A Secure Boot violation immediately after updates is most consistent with a firmware or Secure Boot trust issue, not with the Defender, .NET, or Intel driver updates listed.
The most relevant update in the list is:
- Micro-Star International Co., Ltd. - Firmware - 1.0.0.12
The documented failure patterns are:
- Device fails to boot after a firmware change or Secure Boot state change.
- A firmware or Secure Boot error appears before Windows loads.
- Disabling Secure Boot may allow Windows to start.
Two supported paths are documented.
- If the problem started after Secure Boot settings were reset to firmware defaults
- Resetting Secure Boot defaults can clear the firmware certificate databases.
- On systems already using the newer Windows UEFI CA 2023 trust, that can remove the certificate needed to trust the installed Windows boot manager.
- Recovery method:
- On a second Windows PC with the July 2024 or newer Windows update installed, copy
SecureBootRecovery.efifromC:\Windows\Boot\EFI\. - Put it on a FAT32 USB drive under
\EFI\BOOT\. - Rename it to
bootx64.efi. - Boot the affected PC from that USB drive and let the recovery utility run.
- On a second Windows PC with the July 2024 or newer Windows update installed, copy
- After recovery, install the latest firmware from the device manufacturer.
- If the problem started immediately after the firmware/update restart
- Some UEFI firmware incorrectly overwrites the Secure Boot allowed signature database instead of appending to it.
- Documented next steps:
- Enter firmware/BIOS setup.
- Attempt to reset Secure Boot settings.
- If the PC boots after that, check the device manufacturer support site for a firmware update that corrects Secure Boot DB handling.
- Install that firmware update before re-enabling Secure Boot and reapplying Secure Boot certificate updates.
- If resetting Secure Boot does not restore boot functionality, further recovery likely requires OEM-specific guidance.
Important risk note:
- Resetting Secure Boot to firmware defaults can itself cause boot failure on some devices by clearing required trust certificates.
- If Windows currently boots only with Secure Boot disabled, avoid repeated Secure Boot resets unless following the documented recovery path.
Based on the update list alone, the MSI firmware update is the strongest suspect. The practical next step is:
- Test whether the system boots with Secure Boot disabled.
- In BIOS/UEFI, try a Secure Boot reset only once as a recovery step.
- If that does not fix it, use the Secure Boot recovery utility from USB.
- Then install the newest MSI firmware that addresses Secure Boot behavior.
References: