Italian language translation thread (Upg 2026.05.11090

Version 2026.03.10899 --> 2026.03.10909 - template.xml file (and other languages).

Modify
From <S3466>Browse and select apps from winget and Chocolatey for automated installation</S3466>
To <S3466>Browse and select apps from winget for automated installation</S3466>

From <S1940>Let Windows track opened documents to populate Jump Lists</S1940>
To <S1940>Show recommended files in Start, recent files in File Explorer, and items in Jump Lists</S1940>

The Italian file is also aligned with 2026.03.10909
 

Attachments

Last edited:
Version 2026.03.10909 --> 2026.04.10935 - template.xml file (and other languages).

Add (New)
Post <S3454>
<S3480>Braille</S3480>​
Post <S3345>
<S3481>Remove dependees?</S3481>​

Modify
From <S0619>Main menu</S0619>
To <S0619>Menu</S0619>

The Italian file is also aligned with 2026.04.10935
 

Attachments

Last edited:
Version 2026.04.10935 --> 2026.04.10936 - template.xml file (and other languages).

Add (New)
Post <S3357>
<S3482>AI Component Management</S3482>​
<S3483>Manages built-in AI components, including how they are listed, updated, and optionally removed in Settings - System - AI components.</S3483>​

The Italian file is also aligned with 2026.04.10936
 

Attachments

Version 2026.04.10936 --> 2026.04.10966 - template.xml file (and other languages).

Modify
From <S0214>Please copy to clipboard with CTRL+C, and paste in the email to [email protected]</S0214>
To <S0214>Please paste in the email to [email protected]</S0214>

From <S2949>Extracted files deleted after use</S2949>
To <S2949>Otherwise, extracted files are deleted on closing the tool</S2949>

From <S2951>Requires more disk space during extraction</S2951>
To <S2951>Uses more CPU and disk space</S2951>



Deleted
<S2948>Sequential extraction</S2948>



Add (New)
Post <S3347>
<S3487>Faster extraction using multiple CPU threads</S3487>

Post <S3315>
<S3484>Clean apps</S3484>
<S3485>Removes older versions of provisioned AppX/MSIX packages, keeping only the newest version of each app or a framework. Also supports unregistered packages that are not tracked by Windows/DISM.</S3485>
<S3486>Smart cache</S3486>

The Italian file is also aligned with 2026.04.10966
 

Attachments

Last edited:
Version 2026.04.10966 --> 2026.04.10970 - template.xml file (and other languages).

Modify
From <S1679>If this legacy option is enabled, the user will not be prompted for values that are necessary to successfully complete Windows setup.</S1679>
To <S1679>If this legacy option is enabled, the user will not be prompted for values that are necessary to successfully complete Windows setup, including WiFi.</S1679>

The Italian file is also aligned with 2026.04.10970
 

Attachments

Version 2026.04.10970 --> 2026.05.10996 - template.xml file (and other languages).

Add (New)


Post <S3448>

<S3496>Checked</S3496>

<S3497>Unchecked</S3497>

<S3498>Hide</S3498>

Post <S3479>

<S3493>Remote desktop is selected for removal while being used to connect to this machine.

To not lose a connection, it is recommended to reconnect to this machine in some other manner before continuing.

This also happens with a Hyper-V Enhanced Session option.</S3493>

<S3494>One or more of the following components is selected for removal while this program is running from a network share. During removal the program might crash as it will become unavailable when that service is removed.</S3494>

<S3495>No package data. Use Refresh to download the App Catalog.</S3495>

Post <S1066>

<S3488>Normal</S3488>

<S3489>Deferred</S3489>

<S3490>faster apply but produce a bigger image. Component purge runs on the target machine via Windows servicing scheduled task after install.</S3490>

<S3491>Resets the base of superseded components, further reducing store size. Installed updates can no longer be uninstalled. Microsoft does not recommend it.</S3491>

<S3492>Uses NTLite's custom engine. Useful when DISM does not support the target, e.g. very lite images.</S3492>


Modify

From <S0152>Clean update backup</S0152>

To <S0152>Optimize updates</S0152>


From <S0153>Removes superseded update components and compresses retained versions to reduce store size. Installed updates remain uninstallable.</S0153>

To <S0153>Remove obsolete updated backup files, keeping only latest versions.

