Windows 11 won't boot on a Lenovo Yoga 7i

jsaeg12 45 Reputation points
2026-06-05T01:17:23.57+00:00

Hello, I own a Lenovo Yoga 7i 14IML9 that won't boot Windows. I tried to boot the installation media made with the official Media Creation Tool, and that also won't boot. Rufus gives an error (FAIL: Windows bootmgr encountered a security violation or internal error), and Ventoy reboots after saying "Press any key to boot from CD/DVD..." I also tested Linux Mint, and strangely enough, it boots fine. I already disabled Secure Boot, Device Guard, Intel PTT, and Intel VT-d, and it still won't work.

Windows for home | Windows 11 | Performance and system failures
0 comments No comments

Answer accepted by question author

Thomas4-N 19,240 Reputation points Microsoft External Staff Moderator
2026-06-12T10:39:09.77+00:00

Hello jsaeg12, thanks for the follow up.

At this point, with Secure Boot truly off now (Disabled + User + Standard), the latest BIOS already on the device, a fresh 25H2 ISO on FAT32, and three independent tools all failing the same way while Linux Mint boots fine, pretty much every lever on the Windows/Microsoft side has been pulled. The 1709 stick detail is interesting too.

What that really leaves is firmware-side behavior on your specific unit rejecting the Windows boot manager while still accepting Linux's signed shim. It's not something we can reach, verify, or change from the Microsoft side. There's no Windows setting, no media tweak, no BIOS toggle left that I'd confidently point you to.

At this point the realistic next stop is Lenovo Support for your Yoga 7 2-in-1 14IML9 — they're the ones who can actually look at the firmware-level behavior on the board. Worth sharing the full history so they don't restart from scratch.

Was this answer helpful?

2 people found this answer helpful.

2 additional answers

Sort by: Most helpful
  1. Thomas4-N 19,240 Reputation points Microsoft External Staff Moderator
    2026-06-09T09:45:20.4866667+00:00

    Hello jsaeg12, thanks for the follow up.

    With a current 25H2 ISO and Secure Boot already disabled, the revoked pre-2023 bootloader angle (CVE-2023-24932) doesn't really fit anymore. The thing that stands out now is the Secure Boot state itself. "Disabled" but with Platform Mode: Setup and Secure Boot Mode: Custom isn't a normal clean-off configuration — Setup Mode means the Platform Key has been cleared, and Custom means it's running custom keys rather than the factory set. A genuine "off" is usually just Disabled + Standard. That odd in-between state is a plausible reason Linux Mint sails through (its signed shim satisfies the firmware) while the Windows bootmgr gets rejected at the policy check.

    So before anything drastic, I'd try normalizing that state in BIOS:

    • Set a Supervisor password first — on Lenovo, Secure Boot changes sometimes won't truly stick without one.
    • In the Secure Boot section, look for Restore Factory Keys (or "Reset to Setup" then re-provision) and apply it.
    • Set Secure Boot Mode back to Standard, not Custom.
    • Confirm CSM / Legacy is fully disabled so it's pure UEFI.
    • While you're at it, check Lenovo's support page for a BIOS/firmware update for the 14IML9 — outdated firmware can throw this same violation on newer boards.

    Then retry booting the FAT32 25H2 stick. If it still fails after that, let me know what the BIOS shows for Platform Mode afterward and we'll go from there.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".  

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread. 

    Was this answer helpful?

    1 person found this answer helpful.

  2. Thomas4-N 19,240 Reputation points Microsoft External Staff Moderator
    2026-06-05T10:33:40.7533333+00:00

    Hello jsaeg12,

    Thanks for the detail — the fact that Linux Mint boots but every Windows tool throws a "security violation" actually narrows things down a lot. That specific bootmgr error is usually the revoked pre‑2023 Windows bootloader (CVE‑2023‑24932) being rejected, but a couple of things in your post don't quite line up with the textbook case, so I'd rather confirm than guess and send you down the wrong path.

    Could you check/share a few things:

    • Which Windows ISO/build you used — and roughly when you downloaded it. If it's an older cached ISO, that alone can trigger this; the current build shouldn't.
    • How the USB was formatted — was it FAT32? The Microsoft guidance for this error specifically calls for FAT32 install media.
    • Secure Boot's actual state in firmware, not just the toggle. On Lenovo, go into BIOS (tap F1/F2 at the Lenovo logo) and confirm Secure Boot reads Disabled, and note whether the mode shows as Standard / Setup / Custom. Sometimes the toggle won't truly take unless a Supervisor password is set first.
    • Whether there's already a Windows install on the internal drive, or the disk is blank/new.

    Once I know the ISO age, the USB format, and that Secure Boot is genuinely off (not just flipped), I can point you to the right fix.

    Was this answer helpful?

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.