Microsoft Defender for Endpoint will add a new Secure Score recommendation in late April 2026 to help organizations prepare for Secure Boot 2023 certificate updates replacing expiring certificates in June 2026. It provides visibility into device readiness, tracks progress, and is enabled by default.
Introduction
We’re introducing a new Microsoft Secure Score recommendation in Microsoft Defender for Endpoint (MDE) to help organizations assess and prepare for the transition to Secure Boot 2023 certificates. Secure Boot 2023 certificates replace older certificates (such as Windows UEFI CA 2011) that are scheduled to expire in June 2026, helping ensure devices continue to boot securely and receive future protections. This recommendation improves visibility into device readiness and helps organizations maintain a trusted and secure boot process.
When this will happen:
How this affects your organization:
Who is affected:
What will happen:
Why this matters:
What you can do to prepare:
Compliance considerations:
No compliance considerations identified, review as appropriate for your organization.