iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
The message “Secure Boot Violation — Invalid signature detected. Check Secure Boot Policy in Setup” means your computer’s UEFI firmware rejected a boot component because its digital signature is missing, expired, revoked, or not trusted by the firmware’s Secure Boot databases.
That component might be Windows Boot Manager, a Linux or legacy bootloader, third-party full-disk encryption software, recovery media, or firmware-dependent hardware software. The right fix is therefore not always “repair Windows.” First identify what changed, then use the least disruptive solution.
Before changing Secure Boot
If Windows still starts, back up important files and save your BitLocker recovery key before changing firmware or Secure Boot settings. A Secure Boot, boot-manager, certificate, or firmware change can trigger BitLocker recovery.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Open an Administrator Command Prompt and run:
manage-bde -protectors -get %systemdrive%
Record the 48-digit recovery password somewhere you can access if Windows asks for it after the restart. Do not clear Secure Boot keys indiscriminately: doing so can remove trusted certificates and make recovery more difficult.
#1 Best Overall
- Less chaos, more calm. The refreshed design of Windows 11 enables you to do what you want effortlessly.
- Biometric logins. Encrypted authentication. And, of course, advanced antivirus defenses. Everything you need, plus more, to protect you against the latest cyberthreats.
- Make the most of your screen space with snap layouts, desktops, and seamless redocking.
- Widgets makes staying up-to-date with the content you love and the news you care about, simple.
- Stay in touch with friends and family with Microsoft Teams, which can be seamlessly integrated into your taskbar. (1)
1. Identify when the error appears
| What you see | Most likely area to investigate |
|---|---|
| The error appears after installing Linux or selecting a USB drive | Unsigned, legacy, or incompatible boot media |
| It started after installing disk-encryption software | The product’s pre-boot loader or UEFI certificate |
| It began after a Windows or firmware update | Windows Boot Manager, DBX revocations, or firmware compatibility |
| Only one USB installer fails | Out-of-date recovery or installation media |
| The device reaches a third-party pre-boot password screen first | That product’s bootloader, not necessarily Windows, is being rejected |
Remove nonessential USB devices, docks, and external drives, then restart. If the computer boots normally, reconnect devices one at a time. If the error is tied to one operating system or boot menu entry, avoid changing firmware keys until you have checked that operating system’s Secure Boot support.
2. Try the temporary bypass: disable Secure Boot
Disabling Secure Boot can confirm that an incompatible bootloader is the cause and may let the computer start. It is a workaround, not a complete repair: it reduces protection against pre-boot malware. Re-enable it after updating or replacing the incompatible component.
Enter UEFI settings from Windows
- Hold Shift while selecting Restart from the Windows power menu.
- Select Troubleshoot.
- Select Advanced options.
- Choose UEFI Firmware Settings, then select Restart.
Enter UEFI settings with a startup key
If Windows will not load, power the computer on and repeatedly press the manufacturer’s setup key. Common keys include F1, F2, F12, and Esc, but the correct key depends on the manufacturer and model. Look for a brief “Setup” or “BIOS” prompt, or check the device manual.
Change the setting
- Open the Security, Boot, or Authentication tab.
- Find Secure Boot and set it to Disabled.
- Use the firmware’s Save and Exit command. The wording and location vary by manufacturer.
If Windows starts with Secure Boot disabled, update the affected bootloader, encryption product, operating system, or firmware before turning protection back on. Leaving Secure Boot disabled permanently is especially undesirable on a system used for sensitive work.
3. Update Windows and the affected boot software
Install all available Windows updates and the latest UEFI firmware supplied for your exact computer model. Also update any software that runs before Windows, such as disk encryption, endpoint security, boot managers, or Linux distributions.
This is particularly important for ESET Full Disk Encryption and ESET Endpoint Encryption. ESET reports that affected devices may fail at the pre-boot screen on or after June 27, 2026, when older UEFI CA 2011 certificates expire. The permanent fix is an ESET version with a bootloader signed using updated UEFI CA 2023 certificates. Disabling Secure Boot is only ESET’s temporary workaround.
Do not assume that reinstalling Windows will solve every invalid-signature error. A signature revocation stored in UEFI’s DBX database remains after the disk is reformatted, and an old bootloader or recovery USB can still be rejected.
4. Understand the current Windows Secure Boot certificate transition
Microsoft’s current mitigation guidance covers supported releases including Windows 10 version 22H2 and Windows 11 versions 22H2, 23H2, 24H2, and 25H2, plus applicable Windows Server releases. Microsoft recommends installing the Windows security update released July 8, 2025, or later before deploying the mitigations.
The transition involves:
- Adding the Windows UEFI CA 2023 certificate to the Secure Boot database.
- Using a Windows Boot Manager signed by that certificate.
- Adding the older Windows Production PCA 2011 certificate to the UEFI DBX forbidden-signature database.
- Optionally increasing the Secure Version Number (SVN) to prevent rollback to an older boot manager.
These controls are staged. Installing the relevant Windows update does not, by itself, mean every mitigation is immediately active. Once revocations are applied, old boot managers signed by the revoked certificate remain untrusted, even after reformatting the disk.
Check the certificate and servicing state
After installing the required update, open PowerShell as Administrator. To check whether the Windows UEFI CA 2023 certificate is present, run:
Rank #2
- MICROSOFT WINDOWS 11 PRO (INGLES) FPP 64-BIT ENG INTL USB FLASH DRIVE
[System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match 'Windows UEFI CA 2023'
The expected result is True. Check the servicing state with:
Free tools Windows power users keep installed
One-click scans. No signup required.
(Get-ItemProperty -Path "HKLM:SYSTEMCurrentControlSetControlSecureBootServicing").UEFICA2023Status
Microsoft says the expected state is Updated.
Apply the Windows Secure Boot database updates
Use these commands only after reviewing Microsoft’s current staged-deployment guidance and confirming that your device, encryption software, virtual machines, and recovery media are supported.
To opt into adding the 2023 certificate to the Secure Boot database:
reg add HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSecureboot /v AvailableUpdates /t REG_DWORD /d 0x5944 /f
Start-ScheduledTask -TaskName "MicrosoftWindowsPISecure-Boot-Update"
To opt into adding Windows Production PCA 2011 to DBX:
reg add HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSecureboot /v AvailableUpdates /t REG_DWORD /d 0x80 /f
Start-ScheduledTask -TaskName "MicrosoftWindowsPISecure-Boot-Update"
Verify that the revoked certificate is present:
[System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI dbx).bytes) -match 'Microsoft Windows Production PCA 2011'
The result should be True. Microsoft identifies Event ID 1037 as the event showing that the DBX installation succeeded.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →The optional Secure Version Number update can be initiated with:
reg add HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSecureboot /v AvailableUpdates /t REG_DWORD /d 0x200 /f
Start-ScheduledTask -TaskName "MicrosoftWindowsPISecure-Boot-Update"
The SVN update prevents an older boot manager from being rolled back after the firmware’s stored SVN has increased.
5. Replace outdated recovery or installation media
Old recovery USB drives may stop booting after Secure Boot revocations are applied. Create updated media on a supported, fully patched Windows installation. Microsoft specifies a FAT32-formatted bootable USB for this process.
- Install the July 8, 2025 or later Windows update.
- Make sure the first Secure Boot database mitigation has already been applied.
- Search the Start menu for Create a Recovery Drive.
- Follow the Control Panel applet’s instructions to create the USB.
If the USB is mounted as D:, Microsoft documents rebuilding its UEFI boot files as follows. Confirm the drive letter first; using the wrong letter could modify another volume.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
COPY D:EFIMICROSOFTBOOTBCD D:EFIMICROSOFTBOOTBCD.BAK
bcdboot c:windows /f UEFI /s D: /bootex
COPY D:EFIMICROSOFTBOOTBCD.BAK D:EFIMICROSOFTBOOTBCD
Use recovery media made after the required updates, rather than assuming an older Windows installer will remain compatible.
Rank #3
- STREAMLINED & INTUITIVE UI, DVD FORMAT | Intelligent desktop | Personalize your experience for simpler efficiency | Powerful security built-in and enabled.
