A Microsoft desktop and app virtualization service that runs on Azure. Previously known as Windows Virtual Desktop.
Mian - This behavior is expected on Azure‑hosted Gen 2 virtual machines, including Azure Virtual Desktop (AVD) Windows 11 Enterprise multi‑session hosts.
Although the Secure Boot 2023 (KEK/DB) certificate updates can be triggered via registry keys on supported Windows versions, guest OS initiated updates to Secure Boot variables are not permitted on Azure Gen 2 VMs. Secure Boot variables such as KEK, DB, and DBX are owned and enforced by the Hyper‑V UEFI firmware, not the guest OS.
As a result:
- Event ID 1795 (TPM‑WMI – Access is denied) is expected
- UEFICA2023 Status remains In-Progress
- PowerShell checks for the KEK 2023 certificate return False
- Manual registry‑based or GPO‑based Secure Boot updates cannot complete on AVD Gen 2 machines
Microsoft Rollout Plan - For Azure Virtual Desktop, Azure VMs, and Windows 365, Microsoft manages Secure Boot certificate updates at the platform (backend) level.
The Secure Boot 2023 certificates will be rolled out automatically by Microsoft as part of the Azure virtualization stack before the June 2026 deadline, without requiring customer intervention - https://support.microsoft.com/en-us/topic/registry-key-updates-for-secure-boot-windows-devices-with-it-managed-updates-a7be69c9-4634-42e1-9ca1-df06f43f360d