Share via

Microsoft Intune method of Secure Boot for Windows devices with IT-managed updates

Priya Jayaraman 366 Reputation points
2026-06-12T08:53:35.4833333+00:00

https://support.microsoft.com/en-us/topic/microsoft-intune-method-of-secure-boot-for-windows-devices-with-it-managed-updates-1c4cf9a3-8983-40c8-924f-44d9c959889d

we want the windows automatically begins deploying updated Secure Boot certificates. Option no1 is required to be enabled for the same. Please confirm if option 2 and 3 are required?

  1. Enable Secureboot Certificate Updates
  2. Configure High Confidence Opt-Out

3.Configure Microsoft Update Managed Opt In

cheers

Priya

Windows for business | Windows 365 Enterprise
0 comments No comments

1 answer

Sort by: Most helpful
  1. Quinnie Quoc 11,400 Reputation points Independent Advisor
    2026-06-12T09:52:12.2633333+00:00

    Dear Priya Jayaraman,

    To have Windows automatically deploy updated Secure Boot certificates, only Enable Secureboot Certificate Updates must be enabled. This is the core setting that triggers the certificate deployment task on each device. The other two options are not mandatory: Configure High Confidence Opt-Out is used only if you want to block automatic deployment through monthly cumulative updates, and Configure Microsoft Update Managed Opt In is for organizations that wish to participate in Microsoft’s controlled rollout program, which requires diagnostic data sharing. If your goal is simply to ensure certificates are updated automatically across IT‑managed devices, enabling option 1 alone is sufficient.

    Option 2 should remain disabled unless you explicitly want to prevent automatic deployment on devices Microsoft has validated. Option 3 is optional and only relevant if you want Microsoft to manage the rollout centrally; otherwise, you can rely on your own Intune deployment. In practice, most enterprises enable option 1 and leave 2 and 3 at their defaults, unless they have a specific compliance requirement to control rollout behavior.

    If my answer is useful for you, please hit Accept the answer to support me.

    Thank you,

    QQ,

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.