i cant turn on secure boot to active

izatking 0 Reputation points
2026-09-20T07:24:37.46+00:00

Screenshot_2026-09-19-01-23-14-176_com.google.android.googlequicksearchbox

Windows for home | Windows 11 | Performance and system failures
0 comments No comments

2 answers

Sort by: Most helpful
  1. AI answer

    2026-09-20T07:25:02.1733333+00:00

    The error in the screenshot matches a Secure Boot certificate trust problem: “Secure Boot Violation – Invalid signature detected.” Since Windows starts when Secure Boot is disabled, the practical recovery path is:

    1. Disable Secure Boot temporarily in BIOS/UEFI so Windows can boot.
    2. If the BIOS has it, reset Secure Boot settings / restore factory defaults for Secure Boot.
    3. After Windows starts, check the PC or motherboard manufacturer’s support site for a BIOS/UEFI firmware update and install it before turning Secure Boot back on.
    4. Then re-enter BIOS/UEFI and enable Secure Boot again.

    If the problem started after resetting Secure Boot to firmware defaults, the firmware may have removed the certificate needed to trust the current Windows boot manager. In that case, use the Secure Boot recovery utility:

    1. On a second Windows PC with the July 2024 or newer Windows update installed, copy SecureBootRecovery.efi from C:\Windows\Boot\EFI\.
    2. Put it on a FAT32 USB drive in \EFI\BOOT\.
    3. Rename the file to bootx64.efi.
    4. Boot the affected PC from that USB drive and let the recovery utility run.
    5. After restart, try enabling Secure Boot again.

    Important: BIOS/UEFI reset and Secure Boot changes can make the PC unbootable until the certificate trust is restored. If the device still fails after resetting Secure Boot settings, recovery likely requires OEM-specific guidance from the PC or motherboard manufacturer.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

    1 person found this answer helpful.
  2. DaveM121 935.7K Reputation points Independent Advisor
    2026-09-20T08:00:42.99+00:00

    1

    If you are unable to get into Windows due to that error, boot your system into BIOS, disable Secure Boot, are you then able to boot into Windows?

    2

    If so, boot your system into BIOS, on the Security settings, find the setting to Restore Factory Keys or Install Default Secure Boot Keys, save that setting, then restart your PC to test if Windows will boot up normally.

    3

    If not, go to the support page for your PC or motherboard to check for any BIOS update that may be available and not yet installed.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.