Microsoft recently convened an OEM Secure Boot Office Hours event, where engineers from the tech giant collaborated with representatives from various manufacturers, including Acer, Asus, Dell, and HP, to address concerns surrounding the Windows 11 Secure Boot 2023 certificate rollout. Despite the gathering aimed at providing clarity and solutions, many IT administrators left with unresolved issues, particularly regarding Secure Boot certificate errors that neither Microsoft nor the OEMs could adequately explain.
In a detailed analysis by Windows Latest, it was revealed that while some technical fixes were discussed, a significant number of participants reported persistent problems. These included instances where the official documentation suggested solutions that ultimately failed to apply to their specific hardware configurations.
Ed Tittel, a contributor to Windows Latest, shared his own experience from March, highlighting the challenges faced while attempting to bring a small fleet of PCs into compliance with the CA-2023 certificates. His findings indicated that the issues were not isolated to Microsoft but rather indicative of broader industry challenges. For example, ASUS motherboards sometimes required Secure Boot to be disabled temporarily to apply the revocation list, while MSI models exhibited erratic behavior, ignoring updates despite showing Secure Boot as enabled. ASRock systems necessitated manual key resets and re-enrollment, with scant documentation available to guide users through the process. In contrast, devices from Dell, HP, and Lenovo showed comparatively better performance, although they too experienced staggered rollouts and required multiple reboots for BIOS updates.
Where Windows 11 Secure Boot certificate deployment is still breaking for IT admins
During the event, several IT administrators voiced concerns about issues that remained unexplained by Microsoft or the relevant OEMs. Here are some notable challenges:
HP’s BitLocker recovery loop persists even on the latest BIOS
One of the most alarming reports came from an administrator managing over 7,000 HP EliteBooks and ZBooks. They noted that forcing the certificate installation through the AvailableUpdates registry key led to a BitLocker recovery prompt, regardless of following HP’s guidance on toggling Secure Boot BIOS settings. HP had previously acknowledged that certain BIOS updates could corrupt PCR7 measurements, resulting in recovery prompts on every reboot.
Despite assurances from HP representatives to ensure the latest BIOS was installed, the administrator found that their fleet was already up-to-date, yet the recovery issue persisted. Reverting to an older BIOS version resolved the problem, but such a rollback across thousands of devices is impractical for most IT teams.
HP’s legacy device stance draws direct criticism
Another user raised concerns about HP’s support for legacy devices, detailing their struggles with an EliteBook model that got stuck in a prolonged status of “Under Observation – More Data Needed.” Progress was only made after installing a specific BIOS update, which then led to the same BitLocker recovery loop experienced by others. They criticized HP for removing previously listed supported devices from their documentation, claiming that the manual update package provided was inadequate compared to a proper BIOS fix.
Devices still stuck on Secure Boot Status = Unknown
Another administrator reported devices indicating a Secure Boot Status = Unknown despite meeting all requirements. While Microsoft provided a partial response recommending a specific script for further diagnostics, the root cause of the issue remained unidentified.
Checker-KP’s HP fleet still can’t get the KEK to update
Another participant described a fleet of HP EliteBook units where the DB certificates updated successfully, but the KEK failed to do so, consistently returning to a “Not Started” status after reboots. Despite troubleshooting steps provided by HP representatives, including registry adjustments, the issue persisted without resolution.
Two Dell and HP questions went unanswered
An IT administrator reported success in updating certificates across a Dell fleet, except for a specific model that refused to update the registry key. Similarly, a question directed at HP regarding the difficulties faced by their customers went unanswered during the session.
Secure Boot issues are a pattern across OEMs, not just one vendor
The experiences shared during the event highlighted a troubling trend: HP and Dell customers reported the most significant challenges with Secure Boot among the OEMs present. This aligns with previous findings indicating that inconsistent firmware implementations across the industry, rather than a single vendor’s fault, contributed to the complications surrounding the Secure Boot 2023 certificate transition.
As IT administrators navigate these challenges, it is advisable to pilot updates on representative hardware before broader deployment, ensure BitLocker recovery keys are backed up, and consult OEM-specific advisories for guidance. For those still grappling with unresolved certificate issues, it is essential to recognize that these problems are not isolated incidents but rather part of a more extensive pattern affecting various manufacturers.
What to do if your Windows 11 Secure Boot certificate issue still isn’t fixed
The unresolved issues discussed during the event are not merely edge cases; they represent common challenges faced by many users. If you encounter BitLocker recovery loops, stalled KEK updates, or discrepancies in Secure Boot status, you are likely dealing with documented issues that have emerged across multiple OEMs.
It is crucial to treat BIOS updates and Secure Boot certificate deployments as distinct risks that currently intersect. A device passing its certificate check does not guarantee that the underlying BIOS is safe to update, nor does a new BIOS version ensure a smooth certificate update process. Before making any changes at scale, back up BitLocker recovery keys, and refer to your OEM’s specific guidance rather than relying solely on Microsoft’s general recommendations.
For further assistance, Windows Latest offers a comprehensive OEM Secure Boot guide, which details manufacturer-specific information. Additionally, if you have not yet assessed your fleet’s status, their guide on verifying Secure Boot status provides step-by-step instructions. Finally, if your device is affected by a known firmware block, Microsoft has confirmed that certain device and firmware combinations are currently paused in the rollout, which may explain delays in updates as they work towards a resolution.