Microsoft explains multiple restarts during Windows 11 Secure Boot certificate updates

Microsoft clarifies that several PC restarts during recent Windows updates are expected behaviour linked to the secure boot certificate transition, reassuring users that their devices are not malfunctioning.

Microsoft has confirmed that some Windows PCs may restart several times during an update when Secure Boot certificates are being installed, and says the behaviour is expected rather than a sign of fault. The process is tied to the replacement of older 2011 certificates with newer 2023 certificates, which are being rolled out to keep the boot chain trusted as the old certificates approach expiry, according to Microsoft and Windows Latest.

The reports began after users noticed that recent Windows 11 updates appeared to trigger two, three or even more restarts in quick succession. In one case described by Windows Latest, a machine rebooted four times before appearing to stall at a black screen showing 93 per cent complete, only to finish successfully shortly afterwards. That kind of behaviour, the publication said, is consistent with Secure Boot certificate servicing rather than a failed installation.

Microsoft’s support guidance says certificate servicing can require several reboots because the operating system is changing firmware-related components during the update process. The company adds that, in many cases, those restarts happen very early in the boot sequence and are therefore less visible to the user. Microsoft also provides a troubleshooting guide covering the Secure-Boot-Update scheduled task, the AvailableUpdates registry flag and common failure scenarios.

Users can check whether the process has completed in the Windows Security app under Device Security. Windows Latest and PCWorld both report that a status showing Secure Boot is on and all required certificate updates have been applied means no further action is needed. If the device instead shows that action is required, Microsoft advises checking firmware or BIOS updates, as the certificate transition is meant to be a security upgrade, not a repair for a broken system.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.