Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

If your Windows 11 PC entered a restart loop after you enabled Secure Boot, first identify what appears on screen: a BitLocker recovery prompt, a firmware-level “Secure Boot violation,” or a Windows startup failure. Each points to a different recovery path. Secure Boot may be involved, but timing alone does not prove it caused the problem.

Start by identifying where startup stops

Write down the exact message and note whether you can open UEFI settings, reach Windows Recovery Environment (WinRE), or get as far as the Windows logo. The distinction matters: Startup Repair addresses certain Windows startup problems, while firmware trust-database failures need a firmware-specific response.

  • BitLocker recovery: Windows asks for a recovery key before it can access the encrypted drive.
  • Secure Boot violation: A firmware message appears before Windows loads, saying the boot software is not trusted or cannot be verified.
  • Windows startup failure: You see the Windows logo, Automatic Repair, or repeated restarts without a Secure Boot violation message.

Microsoft’s Secure Boot troubleshooting guidance, published March 19, 2026, covers Windows 11 versions 23H2, 24H2, 25H2, and 26H1, among other products. It describes several distinct causes that can coincide with enabling Secure Boot, including boot-order changes, certificate servicing, reset trust databases, and firmware limitations. Microsoft’s Secure Boot troubleshooting guide is the reference for the firmware-specific cases below.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If Windows asks for a BitLocker recovery key

Enter the recovery key associated with the encrypted device before trying recovery actions that need access to its drive. Microsoft notes that most WinRE recovery options on an encrypted device require the key. A single BitLocker recovery prompt after Secure Boot certificate servicing can be temporary; a prompt that returns on each boot calls for investigation.

#1 Best Overall
Sale
Microsoft Windows 11 (USB)
  • Less chaos, more calm. The refreshed design of Windows 11 enables you to do what you want effortlessly.
  • Biometric logins. Encrypted authentication. And, of course, advanced antivirus defenses. Everything you need, plus more, to protect you against the latest cyberthreats.
  • Make the most of your screen space with snap layouts, desktops, and seamless redocking.
  • Widgets makes staying up-to-date with the content you love and the news you care about, simple.
  • Stay in touch with friends and family with Microsoft Teams, which can be seamlessly integrated into your taskbar. (1)

Check whether network boot comes before Windows Boot Manager

A recurring BitLocker recovery prompt can occur when the PC tries PXE (network) boot first and then falls back to local boot. The two paths can measure different signing authorities. If network boot is not needed, disable PXE in UEFI settings. Otherwise, set Windows Boot Manager ahead of PXE in the boot order, or follow Microsoft’s guidance to use a 2023-signed Windows boot loader when PXE must remain available. Use the computer maker’s instructions for the model-specific UEFI menu names; Microsoft explains how to find Secure Boot settings in Windows 11 and Secure Boot.

If firmware reports a Secure Boot violation

A violation before Windows loads suggests firmware is rejecting the boot manager. Consider what happened immediately before the first failure: did you reset Secure Boot settings to firmware defaults, or did the issue begin right after Secure Boot certificate servicing? Those histories lead to different possibilities.

After resetting Secure Boot settings

On a device already using the Windows UEFI CA 2023-signed boot manager, resetting Secure Boot settings to firmware defaults may remove a trust certificate the boot manager needs. Microsoft documents a specialized recovery process using SecureBootRecovery.efi from a FAT32 USB drive, followed by a device firmware update. This is not an ordinary Windows repair; follow the current Microsoft procedure and the device maker’s instructions for your exact model.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Immediately after certificate servicing

Some firmware implementations may overwrite Secure Boot database entries instead of appending them during certificate updates. Check the device maker’s support information for a firmware correction. If a firmware reset does not restore startup, seek model-specific OEM support; Microsoft notes that unresolved cases can require it. Startup Repair cannot be relied on to restore firmware trust databases.

If Windows reaches its logo or Automatic Repair

When there is no firmware violation and Windows begins loading, treat the issue first as a general startup failure. If WinRE is available, try Startup Repair: Troubleshoot > Advanced options > Startup Repair > Restart. Microsoft says this option can address common problems such as missing or damaged system files and corrupted boot configuration data; it is not a guaranteed fix for a firmware-level trust problem. See Startup Repair.

When WinRE does not open

You can use Windows installation media created on a working PC. Boot the affected computer from that media, then select Repair my PC to enter recovery options. On an encrypted device, have the BitLocker recovery key ready. Microsoft describes the recovery environment and installation-media route in its Windows Recovery Environment guide and its instructions for creating Windows installation media. The USB drive carries recovery media; it is not itself a Secure Boot repair tool.

Quick Machine Recovery availability

Windows 11 version 24H2 or later may offer Quick Machine Recovery if the feature is enabled. In applicable outage scenarios, it can detect repeated startup failures and check Windows Update for a fix. It is not a guaranteed solution to a Secure Boot or firmware certificate problem. Microsoft’s broader options for a PC that will not start are described in Recovery options in Windows.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Temporarily disabling Secure Boot

Microsoft says Secure Boot may need to be disabled temporarily to address an issue, and recommends turning it back on once the issue is resolved. Secure Boot settings are in UEFI firmware, and some devices require UEFI rather than Legacy/CSM boot mode to configure them. Because menu names and firmware behavior vary by model, follow the computer maker’s instructions if you are unsure. See Microsoft’s Secure Boot settings guidance.

Use the symptom to choose the next step

What you see First action What to investigate next
BitLocker recovery prompt Enter the recovery key. If it returns, check whether PXE/network boot precedes Windows Boot Manager.
Secure Boot violation before Windows loads Record whether the failure followed a firmware-default reset or certificate servicing. Use the Microsoft procedure for the matching case and check OEM firmware guidance.
Windows logo, Automatic Repair, or restart without a violation message Open WinRE and try Startup Repair. If WinRE is unavailable, boot Windows installation media and choose Repair my PC.

Avoid repeatedly resetting firmware settings or applying generic boot-record commands without evidence that they fit the failure. A firmware trust-database issue is different from a damaged Windows boot configuration, and the fix depends on which screen appears and what changed before the loop began.

Quick Recap

SaleBestseller No. 1
Microsoft Windows 11 (USB)
Microsoft Windows 11 (USB)
Make the most of your screen space with snap layouts, desktops, and seamless redocking.; FPP is boxed product that ships with USB for installation
$128.99
Bestseller No. 2

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.