To recover from the Secure Boot Violation and stop having to disable Secure Boot, follow these steps in order.
- Boot by temporarily disabling Secure Boot
- Enter the firmware/BIOS menu while the device starts (keys like F1, F2, F12, or Esc, depending on the device).
- Locate the Secure Boot setting (usually under Security, Boot, or Authentication) and set it to Disabled.
- Save changes and restart so Windows can boot.
- Install the fixed/re-released update
The Secure Boot Violation after an update is a known issue on some devices when firmware cannot handle newer bootloader signatures. The documented workaround is:
- With Secure Boot disabled, boot into Windows.
- Install the re-release (fixed version) of the problematic update from Windows Update (or as provided by Microsoft for that issue).
- After the updated boot loader is installed, restart Windows normally.
- Re-enable Secure Boot correctly Once Windows is booting normally with the updated boot loader:
- Uninstall any graphics cards, hardware, or operating systems that are not compatible with Secure Boot, if present.
- Open the PC BIOS/UEFI menu:
- Either press F1/F2/F12/Esc during startup, or
- From Windows, hold Shift while selecting Restart, then go to Troubleshoot > Advanced Options > UEFI Firmware Settings.
- Find Secure Boot and set it to Enabled.
- If there is a Custom option, load the factory Secure Boot keys that are built into the PC.
- If Secure Boot cannot be enabled, reset BIOS/UEFI to factory defaults and try again.
- Save changes and exit so the PC reboots.
- If the PC fails to boot after enabling Secure Boot, go back into BIOS, disable Secure Boot again, and boot Windows. In that case, contact the device manufacturer for firmware assistance.
- If the device will not start at all after certificates/updates For devices that fail to start after Secure Boot–related certificate updates:
- Disable Secure Boot through the firmware/BIOS menu (same steps as above) so the device can start.
- After booting, follow Microsoft’s guidance for Secure Boot revocation/certificate updates and ensure all required updates are installed.
- Re-enable Secure Boot as described above.
- Insider Program and future stability The context provided focuses on fixing Secure Boot and boot issues. For Insider builds that cause boot failures, the supported path is to:
- Recover the device (as above) so it can boot.
- Then follow Microsoft’s standard guidance (outside this context) to move off Insider builds to a stable channel.
If, after these steps, Secure Boot still cannot be enabled without a violation error, the documented next step is to work with the device manufacturer, as firmware limitations or bugs can prevent Secure Boot from accepting updated bootloader signatures.
References:
- Disabling Secure Boot
- Re-enable Secure Boot
- TPM lockout occurs unexpectedly in Windows 8.1 or Windows RT 8.1
- Windows devices for home users, businesses, and schools with Microsoft-managed updates
- How to manage the Windows Boot Manager revocations for Secure Boot changes associated with CVE-2023-24932
- Bug Check 0x145: SECURE_BOOT_VIOLATION
- Secure boot state is still off tried alot of things - Microsoft Q&A
- Can't enable secure boot - Microsoft Q&A