All existing service packs and updates cannot be uninstalled after this operation.

This will not block the uninstallation of future service packs or updates. </S0153>


The Italian file is also aligned with 2026.05.10996
 

Attachments

Last edited:
Version 2026.05.10996 --> 2026.05.11004 - template.xml file (and other languages).

Modify
From <S0153>Removes superseded update components and compresses retained versions to reduce store size. Installed updates remain uninstallable.</S0153>
To <S0153>Removes superseded update components and compresses retained versions to reduce store size. Installed updates can still be uninstalled.</S0153>

From <S3490>faster apply but produce a bigger image. Component purge runs on the target machine via Windows servicing scheduled task after install.</S3490>
To <S3490>faster apply, larger initial image. Component purge runs on the target machine via Windows servicing scheduled task after install. Available offline on Windows 10 v1607 or later.</S3490>

From <S3491>Resets the base of superseded components, further reducing store size. Installed updates can no longer be uninstalled. Microsoft does not recommend it.</S3491>
To <S3491>Resets the base of superseded components, further reducing store size. Installed updates can no longer be uninstalled.</S3491>

The Italian file is also aligned with 2026.05.11004
 

Attachments

Last edited:
Version 2026.05.11004 --> 2026.05.11014 - template.xml file (and other languages).

Delete
<S0918>Reset all pages pending changes to image defaults?</S0918>
<S0922>Reset this page to the current image state, removing the pending changes.</S0922>

Add (New)
Post <S3390> --> </UI>
<Reset>​
<S3527>Reset to image defaults: </S3527>​
<S3528>This page</S3528>​
<S3529>All pages</S3529>​
</Reset>​

Post <S3477>
<S3526>Events</S3526>​
The Italian file is also aligned with 2026.05.11014
 

Attachments

Last edited:
Version 2026.05.11011 --> 2026.05.11012 - template.xml file (and other languages).

Add (New)
Post <S3390> --> </UI>
<Branding>
<S3500>Customize themes, lock screen, OEM information, user avatar, and visual effects</S3500>​
<S3501>Themes</S3501>​
<S3502>Lock Screen</S3502>​
<S3503>Visual Effects</S3503>​
<S3504>Drop shadow under menus</S3504>​
<S3505>Flat menus</S3505>​
<S3506>from image</S3506>​
<S3507>Wallpaper</S3507>​
<S3508>Wallpaper Style</S3508>​
<S3509>Accent Color</S3509>​
<S3510>Auto Colorization</S3510>​
<S3511>Apps Mode</S3511>​
<S3512>System Mode</S3512>​
<S3513>Brand Icon</S3513>​
<S3514>Default Avatar</S3514>​
<S3515>Accent (global)</S3515>​
<S3516>Inactive Title Color</S3516>​
<S3517>LogonUI Accent</S3517>​
<S3518>Import a .theme file from disk</S3518>​
<S3519>Add a new blank theme</S3519>​
<S3520>Remove the selected theme</S3520>​
<S3521>Duplicate the selected theme</S3521>​
<S3522>Bundle a font file with the image</S3522>​
<S3523>Remove all bundled fonts</S3523>​
<S3524>Promote the selected theme to be applied as default</S3524>​
<S3530>Global</S3530>​
<S3531>The theme '%s' is a stock Windows theme and cannot be edited.​
Clone it now so your changes apply to the copy?</S3531>​
</Branding>

The Italian file is also aligned with 2026.05.11012
see above 11014
 
Last edited:
Oops, that feature is not yet ready and strings might change.
Please save aside the Branding element for later, sorry for the confusion.
It won't break anything to keep it there.
 
Version 2026.05.11012 --> 2026.05.11080 - template.xml file (and other languages).

