BIOS. Windows Boot Manager

Amber W 0 Reputation points
2026-08-28T14:09:42.72+00:00

Hello!

I was trying to fix COD new requirements to play l with the anti cheat because i kept getting an error “Failed Attestation Status”. However i followed instructions that told me to clear the keys in the BIOS (i’m sorry im stressed and don’t remember name specifics) Once the keys were clear pressed f10 and could no longer get into my laptop because Windows boot manager. I did a hard restart to get me back into the BIOS and turned off secure boot startup so now i can get back onto my laptop. But if i turn secure boot startup back on im suck in the continuous loop windows boot manager and i can only access my laptop if i have secure boot disabled.

Please help!

Windows for home | Other | Performance and system failures
0 comments No comments

2 answers

Sort by: Most helpful
  1. Ivan B 121.4K Reputation points Independent Advisor
    2026-08-28T14:48:28.0166667+00:00

    Hi,

    So, when you reset the Secure Boot keys, you lost the Windows boot manager upon re-enabling it, correct?

    If the Q&A Assist procedure doesn't work, you would need to restore the default keys and try loading them during startup.

    Could you let me know your laptop model?

    Thanks.

    Was this answer helpful?


  2. AI answer

    2026-08-28T14:10:00.7233333+00:00

    Resetting Secure Boot keys to firmware defaults can remove the certificates required to trust the installed Windows boot manager. That matches the symptom where Windows starts only when Secure Boot is disabled.

    Use this recovery path:

    1. Leave Secure Boot disabled for now so Windows can start.
    2. Update the device firmware/BIOS to the latest version available from the laptop manufacturer.
    3. Avoid resetting Secure Boot to firmware defaults again unless the OEM firmware includes updated Secure Boot defaults that trust the 2023 certificates.
    4. If the device still fails whenever Secure Boot is enabled, use the Secure Boot recovery utility:
      1. On a second Windows PC that has the July 2024 or newer Windows update installed, copy SecureBootRecovery.efi from C:\Windows\Boot\EFI\.
      2. Put that file on a FAT32-formatted USB drive in \EFI\BOOT\.
      3. Rename the file to bootx64.efi.
      4. Boot the affected laptop from that USB drive.
      5. Let the recovery utility run. It adds the Windows UEFI CA 2023 certificate back to the Secure Boot database.
      6. Restart and test booting Windows again with Secure Boot enabled.

    If Windows can boot normally now, re-enable Secure Boot from BIOS/UEFI:

    1. Open the BIOS/UEFI menu.
      • Common keys during startup are F1, F2, F12, or Esc.
      • Or from Windows: hold Shift while selecting Restart > Troubleshoot > Advanced Options > UEFI Firmware Settings.
    2. Find Secure Boot under the Security, Boot, or Authentication tab.
    3. Set it to Enabled.
    4. Save changes and exit.
    5. If the PC fails to boot again after enabling Secure Boot, disable it again and run the recovery utility steps above.

    If the BIOS has an option to Install Default Secure Boot Keys rather than clearing them, that is the correct direction after keys were deleted. On some devices, using Reset/Clear removes trust and causes this exact boot block.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.