• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
HP Recommended
HP ZBook 17 G5 Mobile Workstation IDS Base Model

My PC has presently the following security status: Devices in this group are affected by a known issue. To mitigate the risk, Secure Boot certificate updates are temporarily paused while Microsoft and partners work toward a supported resolution. Please contact your device manufacturer for assistance. 

Is it just a matter of waiting for me? I heard that HP has some powershell script that can help me update the certificates manually in the BIOS. I have the latest version of the BIOS installed. I found a link in the support that could possibly solve my problem, but unfortunately I don't understand how to use it.

 

https://h30434.www3.hp.com/t5/Business-Notebooks/Enabling-new-UEFI-2023-CA-certificates-in-pre-2018-...

1 REPLY 1
HP Recommended

Hi @Swede72 

 

Welcome to the HP Support Community! We're here to help you get back up and running.

 

I understand your concern. Since your HP ZBook 17 G5 already has the latest BIOS installed, the message from Microsoft does not necessarily mean there is a problem with the computer itself.

 

For this platform, HP's Secure Boot certificate transition requires both:

  1. An HP BIOS version that supports the new Microsoft 2023 certificates.
  2. The Microsoft 2023 Secure Boot certificates to be enrolled on the system.

 

Based on HP documentation, many supported commercial systems receive the certificate deployment through Microsoft's update process after the BIOS prerequisites are in place. 

 

Regarding the PowerShell script you mentioned, HP does provide a script-based solution for certain systems that are not covered by the standard BIOS update path. HP's instructions reference an enroll-sb-vars.ps1 PowerShell script used to enroll the Secure Boot variables manually. The instructions specifically note that systems supported by an HP BIOS update for this topic should follow the HP Secure Boot guidance rather than automatically assuming the script is required. 

 

For your ZBook 17 G5 (2018 platform), I recommend:

  • Confirm the BIOS version matches the minimum version listed in HP's Secure Boot certificate support article.
  • Keep Windows fully updated.
  • Check whether the new certificates have already been installed before attempting any manual enrollment.
  • Use the HP script only if HP's guidance for your specific platform indicates it is required. 

 

The HP article you referenced is discussing a manual certificate enrollment method, not simply a BIOS update. Therefore, if Microsoft currently shows the certificate update as paused, it may not be a matter of only waiting; it depends on whether your ZBook already has the required BIOS support and whether the Microsoft certificates have been successfully enrolled. 

 

 

Take care, and have an amazing day!

 

Regards, 

Hawks_Eye

I'm an HP Employee.


If this reply helped resolve your issue, please select the Accept as Solution as it helps others in the community quickly find the answer they’re looking for.


And if you found this reply helpful, clicking Yes below is a great way to let us know we’re providing the support you need, as it encourages us to keep improving and sharing helpful guidance.

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->