Hello,
The 2023 Secure Boot certificates (UEFICA2023) are not yet being force‑deployed to legacy Windows 10 ESU devices with unsupported OEM firmware. Microsoft has confirmed that updates are paused on older hardware to prevent boot failures, and there is currently no supported registry override or manual injection path for these certificates into UEFI NVRAM. The only official remediation is through OEM firmware updates or Microsoft‑managed rollout, which is still under controlled release.
At present, Microsoft’s roadmap makes clear that the original 2011 Secure Boot certificates will expire in June 2026, and all devices must transition to the 2023 set before then. For enterprise environments, the supported deployment methods are Windows Update, Intune policy, Group Policy, or PowerShell automation. These rely on the scheduled task \Microsoft\Windows\PI\Secure-Boot-Update, which reads registry values under HKLM\SYSTEM\CurrentControlSet\Control\SecureBoot and applies certificate updates in sequence. However, Microsoft has explicitly placed safeguard holds on legacy OEM platforms, such as your HP ProDesk 400 G2 MT, to avoid bricking systems that cannot handle the new DB/KEK entries.
To answer your specific questions:
Deployment to ESU devices: Microsoft has stated that ESU subscribers will continue to receive cumulative updates, but Secure Boot certificate updates are only applied when the hardware and firmware are validated as compatible. For unsupported OEMs, there is no guaranteed timeline for standalone certificate delivery. The expectation is that Microsoft will provide a remediation package closer to the 2026 cutoff, but only after further testing.
Manual injection via script or registry: There is no supported registry override or PowerShell script that can safely force the UEFICA2023 certificates into NVRAM on legacy hardware. While the AvailableUpdates registry value can be manipulated, Microsoft warns against doing so outside of managed deployment because it risks unrecoverable boot loops. The UEFICA2023Status registry key is informational only and cannot be forced to “Updated” without the official servicing stack completing the process.
Manual remediation path: For enterprise desktops where OEM firmware is frozen, the only supported path is to maintain ESU updates and wait for Microsoft’s controlled rollout. There is no official manual remediation for injecting certificates into unsupported firmware. Attempting to sideload the DB/KEK updates manually is not supported and could invalidate Secure Boot entirely. The recommended mitigation is to plan hardware refresh cycles before the 2011 certificates expire, especially for systems that are mission‑critical and cannot risk startup failure.
In short, your current system will continue to boot and receive ESU updates, but Secure Boot will not gain the 2023 protections until Microsoft provides a safe rollout path. There is no supported manual override, and the only long‑term secure option is hardware replacement before mid‑2026.
I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!
HL.