Surface Pro 3 missing PK-signed key Exchange Key

Gordon Currie 21 Reputation points
2026-07-11T21:26:09.6233333+00:00

I have a Surface Pro 3 that is booting under TPM 2.0 and Secure Boot.

I saw this alert in Event Viewer event id 1803:

A PK-signed Key Exchange Key (KEK) cannot be found for this device. Check with the device manufacturer for proper key provisioning.

This device signature information is included here.

DeviceAttributes: FirmwareManufacturer:American Megatrends Inc.;FirmwareVersion:3.11.2650;OEMModelNumber:Surface Pro 3;OEMManufacturerName:Microsoft Corporation;OSArchitecture:amd64;

BucketId: 416f1d3669071b8d06d082332d4acbf2434291c7b4b4222df75bfdffccdb2115

BucketConfidenceLevel: Under Observation - More Data Needed.

For more information, please see https://go.microsoft.com/fwlink/?linkid=2339472


Since the manufacturer is Microsoft, exactly how do I proceed?

Surface | Surface Pro | Safety and security
0 comments No comments

Answer accepted by question author
S.Sengupta 32,021 Reputation points MVP Volunteer Moderator
2026-07-12T00:46:18.0466667+00:00

Unfortunately, none fix is available. This isn't a config issue on your end — there's no manual enrollment path without the OEM-signed KEK, and Microsoft won't be issuing one for this model.

If all of these are true:

Secure Boot = On

Windows boots normally

BitLocker works

TPM works

No Event ID 1795/1796/1797 Secure Boot failures

No boot errors

Then event 1803 is generally considered informational and can often be ignored. Similar events have appeared on older systems as Microsoft introduced newer Secure Boot certificate updates.

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.