Secure Boot certificates have been updated but are not yet applied

Wilson T 245 Reputation points
2025-12-09T05:17:43.8733333+00:00

Hello,

User's image

What's this? Do I need to take any action about it or just leave it alone?

Thanks very much😀

Windows for home | Windows 11 | Performance and system failures

Answer accepted by question author
Alexandr S 106.4K Reputation points Independent Advisor
2025-12-09T06:03:24.0433333+00:00

Hello, Wilson T.

If the OS is stable, you can ignore these messages. Judging by the information from the screenshot, they relate to updates from Lenovo (the manufacturer of your PC).

P.S. Even on a fully functional PC and a working OS, there are always similar messages in the Event Viewer. This is the normal behavior of the log collector.

Was this answer helpful?

2 people found this answer helpful.

9 additional answers

Sort by: Oldest
  1. Michael Held 25 Reputation points
    2026-07-12T08:35:15.81+00:00

    With some BIOS version like my Dell Optiplex 7050 you first have to empty your certificate memory in your BIOS. Do NOT user Factory Settings => USe DELETE ALL! With this EMPTY certificate memory you can boot your machine in SETUP MODE and Windows will write the new certificates in your BIOS Memory. If it doesn't, use Garlin UEFI Tool from GitHub. I managed to update my machine to the new certs and I'm happy now. btw, the option to delete the certificates in BIOS may only be visible in "Custom Mode" NOT "Standard Mode". Some machines like Acer Aspire even need you to setup a BIOS password to get into Secure Boot Custom Mode and to DELETE ALL certificates. Use an easy password and delete it immed afterwards. All the best to you

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.