Modify
From <S1307> Windows Recovery (WinRE)</S1307>
To <S1307> Windows Recovery Environment</S1307>

From <S0207>Convert selected image to a high-compression ESD format, supported on Windows 8 or newer setup.</S0207>
To <S0207>High-compression read-only format, not supported on Windows 7 or boot/winre images.</S0207>

From <S0209>Convert selected image to a spanned, SWM format; also known as image splitting. Used for example to bypass the FAT32 single-file 4GB limitation, or span the image across multiple media.</S0209>
To <S0209>Image splitting format. Used to bypass the FAT32 single-file 4GB limitation, or span the image across multiple media.</S0209>

From <S0211>Convert selected image to a standard WIM format, ready for mounting and editing.</S0211>
To <S0211>Standard image format, ready for mounting and editing.</S0211>

From <S1793>Total pending tasks overview</S1793>
To <S1793>Pending tasks</S1793>

From <S1798>Remove other editions</S1798>
To <S1798>Remove editions</S1798>

From <S0789>Please BACKUP your activation by exporting the license.dat file. Optionally also backup the settings.xml file which contains general tool settings and the license code. Both files can be found in the installation directory of this application.</S0789>
To <S0789>Please BACKUP your activation by exporting the license.dat file.
Optionally also backup the settings.xml file which contains general tool settings and the license code.
Both files can be found in the installation directory of this application.</S0789>

From <S1066>Start applying all of the pending changes.</S1066>
To <S1066>Start applying pending tasks.</S1066>


Add (New)
Post <S1761>
<S3527>Reset to image defaults: </S3527>
<S3528>This page</S3528>
<S3529>All pages</S3529>


Post <S1420>
<S1421>Rewrite in place with current compression, no format change. Useful for shrinking the file after edits.</S1421>

Post <S3065>
<S3564>Overwrite source</S3564>
<S3565>File exists - will be overwritten</S3565>
<S3566>Some characters are invalid and will be removed on commit (max 32).</S3566>

Post <S3526>
<S3530>Visual Effects</S3530>
<S3531>Extras</S3531>
<S3532>Appearance</S3532>
<S3533>Performance</S3533>
<S3536>Animate controls and elements inside windows</S3536>
<S3537>Animate windows when minimizing and maximizing</S3537>
<S3538>Animations in the taskbar</S3538>
<S3539>Enable Peek</S3539>
<S3540>Fade or slide menus into view</S3540>
<S3541>Fade or slide ToolTips into view</S3541>
<S3542>Fade out menu items after clicking</S3542>
<S3543>Save taskbar thumbnail previews</S3543>
<S3544>Show shadows under mouse pointer</S3544>
<S3545>Show shadows under windows</S3545>
<S3546>Show thumbnails instead of icons</S3546>
<S3547>Show translucent selection rectangle</S3547>
<S3548>Show window contents while dragging</S3548>
<S3549>Slide open combo boxes</S3549>
<S3550>Smooth edges of screen fonts</S3550>
<S3551>Smooth-scroll list boxes</S3551>
<S3552>Use drop shadows for icon labels on the desktop</S3552>
<S3554>Flat Menus</S3554>
<S3555>Hot Tracking</S3555>
<S3556>Gradient Captions</S3556>
<S3557>Active Window Tracking</S3557>
<S3558>Visuals</S3558>
<S3559>Graphics and rendering tweaks.</S3559>
<S3561>NTFS 8.3 file name creation</S3561>
<S3562>Windows creates legacy 8.3 short file names (e.g. PROGRA~1) for new NTFS files to maintain compatibility with old 16-bit apps. Disabling improves security and slightly speeds operations on large folders, but may break some legacy installers.</S3562>
<S3563>Existing short names are kept.</S3563>
<S3567>View mode</S3567>
<S3568>Category</S3568>
<S3569>Grid</S3569>
<S3570>List</S3570>
<S3571>All apps</S3571>

Delete
<S0940>Save existing changes to the image</S0940>

<S0205>Convert selected image to a WIM, ESD or SWM format.</S0205>
<S0206>Convert to ESD</S0206>
<S0208>Convert to SWM (Split image)</S0208>

<Reset>
<S3527>Reset to image defaults: </S3527>
<S3528>This page</S3528>
<S3529>All pages</S3529>
</Reset>

The Italian file inserted is also aligned with 2026.05.11080
 
Version 2026.05.11080 --> 2026.05.11090 - template.xml file (and other languages).

