Usage guide: Secure Boot readiness and compliance
This page outlines various ways to use the pack, including use case examples.
Administrators can refer to the Configuration guide: Secure Boot readiness and compliance to set up and customize the installed content.
The Secure Boot readiness and compliance library pack enables EUC teams to:
Assess fleet readiness for Microsoft Secure Boot 2023 certificate updates.
Identify non-compliant or at-risk devices before 2011 certificate expiration deadlines.
Prioritize remediation using actionable insights from live dashboards and Remote Actions.
Monitor rollout progress across firmware, certificates, and update stages.
In addition, this library pack provides preconfigured Remote Actions to collect accurate telemetry and support decision-making.
Library pack uses
Jump to Use cases on this page to see relevant scenario applications.
Use the library pack content for the following purposes.
Monitoring readiness from the Summary dashboard
The Secure Boot readiness and compliance live dashboard is the starting point. The Summary tab consolidates key readiness indicators in one place.

You can:
Identify devices requiring action via Secure Boot and firmware posture.
Detect rollout blockers with Key update pending state.
Track overall compliance using Certificate presence.
Ensure eligibility using Telemetry health.
This view helps you quickly understand fleet posture and focus remediation efforts.
Investigating compliance gaps
Use dashboard widgets to drill down into affected devices.
Secure Boot and firmware posture highlights devices marked Not ready.
Certificate presence reveals missing firmware certificates.
Key update pending state shows devices stalled due to pending updates or reboots.
From the live dashboard, drill down into devices and open Investigations for deeper analysis.
Use the corresponding tab to drill down into the detailed metrics and device-level specifics for each section shown on the Summary (main) page.
Collecting accurate telemetry data
The Admin tab relies on Remote Actions for up-to-date insights.
Key actions include:
Get Secure Boot Compliance Details
Get Windows telemetry status
Ensure these remote actions are scheduled and executed regularly. Without sufficient data, readiness insights may be incomplete.
Supporting remediation and rollout
Use insights from the dashboard to prioritize actions:
Deploy missing Secure Boot certificates.
Trigger required updates.
Enforce device reboots when needed.
Restore telemetry configuration for affected devices.
This structured approach aligns with Microsoft’s staged rollout process.
Use cases
In addition to the relevant use cases covered below, you may uncover other troubleshooting scenarios specific to your environment.
Identifying non-compliant devices
Use the Secure Boot Readiness and Compliance live dashboard to find devices requiring action.
Open the Summary tab in the dashboard.
Review the Secure Boot compliance widget.
Select Not ready devices to drill down.
Open results in Investigations to analyze root causes.
Focus on devices missing certificates or failing compliance checks.
Validating certificate readiness
Ensure devices have the required 2023 Secure Boot certificates.
In the Summary tab, locate Certificate presence.
Identify devices under Missing certificates.
Drill down to view affected endpoints.
Trigger remediation using deployment tools or scripts.
Devices must include:
Windows UEFI CA 2023
Microsoft UEFI CA 2023
Microsoft KEK CA 2023
Resolving update blockers
Detect devices stuck in the rollout process.
Go to Update readiness in the Summary tab.
Review devices marked Pending.
Drill down to identify causes (deployment or reboot).
Trigger updates or enforce reboot policies.
A status of 0x0 confirms no pending updates.
Restoring telemetry coverage
Ensure accurate readiness classification.
Check Telemetry coverage in the dashboard.
Identify devices under Not reporting.
Run Get Windows telemetry status via Remote Actions.
Verify telemetry service and configuration.
Accurate telemetry is required for Microsoft rollout eligibility.
Ensuring telemetry health compliance
Fix devices flagged in Telemetry health.
Open the Telemetry health widget.
Drill down into devices marked Action needed.
Investigate issues such as:
Disabled telemetry service
Diagnostic data levels
Unknown configuration states
Apply configuration fixes using endpoint management tools.
Healthy telemetry ensures proper classification and update eligibility.
Each section shown in the Summary tab has a dedicated tab to view more detailed information in each one.
RELATED TOPICS
Last updated
Was this helpful?