4-Hour Live Workshop

Speed Date with Kaido Järvemets
Secure Boot Workshop

Walk through the tools, the setup, and the deployment approach for the Secure Boot 2026 certificate transition. See the assessment solutions in action and leave with a plan for your environment.

Taught by Someone Who
Built the Tools

Your trainer built the Secure Boot BIOS assessment tooling from scratch: multi-vendor BIOS databases, interactive HTML reports, and automated fleet assessment pipelines for SCCM and Intune.

  • Built the assessment solution: Multi-vendor BIOS readiness assessment covering Dell, HP, and Lenovo with interactive HTML reports.
  • SCCM and Intune pipelines: Separate assessment workflows for ConfigMgr SQL queries and Intune Graph API environments.
  • Vendor database maintenance: Tracking Dell, HP, and Lenovo firmware requirements as they publish updates.
  • Production deployments: Running this across enterprise fleets with workstation and server pipelines.

You're not learning from someone who read the docs.
You're learning from someone who built the tools.

4 hours. One workshop.
Walk away with a deployment plan.

What You'll Actually Learn

This workshop walks through the tools and approach for handling the Secure Boot certificate transition across your fleet.

Fleet Assessment with SCCM

Run the assessment pipeline against your ConfigMgr database. See how devices are classified: OK, NEEDS_UPDATE, UNKNOWN_MODEL, or NOT_SUPPORTED.

Fleet Assessment with Intune

Use the Intune Graph API module to assess cloud-managed devices. Same comparison logic, different data source.

Multi-Vendor BIOS Databases

Understand how the Dell, HP, and Lenovo JSON databases work. How models are matched, how versions are compared, and how to handle unknowns.

Certificate Deployment Methods

Intune Settings Catalog, Group Policy, ConfigMgr registry deployment, and direct PowerShell triggers. Pick the right method for your environment.

Azure VM Coverage

Identify Trusted Launch VMs with Secure Boot enabled using Azure Resource Graph. Deploy the certificate update via Run Command or automation.

Interactive HTML Reports

Read the assessment output: donut charts, vendor breakdowns, per-device drill-down tables, and progress tracking over time.

The FULL Curriculum

4 parts: introduction, assessment, BIOS updates, and certificate deployment for workstations and servers

Part 1: Introduction

  • Three Secure Boot certificates expiring in 2026
  • KEK expires June 24, UEFI CA June 27, Windows PCA October 19
  • Why devices need a BIOS update before the certificate deployment

Part 2: Fleet Assessment

  • SCCM assessment for workstations and servers
  • Intune assessment for workstations
  • Azure VM assessment
  • Comparing current BIOS versions against vendor minimum requirements (Dell, HP, Lenovo)
  • HTML reports with per-device status

Part 3: BIOS Updates

  • SCCM BIOS update packages
  • Intune Windows driver update policies for firmware updates

Part 4: Certificate Deployment

  • Intune Settings Catalog configuration
  • Configuration Manager baselines and configuration items
  • Group Policy deployment
  • Live progress tracker built on Teams and SharePoint

Next TRAINING DATE

APRIL
08
2026
13:00 - 17:00 CEST
Microsoft Teams
4 Hours Live
Reserve Your Spot

10 spots available • April 8, 2026

Your INVESTMENT

What You'll Walk Away With:

Complete tool walkthrough: every script and report template in action.
Direct access to the tool author: ask anything about your specific fleet and vendor mix.
Deployment plan: leave with a plan for your environment and timeline.
€250
per person
Compare your options: Onsite assessment: €2,500
Implementation project: €10,000+
Consultant day rate: €1,500+

Same expertise. Workshop price.
Reserve Your Spot
Limited to 10 participants

Your TRAINER

Kaido Järvemets
Microsoft MVP 15+ Years Experience

With over 15 years of experience in IT, cybersecurity, and Microsoft technologies, Kaido specializes in Microsoft Azure, Microsoft 365, and hybrid-cloud security solutions. As a Microsoft MVP since 2010, he has deep expertise in Configuration Manager, Enterprise Mobility, and Azure Hybrid & Security.

Kaido was a Microsoft Certified Trainer for 6+ years and has been traveling across Europe for the past 12 years, speaking at events including the Microsoft Management Summit and Midwest Management Summit. He founded User Group Estonia and System Center User Group Estonia, building strong communities of Microsoft technology professionals.

Got Questions? We've Got Answers

Everything you need to know about the Secure Boot Workshop.

Is this training live or recorded?

+

This is a live, interactive 4-hour workshop delivered via Microsoft Teams. You can ask questions throughout, discuss your specific environment, and see the tools in action. Not a recording.

What do I need to prepare?

+

Nothing. Just show up. I walk through everything during the workshop.

Will I get access to the assessment tools?

+

Yes. All participants get access to the assessment tools and solutions covered in the workshop.

What level of experience do I need?

+

You should have working knowledge of Windows Server, UEFI/Secure Boot concepts, and either SCCM or Intune. If you're responsible for patching or firmware management, this workshop is for you.

What if I can't attend on April 8?

+

This is a one-time workshop. There are no future sessions planned. If you can't make it, you miss it.

Can I bring my team?

+

Yes. €250 per person. Having your whole team attend means everyone understands the approach and can ask questions about your specific fleet.

Register for WORKSHOP

Secure Your Spot

4 Hours • Microsoft Teams • April 8, 2026
Complete the form below to register for the Secure Boot Workshop.
Need hands-on help with your deployment? See our Secure Boot consulting service.

If you don't see the registration form below, please click here to open the Microsoft Forms registration form.