Action Required: Update IGEL OS on Devices Before October 14, 2025
On October 14, 2025, Microsoft will deliver an updated Secure Boot revocation list. Once applied, this update will prevent IGEL OS versions prior to 11.10.410 (OS 11) and 12.7.0 (OS 12) from booting.
The revocation list is delivered through BIOS/UEFI firmware updates from your hardware vendor. IGEL OS will only be affected once the BIOS/UEFI update is applied to your endpoint devices.
What You Need To Do
Update IGEL OS before applying any BIOS/UEFI firmware updates:
IGEL OS 12 → Update to version 12.7.0 or later (latest 12.7.2)
IGEL OS 11 → Update to version 11.10.410 or later
IGEL UD Pocket /USD Boot devices → Update to IGEL OS 12.7.0 or later
After updating IGEL OS:
You can safely update the BIOS/UEFI firmware on your endpoint device.
Key Points
IGEL OS endpoints will only be affected if a BIOS/UEFI firmware is applied before updating to IGEL OS 12.7.0, or 11.10.410 (or later).
As long as you do not update the UEFI on your IGEL endpoints, there will be no impact on your active devices.This applies to IGEL UD Pocket (bootable USB drives) as well.
If you cannot update IGEL OS before updating the BIOS/UEFI, you may temporarily disable Secure Boot.
This will allow older versions of IGEL OS to boot.
Only do this with approval from your security team.
Strongly recommended: Re-enable Secure Boot after updating IGEL OS on your endpoints.
Please consult your hardware vendor’s instructions to disable Secure Boot
Similar to the above, if you have updated the BIOS/UEFI and IGEL OS will no longer boot, you can disable Secure Boot, which will recover the IGEL OS endpoint and allow the update process.
Device Impact Overview
Devices Not Impacted
IGEL-branded devices (pre-tested and validated)
Devices using a UEFI version released before October 14, 2025
Devices without Secure Boot enabled or that do not support Secure Boot
Devices Potentially Impacted
Devices with a UEFI version released after October 14, 2025
Devices that came with Windows preinstalled (these may auto-update UEFI via Windows update)
UD Pockets on third-party devices that auto-apply UEFI updates via Windows or OEM software
How to Ensure Devices Have the Updated Certificate
To prevent boot issues after UEFI updates released after October 14, 2025:
Apply the Current OS Release:
IGEL OS 12: Upgrade to 12.7.2 or later
IGEL OS 11: Upgrade to 11.10.410 or later
Before Updating UEFI:
Ensure the device is already running one of the OS versions listed above.
This ensures the Secure Boot certificate used in newer UEFI versions is already present.
Temporarily Disable Secure Boot (if needed):
If the UEFI is already updated and the device won’t boot, disable Secure Boot in BIOS.
Re-enable Secure Boot after upgrading IGEL OS to a version with the new certificate.
Please consult your security department, before disabling secure boot.
Reminder
IGEL OS 11 reaches End of Maintenance on June 30, 2026. It will no longer receive updates — including Secure Boot certificates — after this date.
Need help?
For step-by-step instructions to update from OS 11 to OS 12, please see:
To open a ticket with IGEL Technical Support:
To speak with the IGEL Customer Experience Team
EMEA: igelcxmemea@igel.com