PowerShell: Check Secure Boot 'Windows UEFI CA 2023' status on a device
Scripts & AutomationOS Engineering
The Microsoft Secure Boot certificates from 2011 start expiring in 2026, and devices need the Windows UEFI CA 2023 certificate in their Secure Boot DB before that happens. When you’re tracking this across a large fleet, the first thing you need is a quick, read-only answer per device: is Secure Boot on, and is the 2023 CA already in the DB?
What the script checks
| Check | Source |
|---|---|
| Secure Boot enabled | Confirm-SecureBootUEFI |
| 2023 CA present in the DB | Get-SecureBootUEFI -Name db |
| Servicing status | HKLM\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing → UEFICA2023Status |
| Pending update bits | HKLM\SYSTEM\CurrentControlSet\Control\SecureBoot → AvailableUpdates |
The script
<#
.SYNOPSIS
Reports whether the 'Windows UEFI CA 2023' certificate is present in the Secure Boot DB.
.DESCRIPTION
Read-only. Run elevated. Returns one object per device.
-AsDetection : exit 1 when the 2023 CA is missing (Intune Remediation detection), else exit 0.
.NOTES
Author : Mohammad Zubair Akhtar - zubaircloud.com
Provided as-is. Test in a pilot group before fleet-wide use.
#>
[CmdletBinding()]
param(
[switch]$AsDetection
)
$result = [ordered]@{
ComputerName = $env:COMPUTERNAME
SecureBootEnabled = $null
CA2023InDB = $null
UEFICA2023Status = $null
AvailableUpdates = $null
}
try {
$result.SecureBootEnabled = Confirm-SecureBootUEFI -ErrorAction Stop
}
catch {
$result.SecureBootEnabled = 'Unsupported (legacy BIOS or not elevated)'
}
if ($result.SecureBootEnabled -eq $true) {
try {
$db = Get-SecureBootUEFI -Name db -ErrorAction Stop
$result.CA2023InDB = [System.Text.Encoding]::ASCII.GetString($db.Bytes) -match 'Windows UEFI CA 2023'
}
catch {
$result.CA2023InDB = "Error: $($_.Exception.Message)"
}
}
$sbKey = 'HKLM:\SYSTEM\CurrentControlSet\Control\SecureBoot'
$svcKey = Join-Path $sbKey 'Servicing'
$status = Get-ItemProperty -Path $svcKey -Name UEFICA2023Status -ErrorAction SilentlyContinue
$result.UEFICA2023Status = if ($status) { $status.UEFICA2023Status } else { 'Not present' }
$avail = Get-ItemProperty -Path $sbKey -Name AvailableUpdates -ErrorAction SilentlyContinue
$result.AvailableUpdates = if ($avail) { '0x{0:X}' -f $avail.AvailableUpdates } else { 'Not present' }
$out = [pscustomobject]$result
if ($AsDetection) {
# One line for the Intune Remediation output column
Write-Output ("SB={0}; CA2023={1}; Status={2}; Avail={3}" -f $out.SecureBootEnabled, $out.CA2023InDB, $out.UEFICA2023Status, $out.AvailableUpdates)
if ($out.CA2023InDB -eq $true) { exit 0 } else { exit 1 }
}
$out
Run it elevated. With -AsDetection it exits 1 when the 2023 CA is missing, so you can drop it straight into an Intune Remediation as the detection script and report on the output column.
Sample output
ComputerName : LAPTOP-01
SecureBootEnabled : True
CA2023InDB : True
UEFICA2023Status : Updated
AvailableUpdates : 0x0