• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
HP Recommended
HP ZBook 17 G3 IDS Base Model Mobile Workstation
Microsoft Windows 11

I've had this PC since 2016 that I updated to Windows 10, and a couple of years ago to Windows 11 and am now at 25H2. Before updating to Windows 11, I also updated TPM to 2.0 and installed the latest/last HP Notebook System BIOS Update (N81) version 01.62A dated May 23, 2024. After the MS Security Update in August my windows device security for Secure Boot displays the well-known message that "... Secure Boot certificate updates are temporarily paused while Microsoft and the partners work towards a supported resolution." I ran the windows admin command and confirmed that I do not have the 2023 certificates. As I understand it, my BIOS is in UEFI mode but does not provide the full support Microsoft needs to complete the update. My laptop is fairly secure but missing the new certificates. Oddly enough, my daughter's college laptop from another brand which is even older and slower but updated to Windows 11 AND got the secure boot certificates. It seems I need an updated BIOS, but my platform may be stuck at the last 2024 update.

1 ACCEPTED SOLUTION

Accepted Solutions
HP Recommended

@Bobcat4363 

 

According to this HP document, your PC will not be getting a BIOS update to allow for the 2023 secure boot certificates:

 

HP Business PCs - Prepare for new Windows Secure Boot certificates | HP® Support

View solution in original post

10 REPLIES 10
HP Recommended

Greetings @Bobcat4363 

 

Opinions or troubleshooting suggestions in this response are provided independently. I am not employed by: HP, Inc. or the HP Forum.

 

Your assessment of your PC's inability to install Windows 2023 security certificate updates is on target.

 

Please refer to this Microsoft position paper. 

 

I don't know if HP will provide a future BIOS update to correct this issue.

 

HP may have placed your specific product number in Legacy status; no more BIOS updates.

 

The latest BIOS update I could find for your PC is 01.62 Rev.A.

 

I can only suggest periodically checking this HP Site to for a possible future BIOS update.

 

Regards

HP Recommended

@Bobcat4363 

 

According to this HP document, your PC will not be getting a BIOS update to allow for the 2023 secure boot certificates:

 

HP Business PCs - Prepare for new Windows Secure Boot certificates | HP® Support

HP Recommended

@Paul_Tikkanen 

 

Very nice.

 

I was going to tag you but did not.

 

Regards

HP Recommended

Thank you @Bill_To. I appreciate your reply. HP support and this community have been very helpful with understanding my legacy platform firmware issue. This notebook is a beast, and I plan to use it for years to come.

HP Recommended

Thank you @Paul_Tikkanen. It was useful to read the attached HP link. While some older platforms will get the updated firmware, my legacy platform will not, and I understand.

HP Recommended

You're very welcome.

 

I'm running W11 26H2 on all of my unsupported HP and Dell PCs and notebooks.

 

I 100% agree that if you have a PC that serves your needs perfectly fine, there is no need to buy one that fully supports W11 unless the W10 or older drivers don't work on W11 (I've only had that happen in one of my 8 or so PC's).

 

Are you familiar with how Microsoft has been doing the build upgrades from W11 24H2 and newer via an enablement package?

 

Unsupported PC's don't get the update but you used to be able to download it from the Microsoft Update Catalog.

 

However, if you look at the original link for the update, Microsoft has now removed the 25H2 feature update enablement package from the catalog website and my concern is they may no longer include it when the 26H2 feature update is released.

 

KB5054156: Feature update to Windows 11, version 25H2 by using an enablement package | Microsoft Sup...

 

Before you can install the enablement package (KB5121794), the device must have the Windows 11 update KB5120998 (build 26200.9278) already installed.

 

If Microsoft does not include the W11 26H2 enablement file on the Microsoft Update Catalog website, you can download it from the link below:

 

Windows 11 26H2 Enablement Package (KB5121794) direct download for x64 and ARM64 - Pureinfotech

 

When you run the file, your PC will be updated to W11 26H2 in less than a couple of minutes.

 

 

HP Recommended

Thank you for the very detailed follow up! I was not familiar at all with how Microsoft enablement package mechanism for build upgrades, but I did read the article you linked (a lot to unpack).

 

On my platform, windows update installed KB5064081 W11 24H2 cumulative preview on 8/2025, followed by a few more cumulative updates until 10/2025 when preview and security update monthly installs began. I believe that 10/2025 KB5067036 (build 26200.7019) preview was labeled Windows 11 25H2 in windows update.

 

The KB5120998 preview update installed 8/29/2026 and the KB5124008 security update installed 9/9/2026, but as of now I do not have the KB5121794 enablement package. If I am reading your message correctly, you are saying that I can manually download and install the enablement package any time. Is that right?

 

 

HP Recommended

You're very welcome. 

 

That's correct, except that no unsupported PC's will automatically get that update via Windows Update. 

 

The only way for an unsupported PC to get the package is to download it.

 

The W11 26H2 Enablement Package should show up in a couple of weeks or so as a bulletin, but if there's no option to get the file from the Microsoft Update Catalog website like there was last year, you can download it from the link I posted. 

 

I just don't understand why Microsoft removed the 25H2 enablement file from the Catalog last year. 

 

It was on there for months. 

 

I wonder if Microsoft found out that the file easily updates unsupported PC's the same way it does supported ones, and wanted to keep it difficult to update unsupported platforms?

 

I used the W11 26H2 enablement package file on my one and only W11 supported PC, because I didn't want to wait for Windows Update to send it to my PC.

HP Recommended

My platform failed the processor check a few years ago and I had to do a manual update from 10 to 11. I’m assuming that’s why my unsupported pc didn’t get the new enablement package. The reply and link look pretty straightforward and the risk seems low, so I’ll pull the trigger and run the package install.

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->