Skip to main content
Skip table of contents

Action Required: Update IGEL OS on Devices Before October 14, 2025

On October 14, 2025, Microsoft will deliver an updated Secure Boot revocation list. Once applied, this update will prevent IGEL OS versions prior to 11.10.410 (OS 11) and 12.7.0 (OS 12) from booting.

The revocation list is delivered through BIOS/UEFI firmware updates from your hardware vendor. IGEL OS will only be affected once the BIOS/UEFI update is applied to your endpoint devices.

What You Need To Do

  1. Update IGEL OS before applying any BIOS/UEFI firmware updates:

    • IGEL OS 12 → Update to version 12.7.0 or later (latest 12.7.2)

    • IGEL OS 11 → Update to version 11.10.410 or later

    • IGEL UD Pocket /USD Boot devices → Update to IGEL OS 12.7.0 or later

  2. After updating IGEL OS:

    • You can safely update the BIOS/UEFI firmware on your endpoint device.

Key Points

  • IGEL OS endpoints will only be affected if a BIOS/UEFI firmware is applied before updating to IGEL OS 12.7.0, or 11.10.410 (or later).
    As long as you do not update the UEFI on your IGEL endpoints, there will be no impact on your active devices.

  • This applies to IGEL UD Pocket (bootable USB drives) as well.

  • If you cannot update IGEL OS before updating the BIOS/UEFI, you may temporarily disable Secure Boot.

    • This will allow older versions of IGEL OS to boot.

    • Only do this with approval from your security team.

    • Strongly recommended: Re-enable Secure Boot after updating IGEL OS on your endpoints.

    • Please consult your hardware vendor’s instructions to disable Secure Boot

  • Similar to the above, if you have updated the BIOS/UEFI and IGEL OS will no longer boot, you can disable Secure Boot, which will recover the IGEL OS endpoint and allow the update process.

Device Impact Overview

Devices Not Impacted

  • IGEL-branded devices (pre-tested and validated)

  • Devices using a UEFI version released before October 14, 2025

  • Devices without Secure Boot enabled or that do not support Secure Boot

Devices Potentially Impacted

  • Devices with a UEFI version released after October 14, 2025

  • Devices that came with Windows preinstalled (these may auto-update UEFI via Windows update)

  • UD Pockets on third-party devices that auto-apply UEFI updates via Windows or OEM software

How to Ensure Devices Have the Updated Certificate

To prevent boot issues after UEFI updates released after October 14, 2025:

  1. Apply the Current OS Release:

    • IGEL OS 12: Upgrade to 12.7.2 or later

    • IGEL OS 11: Upgrade to 11.10.410 or later

  2. Before Updating UEFI:

    • Ensure the device is already running one of the OS versions listed above.

    • This ensures the Secure Boot certificate used in newer UEFI versions is already present.

  3. Temporarily Disable Secure Boot (if needed):

    • If the UEFI is already updated and the device won’t boot, disable Secure Boot in BIOS.

    • Re-enable Secure Boot after upgrading IGEL OS to a version with the new certificate.

Please consult your security department, before disabling secure boot.

Reminder

IGEL OS 11 reaches End of Maintenance on June 30, 2026. It will no longer receive updates — including Secure Boot certificates — after this date.

Need help?

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.