Modify
From <S0559>ISO image will be created from the whole directory</S0559>
To <S0559>ISO image will be created from the whole image directory</S0559>

Add (New)
Post <S3487>
<S3573>Preparing...</S3573>

Post <S3495>
<S3572>Modified</S3572>

Delete
<S0945>Save changes, and unload the image</S0945>

The Italian file is also aligned with 2026.05.11090
 

Attachments

For Nuhi
THIS TIME IT WAS EXTREMELY HARD AND COMPLICATED...

Version 2026.05.11090 --> 2026.06.11200 - template.xml file (and other languages).

Modify

From <S0481>'Sources ei.cfg', with it removed and the final image has more than one edition, user will be prompted to select Windows edition on booting the ISO. If you see the error 'Windows cannot find Microsoft Software License Terms', return this file from the original ISO and try again.</S0481>

To <S0481>'Sources\ei.cfg', with it removed and the final image has more than one edition, user will be prompted to select Windows edition on booting the ISO. If you see the error 'Windows cannot find Microsoft Software License Terms', return this file from the original ISO and try again.</S0481>

From <S1659>Similar to Network QoS, but related to virtual machine storage performance, automatically improves storage resource fairness between multiple virtual machines using the same file server cluster and allows policy basedminimum and maximum performance goals to be configured in units of normalized IOPs.</S1659>

To <S1659>Similar to Network QoS, but related to virtual machine storage performance, automatically improves storage resource fairness between multiple virtual machines using the same file server cluster and allows policy based minimum and maximum performance goals to be configured in units of normalized IOPs.</S1659>

From <S3176>Contains latest EFI Secure Boot updates. CAUTION, if the deployed machine already has CVE-2023-24932 Boot Manager revocations enabled, removing this might make the image unbootable.</S3176>

To <S3176>Contains latest EFI Secure Boot updates.</S3176>

From <S2909>Rendering engine to display web content in native apps which explicitely use this control. For example it's used in web popups like PowerPoint insert online picture. Leaving Edge Update will install the latest version of this component.</S2909>

To <S2909>Rendering engine to display web content in native apps which explicitly use this control. For example it's used in web popups like PowerPoint insert online picture. Leaving Edge Update will install the latest version of this component.</S2909>

From <S2960>Taskbar popup menus, including langauge keyboards, network connections and others sharing the same popups.</S2960>

To <S2960>Taskbar popup menus, including language keyboards, network connections and others sharing the same popups.</S2960>

From <S1148>This services monitors the current location of the system and manages geo-fences (a geographical location with associated events).</S1148>

To <S1148>This service monitors the current location of the system and manages geo-fences (a geographical location with associated events).</S1148>

From <S1444>Remoting and Privacy</S1444>

To <S1444>Remoting &amp; Privacy</S1444>

From <S2957>Provides OEMs a way to publish OEM custom packages(OCP) to Windows Update Cloud, and to flight OS updates to their devices based on flight rings.</S2957>

To <S2957>Provides OEMs a way to publish OEM custom packages (OCP) to Windows Update Cloud, and to flight OS updates to their devices based on flight rings.</S2957>

From <S3145>Windows Local Administrator Password Solution(LAPS)</S3145>

To <S3145>Windows Local Administrator Password Solution (LAPS)</S3145>

From <S3331>Built-in support for email accounts, used in Settings - Accounts - Email &amp; Accounts. Icluding Live.com, Outlook, Office 365, Mail, Exchange and related.</S3331>

To <S3331>Built-in support for email accounts, used in Settings - Accounts - Email &amp; Accounts. Including Live.com, Outlook, Office 365, Mail, Exchange and related.</S3331>

From <S0886>Depends on:</S0886>

To <S0886>Depends on</S0886>

From <S1622>Too long file path detected, move the installation files to a shorted directory path and retry this step.</S1622>

To <S1622>Too long file path detected, move the installation files to a shorter directory path and retry this step.</S1622>

From <S0239>Delete selected presets?</S0239>

To <S0239>Delete selected presets</S0239>

From <S0967>Select a directory containing updates or language packs</S0967>

To S0967>Select a directory containing supported packages</S0967>

From <S2864>Run 'Remove Returns' after a reboot?</S2864

To <S2864>Run 'Remove Reinstalls' after a reboot?</S2864>

From <S0022>Add update or language packages to the list. For red marked packages, use Analyze.</S0022>

