Hello Fernand,
Thank you for posting question on Microsoft Windows Forum!
Well! The plausible explanation to your query is that based on the best available information, not installing the Secure Boot update on your servers will lead to a degraded security posture over time. While your servers will continue to boot normally in the short term, they will lose the ability to receive critical future protections against boot-level threats.
The potential operational impacts for not updating is the loss of Future Boot-Level Security Updates. The servers will not be able to receive future updates to the Secure Boot database, revocation lists (DBX), or the Windows Boot Manager. This means that if new vulnerabilities or bootkits are discovered after the old certificates expire, your servers will remain unprotected against them. On the other hand, any new, properly signed pre-boot components (like firmware drivers or OS loaders) may not be trusted by your server's firmware if it lacks the new 2023 certificates. This could lead to compatibility issues, especially during future OS upgrades or when applying third-party signed firmware. In addition to that, since the update is primarily a security hardening measure. Without it, the server remains protected only by the older Secure Boot trust chain. It cannot benefit from Microsoft's newer boot security improvements and remains exposed to attack scenarios involving compromised or outdated bootloaders that Microsoft is actively revoking.
The best practice is to verify that server hardware and hypervisors have up-to-date UEFI firmware capable of handling the 2023 certificate rotation. Also performing a pilot deployment by staggering updates through Windows Update or managed deployment policies across pilot server cohorts ( or test the update process on a small group of servers representing your different hardware platforms to identify and resolve any vendor-specific quirks) rather than applying changes all at once. Ensure your BitLocker recovery keys are securely escrowed or backed up and accessible before deploying any updates known to impact Secure Boot. This will help you recover swiftly if a server triggers a recovery prompt on reboot
You are strongly encouraged to consult the following link for more information about Secure Boot Certificate updates guidance.
Hope the above information is helpful! If it is. Free feel to hit "Accepted" for benefitting others in community having the same query too.