Overview
Microsoft is replacing the Secure Boot certificates issued in 2011. A device that does not complete the transition can still start, but it stops receiving newer boot security updates and no longer trusts firmware and drivers signed with the new certificate.
This DEX pack adds a Secure Boot PCA 2011 Cert Transition dashboard to your SysTrack environment. The dashboard shows every device in the selected group and its status in the Secure Boot certificate transition from the Windows Production PCA 2011 certificate to the Windows UEFI CA 2023 certificate.
The dashboard uses eight sensors and no other data sources. Devices that require no action report no findings, so the dashboard focuses on the devices that still need attention.
How This Feature Helps You
The dashboard answers three questions without requiring a script or direct access to a device:
How far the estate has progressed in a single view
Which devices need action and what each device requires
Whether the estate has made progress over the last 30 days
Operational Scope and Safety
This pack only reads and reports data. It does not:
Change anything on a device
Start, schedule, or trigger a certificate update
Require a collection extension, a view, a role, or a group
The pack reads the values that Windows writes during certificate servicing. It does not derive any values from a script running on the device.
How to Use the Dashboard
In the left navigation bar, open Dashboards, filter by the DEX Pack category, and select Secure Boot PCA 2011 Cert Transition.
The group selection at the top of the page determines which devices the dashboard reports on. Every pane on the page uses the same group selection.
.png?sv=2026-02-06&spr=https&st=2026-08-16T01%3A24%3A28Z&se=2026-08-16T01%3A40%3A28Z&sr=c&sp=r&sig=XNeW7HfuKJYPcKC4HcIg2WVhBNfeVu6EfJF279l1zMw%3D)
Ten Categories
Each device appears in exactly one category. If a device triggers more than one sensor, it is counted in the first applicable category in this list.
Category | What It Means | What To Do |
|---|---|---|
Update Failed | Windows recorded an error while applying the 2023 certificates. The device still uses the 2011 certificates. | Review the reported event ID and check with the manufacturer for a firmware update. |
No Automatic Update | Microsoft has classified the device as unable to receive the update automatically. | Review the classification attached to the finding, then test the update on that model or record the device as an exception. |
Automatic Update Opted Out | A local policy disables the automatic update, so the device does not receive it. | Remove the policy, or deploy the update manually. |
Readiness Unknown | Microsoft does not publish a readiness classification for this device type. This is common on older server builds. | Validate the update on this model before you deploy it. |
Update Status Missing | The device reports no certificate servicing status. | Check that the device receives the cumulative updates that include the servicing component. |
Not Applied to Firmware | The update is prepared but not yet applied in firmware. | Restart the device. The transition requires two restarts in total. |
Secure Boot Off | Secure Boot is turned off, so the certificates do not apply. | Turn on Secure Boot in firmware. The transition can then begin. |
Non-Windows | The device does not run Windows. | No action is required. The sensors do not evaluate on this device. |
Not Measured | No sensor result was reported in the last 30 days, or the device does not yet have all eight sensors. | Check that the device is still in use and still reporting. |
Completed | None of the other categories apply. | No action is required. |
Transition Readiness
This chart shows how the devices in the selected group are distributed across the 10 categories. Click a segment to filter the device list below by that category. Select All to clear the filter.

Transition Over Time
This chart shows one column for each of the last 30 days. Each column is a snapshot of the fleet on that day, not a count of what changed on that day.
A device does not need to report every day. If a device is turned off, it remains in the last category it reported, so weekends and holidays do not create gaps. The height of each column reflects the number of devices in the group on that day, so the columns grow as devices are added.
Before the pack is installed, the entire fleet appears in Not measured because no sensors in the pack have reported data yet. This band disappears 30 days after installation.

Systems by Status
This table shows one row per device and uses the same categories as the charts. The list follows the selected group, the category selected in the chart, and any text entered in the search box.
Column | Description |
|---|---|
System | The device name. Select it to open the system view. |
Days Since Active | How many days have passed since the device last contacted SysTrack. |
Status | The category the device belongs to. |
Secure Boot Alerts | How many of the eight sensors are currently reporting findings for the device. |
Error Event | The event ID that Windows recorded. This value appears only when the update failed. |
OS, Manufacturer, Model | Details about the device. |
The category shows only the most urgent finding for a device. Use Secure Boot Alerts to identify devices that require more than one action. Sorting by this column brings those devices to the top.
.png?sv=2026-02-06&spr=https&st=2026-08-16T01%3A24%3A28Z&se=2026-08-16T01%3A40%3A28Z&sr=c&sp=r&sig=XNeW7HfuKJYPcKC4HcIg2WVhBNfeVu6EfJF279l1zMw%3D)
Selected System
This table shows details for the device selected in the list above, with one row for each property. Each sensor in the pack is listed separately, so you can see additional findings beyond the category the device is counted in.
Sensor State | Description |
|---|---|
Alert now | The sensor is currently reporting a finding for this device. |
Alert today | The sensor reported a finding earlier today, but it is not reporting one now. |
Alert N days ago | The sensor most recently reported a finding this many days ago. |
Monitored, no alert in 30 days | The device has the sensor, and the sensor has not reported a finding in the last 30 days. |
Not deployed | The device does not have the sensor yet. |
Not applicable | The device does not run Windows. |
The last two rows show the values returned with a sensor finding: the event ID that Windows recorded for a failed update and the confidence level that Microsoft assigns to the device type.

Recommended Workflow
Start with the full estate by selecting the All Systems group, then review the chart.
Select Update Failed. These devices attempted the transition and failed. They typically need a firmware update from the manufacturer.
Select Not Applied to Firmware. These devices usually need only a restart.
Sort the list by Secure Boot Alerts to identify devices with more than one finding, then open each device in the detail pane below the list.
Work through No Automatic Update, Automatic Update Opted Out, and Readiness Unknown by model rather than by device. These findings usually point to a hardware or policy decision, not a single machine.
Use Transition Over Time to confirm that the estate is progressing. If a band does not shrink over two weeks, that part of the estate is not moving.
Secure Boot Certificate Transition Responsibilities
Activity | Handled By |
|---|---|
Delivering the 2023 certificates | Microsoft, through Windows Update. |
Determining whether a device can receive the update automatically | Microsoft, based on data included in the cumulative update. |
Applying the certificates to firmware | Windows, on the device, across two restarts. |
Reporting each device’s transition status | SysTrack, through this pack. |
Remediating a device | Not part of this pack. |
The Confidence Level
Windows generates this classification on the device by using data included in the cumulative update. It is the same classification shown in the Secure Boot status report in the Intune admin center. It does not require any management platform.
This value is absent on Windows versions for which Microsoft does not publish confidence data. In this dashboard, that condition appears as Readiness Unknown. It does not indicate a fault with the device.
Troubleshooting
Issue | Explanation |
|---|---|
Every device appears as Not Measured | The pack was installed recently, and no sensors have reported yet. Wait for the next sensor evaluation cycles. |
A device remains in Not Measured | The device has not reported for more than 30 days, or it does not yet have all eight sensors. Check whether the device is still in use and receiving its configuration. |
The history chart shows fewer than 30 days | Daily sensor records are retained for 30 days. A longer history is not available from sensor data. |
A device shows one status today and a finding in yesterday’s column | The newest column shows the current state, while earlier columns show the daily record. If a finding appeared and cleared on the same day, it appears only in the daily record. Both values are correct for the data they show. |
The chart and the device list do not match | They should match because both use the same categories from the same source. Check the selected group and the search box. |