To <S0022>Add packages to the list; supports updates, languages, apps, their licenses and provisioning packs.</S0022>

From <S2509>Add to the integration queue and download only missing updates in sequence.</S2509>

To <S2509>Add to the integration queue and download missing updates in sequence.</S2509>

From <S0746>OOBE (Final install options)</S0746>

To <S0746>Final install options</S0746>

From <S1965>In order to use the DISM's /ResetBase functinality to the fullest, you must enable this option. On Windows 10 it is disabled by default, only does delta compression instead of true base reset.</S1965>

To <S1965>In order to use the DISM's /ResetBase functionality to the fullest, you must enable this option. On Windows 10 it is disabled by default, only does delta compression instead of true base reset.</S1965>

From <S3082>Delay in miliseconds between authentication attemps, increases security by slowing down brute force attacks. Set in steps of 100ms, recommended 2000ms.</S3082>

To <S3082>Delay in milliseconds between authentication attempts, increases security by slowing down brute force attacks. Set in steps of 100ms, recommended 2000ms.</S3082>

From <S3555>Hot Tracking</S3555>

To <S3555>Hot-Tracking</S3555>

Delete

<S3177>To make this image bootable on a newly patched UEFI Secure Boot machines, make sure to update it with the latest cumulative update, including the boot.wim 'Windows Setup' edition and optionally winre.wim.</S3177>

<S1417>System Apps</S1417>

<S0678>Multimedia</S0678>

<S2498>Append</S2498>

<S2523>Downloaded updates cache</S2523>

<S0599>Direct deployed image editing is for licensed version only. Applying will be disabled, try the tool on an installation image instead.</S0599>

<S0833>Previous instance of this program is already running.</S0833>

<S0974>Select update or language pack files to add</S0974>

<S2953>Extracted updates cache</S2953>

<S3556>Gradient Captions</S3556>


END PART1
 

Attachments

part 2

Add (New)

Post <S3483>

<S3750>Productivity &amp; Tools</S3750>

<S3752>API &amp; Runtime</S3752>

<S3754>Other apps</S3754>

<S3784>Entertainment &amp; Personalization</S3784>

<S3785>Audio</S3785>

<S3787>Uncategorized</S3787>

Post <S3420>

<S3690>Merge</S3690>

<S3747>Sort mounted images first</S3747>

Post <S2547>

<S3777>New instance</S3777>

<S3778>Open a new, independent NTLite instance</S3778>

Post <S2599>

<S3786>With NTLite already running, a command routes into that instance and controls it, rather than starting a throwaway process. Use /NewInstance to start a separate, independent process instead.</S3786>

Post <S3566>

<S3581>Part size (MB)</S3581>

<S3582>SWM images cannot be re-saved in place. Select a different destination.</S3582>

<S3583>FAT32 cannot store a single file of 4GB or larger. For a FAT32 bootable USB, use the Split or potentially ESD image format.</S3583>

<S3584>Re-splitting an SWM into smaller parts is not yet supported. Keep the part size at or above the source's current part size, or export to WIM or ESD instead.</S3584>

Post <S3573>

<S3743>The following updates could not be prepared. Continue integration without them, or cancel to abort:</S3743>

<S3744>Update cache</S3744>

Post <S3442>

<S3742>Resume</S3742>

<S3749>Select</S3749>

<S3753>Yesterday</S3753>

Post <S3442> à </Downloader>

<SecureBoot>

<S3580>signer could not be identified</S3580>

<S3585>Secure Boot</S3585>

<S3586>Critical</S3586>

<S3587>Signed</S3587>

<S3589>Current</S3589>

<S3590>Pending</S3590>

<S3591>Expiring</S3591>

<S3592>Ready</S3592>

<S3593>Boot Sector</S3593>

<S3594>Check host Secure Boot readiness via the C:\Windows row on the Image page.</S3594>

<S3596>Load the host Windows to manage its Secure Boot settings</S3596>

<S3597>This Windows version predates the Secure Boot certificate updates, so it cannot deploy the 2023 certificates yet.</S3597>

