Detect-SecureBootCA2023SCCM

1.0.0

This discovery script evaluates the Secure Boot CA 2023 certificate update status on Windows 11 devices.
It reads UEFI servicing registry values and returns a single string output suitable for SCCM CI rules.

Possible return values:
   Compliant
   PendingRemediation
   PendingRestart
   ManualReview
   NotApplicable

Recommended SCCM CI configuration:
   Settin
This discovery script evaluates the Secure Boot CA 2023 certificate update status on Windows 11 devices.
It reads UEFI servicing registry values and returns a single string output suitable for SCCM CI rules.

Possible return values:
   Compliant
   PendingRemediation
   PendingRestart
   ManualReview
   NotApplicable

Recommended SCCM CI configuration:
   Setting type : Script
   Data type    : String
   Rule         : Equals "Compliant"

Show more

Installation Options

Copy and Paste the following command to install this package using PowerShellGet More Info

Install-Script -Name Detect-SecureBootCA2023SCCM

Copy and Paste the following command to install this package using Microsoft.PowerShell.PSResourceGet More Info

You can deploy this package directly to Azure Automation. Note that deploying packages with dependencies will deploy all the dependencies to Azure Automation. Learn More

Manually download the .nupkg file to your system's default download location. Note that the file won't be unpacked, and won't include any dependencies. Learn More

Owners

Copyright

(c) 2026 Mert Efe Kanlikilic. All rights reserved.

Package Details

Author(s)

  • Mert Efe Kanlikilic

Tags

SecureBoot Windows11 SCCM ConfigMgr ConfigurationManager ComplianceBaseline SecureBootCertificate UEFI

Dependencies

This script has no dependencies.

Release Notes

Initial release for SCCM / Configuration Manager Configuration Item discovery.

FileList

Version History

Version Downloads Last updated
1.0.0 (current version) 10 6/24/2026