Secure Boot Rollout Fails on HP, Dell, ASUS, and MSI PCs
Windows 11 Secure Boot 2023 rollout problems continue to affect PCs from HP, Dell, ASUS, MSI, ASRock, and other manufacturers.
Microsoft held an OEM Secure Boot Office Hours event on July 15 to discuss the transition from older Secure Boot certificates to the newer 2023 certificates. Representatives from major PC manufacturers attended the session, according to Windows Latest.
Administrators reported unresolved firmware, certificate, registry, and BitLocker issues. Some devices still fail to complete the rollout even when IT teams follow Microsoft and OEM instructions.
Secure Boot Problems Affect Multiple PC Manufacturers
The deployment problems do not appear limited to one manufacturer.
Some ASUS systems required administrators to temporarily disable Secure Boot before installing revocation updates. Certain MSI devices ignored certificate updates despite reporting that Secure Boot was enabled.
ASRock computers sometimes required administrators to reset Secure Boot keys manually and enroll the certificates again.
Dell, HP, and Lenovo systems generally performed better during earlier testing. However, administrators still encountered BIOS dependencies, delayed deployments, repeated restarts, and inconsistent certificate states.
These differences suggest that firmware implementation plays a major role in whether a PC can complete the Secure Boot transition successfully.
HP Devices Enter BitLocker Recovery Loops
An administrator responsible for more than 7,000 HP EliteBooks and ZBooks reported repeated BitLocker recovery prompts after forcing the certificate deployment.
The same problem occurred after the administrator followed HP’s official BIOS guidance. The affected computers already had current BIOS versions installed.
Testing on an HP EliteBook 640 G10 showed that rolling back to an older BIOS stopped the BitLocker recovery prompts.
Microsoft and HP did not confirm the cause or provide a permanent solution before the Office Hours session ended.
Older HP PCs Face Certificate Storage Limits
Some older HP devices reportedly remain stuck in an “Under Observation – More Data Needed” rollout state.
Certain systems only moved forward after receiving newer BIOS updates. However, those updates did not always prevent BitLocker recovery problems.
Administrators also reported that HP removed some older models from its supported-device list because their NVRAM lacked enough space for the new certificates.
Affected customers questioned why HP could not provide a permanent BIOS update for these systems. Devices with limited firmware storage may never support the full Secure Boot certificate package.
Secure Boot Status May Appear Incorrect
Some Windows 11 devices show “Secure Boot Status = Unknown” even when the 2023 certificates have already installed successfully.
These computers may also have Secure Boot enabled and a functioning Trusted Platform Module.
Microsoft recommended running the Get-SecureBootRolloutStatus.ps1 script to obtain more detailed certificate and rollout information.
However, the company did not provide a clear explanation for why Windows reports an unknown status on otherwise properly configured systems.
KEK Updates Continue to Fail on HP EliteBooks
One administrator reported problems across approximately 700 HP EliteBook G9 and G10 devices.
The Secure Boot database certificates installed successfully, but the Key Exchange Key, or KEK, failed to update. After each reboot, the KEK deployment status returned to “Not Started.”
HP recommended installing the latest BIOS and forcing the update through Windows registry settings.
Testing with the newest BIOS did not fix the issue.
Microsoft may have intentionally blocked the rollout on these devices because of known compatibility problems involving specific firmware configurations.
Dell OptiPlex Systems Also Show Problems
One Dell administrator reported that most devices in the company’s fleet received the new certificates successfully.
However, some OptiPlex 5000 systems refused to update the required Windows registry key.
No Dell representative provided an answer during the session. Questions about HP’s NVRAM limitations and BitLocker recovery problems also remained unanswered.
Dell has taken a cautious approach on newer hardware by including both the older and newer Secure Boot certificates. This may reduce compatibility risks during the transition.
Firmware Differences Complicate the Secure Boot Rollout
The Secure Boot 2023 certificate transition has exposed major differences between UEFI implementations from PC manufacturers.
A process that works on one device model may fail on another model from the same manufacturer. BIOS versions, NVRAM capacity, registry settings, BitLocker configuration, and existing certificate states can all affect the rollout.
HP and Dell customers reported several of the most significant problems during the July 15 session.
HP has also faced multiple rounds of BitLocker complaints, including on BIOS versions released to address earlier Secure Boot issues.
What IT Administrators Should Do
IT teams should test the Secure Boot certificate updates on representative hardware before deploying them across an entire organization.
Administrators should also back up BitLocker recovery keys before changing BIOS settings, Secure Boot keys, or rollout-related registry values.
Microsoft’s diagnostic scripts can provide more reliable information when the Windows Secure Boot status does not match the certificates installed on the device.
IT teams should review advisories from each PC manufacturer instead of relying only on Microsoft’s general deployment guidance.
Microsoft May Be Blocking Some Devices
Microsoft has paused the Secure Boot certificate rollout on certain device and firmware combinations with known compatibility problems.
A PC that has not received the update may therefore face an intentional safeguard hold rather than a deployment failure.
Microsoft and its hardware partners continue to investigate affected systems and develop firmware or deployment fixes.
In related news, Windows 11 may restart twice while installing the July 2026 Patch Tuesday updates, particularly when separate .NET Framework or Secure Boot updates require their own reboot.
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages