microsoft / microsoft/secureboot_objects
GetSecureBoot Documentation Request: Hyper-V
Open
@mebersol is already working on this.
Since May 18, 2026.
state:backlog
- Dominant language
- Python
- Stars
- 289
- Forks
- 89
- Avg merge
- 3d 10h
- Merged PRs (30d)
- 7
Description
I think admins (myself included) have a lot of questions about the SB updates on Hyper-V and a new document specific to it is warranted (I think under https://aka.ms/getsecureboot would make sense to strengthen the already quality documentation there).
Some things to document (maybe a FAQ format) include:
- March CU requirements, what changed.
- Hotpatch vs coldpatch CU
- Version compatibility for HV hosts supporting KEK updates (Windows Server 2012R2 I think with ESU entitlements?)
- Gen 1 vs Gen 2 security posture
- Compare + contrast the "features" of the three secure boot templates
- Impacts of VMs with TPMs (and shielding)
- Guest operating systems supported (in theory it shouldn't matter, even linux VMs updating with fwupd should work....)
- Why is the PK expired?
- Do VMs created after the March LCU is applied automatically include the 2023 certs? Or which version/patch combinations of HV VMs include all 2023 certs/keys "out of the box"?
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.