Microsoft is distributing the 2023 Secure Boot certificates through Windows updates, but it is unclear whether that is enough for a Lenovo fleet. Do Lenovo desktops and laptops also need a BIOS or firmware update, or can compatible systems receive and activate the certificates through Windows alone? Some of the systems are around four years old and have not had their BIOS updated since deployment, yet they appear to show the 2023 certificates. What is the best way to verify model compatibility, required BIOS versions, and rollout status?
5 Answers
A PowerShell inventory script can help confirm what is happening on each device. The useful checks include the installed Secure Boot databases, firmware version, Secure Boot state, and whether the updated boot manager has been activated. That gives you a more reliable answer than assuming every machine with current Windows patches has completed the full transition.
For a controlled rollout, deploy the approved Lenovo BIOS first, then push the certificate update and manage the two required reboot stages. Test a representative sample of models before broad deployment, especially if BitLocker is enabled, and keep a dashboard or compliance report so systems that remain pending can be identified.
Windows updates can contain the certificate payload, but they do not guarantee that it will be installed automatically. Automatic deployment generally depends on telemetry being enabled, the specific Lenovo model and firmware supporting the update, and Microsoft classifying that hardware combination as sufficiently tested. The process typically installs the certificates after one reboot and activates the updated boot manager after another.
For managed environments, check Lenovo’s compatibility and expiration documentation for each model, update the BIOS to at least the listed minimum version, and then trigger the certificate deployment through the appropriate registry setting or management platform. It is also worth controlling the scheduled tasks and reboots, temporarily suspending BitLocker if required by your testing, and reporting on Secure Boot state across the fleet.
Do not forget servers, virtual machines, PXE images, recovery media, installation media, VM templates, and other appliances that rely on Secure Boot.
The BIOS update is not universally required, but it is required when Lenovo lists a newer minimum firmware version for that model. Some older systems can already accept the 2023 certificates, which would explain why a four-year-old desktop received them without a recent BIOS update. The age of the machine alone is not enough to determine compatibility.
Lenovo publishes a model-by-model guide that lists supported systems and the minimum BIOS version for the Secure Boot certificate transition. Compare the exact machine type and current firmware version against that list rather than relying only on the Windows update history.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures