Updates

Windows 11 Multiple Reboots Explained: Why Secure Boot Updates Are Keeping You Waiting

5 min read Editorial

If you have noticed your Windows 11 PC restarting two or three times during a single Patch Tuesday installation, you are not alone. This behavior has become increasingly common since April 2026, often leaving users staring at a black screen or a spinning circle for extended periods. While the experience can feel alarming, Microsoft has confirmed that these repeated restarts are an intentional part of a broader security infrastructure change.

The core driver behind this behavior is the ongoing deployment of new Secure Boot certificates across millions of devices. As Microsoft continues to push these updates alongside standard monthly cumulative patches, the installation process now requires additional steps to write changes directly into your system’s firmware. This article breaks down exactly why this is happening, the technical steps involved, and how you can verify your device’s status.

The Secure Boot Certificate Rollout Continues

Microsoft is currently executing a large-scale update to the Secure Boot certificates used to verify the integrity of the Windows bootloader. This initiative is designed to enhance security by ensuring that only trusted software can load during the startup sequence. The August 2026 Patch Tuesday update, which delivered as many as 400 security fixes and bumped systems to Build 26200.9168, included additional high-confidence device targeting data to expand coverage for this rollout.

Advertisement
A clean, modern graphic showing a timeline of a Windows 11 update process with multiple reboot icons, representing the s
The August 2026 Patch Tuesday update expanded coverage for devices eligible to receive the new Secure Boot certificates automatically.

The company explicitly noted in the release notes for KB5121003 that certificate deployment via Windows Update continues across supported PCs and non-managed business devices in the coming months. If your device has not yet received the new Secure Boot 2023 certificate, it is likely still pending delivery. This is a one-time process per device, but because Microsoft is targeting a vast array of OEM configurations, the rollout spans several months rather than occurring in a single wave.

The Technical Reason Behind the Reboots

Updating a Secure Boot certificate is fundamentally different from applying standard software patches. The process requires writing new cryptographic keys directly into the motherboard’s firmware. During an Ask Me Anything session, Microsoft engineers clarified that this multi-step procedure is what necessitates multiple restarts.

A detailed 3D render of a UEFI firmware chip on a motherboard with data streams flowing into it, visualizing the certifi
Microsoft explained that the update stages data, applies certificates to firmware, and then boots the signed bootloader, requiring three distinct restarts.

The workflow typically follows three distinct phases, each requiring a reboot to complete safely. First, the update stages the new certificate data in preparation for the firmware write. Second, the system restarts to allow the firmware to apply the updated certificates. Third, a final reboot is required to boot Windows using the newly signed bootloader. Microsoft stated that most of these restarts occur early in the boot process, which is why they often go unnoticed during automated flows, but they become highly visible when triggered alongside a standard cumulative update.

Other Factors Triggering Reboots

While the Secure Boot certificate is the primary culprit for the recent surge in multiple restarts, it is not the only factor. Windows Update frequently delivers separate firmware and driver updates alongside security patches. If your device has pending firmware changes from the OEM, these will trigger additional restarts as the system applies hardware-level configurations.

A split-screen comparison showing a standard single reboot icon versus a multiple reboot icon, highlighting the differen
Pending firmware or driver updates can trigger additional restarts even after the Secure Boot certificate has been fully applied to your device.

This explains why some users may experience multiple reboots across different monthly updates, even after the Secure Boot certificate has been fully applied. A pending driver update or a BIOS/UEFI firmware patch can introduce new restart cycles independent of the certificate deployment. If you notice another reboot later in the same update cycle, it is likely related to these auxiliary components rather than a repeat of the Secure Boot process.

What This Means for You

For everyday users, the immediate takeaway is patience. If your PC is cycling through multiple restarts, it is actively working on critical security infrastructure. Interrupting the process by holding the power button can corrupt the firmware update and may leave the device in an unbootable state. Microsoft advises against delaying updates past three days, as doing so may expose systems to AI-powered security threats that target unpatched vulnerabilities.

A user-friendly screenshot mockup of the Windows System Information window highlighting the Secure Boot State setting wi
You can verify your Secure Boot status in System Information to confirm whether your device has received the latest certificate update.

Once the Secure Boot certificate is successfully applied to your specific hardware, you should see a return to the standard single-reboot behavior for future updates. If your device remains stuck on a black screen for an unusually long time or fails to progress past the spinning circle, it may indicate a firmware conflict that requires troubleshooting.

How to Verify Your Secure Boot Status

You can check whether your device has received the latest Secure Boot certificate by navigating to Settings > System > Recovery > Advanced startup, or by using the System Information tool. Look for the Secure Boot State entry, which should indicate whether the current certificates are up to date. If you are managing a fleet of devices, administrators should monitor the deployment progress via the Windows Update for Business dashboard to identify devices that may be stuck in the rollout queue.

Source: Windows Latest

Build details:

  • kb5121003

Over to you: Have you experienced multiple reboots during this month’s Patch Tuesday, and did your device eventually complete the update successfully?

Advertisement
Share:
Editorial
Written by
Editorial

Windows & Microsoft news editor at 9to5Windows. Covering everything from Windows 11 builds to enterprise updates.

Advertisement