this is first post for me here, and hope i get support.
i've optiplex 7020 disktop,
how i update secure boot certificate?
windows update shows this message
Secure Boot is on, but your device does not support the automated Secure Boot certificate update due to hardware or firmware limitations. Contact your device manufacturer for assistance.
what shall we do now to fix it?
also, could I buy external tpm chip as my device doesn't have one?
Yeah, you need to running the latest published BIOS-Firmware for your computer. And I think Windows-11 as we are not really doing all this work for computers locked-back-at Windows-10. Of course, computer must be UEFI-class.
(edited)
Dell Rockstar
Microsoft Windows and Apple iOS Developer (Retired) - Like many of you, I can appreciate a good game-engine. - I answer questions here, but I'm not a Dell employee. - Consider giving posts you like a "thumbs-up" - Posting models-numbers and software versions speeds trouble-shooting. - Click "Mark as Accepted Answer" on any post that answers your question best.
No, there's no way to fit an external TPM -- if the system doesn't have the TPM (and if this is the 2012-vintage 7020, even if it does it's so far out of date it's essentially useless for Windows 11), that cannot be added.
Dell won't have updates including the 2023 secure boot certificates. You may or may not be able to add them manually -- see
would you please, which tool i should use to share needed report? and wish it could be accessible with screenreader.
and could i just coppy info not share as image?
system info:
[System Summary]
OS Name Microsoft Windows 10 Pro Version 10.0.19045 Build 19045 System Manufacturer Dell Inc. System Model OptiPlex 7020 System SKU 05A5 Processor Intel(R) Core(TM) i5-4570 CPU @ 3.20GHz, 3201 Mhz, 4 Core(s), 4 Logical Processor(s) BIOS Version/Date Dell Inc. A09, 5/18/2016 SMBIOS Version 2.7 Embedded Controller Version 255.255 BIOS Mode UEFI BaseBoard Manufacturer Dell Inc. BaseBoard Product 08WKV3 BaseBoard Version A01 Secure Boot State On PCR7 Configuration Binding Not Possible
OS Name Microsoft Windows 10 Pro Version 10.0.19045 Build 19045 System Manufacturer Dell Inc. System Model OptiPlex 7020 System SKU 05A5 Processor Intel(R) Core(TM) i5-4570 CPU @ 3.20GHz, 3201 Mhz, 4 Core(s), 4 Logical Processor(s) BIOS Version/Date Dell Inc. A09, 5/18/2016 SMBIOS Version 2.7 Embedded Controller Version 255.255 BIOS Mode UEFI BaseBoard Manufacturer Dell Inc. BaseBoard Product 08WKV3 BaseBoard Version A01 Secure Boot State On PCR7 Configuration Binding Not Possible
Note 1: Before updating the BIOS, ensure that you suspend BitLocker encryption on a BitLocker-enabled system. If BitLocker is not enabled on your system, you can ignore this step. Note 2: Do not turn off the power or interrupt the BIOS update process during the update.
Download and Installation 1. Click Download File, to download the file. 2. Click Save to save the file to your hard drive. 3. Browse to the location where you downloaded the file and double-click the new file. The system restarts automatically and updates the BIOS at the system startup screen. After the BIOS update is complete, system restarts again.
Updating the BIOS from DOS (Non-Windows users)
Note 1: Before updating the BIOS, ensure that you suspend BitLocker encryption on a BitLocker-enabled system. If BitLocker is not enabled on your system, you can ignore this step. Note 2: Do not turn off power or interrupt the BIOS update process during the update.
Installation Note: You must provide a bootable USB drive. This executable file does not create the DOS system files. 1. Copy the downloaded file to a bootable USB drive. 2. Power on the system and then Press the F12 key. 3. Select USB Storage Device and boot to the DOS prompt. 4. Run the file by typing following command. For example: C:\ 7020A18.exe Where C is the drive letter of the USB device where the executable file is located and 7020A18.exe is the name of the downloaded file. The system restarts automatically and updates the BIOS at the system startup screen. After the BIOS update is complete, system restarts again.