<S3598>Upgrade your base Windows version to a newer one that still receives updates.</S3598>

<S3599>The 2023-signed boot manager can still be applied (Boot Manager section below).</S3599>

<S3600>Boots most machines today but its certificate expires in 2026.</S3600>

<S3601>Boots only machines that already trust the 2023 certificate.</S3601>

<S3602>Service boot.wim with the same cumulative update so the install media boots where the 2023 Secure Boot revocations are enforced.</S3602>

<S3603>Boot manager 2011 is expiring and no 2023 source is available.</S3603>

<S3604>Certificate staging</S3604>

<S3605>Automatic update opt-out</S3605>

<S3606>Managed rollout opt-in</S3606>

<S3607>Device applicability check bypass</S3607>

<S3608>Refresh due to pending CU</S3608>

<S3609>Integrate the latest cumulative update.</S3609>

<S3610>Or unselect the SVN anti-rollback staging.</S3610>

<S3611>Readiness</S3611>

<S3612>Repair the Secure Boot update task</S3612>

<S3613>Deploy the Secure Boot recovery loader to the EFI partition</S3613>

<S3614>Block automatic certificate deployment</S3614>

<S3615>Opt in to the Microsoft-managed certificate rollout</S3615>

<S3616>Skip device check</S3616>

<S3617>Not staged</S3617>

<S3618>Irreversible</S3618>

<S3619>Boot manager already updated</S3619>

<S3620>Boot manager signed with the expiring 2011 certificate; update to the 2023 certificate before firmware revokes 2011 (optional until then).</S3620>

<S3621>No certificate update staged.</S3621>

<S3622>Stages the 2023 certificate for deployment on first boot (reversible); the existing 2011 boot manager keeps working.</S3622>

<S3623>Stages the 2023 certificate deployment; the Secure-Boot-Update servicing task applies one step per run (reversible until applied).</S3623>

<S3624>2011-signed boot managers and media cannot boot on a host this gets fully deployed to.</S3624>

<S3625>Clears the staged certificate deployment.</S3625>

<S3626>Windows Update will not auto-deploy the 2023 certificates.</S3626>

<S3627>Microsoft schedules the deployment via its controlled rollout (requires telemetry; not applicable to Server).</S3627>

<S3628>Forces the certificate update to proceed on firmware the applicability check would otherwise hold back (Arm64/Qualcomm known-issue block) - set only when you know the firmware is fixed.</S3628>

<S3629>Recreate or re-enable the Secure Boot update task so the staged certificate migration can continue. A disabled or deleted task permanently stalls it. This repairs the task; it does not run it (the deployment applies on later restarts).</S3629>

<S3630>Copies securebootrecovery.efi onto this disk's EFI partition fallback loader (\EFI\Boot), so the 2023 certificate is re-applied automatically if the firmware Secure Boot settings are later reset. The previous loader is backed up first as a .bak copy beside it. Note: Microsoft's documented method is a one-time boot from a USB recovery drive; if the fallback path holds a non-Windows loader (such as a dual-boot GRUB or shim), it is replaced.</S3630>

<S3631>Also raises the boot manager's minimum Security Version Number (anti-rollback).

Update ALL bootable media for the machine FIRST: firmware then refuses lower-SVN boot managers, so older recovery drives and install media stop booting.</S3631>

<S3632>Deploy only to machines that already trust the 2023 certificate.</S3632>

<S3633>Stage the irreversible setting?</S3633>

<S3634>a non-Windows certificate authority</S3634>

<S3635>non-Windows signer</S3635>

<S3636>unrecognized signer</S3636>

<S3637>Windows Boot Manager</S3637>

<S3638>Windows OS Loader</S3638>

<S3639>Windows Resume Loader</S3639>

<S3640>present,</S3640>

<S3641>present, but its embedded signature is missing or untrusted.</S3641>

<S3642>present, but its hash is revoked by the Secure Boot revocation list (dbx).</S3642>

<S3643>Embedded signature</S3643>

<S3644>valid</S3644>

<S3645>missing or untrusted</S3645>

<S3646>File hash</S3646>

<S3647>revoked</S3647>

<S3648>not revoked</S3648>

<S3649>blocked by Secure Boot</S3649>

<S3650>All 2023 certificates staged for deployment</S3650>

<S3651>Certificate deployment complete (0x4000); all deployable bits cleared.</S3651>

