NEWS
Windows 11 Secure Boot Fixes Fail HP and Dell Fleets, Microsoft Says
Microsoft’s July 15 Secure Boot Q&A resolved plenty, but HP’s BitLocker loops, a stuck KEK on 700 laptops, and dropped EliteBooks still have no fix.
Microsoft and engineers from twelve PC makers spent twelve hours on July 15 fielding Windows 11 Secure Boot certificate questions from IT admins. A good chunk of the hardest ones still have no answer. Windows Latest already published a rundown of the fixes that came out of that session, covering everything from a registry key workaround to how confidence ratings work on enterprise fleets.
This is the part of that same thread nobody has finished covering. Devices that meet every documented prerequisite are still failing, on BIOS versions that were supposed to have fixed the problem, and HP customers are describing the roughest ride of any manufacturer in the room.
The Questions Microsoft and OEMs Could Not Answer
The OEM Secure Boot Office Hours event put Microsoft engineers in the same comment thread as representatives from Acer, Asus, Cisco, Clevo, Dell, Fsas/Fujitsu, Honor, HP, Lenovo, LG, Surface, and Xiaomi, all answering live questions about the Windows 11 Secure Boot 2023 certificate rollout.
A large share of the thread got resolved. But a separate portion is admins describing certificate errors nobody at Microsoft or the OEMs could explain, or fixes that matched the official documentation exactly and still did not work on their hardware.

HP’s BitLocker Loop Outlives Its Newest BIOS
The most concerning post came from a user called epoch71, who manages more than 7,000 HP EliteBooks and ZBooks spanning generation G7 through current models. Forcing the certificate install through the AvailableUpdates registry key triggered BitLocker recovery in testing. So did following HP’s own published guidance to manually toggle the four Secure Boot BIOS settings HP documents in its support advisory.
HP had already acknowledged part of this problem. Windows Latest reported in May that a batch of April 2026 BIOS updates could corrupt the PCR7 measurements BitLocker seals its key against, forcing a recovery prompt on every reboot until the certificate handoff finishes. That did not stop it from happening again in July.
HP’s Juergen_Bayer initially told epoch71 to confirm the latest BIOS was installed and leave the new certificate settings alone, letting Windows Update handle certificate additions automatically. epoch71 pushed back: the fleet was already running the newest BIOS through HP Image Assistant, and BitLocker recovery still triggered without touching any of the settings HP had warned against changing.
Forcing certificates through the registry key on an EliteBook 640 G10 running BIOS V75 01.12.01 sent it into recovery mode every time. Reverting to the older V75 01.11.00 made the problem disappear, but rolling back BIOS versions across thousands of deployed machines is not something most IT teams can do without real disruption. Neither HP nor Microsoft had a follow-up by the time the session closed. This is a different failure than the backdoor bypasses Microsoft has spent the year patching on the BitLocker encryption side; this one starts with the certificate handoff itself.
Older EliteBooks Quietly Drop Off HP’s Support List
A user posting as Shapalapa described a similar fight on an EliteBook 840 G6. The device sat in Under Observation, More Data Needed for an extended stretch, only progressing after installing the 01.35.01 BIOS. Then it hit the same BitLocker recovery loop epoch71 described, resolved only after discovering three specific BIOS toggles were disabled by default and needed manual enabling.
Shapalapa also flagged a change to HP’s own documentation. HP’s support page originally listed 2018-and-newer devices as supported, including models like the ZBook 14u G5 and ProBook 650 G4, before those entries were quietly removed once HP determined the NVRAM on that hardware could not fit the new certificates.
an insufficient substitute for a proper BIOS fix
That is how Shapalapa described HP’s manual update package for those out-of-service devices, in the same thread. Neither HP nor Microsoft responded to the post.
Three Fleets, Three Dead Ends
Other admins hit walls of their own. salmankhan1 asked about devices reporting Secure Boot Status = Unknown despite having the 2023 certificates, an enabled Secure Boot flag, and a working TPM. Microsoft’s Prabhakar pointed to a diagnostic script for a fuller picture but never identified why the status reporting was wrong on hardware that met every prerequisite.
| Admin / Fleet | Issue Reported at the July 15 Session | Status When the Session Closed |
|---|---|---|
| salmankhan1 | Secure Boot Status reads Unknown despite 2023 certificates, an enabled flag, and a working TPM | Partial answer from Microsoft; no root cause identified |
| Checker-KP (roughly 700 HP EliteBook G9 and G10 units) | DB certificates update after setting the registry key to 0x5944, but the KEK stays stuck at Not Started | HP tried forcing 0x4 and a newer BIOS; KEK still had not updated |
| pbormet (Dell fleet) | Optiplex 5000 units refuse the registry key command that worked on the rest of the fleet | No Dell representative responded |
Checker-KP’s case dragged on the longest. HP’s Duane_Gatlin and Juergen_Bayer suggested trying 0x4 in the registry to force the KEK update directly and confirmed the latest BIOS versions for both models. Checker-KP updated one test machine to that BIOS anyway, and the KEK still had not moved. The thread ended there, with Checker-KP wondering whether those units were caught by Microsoft’s own list of known certificate issues, which does not yet cover a fix for fleets like theirs. Windows Latest reported earlier this month that Microsoft has started pausing the rollout on specific device and firmware combinations rather than let a known-broken update proceed, which may or may not explain it.
Why Is a 2023 Certificate Still Breaking PCs in 2026?
Microsoft’s original Secure Boot certificates from 2011 expire in June 2026, and the replacement 2023 certificates exist to close a boot-level flaw called BlackLotus, tracked as CVE-2023-24932. Pushing new trust certificates into firmware that manufacturers wrote years ago, on hardware some of which HP has since delisted, is what keeps producing failures nobody fully predicted.
