Can't Boot From Bootable CD -- Bios Set Correctly

Anonymous
2015-11-02T05:57:29+00:00

I am trying for the first time to boot my Windows 8.1 laptop from the internal CD-DVD drive. I have a bootable CD in there, and yes, I do have the bios set with CDROM drive as first in the list to boot from. But when I try to boot from the CD, it won't boot, instead the computer gives me this message:

"ATAPI CDROM has been blocked by the current security policy."

(Its actually a DVD drive.) All it lets me do at that message is hit the Enter key to OK the message, and then it boots from the hard drive.

I have no idea where "security policy" settings are or what they are set for. What do I have to do to get this to boot?

This is a Gateway laptop, 2.2 MHz Intel Pentium processor, 4 GB RAM, 64 bit OS, with Windows 8.1 fully updated, and Windows Defender running and fully updated.

I have already looked everywhere I can find, but nothing seems to address this message or issue, as follows:

*I went to Help menu to look up "Security Policy." While the computer is giving me the message about "security policy," the Help menu has no idea what "security policy" is, it just comes up blank!

*I went to Control Panels/System and Security/Action Center/Change Windows Settings/Smart Screen/... All I found in there that might be involved is a setting to block anything downloaded from the Internet until I give administrator access. Well, the booting issue didn't allow me to give administrator access (yes, I am the administrator) when I tried to boot, I only could hit the enter key to OK. Nonetheless, I changed to: notify me but proceed (not a quote).

With that, I tried again, but it still would not boot from the CD, got the same message, so that setting is not it. I changed the setting back.

I see no other setting there that could be related by even a stretch. And the control panels should be dealing with the OS anyway, and this is happening while trying to boot from the OS on the CD, not the hard drive. That is, this is something in the root.

*I then went into bios area (UEFI Firmware) by sweeping in from the right and into Settings/Change PC settings ..., and found a tab in bios for Security. Looking there, there is a list of things, but it lets me access only "Supervisor Password." It was currently set as "clear," meaning no password. I left it as that -- surely I can't need a password just to boot from a CD, and the message I got in trying to boot from the CD did not allow me to enter a password.

Other settings in the Security tab were not accessible. The only ones they included that might be remotely related were:

*Password on Boot, which was set as no password. But again, the message I get with this issue does not ask for nor allow me to enter a password.

*Secure Boot Mode: Standard (It does not let me access to change that.)

Some others also were in the list that are not worth listing, not even vaguely related.

I then went into some other things elsewhere in the main settings called Startup Settings. The only thing in there that sounded the least bit vaguely related was "Enable boot logging." I punched F2 to go into that, but the machine instead restarted, and did not start from the CDROM, same message again. I went back to it, and it is still listed as Enable boot logging, does not instead say Disable - so I don't know if anything even got changed. I did not touch it again, left it as-is.

So, that's it. I've checked all the settings I know about. Nothing about this bit about "ATAPI CDROM has been blocked by current security policy."

I tested with two DVDs that I have booted from in the past on other Windows machines -- they also would not boot, but they did not give me that message.

I note, all three CDs/DVDs are being read fine by the DVD drive once the machine is booted in Windows 8.1 from the hard drive - so the issue is not that the DVD drive can't read the disks.

Where is this "security policy" set?! What do I need to do to get this to boot from the CD?

Windows for home | Previous Windows versions | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2016-08-24T15:35:47+00:00

Hi,

So everything is back to normal... or at least working to your satisfaction ?

You seem to know more about manipulating your email than I do, but though I may be able to help by describing what my screen looks like !

I know how that kind of conversation goes... Not so much with Microsoft, but with my internet provider sometimes..

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments

596 additional answers

Sort by: Newest
  1. Anonymous
    2016-08-23T02:56:44+00:00

    Yes, you will recall, I had to learn about that UEFI stuff. In order to boot from USB or from a DVD, I have to first go to bios, switch to Legacy, and then proceed with the boot. And then I have to switchback to UEFI to boot my internal hard drive. So, if I were to install from a DVD, I have to go to Legacy to boot that disk, so would be installing from Legacy.

    Are you saying if I did a clean install from DVD, so in Legacy mode, it might install it in Legacy, not in UEFI, even to a GPT disk? Its academic at this point anyway.

    Win 8.1 and 10 are formatting the flash drive as only FAT32? That's an older format, they specifically made NTFS for some reason that it was better. But FAT32 is the normal format for a flash drive, although that can take other formats. Mac can read FAT, but not NTFS. There's also a Mac format that can be used, whatever it might be called. but Windows can't read that. So FAT is used if you want it to be readable on both Mac or Windows, and so that's what they put on a flash drive, so it can be used by both. However, a Windows installation media is not of any use on a Mac! So why put that format on the flash drive for it. Actually, maybe the creation tool is not putting that formation on, maybe if you pre-formatted it as NTFS it would just use that. I wonder. Again, just academic.

    Yes, I now not all those partitions are for the UEFI. Without looking, I think only one or two of them are. But I had read that UEFI requires a GPT disk -- I think I read that somewhere at MS, not just somewhere else on the Web. But you have proven otherwise. Yes, UEFI requires GPT, but more than four partitions also requires GPT.

    Re the imaging, I did mine in Acronis (probably should do a newer one at some point). But that is another thing the recovery drive could be used for, to recover an image done with Windows -- it has that imaging software on it.

    I wasn't talking of a Recovery drive making a restore point, I was talking of when that is made, take a restore point from the internal drive and have it in there on the recovery drive for use. It otherwise does not let you access those restore points, and you have nothing but restore software that can be used.

    You finally said why not to use the Windows imaging: you have found it unreliable. I found the same with a function in Mac that clones the drive, (they have a stupid name for it instead of clone, and most people don't even know what it is for). But it was quite unreliable, so I found a very excellent third party cloning software,

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2016-08-23T02:16:34+00:00

    Hi,

    The UEFI is not a requirement, but there are a small number of features that work better\faster with UEFI... Primarily the boot time..

    The type of installation media makes a difference because it requires a certain type of formatting of the Flash Drive to boot with\into UEFI Bios...

    The exact method varies with who wrote the BIOS, but if you were to make a Flash Drive with the Win 7 USB\DVD Tool and tried to boot with it in a UEFI machine, it probably wouldn't boot... And if it did boot, probably wouldn't install... 

    The same type of thing applies with the Win 8.1\10 Create Media Tool. except the opposite.. It will not boot with LEGACY Bios, and\or will not install..

    A DVD may or may not work to install into UEFI Bios, but works great with Legacy...

    The difference in the media amounts to the file format of the flash drive...

    The Win 7 USB\DVD Tool formats the drive as NTFS, which works with Legacy...

    The Win 8.1\10 Create Media Tool formats the drive as FAT32, and this is required for UEFI, but won't work with Legacy...

    At one time when Win 8\8.1 were first released, the Create Media Tool didn't create a FAT32 flash drive, and thousands of people (or more) couldn't get windows to install as a result... A 3rd party tool was required to create a flash drive that would work...

    As far as the number of partitions goes... A UEFI machine can get by with less than six partitions... At least one of yours is provided by Gateway, and it is not needed for windows to function...

    Windows in UEFI really only needs two partitions, but a default installation usually creates at least three...

    UEFI requires a GPT drive for the boot drive regardless of the number of partitions...

    As far as when Restore Points are made... I believe that they are only created when windows changes a setting or file of some type... and that wouldn't apply to a Recovery Drive, but maybe...

    Other programs can create restore points independently of windows, in the same way you can create one manually... The installer simply has the command to create a restore point built into it by the author..

    In reality... the only thing that is going to save your bacon in the event of a serious crash, or something like a hard drive failure, is a system image... preferably by Acronis or someone similar... I wouldn't even count on Microsoft's Imaging Tool...

    I have found the windows stuff to just be too unreliable over the years... When it works, it's great... But finding out it DOESN'T work at a inopportune time can be a serious disaster...

    I think you are beginning to get a taste of that...

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2016-08-23T01:22:57+00:00

    By the 15 GB partition, you're talking about that one of mine we dealt with. Actually, it originally was 16 GB -- but it was not full, and I moved a little space over to make the primary partition a bit larger -- I kept getting those messages that there was not enough room. I'm sure you recall that and all the guessing we were doing because of it. (I just checked it. It is now 15.76 GB).

    Yes, I understood what you were talking about. I just thought calling those "versions" was correct.

    Yes, that is all I was left with, do a Recovery or a clean install, and I'm afraid the Recovery might be basically a clean install but using that older recover very  stuff, or otherwise kill files I want. A Recovery is more than a Restore. They offer the Restore function, but as I have explained, you don't have access to any Restore points. So, command lines might be all it offers other than to completely re-do all. (I don't recall, I think I tried running chkdsk, but I think it hung up, would not do it. Or maybe it just ran, but the booting issue remained.)

    Considering what I was looking at yesterday about the actual size of the restore points, they should take one when they make this repair drive, it is very little space, MB size. I think that's a real oversight.

    OK on the UEFI. In addition to the motherboard, it would be considering how many partitions. Mine has 6, so needs UEFI (or was it 6 partitions required GPT. One or the other or both.) Well, I don't see why the "type" of installation media would determine that. I think it might be the motherboard, yes. You're running Win 10 in Legacy - OK, if that works, it works; still, I had read that Win 8 and up requires UEFI -- but again, you have proven that wrong. As I have said so many time, there is so much very poor writing by MS.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2016-08-23T00:43:31+00:00

    Hi,

    I suppose that under some circumstances with machines running preinstalled windows...

    AND having a Factory Recovery Partition... The one around 15GB... that the Factory Recovery Partition may be recognized as Windows Installation Files, and included in the Recovery Drive to enable Restoring To Factory Condition...

    I wasn't talking about different versions of windows actually... I was comparing a 32bit installation ISO to a 64bit installation ISO... There are size differences between the Home and Pro as well... With every build the file size is getting larger...

    Another factor may be whether the install files are a .WIM file, or a .ESD file...

    A .ESD file is about 2.5GB as compared to 3.5GB for the exact same installer that is a .WIM file... Which is on your machine is determined by how the ISO was obtained...

    My experience with a Recovery Flash Drive and it's function, is that it simply\basically, does a Clean Install of Windows, and gives the option to simply delete the old OS and overwrite it, or to WIPE the drive before reinstalling...

    Either way, all your stuff is gone...

    As I mentioned, it may function differently if you have a Factory Recovery Partition on your hard drive...

    BTW... My machine is UEFI capable, but I run it in Legacy Mode...

    How windows and\or my motherboard configures the install is determined by the type of  type of installation media...

    Of course the proper type of hard drive probably needs to be present, but I suppose it could reformat the drive to GPT or MBR as needed automatically...

    I normally format my drives MBR, but the drives over 2TB need to be GPT to use the space over the 2TB, of which I have several...

    In my case it's not because of the number of partitions, but the way I switch between Win 7, 8, and 10 by reloading images... It's just too much trouble to try and jump through all the hoops required to do it with UEFI Bios...

    Was this answer helpful?

    0 comments No comments