I have been doing application testing on the Surface 4/W10 for two weeks and had this exact problem. When I first received the machine, I turned off Secure Boot and TPM in BIOS/Setup, (habit I guess).
Turning both Secure Boot and TPM back on, and installing the latest firmware update solved the problem.
The Surface was able to apply the firmware updates, and restart properly. All device drivers are applied, and devices are enabled.
The firmware updates apparently assume that Secure Boot and TPM are in the out of box state to be successful.
Just sharing...