Can not disable secure boot (Secure boot error)

Anonymous
2023-05-24T18:42:05+00:00

Hello I am having a weird issue on my Surface Pro 7.

When I try to change the secure boot setting in the surface UEFI to 'None' it fails and gives the following error: "The system failed to update the secure boot certificate keyset".

It also says "Secure Boot is Enabled with custom key configuration"

I have tried to factory reset windows with no success.

Why is there no reset keys button in the UEFI? None of the secure boot options work.

Best regards,

Linus

***Post moved by the moderator to the appropriate forum category***

Surface | Surface Pro | Performance and maintenance

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question. To protect privacy, user profiles for migrated questions are anonymized.

0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Anonymous
    2023-05-25T19:01:18+00:00

    Hi Linus Thorsell,

    Thank you for reaching Microsoft Community.

    I would like to know first the reason why we are trying to disable Secure Boot on the device? Is it because that we are trying to install a third-party operating system or due to some issues? Secure Boot is a security feature of the device to avoid vulnerabilities and thus, disabling it is not recommended.

    You mentioned also that it states it UEFI settings "Secure Boot is Enabled with custom key configuration", is this device being managed by an organization or company? or is this a company device or a personal device?

    Furthermore, since a factory reset was tried already, I suggest that we proceed to a clean installation of Windows on the device through USB Recovery. This option will reimage the entire device and reload Windows including the drivers and firmware. It is the most complete form of Reset and it will wipe out everything on the device. You will need also a 16GB/32GB of flash drive that must be formatted into FAT32 prior to downloading the Recovery Image. See the steps below for guidance.

    How to Download, Create and Use a USB recovery drive

    To download the Recovery Image:

    • You'll need another working device running on Windows.
    1. Visit the page to Download the recovery image for your Surface
    2. Sign in with your Microsoft Account
    3. From the list of Surface devices available, select the device that you need a recovery image for
      Please note that while you will only be presented with devices that are currently registered on your account, you will also be presented with the option to get an image for a different type of device. If you try to use this option, you will be prompted to enter the serial number for that device
    4. Download the recovery image using the button on the page
    5. When the download bar pops up at the bottom of your screen, save the file in a location you will be able to find it.

     Format USB Drive:

    • Note: Formatting a recovery drive will erase anything that is already stored on your USB drive. Make sure to transfer any important data from your USB drive to another storage device before using it to create a Surface USB recovery drive.
    1. Insert your USB drive into the USB port of your PC.
    2. From the desktop, open File Explorer
    3. Tap and hold or right-click on the USB drive and choose Format
    4. Select FAT32 as the file system and enter a Volume label to name the USB drive, such as RECOVERY, and then tap or click Start
    5. Tap or click OK to erase the contents of the USB drive
    6. Tap or click OK when the format is complete

    Create a recovery drive:

    1. On your Surface or PC, open recovery image that you downloaded by double-clicking it or right click then select Extract and then Extract all.
    2. Select the USB drive you formatted earlier for the location and click Extract.

    Use a USB recovery drive to reset your Surface:

    1. Shutdown the Surface
    2. Insert the USB recovery drive into the USB port
    3. Press and hold the volume-down (-) rocker
    4. Press and release the power button
    5. When the Surface logo appears, release the volume-down (-) rocker
    6. Surface will start the recovery software on the USB recovery drive
    7. When prompted, choose your language options and keyboard layout
    8. Select Troubleshoot
    9. Select Recover from a Drive. Choose Remove Everything and Fully Clean the Drive. Recovering this PC.
    10. If prompted, select Repartition the drives
    11. If prompted for BitLocker Key, tap Skip this Drive

    Kind regards,
    Marrion

    0 comments No comments
  2. Anonymous
    2023-05-30T13:20:44+00:00

    Hi Linus Thorsell,

    We haven't heard from you, so we assume that your issue has already been resolved. We will not be monitoring this thread moving forward so, if you need further assistance, please create a new thread to discuss these concerns by clicking this link: Create a new question or start a discussion (microsoft.com)

    Thank you for understanding. 

    Kind regards,
    Marrion

    0 comments No comments
  3. Anonymous
    2023-12-20T15:02:12+00:00

    Hello, I'm experiencing the exact same problem. I attempted a factory reset using a USB drive, but unfortunately, it was not successful. While Windows is operational, a red bar consistently appears at the top. Additionally, when I attempt to modify the secure boot options, it consistently reverts to Microsoft but remains non-functional.

    0 comments No comments