Posts

Windows April 2026 Updates and the BitLocker Recovery Key Issue on Servers and Windows devices

Image
 Windows April 2026 Updates and the BitLocker Recovery Key Issue on Servers and Windows devices Technical deep dive for IT organizations and professionals. Microsoft released the April 2026 Patch Tuesday updates on April 14, 2026, including the cumulative security update KB5082142 (OS Build 20348.5020) for Windows Server 2022. This update includes important security fixes, quality improvements, and most notably changes to Secure Boot certificate handling. While most organizations will install it without incident, a known issue is causing some Windows servers (and a limited number of enterprise Windows 11 devices) to boot into BitLocker recovery mode on the first restart after installation. The issue is tied to the update’s Secure Boot improvements and affects only systems with a specific BitLocker Group Policy configuration that Microsoft recommends against. What’s New in Server update KB5082142, April 2026. Key highlights include: • Security fixes and quality improvements ca...

UEFI Secure Boot CA 2023

Image
   How frequently do you observe this topic on LinkedIn or X? Perhaps your organization is discussing it. Upon logging into Intune, you will notice this banner at the top of your Intune dashboard.  Microsoft announced this issue back in 2025, but surprisingly, it didn’t get much attention until recently. While Microsoft shared some details about the registry keys involved, clear step-by-step instructions for fixing the problem are quite hard to find. Last week, I was working on this issue on my own tenant and one of the customers, and I decided to share this information so that you can address it earlier and avoid waiting until the last minute. What is Secure Boot:- Secure Boot, a UEFI security feature, ensures only trusted software runs during boot by verifying digital signatures against trusted certificates stored in firmware. UEFI Secure Boot standardizes how platform firmware manages certificates, authenticates firmware, and interfaces with the OS.   For example,...