Hello Victoria O,
Welcome to Microsoft Community.
Secure Boot is a security feature that ensures that only trusted software is loaded during the boot process and relies on digital signatures to verify the authenticity of the loaded software.
The error message "Invalid signature - please check the security boot policy in your Settings" usually indicates that there is a problem with the security boot configuration on your computer.
I have tried to put together a process for you that I hope will help you solve this problem.
1. Access BIOS/UEFI Settings:
Security boot Settings are usually located in your computer's BIOS or UEFI Settings. To access these Settings, you need to restart your computer and press the appropriate key during the boot process. Common keys include F2, F12, Del, or Esc. Keys to access BIOS/UEFI may vary by computer manufacturer, so check your motherboard's documentation for the correct keys, or consult your device's after-sales support.
2. Check the safe startup status:
Once you are in BIOS/UEFI Settings, look for the "Secure Boot" option. Usually located in the Security or Startup section. If you want to use secure boot, make sure it is enabled, and if you want to turn it off, disable it. However, if you can't make changes in BIOS/UEFI, you may want to check if there are other options that prevent this from happening, and you can report the error to the motherboard's support staff to help you debug it.
3. Secure startup key:
Secure booting relies on digital signatures to verify the authenticity of boot loaders and operating system files. This error may occur if there is a problem related to the secure startup key or certificate. In your BIOS/UEFI Settings, there may be an option to manage a secure boot key. You may need to clear existing keys and re-register them. Consult your computer's documentation or your device's after-sales support for guidance on this process.
4. Update BIOS/UEFI firmware:
Updating your computer's BIOS/UEFI firmware can sometimes resolve compatibility issues related to a secure boot. Visit the computer manufacturer's website to see if there is a BIOS/UEFI update for your model and follow their instructions. However, this operation is associated with certain risks, so before performing this operation, be sure to back up your important data to prevent loss.
5. Reset BIOS/UEFI to the default Settings:
If you have made extensive changes to your BIOS/UEFI Settings and are not sure if any changes are causing the problem, you can try resetting your BIOS/UEFI Settings to the default values. There should be an option to do this in the BIOS/UEFI Settings.
If you have tried the above steps on your own and still experience problems, it is recommended to contact the manufacturer of your computer or the aftermarket support of your device for specific troubleshooting instructions related to the safe boot of your particular model.
Again, changing BIOS/UEFI Settings may affect how your computer boots and operates, so exercise caution before making major changes and be sure to back up any important data before making major changes.
Best regards,
Mitchell - | Microsoft community support expert from MSFT