Windows, at least for right now, does not seem to be updating CPU microcode during boot. If you run the PowerShell Get-SpeculationControl script that gives you the status of the updates it states that the CVE-2017-5715 fix requires hardware support. If you don't have it you are told to get a BIOS update from your OEM. WIthout it, the status for CVE-2017-5715 is listed as not enabled due to missing hardware support.
Of all of my computers only one has been issued a BIOS update so far. I ran the PowerShell script before and after installing the BIOS. Installing the BIOS flipped the status of the fix for CVE-2017-5715 to on.
I also ran the free HwInfo utility that will show the microcode revision before and after installing the Windows update and before and after installing the BIOS. It only ever changed with the BIOS update.
I hope this changes and Windows does start updating CPU microcode. I also have a few older motherboard's that aren't likely to ever see a BIOS update again.
This appears to be my experience too. I'm checking a few VMs and they are showing as missing hw support.
Do note that Microsoft appears to have updated their doc in the last day or so. They are now saying that three registry settings need to be set (instead of 2 previously).
Of all of my computers only one has been issued a BIOS update so far. I ran the PowerShell script before and after installing the BIOS. Installing the BIOS flipped the status of the fix for CVE-2017-5715 to on.
I also ran the free HwInfo utility that will show the microcode revision before and after installing the Windows update and before and after installing the BIOS. It only ever changed with the BIOS update.
I hope this changes and Windows does start updating CPU microcode. I also have a few older motherboard's that aren't likely to ever see a BIOS update again.