Windows users are reporting a frustrating issue in which their PCs completely freeze shortly after connecting to the internet. While the exact cause remains unconfirmed, a built-in Windows task responsible for updating Secure Boot certificates has emerged as a possible culprit.

The problem appears to affect some older PCs running outdated UEFI firmware. Microsoft has acknowledged that Secure Boot certificate updates can fail on unsupported firmware and repeatedly retry, although the company has not confirmed that these failures are responsible for the reported system freezes.

For affected users, the situation presents a difficult trade-off: disabling the suspected task may stop the freezes, but it could also prevent their PCs from receiving important future Secure Boot updates.

What Is Causing Windows PCs to Freeze?

The suspected issue is linked to Windows’ built-in Secure-Boot-Update scheduled task, which helps install updated Secure Boot certificates.

According to Microsoft’s Secure Boot troubleshooting guide , the task runs at system startup and every 12 hours. It checks for pending certificate updates and attempts to apply them in coordination with the PC’s UEFI firmware.

When an update fails, Windows records the error and retries the operation during a subsequent run. This behavior is intended to help devices complete the update when a temporary problem prevents it from succeeding.

However, firmware compatibility issues can prevent some updates from completing. Microsoft confirms that unsupported or faulty firmware can cause Secure Boot servicing to stall or repeatedly retry. The company has also documented more serious problems associated with Secure Boot updates, including startup hangs and boot failures.

What remains unclear is whether this retry behavior is directly responsible for the complete system freezes reported by users after connecting to the internet. The connection may coincide with the update process running, but that alone does not establish a direct cause.

Why Microsoft Is Updating Secure Boot Certificates

Secure Boot is a security feature that helps protect the Windows startup process. It checks whether software loaded before Windows is properly signed by a trusted source, helping prevent malicious or unauthorized bootloaders from running.

Microsoft is transitioning devices from older 2011 Secure Boot certificates to newer 2023 certificates. The older certificates began reaching their expiration dates in June 2026, making the transition important for maintaining protection against threats targeting the boot process.

Microsoft explains the transition and its potential impact in its official Secure Boot certificate update documentation .

Devices that cannot install the updated certificates may continue to start Windows and receive regular Windows updates. However, they could miss future security protections for boot components.

This is particularly relevant for older PCs whose manufacturers no longer provide the firmware updates needed to support the certificate transition.

Disabling the Secure Boot Task May Stop the Freezes

Some affected users report that disabling the Secure-Boot-Update scheduled task appears to prevent the freezes.

While this may offer temporary relief, it comes with an important security trade-off.

Microsoft explicitly states that disabling or removing the task prevents Windows from applying Secure Boot certificate updates. The task is a necessary part of the certificate servicing process, so leaving it disabled could prevent future updates from being installed.

For that reason, disabling the task should not be treated as a permanent fix for the reported freezing issue.

Users should also avoid disabling Secure Boot itself, as doing so reduces protection for the startup process.

What Should Affected Windows Users Do?

If your PC freezes shortly after connecting to the internet, there are several steps worth considering before disabling a Windows security task.

  • Check for UEFI firmware updates: Visit your PC manufacturer’s official support website and look for firmware updates for your exact model.

  • Install the latest Windows updates: Microsoft continues to distribute updated Secure Boot certificates through Windows Update.

  • Check Secure Boot status: Open Windows Security, navigate to Device security, and select Secure Boot to review the certificate update status.

  • Look for firmware compatibility warnings: If Windows reports that certificate updates are blocked by hardware or firmware limitations, follow the manufacturer’s guidance.

  • Investigate system logs: Windows’ System event log can help identify failed Secure Boot update operations and determine whether the servicing process is making progress.

Microsoft’s Secure Boot certificate status guide  provides additional information about identifying update problems and understanding the warnings displayed by Windows Security.

If the PC continues to freeze, users should avoid making changes to firmware security settings without understanding the consequences. A manufacturer-supported firmware update or a confirmed Microsoft fix would be a safer long-term solution.

Microsoft Has Yet to Confirm the Freezing Issue

The reported freezes raise questions about how Windows handles Secure Boot certificate updates on older hardware. Microsoft has documented certificate installation failures, firmware compatibility problems, and repeated retries, but these details do not confirm that the update task is responsible for the reported system-wide freezes.

Until the cause is established, users should distinguish between a confirmed Secure Boot update failure and a freeze that merely occurs around the same time.

For affected PC owners, the priority is to identify whether firmware compatibility is involved while preserving the security protections provided by Secure Boot.

Stay tuned to TheWinCentral for further details related to Microsoft and Windows news.

Add WinCentral as a preferred source on Google News
Add WinCentral as a preferred source on Google News