30ec\u30b8\u30b9\u30c8\u30ea\u30ad\u30fc\u3084\u30b0\u30eb\u30fc\u30d7\u30dd\u30ea\u30b7\u30fc\u306b\u52a0\u3048\u3001\u3053\u306e\u66f4\u65b0\u30d7\u30ed\u30bb\u30b9\u306e&nbsp;\u5c55\u958b\u3001\u7ba1\u7406&nbsp;\u3001\u76e3\u8996&nbsp;\u306b\u4f7f\u3048\u307e\u3059\u3002&nbsp;\u3053\u308c\u30893\u3064\u306e&nbsp;\u65b0\u3057\u3044&nbsp;\u8a2d\u5b9a\u306f\u30c7\u30d5\u30a9\u30eb\u30c8\u3067\u7121\u52b9\u306b\u306a\u3063\u3066\u3044\u307e\u3059&nbsp;\u3002&nbsp;\u305d\u308c\u3089\u3092\u6709\u52b9\u306b\u3057\u3066\u53d6\u5f97\u3092\u958b\u59cb\u3057\u3066\u304f\u3060\u3055\u3044\u671b\u307e\u3057\u3044&nbsp;\u6a5f\u80fd\u306e\u5229\u70b9\u3092\u6d3b\u304b\u3059\u3002&nbsp;<\/div>\n<div>&nbsp;<\/div>\n<div><b>\u6e96\u5099\u306e\u305f\u3081\u306b\u3084\u308b\u3079\u304d\u3053\u3068:<\/b>&nbsp;<\/div>\n<div>Intune\u3067Secure Boot\u8a3c\u660e\u66f8\u306e\u66f4\u65b0\u3092\u7ba1\u7406\u3059\u308b\u306b\u306f\u3001Microsoft Intune&nbsp;&nbsp;\u7ba1\u7406\u30bb\u30f3\u30bf\u30fc\u304b\u3089&nbsp;\u65b0\u3057\u3044\u8a2d\u5b9a&nbsp;\u3092\u6709\u52b9\u306b\u3057\u3066\u304f\u3060\u3055\u3044:&nbsp;<\/div>\n<ol>\n<li>\u4e0b\u3002<b>\u30c7\u30d0\u30a4\u30b9\u3002<\/b>&gt;?<b>\u30c7\u30d0\u30a4\u30b9\u3092\u7ba1\u7406\u3059\u308b\u304b<\/b>\u3001\u9078\u629e\u3059\u308b?<b>\u69cb\u6210\u3002<\/b>&nbsp;<\/li>\n<li>\u9078\u3076\u3002<b>\u5275\u9020\u3059\u308b\u3002<\/b>\u305d\u3057\u3066\u9078\u629e?<b>\u65b0\u3057\u3044\u65b9\u91dd\u3002<\/b>&nbsp;<\/li>\n<li>\u53f3\u5074\u306e\u30da\u30a4\u30f3\u3067\u300c<b>\u30d7\u30ed\u30d5\u30a1\u30a4\u30eb\u3092\u4f5c\u6210<\/b>?\u300d\u3092\u9078\u629e\u3057\u307e\u3059&nbsp;\u3002&nbsp;<\/li>\n<li>\u66f8\u304d\u8fbc\u3080\u3002<b>\u30d7\u30e9\u30c3\u30c8\u30db\u30fc\u30e0\u3002<\/b>\u3067\u3002<b>Windows 10\u4ee5\u964d<\/b>\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u3067\u3059\u3002&nbsp;<\/li>\n<li>\u9078\u629e\u3059\u308b?<b>\u8a2d\u5b9a\u30ab\u30bf\u30ed\u30b0<\/b>\u306e\u4e0b?<b>\u30d7\u30ed\u30d5\u30a1\u30a4\u30eb\u30bf\u30a4\u30d7<\/b>??????&nbsp;<\/li>\n<li>\u30d7\u30ed\u30d5\u30a3\u30fc\u30eb\u4f5c\u6210&nbsp;\u3092\u59cb\u3081\u3001\u30d7\u30ed\u30d5\u30a3\u30fc\u30eb\u306b\u540d\u524d\u3092\u4ed8\u3051\u307e\u3059\u3002\u62bc\u3059\u3002<b>\u6b21<\/b>\u3002??????&nbsp;<\/li>\n<li>\u4e0b\u3002<b>\u8a2d\u5b9a\u8a2d\u5b9a<\/b>\u3001\u9078\u629e?<b>\u8a2d\u5b9a\u3092\u8ffd\u52a0\u3059\u308b<\/b>?\u8a2d\u5b9a\u30d4\u30c3\u30ab\u30fc\u3067&nbsp;\u300cSecure Boot<em>.<\/em>?\u300d\u3092\u691c\u7d22\u3057&nbsp;\u3066\u304f\u3060\u3055\u3044&nbsp;\u3002Secure Boot\u30ab\u30c6\u30b4\u30ea\u306b\u306f3\u3064\u306e\u8a2d\u5b9a\u304c\u3042\u308b\u306f\u305a\u3067\u3059&nbsp;\u3002&nbsp;<\/li>\n<li>\u7d44\u7e54\u306b\u9069\u3057\u305f\u8a2d\u5b9a&nbsp;&nbsp;\u3092\u9078\u629e\u3057&nbsp;&nbsp;\u3066\u304f\u3060\u3055\u3044:&nbsp;Microsoft Update \u7ba1\u7406\u3055\u308c\u308b\u30aa\u30d7\u30c8\u30a4\u30f3\u306e\u8a2d\u5b9a\u3001&nbsp;\u9ad8\u4fe1\u983c\u5ea6\u306e\u30aa\u30d7\u30c8\u30a2\u30a6\u30c8\u306e\u8a2d\u5b9a\u3001&nbsp;&nbsp;SecureBoot&nbsp;\u8a3c\u660e\u66f8\u66f4\u65b0&nbsp;\u3092\u6709\u52b9\u306b\u3059\u308b&nbsp;(\u4e8b\u524d\u306b&nbsp;\u9078\u629e)\u3002<\/li>\n<li>\u3053\u308c\u3089\u306e\u8a2d\u5b9a\u3092\u4f7f\u3046&nbsp;\u30c7\u30d0\u30a4\u30b9\u306e&nbsp;\u30d7\u30ed\u30d5\u30a1\u30a4\u30eb\u3092\u5b8c\u6210\u3055\u305b\u3066\u304f\u3060\u3055\u3044\u3002&nbsp;<\/li>\n<\/ol>\n<div>&nbsp;<\/div>\n<div><b>\u8ffd\u52a0&nbsp;\u60c5\u5831:<\/b>&nbsp;<\/div>\n<ul>\n<li>Microsoft <a href=\"https:\/\/support.microsoft.com\/topic\/microsoft-intune-method-of-secure-boot-for-windows-devices-with-it-managed-updates-1c4cf9a3-8983-40c8-924f-44d9c959889d\" rel=\"noopener noreferrer\" target=\"_blank\">  Intune\u306e\u300cIT\u7ba1\u7406\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u4ed8\u304dWindows\u30c7\u30d0\u30a4\u30b9\u5411\u3051\u30bb\u30ad\u30e5\u30a2\u30d6\u30fc\u30c8\u65b9\u6cd5<\/a>\u300d\u306e\u5b8c\u5168\u306a\u30ac\u30a4\u30c0\u30f3&nbsp;\u30b9\u3092\u3054\u89a7\u304f\u3060\u3055\u3044\u3002&nbsp;<\/li>\n<li>\u3053\u306e&nbsp;\u65b9\u6cd5&nbsp;\u3092<a href=\"https:\/\/support.microsoft.com\/kb\/5068202\" rel=\"noopener noreferrer\" target=\"_blank\">\u3001IT\u7ba1\u7406\u306e\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u3092\u6301\u3064Windows\u30c7\u30d0\u30a4\u30b9\u306e\u30bb\u30ad\u30e5\u30a2\u30d6\u30fc\u30c8\u306e\u30ec\u30b8\u30b9\u30c8\u30ea\u30ad\u30fc\u66f4\u65b0<\/a>\u3068\u6bd4\u8f03\u3057\u3066&nbsp;\u304f\u3060\u3055\u3044\u3002&nbsp;&nbsp;<\/li>\n<li>\u3053\u306e\u65b9\u6cd5\u306f<a href=\"https:\/\/support.microsoft.com\/kb\/5068198\" rel=\"noopener noreferrer\" target=\"_blank\">\u3001IT\u7ba1\u7406\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u3092\u6301\u3064Windows\u30c7\u30d0\u30a4\u30b9\u5411\u3051\u306e\u30b0\u30eb\u30fc\u30d7\u30dd\u30ea\u30b7\u30fc\u30aa\u30d6\u30b8\u30a7\u30af\u30c8(GPO)\u30bb\u30ad\u30e5\u30a2\u30d6\u30fc\u30c8\u65b9\u5f0f<\/a>\u3068\u6bd4\u8f03\u3057\u3066&nbsp;\u304f\u3060\u3055\u3044\u3002&nbsp;<\/li>\n<li>\u3053\u308c\u3089\u306e\u624b\u6cd5\u304c\u3069\u306e\u3088\u3046\u306b\u9023\u643a\u3059\u308b\u304b\u306f\u3001<a href=\"https:\/\/techcommunity.microsoft.com\/blog\/windows-itpro-blog\/secure-boot-playbook-for-certificates-expiring-in-2026\/4469235\" rel=\"noopener noreferrer\" target=\"_blank\">2026\u5e74\u306b\u671f\u9650\u5207\u308c\u306e\u8a3c\u660e\u66f8\u306b\u95a2\u3059\u308bSecure Boot\u306e\u30d7\u30ec\u30a4\u30d6\u30c3\u30af<\/a>\u3092\u3054\u89a7\u304f\u3060\u3055\u3044&nbsp;\u3002<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>MC1193371 | How to use Microsoft Intune to update expiring Secure Boot certificates Classification stayInforme [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-14189","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts\/14189","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/comments?post=14189"}],"version-history":[{"count":0,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts\/14189\/revisions"}],"wp:attachment":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/media?parent=14189"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/categories?post=14189"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/tags?post=14189"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}