<S3652>All 2023 certificates staged with PCA 2011 dbx revocation</S3652>

<S3653>All 2023 certificates staged with the SVN anti-rollback increment</S3653>

<S3654>PCA 2011 dbx revocation staged alongside the certificate update.</S3654>

<S3655>Certificate deployment partially applied; remaining steps are queued and apply over future boots, paced by Microsoft's staged rollout.</S3655>

<S3656>applies on next boots</S3656>

<S3657>Secure Boot update payload present</S3657>

<S3658>minimum boot SVNs:</S3658>

<S3659>unknown component</S3659>

<S3660>The image's boot manager security version</S3660>

<S3661>is below the minimum the image's own Secure Boot update payload publishes</S3661>

<S3662>once those minimums are applied to firmware, media booting this manager will be refused.</S3662>

<S3663>A boot manager is available in the image to deploy to the output media</S3663>

<S3664>is queued for removal; the 2023 certificate migration will not run on the deployed image.</S3664>

<S3665>boot sector present on the media.</S3665>

<S3666>Legacy boot sector on the media.</S3666>

<S3667>Not active</S3667>

<S3668>unreadable</S3668>

<S3669>Staged only - clearing the staged value fully cancels the certificate deployment.</S3669>

<S3670>Partially applied - remaining bits can be cleared, but certificates already written to firmware NVRAM stay; only a firmware reset removes them.</S3670>

<S3671>Firmware committed - image registry changes cannot undo certificates already in firmware NVRAM.</S3671>

<S3672>dbx revocation staged - do NOT roll back the boot manager; the old one is revoked and the system will not boot.</S3672>

<S3673>This Windows version does not receive the 2023 Secure Boot certificate update support.</S3673>

<S3674>If a machine no longer boots its media: temporarily disable Secure Boot in firmware (no signature checks run while off), update the media, then re-enable it. BitLocker note: the change makes the existing OS volume prompt for its recovery key once.</S3674>

<S3675>Certificates</S3675>

<S3676>not trusted</S3676>

<S3677>Without the 2023 KEK the firmware cannot receive 2023-signed certificate updates.</S3677>

<S3678>Full 2023 migration optional until the 2011 certificates expire (June/October 2026).</S3678>

<S3679>Apply the certificate update before the 2011 certificates expire (June/October 2026), or this PC may stop booting updated media.</S3679>

<S3680>Setup Mode - Secure Boot is not enforcing.</S3680>

<S3681>No boot signer is trusted: the 2011 certificate is revoked and the 2023 certificate is not trusted, which can prevent this PC from booting.</S3681>

<S3682>Deploy all image files, not just install.wim - the boot manager sits outside it.</S3682>

<S3683>not present</S3683>

<S3684>Summary</S3684>

<S3685>Secure Boot is fully migrated to the 2023 certificates. No action needed.</S3685>

<S3686>This image is ready for 2023 Secure Boot. No action needed.</S3686>

<S3687>Secure Boot is using the 2023 certificate. No action needed. The 2011 certificate is still trusted; revoking it is optional.</S3687>

<S3688>Host dependent</S3688>

<S3689>Update Secure Boot certificates</S3689>

<S3693>certificate added to the firmware db</S3693>

<S3694>dbx revocation applied</S3694>

<S3695>Firmware handoff error</S3695>

<S3696>Firmware update error code logged</S3696>

<S3697>Boot manager applied</S3697>

<S3698>Reboot pending - normal mid-migration state</S3698>

<S3699>Certificates available, not yet applied</S3699>

<S3700>Paused: known firmware issue</S3700>

<S3701>Matching KEK not found - OEM firmware update needed</S3701>

<S3702>Certificate deployment complete</S3702>

<S3703>Stuck at KEK step: the OEM-signed KEK is missing (event 1803). Needs an OEM firmware or virtualization-platform update.</S3703>


END PART 2
 

PART 3

<S3704>No progress from the staged value: firmware handoff error (event 1795). Check the event log; an OEM firmware update may be needed.</S3704>

