Windows 10 ESU: Manual Enrollment of UEFI Secure Boot 2023 Certificates on EOL Hardware (HP ProDesk 400 G2 MT)

Don 0 Reputation points
2026-08-23T00:45:04.9966667+00:00

Hello,

I am writing to inquire about the deployment roadmap and manual installation procedures for the new Windows Secure Boot 2023 certificates (UEFICA2023 / Windows UEFI CA 2023) within the UEFI NVRAM environment on older, enterprise-enrolled hardware.

My system is currently running Windows 10 Pro, running natively in UEFI boot mode, and I am an active subscriber to the Extended Security Updates (ESU) program.

Here are my official and detailed system specifications:

- System Manufacturer: Hewlett-Packard (HP)

- System Model: HP ProDesk 400 G2 MT

- OS Version: 10.0.19045 Build 19045 (Version 22H2, OS Build 19045.7663)

- BIOS Version/Date: Hewlett-Packard L02 v02.56, 24/04/2019

The Problem:

The OEM (HP) has officially ceased UEFI firmware support for this specific platform, with the final firmware release dating back to April 2019. Consequently, HP has not included the 2023 Secure Boot keys (Db/Kek) in the default factory NVRAM configurations. The certificate updates have not been pushed to my device via Windows Update, which I suspect is due to a safeguard hold implemented by Microsoft on legacy OEM hardware to prevent catastrophic boot failures.

As an ESU subscriber running on native UEFI, I need to ensure my device remains fully secure during startup.

My specific technical questions are:

1. Since the OEM will not provide a native UEFI firmware update containing the 2023 certificates, when or how will Microsoft deploy the standalone DB/KEK updates to Windows 10 ESU devices with legacy UEFI environments?

2. Is there an officially supported deployment script, PowerShell configuration, or specific registry key override (such as forcing the MicrosoftUpdateManagedOptIn key) that I can safely execute to write the updated 2023 certificates directly into the UEFI NVRAM variables from within Windows?

3. If Windows Update cannot enforce this due to UEFI hardware age, what is the official manual remediation path for standalone enterprise desktops to avoid security compromise when the remaining 2011 certificates fully expire later this year?

Thank you for your technical guidance.

pc11

pc111

Windows for business | Windows Client for IT Pros | Devices and deployment | Install Windows updates, features, or roles
0 comments No comments

1 answer

Sort by: Oldest
  1. Hoang Le 4,580 Reputation points Independent Advisor
    2026-08-23T04:30:38.9933333+00:00

    Hello,

    The 2023 Secure Boot certificates (UEFICA2023) are not yet being force‑deployed to legacy Windows 10 ESU devices with unsupported OEM firmware. Microsoft has confirmed that updates are paused on older hardware to prevent boot failures, and there is currently no supported registry override or manual injection path for these certificates into UEFI NVRAM. The only official remediation is through OEM firmware updates or Microsoft‑managed rollout, which is still under controlled release.

    At present, Microsoft’s roadmap makes clear that the original 2011 Secure Boot certificates will expire in June 2026, and all devices must transition to the 2023 set before then. For enterprise environments, the supported deployment methods are Windows Update, Intune policy, Group Policy, or PowerShell automation. These rely on the scheduled task \Microsoft\Windows\PI\Secure-Boot-Update, which reads registry values under HKLM\SYSTEM\CurrentControlSet\Control\SecureBoot and applies certificate updates in sequence. However, Microsoft has explicitly placed safeguard holds on legacy OEM platforms, such as your HP ProDesk 400 G2 MT, to avoid bricking systems that cannot handle the new DB/KEK entries.

    To answer your specific questions:

    Deployment to ESU devices: Microsoft has stated that ESU subscribers will continue to receive cumulative updates, but Secure Boot certificate updates are only applied when the hardware and firmware are validated as compatible. For unsupported OEMs, there is no guaranteed timeline for standalone certificate delivery. The expectation is that Microsoft will provide a remediation package closer to the 2026 cutoff, but only after further testing.

    Manual injection via script or registry: There is no supported registry override or PowerShell script that can safely force the UEFICA2023 certificates into NVRAM on legacy hardware. While the AvailableUpdates registry value can be manipulated, Microsoft warns against doing so outside of managed deployment because it risks unrecoverable boot loops. The UEFICA2023Status registry key is informational only and cannot be forced to “Updated” without the official servicing stack completing the process.

    Manual remediation path: For enterprise desktops where OEM firmware is frozen, the only supported path is to maintain ESU updates and wait for Microsoft’s controlled rollout. There is no official manual remediation for injecting certificates into unsupported firmware. Attempting to sideload the DB/KEK updates manually is not supported and could invalidate Secure Boot entirely. The recommended mitigation is to plan hardware refresh cycles before the 2011 certificates expire, especially for systems that are mission‑critical and cannot risk startup failure.

    In short, your current system will continue to boot and receive ESU updates, but Secure Boot will not gain the 2023 protections until Microsoft provides a safe rollout path. There is no supported manual override, and the only long‑term secure option is hardware replacement before mid‑2026.

    I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!

    HL.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.