The OEM is responsible for creating and securing the BIOS or firmware update itself. Microsoft’s role is in the Windows-side delivery and trust chain, not in authoring the firmware payload.
For firmware updates delivered through Windows Update:
- OEM/IHV responsibility
- The firmware update is delivered as a driver package.
- That package must pass Windows HLK testing and be submitted to Partner Center for signing.
- The OEM/IHV is responsible for the integrity and security of the firmware itself, including signature verification, encryption, or other protections.
- Firmware defaults stored in device firmware are maintained by the OEM.
- Microsoft responsibility
- Windows uses the signed driver package to verify integrity before handing the firmware payload to UEFI.
- Secure Boot and some certificate updates can be applied through Windows Update.
- Microsoft can also pause offering an update to affected devices when compatibility issues are identified.
Based on that, the responsibility is effectively both, but in different parts of the process:
- Approving/publishing the firmware package for Windows Update delivery: the OEM prepares and submits the update package; Microsoft provides the signing and Windows Update delivery path.
- Authoring and validating the BIOS update itself: the OEM.
- Withdrawing or stopping broad Windows Update offering after an issue is found: Microsoft can pause the offering, and OEMs are involved in investigation and remediation.
For a known critical issue such as a BitLocker recovery loop:
- The context shows that when startup failures were linked to third-party firmware on specific models, Microsoft paused the offering of the update to affected devices.
- The same context also states that the issue could only be addressed with firmware updates provided by the device manufacturer.
So the practical split is:
- Microsoft can stop or pause further Windows Update distribution to prevent more devices from being affected.
- The OEM is responsible for producing the corrected firmware update.
For Windows IoT Enterprise scheduling:
The context does not provide a product-specific statement about whether Windows IoT Enterprise receives OEM BIOS updates on a Microsoft-controlled schedule versus an OEM-controlled schedule. The supported facts are only that:
- Firmware updates are packaged and signed like driver packages for Windows delivery.
- Availability through Windows Update can differ from vendor tools because the vendor or OEM determines the availability of their updates.
That supports only this conclusion: the OEM determines update availability, while Microsoft provides the Windows Update distribution mechanism.
References:
- Certify and sign the update package
- Windows Driver Update Policies FAQs
- Windows might fail to start on some devices after installing the June 2025 Windows security update - Microsoft Q&A Microsoft is aware of reports that a small subset of specific models of Windows devices fail to start after installing the June 2025 Windows security update. Some of the devices mentioned in these reports include models from Fujitsu, GIGABYTE and ThundeRobot. These reports are not necessarily related, as they include different symptoms for each of the manufacturers, including some models reporting problems on Windows 10, while others report problems on Windows 11.
- Frequently asked questions about the Secure Boot update process