Risk of BitLocker/boot issues with Secure Boot updates on outdated UEFI firmware?

Posted by Zarphyl@reddit | sysadmin | View on Reddit | 16 comments

Hi all,

I’m managing \~1,600 endpoints in a constrained environment (WSUS-only, no budget for additional tooling like SCCM/Intune or third-party patch management).

We have a mixed hardware fleet, and a significant number of devices are running outdated BIOS/UEFI firmware. With the recent Windows updates that touch Secure Boot / UEFI trust chain (e.g., DB/DBX updates, revocation lists, etc.), I’m concerned about potential mismatches between OS-level updates and firmware state.

My main questions:

Given that we don’t have centralized firmware management, I’m trying to assess the real risk before broadly approving updates in WSUS.

Any insights, especially from people who’ve dealt with Secure Boot DBX rollouts or similar scenarios at scale, would be very helpful.

Thanks!