<S3705>Awaiting reboot: the 2023-signed boot manager is staged (event 1800). Restart to complete - not an error state.</S3705>

<S3706>KEK update rejected by firmware (e.g. VMware ESXi older than 8.0.2).</S3706>

<S3707>Not available</S3707>

<S3708>User mode</S3708>

<S3709>Third-party</S3709>

<S3710>entries</S3710>

<S3711>Servicing task</S3711>

<S3712>Last run</S3712>

<S3713>Result</S3713>

<S3714>success</S3714>

<S3715>2023 enrolled; still booting 2011 until the servicing task activates it.</S3715>

<S3716>contradicts the registry migration state above</S3716>

<S3717>Expires October 2026.</S3717>

<S3718>Expires June 2026.</S3718>

<S3719>Lets the firmware receive signed certificate-store updates</S3719>

<S3720>The certificate migration cannot progress until the task is running.</S3720>

<S3722>runs at startup and on Windows' schedule, applying one staged certificate step per run.</S3722>

<S3723> Has not run yet (waiting for the next startup or scheduled run).</S3723>

<S3724>EFI - Partition</S3724>

<S3725>Certificates the firmware trusts to boot</S3725>

<S3726>Certificates the firmware refuses to boot</S3726>

<S3727>Auto-update deferred until</S3727>

<S3728>Microsoft rollout pacing</S3728>

<S3729>Device</S3729>

<S3730>firmware</S3730>

<S3731>Open</S3731>

<S3732>Deploy certificate</S3732>

<S3733>Revoke</S3733>

<S3734>Anti-rollback</S3734>

<S3735>signed by</S3735>

<S3736>Certificate migration</S3736>

<S3737>step(s) remaining</S3737>

<S3738>Each remaining step is applied by the scheduled Secure Boot update task on a later run.</S3738>

<S3739>Restart once, then wait - it continues automatically, paced by Windows.</S3739>

<S3740>2023 Secure Boot certificate deployment is staged - it applies on the next restart.</S3740>

<S3741>Bypassing the device applicability check together with an irreversible revocation risks leaving incompatible hardware unable to boot.</S3741>

<S3745>Microsoft's 2011 Secure Boot certificates are expiring: the KEK CA 2011 and UEFI CA 2011 in June 2026, the Windows Production PCA 2011 in October 2026. Deploy the 2023 certificate set (KB5062710) before then.</S3745>

<S3746>Third-party bootloaders and option ROMs stop loading when the 2011 CA expires in June 2026.</S3746>

<S3748>Secure Boot certificate staging is queued, but this image's Secure Boot update payload is incomplete - the migration will probably fail. Restore the payload from an original, updated image, and do not remove Secure Boot components.</S3748>

<S3779>Updated</S3779>

<S3780>Disabling the Secure Boot servicing task halts the certificate migration on this host. Disable it?</S3780>

<S3781>Allowed Signatures</S3781>

<S3782>Revoked Signatures</S3782>

<S3783>CAUTION, if the deployed machine already has CVE-2023-24932 Boot Manager revocations enabled, removing this might make the image unbootable.</S3783>

</SecureBoot>

Post <S3572>

<S3588>Unsupported machine ID, please contact support.</S3588>

Post <S3464>

<S3691>Use only if the pre-defined Input locale options do not cover your needs.</S3691>

<S3692>Use the same localization for Windows Setup as for the installed Windows (OOBE). Turn off to configure the Setup-phase language separately.</S3692>

Post <S3571>

<S3574>Background dimming</S3574>

<S3575>Wallpaper dim level behind the modern Alt-Tab grid (0-100). Higher is darker.</S3575>

<S3576>Grid opacity</S3576>

<S3577>Opacity of the modern Alt-Tab grid panel (0-100). Higher is more solid, lower more transparent.</S3577>

<S3578>Icon cache</S3578>

<S3579>Maximum number of icons Explorer keeps cached. Windows uses 500 when unset; a higher value reduces icon re-fetching and flicker.</S3579>

<S3595>Security warnings when launching unsigned RDP files</S3595>

The Italian file is also aligned with 2026.06.11200

 

Attachments

Back
Top