This is not a new problem, and it is not an HP-only problem. Back in March, Windows Latest’s Ed Tittel wrote about trying to get a fleet of 10 to 15 PCs compliant with the CA-2023 certificates. ASUS boards sometimes refused the revocation list unless Secure Boot was temporarily switched off. MSI boards ignored updates on some models while the UI still showed Secure Boot as enabled. ASRock needed manual key resets and re-enrollment on almost every system, with documentation that was thin to nonexistent. Tittel’s ASRock B550 Extreme4 desktop got stuck throwing a false CPU change warning on every restart; he eventually gave up and replaced the motherboard.
Dell, HP, and Lenovo fared better in that round, though even they had staggered rollouts and BIOS updates needing more than one reboot. An OEM comparison Windows Latest published in June found Dell had shipped both the 2011 and 2023 certificates on new hardware since late 2024, the most conservative approach of any OEM tracked. HP’s rollout, by contrast, has now produced two separate rounds of BitLocker complaints spanning three months, April and again in July, with the second batch landing on BIOS versions that were supposed to have already fixed it. Windows Latest also tied HP and Dell firmware issues to wider Windows 11 reliability complaints, including BitLocker recovery prompts and boot failures that came with the June 2026 Patch Tuesday update. It would not be the first cumulative update this year to leave PCs stuck mid-reboot after a routine patch, either.
What IT Admins Can Do While Microsoft Keeps Digging
A device passing its certificate check does not guarantee the BIOS behind it is safe to update, and a fresh BIOS does not guarantee the certificate update completes cleanly. epoch71 and Checker-KP both found that out directly. Until that changes, treat the two as separate risks that happen to overlap right now.
- Pilot first. Test the certificate push on a small, representative slice of hardware before pushing it fleet-wide.
- Back up BitLocker recovery keys before changing any registry key or BIOS setting tied to Secure Boot.
- If a device’s status does not match its certificate state, run the Detect-SecureBootCertUpdateStatus.ps1 script from the ExampleRolloutScripts folder before assuming something is broken.
- Check the specific OEM advisory for the exact model rather than relying only on Microsoft’s general troubleshooting guidance.
Here is what the July 15 session actually settled, and what it left open.
- What we know: Microsoft is pausing the certificate rollout on specific device and firmware combinations rather than let a broken update proceed.
- What we know: HP’s April 2026 BIOS batch has been tied to corrupted PCR7 measurements that trigger BitLocker recovery.
- What we know: Dell has shipped both certificate sets on new hardware since late 2024, avoiding the scramble other OEMs now face.
- Unconfirmed: why EliteBook 640 G10 units fail on the newest BIOS but not the version before it.
- Unconfirmed: why roughly 700 EliteBook G9 and G10 units cannot get the KEK to update even on fresh firmware.
- Unconfirmed: why Optiplex 5000 units reject a registry command Dell’s other models accept without issue.
Microsoft’s firmware pause on affected device and model combinations is still active as of this session. Some fleets are being held back from the update on purpose, while Microsoft and its OEM partners keep working the rest of it out.
Frequently Asked Questions
What Happens if a PC Misses the Secure Boot Certificate Deadline?
Nothing catastrophic happens right away. Microsoft’s own guidance says a device that reaches the June 2026 expiration without the new certificates will keep starting and operating normally; it simply stops receiving future Secure Boot security updates until the certificates land.
How Can I Check My PC’s Secure Boot Certificate Status?
The Windows Security app shows whether a device’s Secure Boot certificates are current or whether a manufacturer firmware update is required first. IT admins managing fleets can get more detail by running Microsoft’s rollout status script instead of checking devices one at a time.
Why Does BitLocker Demand a Recovery Key After a BIOS Update?
BitLocker seals its encryption key against a measurement called PCR7, which records the state of Secure Boot components at startup. When a BIOS update changes that state unexpectedly, such as through a botched certificate handoff, BitLocker treats the machine as potentially compromised and demands the recovery key instead of unlocking silently.
What Do the DB and KEK Certificates Actually Do?
The DB, or signature database, holds the certificates that decide which boot loaders and drivers a PC trusts at startup. The KEK, or key exchange key, is what authorizes changes to that database in the first place. When a KEK update stalls, as it did for Checker-KP’s fleet, the DB updates that depend on it cannot be trusted to stick either.
What Does the AvailableUpdates Registry Key Control?
Setting the AvailableUpdates registry key to 0x5944, under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot, tells Windows to deploy the full set of 2023 certificates and update to the new signed boot manager at once. A value of 0x4 is narrower: it specifically forces the KEK update alone, which is the setting HP support staff suggested when the standard value would not budge.
-
NEWS2 months agoCall of Duty Warzone Delisted on Xbox One and PS4 June 4
-
AZURE1 month agoMicrosoft’s MAI Models Signal a Five-Year Bet on AI Independence
-
NEWS1 month agoXbox Games Showcase 2026: Start Time, Expected Games, What to Watch
-
AZURE1 month agoMicrosoft IQ Gives Enterprise AI Agents a Shared Memory
-
NEWS2 months agoMicrosoft Build 2026 Skips Windows 12 for the AI Bet That Counts
-
AZURE2 months agoAnthropic Hits $965B, and Microsoft Profits Either Way
-
MICROSOFT 3651 month agoSatya Nadella Rebukes Scout VP Over ‘Make People Addicted’ Memo
-
NEWS1 month agoModern Warfare 4 DMZ Returns with What the 2022 Beta Was Missing