- OEM IS TO BE INSTALLED ON A NEW PC with no prior version of Windows installed and cannot be transferred to another machine.
- OEM DOES NOT PROVIDE SUPPORT | To acquire product with Microsoft support, obtain the full packaged “Retail” version.
- PRODUCT SHIPS IN PLAIN ENVELOPE | Activation key is located under scratch-off area on label.
- GENUINE WINDOWS SOFTWARE IS BRANDED BY MIRCOSOFT ONLY.
6. Re-enable Secure Boot
- Return to UEFI setup using Shift + Restart → Troubleshoot → Advanced options → UEFI Firmware Settings, or use the manufacturer’s startup key.
- Open the Security, Boot, or Authentication section.
- Set Secure Boot to Enabled.
- If the firmware offers Custom key management, load the built-in or factory Secure Boot keys. Do not simply delete every key.
- Save the changes and restart.
If the firmware refuses to enable Secure Boot, try restoring BIOS settings to factory defaults, as Microsoft recommends. If Windows will not boot afterward, disable Secure Boot again and contact the computer manufacturer rather than repeatedly changing key databases.
Hardware and software cases that need extra caution
- HP Sure Start: Microsoft says the mitigations can be blocked until the required current HP firmware is installed.
- Qualcomm ARM64 devices: Known UEFI firmware issues may require a manufacturer-provided fix.
- VMware: An x86 VMware virtual machine with Secure Boot enabled can fail to boot after the mitigations are applied.
- Symantec Endpoint Encryption: Microsoft says Secure Boot mitigations cannot be applied while it is installed.
- Windows Server 2012 or 2012 R2 with TPM 2.0: Microsoft blocks some mitigation steps on affected systems because of TPM-measurement compatibility issues.
- Older tablets and AMI firmware: Some Windows 8.1-era Dell Venue and Linx devices failed with larger boot-manager signatures. The documented remedy was the re-released update, with Secure Boot disabled temporarily if necessary.
What not to do
- Do not treat disabling Secure Boot as the final fix unless you accept the reduced pre-boot protection.
- Do not clear all Secure Boot keys as a first troubleshooting step.
- Do not assume corrupted Windows files are the only cause.
- Do not rely on an old recovery USB after DBX revocations have been applied.
- Do not start firmware or certificate changes without a BitLocker recovery key.
FAQ
Will disabling Secure Boot fix the error permanently?
Usually not. It bypasses signature validation and may let an incompatible bootloader start, but it reduces pre-boot protection. Update or replace the rejected boot component, then re-enable Secure Boot.
Can I fix this by reinstalling Windows?
Not always. UEFI DBX revocations survive disk formatting, and an old Windows bootloader or recovery USB can still be rejected. Use compatible, updated boot files and recovery media.
Why did the error appear after installing disk encryption software?
Full-disk encryption products often install a pre-boot authentication loader. If its certificate is expired, revoked, or not trusted by the firmware, Secure Boot can reject it before Windows starts.
What should I do if BitLocker asks for a recovery key?
Enter the saved 48-digit recovery password. Secure Boot, firmware, certificate, and boot-manager changes can alter measurements that BitLocker uses. If you do not have the key, stop changing firmware settings and recover the key through your organization or Microsoft account where applicable.
Should I clear the Secure Boot keys?
No. That is not Microsoft’s general recovery instruction. If enabling Secure Boot is blocked, try the firmware’s option to load built-in Secure Boot keys or reset BIOS settings to factory defaults, using the labels provided by your device manufacturer.
What does Event ID 1037 mean?
Microsoft identifies Event ID 1037 as the event indicating that the Secure Boot DBX installation or revocation list was successfully applied.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11The Bottom Line
“Invalid signature detected” is a firmware trust decision, not proof that Windows itself is damaged. Protect the BitLocker recovery key, identify whether Windows, recovery media, Linux, encryption software, or firmware changed, and update the rejected boot component. Disable Secure Boot only as a controlled temporary bypass. After installing compatible boot files and updating recovery media, restore Secure Boot and load the manufacturer’s built-in keys if required.
For the Windows certificate transition, follow Microsoft’s KB5025885 guidance. For ESET encryption installations, use ESET’s certificate advisory.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

