PowerShell: Check Secure Boot 'Windows UEFI CA 2023' status on a device

Scripts & AutomationOS Engineering


The Microsoft Secure Boot certificates from 2011 start expiring in 2026, and devices need the Windows UEFI CA 2023 certificate in their Secure Boot DB before that happens. When you’re tracking this across a large fleet, the first thing you need is a quick, read-only answer per device: is Secure Boot on, and is the 2023 CA already in the DB?

What the script checks

CheckSource
Secure Boot enabledConfirm-SecureBootUEFI
2023 CA present in the DBGet-SecureBootUEFI -Name db
Servicing statusHKLM\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing → UEFICA2023Status
Pending update bitsHKLM\SYSTEM\CurrentControlSet\Control\SecureBoot → AvailableUpdates

The script

Get-SecureBootCA2023Status.ps1 Download
<#
.SYNOPSIS
    Reports whether the 'Windows UEFI CA 2023' certificate is present in the Secure Boot DB.

.DESCRIPTION
    Read-only. Run elevated. Returns one object per device.
    -AsDetection : exit 1 when the 2023 CA is missing (Intune Remediation detection), else exit 0.

.NOTES
    Author : Mohammad Zubair Akhtar - zubaircloud.com
    Provided as-is. Test in a pilot group before fleet-wide use.
#>
[CmdletBinding()]
param(
    [switch]$AsDetection
)

$result = [ordered]@{
    ComputerName      = $env:COMPUTERNAME
    SecureBootEnabled = $null
    CA2023InDB        = $null
    UEFICA2023Status  = $null
    AvailableUpdates  = $null
}

try {
    $result.SecureBootEnabled = Confirm-SecureBootUEFI -ErrorAction Stop
}
catch {
    $result.SecureBootEnabled = 'Unsupported (legacy BIOS or not elevated)'
}

if ($result.SecureBootEnabled -eq $true) {
    try {
        $db = Get-SecureBootUEFI -Name db -ErrorAction Stop
        $result.CA2023InDB = [System.Text.Encoding]::ASCII.GetString($db.Bytes) -match 'Windows UEFI CA 2023'
    }
    catch {
        $result.CA2023InDB = "Error: $($_.Exception.Message)"
    }
}

$sbKey  = 'HKLM:\SYSTEM\CurrentControlSet\Control\SecureBoot'
$svcKey = Join-Path $sbKey 'Servicing'

$status = Get-ItemProperty -Path $svcKey -Name UEFICA2023Status -ErrorAction SilentlyContinue
$result.UEFICA2023Status = if ($status) { $status.UEFICA2023Status } else { 'Not present' }

$avail = Get-ItemProperty -Path $sbKey -Name AvailableUpdates -ErrorAction SilentlyContinue
$result.AvailableUpdates = if ($avail) { '0x{0:X}' -f $avail.AvailableUpdates } else { 'Not present' }

$out = [pscustomobject]$result

if ($AsDetection) {
    # One line for the Intune Remediation output column
    Write-Output ("SB={0}; CA2023={1}; Status={2}; Avail={3}" -f $out.SecureBootEnabled, $out.CA2023InDB, $out.UEFICA2023Status, $out.AvailableUpdates)
    if ($out.CA2023InDB -eq $true) { exit 0 } else { exit 1 }
}

$out

Run it elevated. With -AsDetection it exits 1 when the 2023 CA is missing, so you can drop it straight into an Intune Remediation as the detection script and report on the output column.

Sample output

ComputerName      : LAPTOP-01
SecureBootEnabled : True
CA2023InDB        : True
UEFICA2023Status  : Updated
AvailableUpdates  : 0x0

#Secure Boot#UEFI CA 2023#PowerShell#Intune Remediation