Updating the BIOS from DOS with UEFI boot mode enabled (Non-Windows users, Load Legacy Option Disabled)
Note 1: Before updating the BIOS, ensure that you suspend BitLocker encryption on a BitLocker-enabled system. If BitLocker is not enabled on your system, you can ignore this step. Note 2: Do not turn off the power or interrupt the BIOS update process during the update.
Installation 1. Copy the downloaded file to a bootable DOS USB drive. 2. Power on the system and then go to BIOS Setup by pressing the F2 key. 3. Go to General > Boot Sequence > Boot > Boot List Option. 4. Change UEFI to Legacy of Boot List Option. 5. Go to Exit > Save Changes and reboot system. 6. Press F12 and then select USB Storage Device and boot to the DOS prompt. 7. Run the file by typing the file name. The system restarts automatically and updates the BIOS at the system startup screen. After the BIOS update is complete, the system restarts again. 8. Go to BIOS Setup by pressing the F2 key and go to General > Boot Sequence > Boot > Boot List Option. 9. Change Legacy to UEFI Boot Option. 10. Go to Exit > Save Changes and reboot the system.
Hopefully if you run some updates of the BIOS then maybe there will be MS updates that will install your certificates.
If in doubt please ask.
For a Dell OptiPlex 7020 Tower, you generally do not manually “install Microsoft Windows 10 2023 certs” in Windows itself; Dell says the right path is to keep the BIOS updated so the platform receives the new Secure Boot certificates in firmware/default Secure Boot databases, while Microsoft is also rolling updates out through Windows Update in phases.
What to do
Update Windows 10 fully through Windows Update. Microsoft’s rollout is staged, so supported systems may receive the Secure Boot certificate update automatically.
Update the OptiPlex 7020 Tower BIOS from Dell Support. Dell specifically recommends keeping BIOS current so the 2023 Secure Boot certificate is present in the default Secure Boot database.
After the BIOS update, check Secure Boot status in Windows and verify whether the newer trust configuration is present. Dell and Microsoft both indicate that firmware level matters for this transition.Important note
A “manual certificate install” is not the normal end-user method for this issue on a home or small-business PC; the supported approach is Windows Update plus Dell firmware/BIOS updates.
Dell-specific path
Go to the Dell support page for the OptiPlex Tower 7020 and install the latest BIOS. dell
Read the BIOS release notes carefully for wording like “This BIOS contains the new 2023 Secure Boot Certificates.” Dell says that phrase may appear in driver details for affected updates.
If the machine is BitLocker-protected, suspend BitLocker before the BIOS update, then re-enable it afterward. This is standard practice for firmware changes, though Dell’s Secure Boot articles emphasize keeping firmware current rather than manually editing certificates.
Tesla1856
10 Wizard
•
17985 Posts
•
71600 Points
0
0
Posted July 1st, 2026 20:05
Do this and post the picture of the report here in your thread:
https://www.dell.com/community/en/conversations/xps-desktops/xps-8930-purchased-2018-2023-secure-boot-certificates/699cdb010daada5e7a6c379f?commentId=6a1a2ebe5e24e611a5a521fc
I'll take a look at it for you and advise.
Edit:
Yeah, you need to running the latest published BIOS-Firmware for your computer. And I think Windows-11 as we are not really doing all this work for computers locked-back-at Windows-10. Of course, computer must be UEFI-class.
(edited)
Dell Rockstar
Microsoft Windows and Apple iOS Developer (Retired)
- Like many of you, I can appreciate a good game-engine.
- I answer questions here, but I'm not a Dell employee.
- Consider giving posts you like a "thumbs-up"
- Posting models-numbers and software versions speeds trouble-shooting.
- Click "Mark as Accepted Answer" on any post that answers your question best.