You can now deploy, manage, and monitor Secure Boot certificate updates. This method represents an alternative to setting registry keys and using Group Policy. You can use Intune to deploy on all domain-joined Windows clients, opt out of high-confidence buckets, and opt in to Microsoft managing these updates. When will this happen: The following settings are now available in the Intune settings catalog: Configure Microsoft Update Managed Opt-In Configure High-Confidence Opt-Out Enable SecureBoot...
Applies to: Windows
Source: mc.merill.net — data via Merill Fernando's open archive (MIT).