Windows 11 Secure Boot Is Breaking Older PCs and Even Microsoft Can’t Fix It

The distribution of Microsoft's Secure Boot certificate was intended to improve Windows 11 security. Rather, it has emerged as one of the most destructive firmware issues in recent memory, and there might be no solution at all for many older PCs.
To address the growing issues, Microsoft developers met with officials from Acer, Asus, Dell, HP, Lenovo, and other companies during an OEM Secure Boot Office Hours event in July 2026. Clarity was the goal of the workshop. Rather, it revealed an unpleasant truth: a lot of Secure Boot certificate issues are still unfixed, and even Microsoft is unable to explain why solutions that work on paper don't function on actual hardware.
The Nightmare Across OEMs
The faults impact the entire PC sector, but HP and Dell users have reported the harshest experience. Even after upgrading the most recent BIOS and adhering to HP's recommended instructions, an IT administrator overseeing more than 7,000 HP EliteBooks and ZBooks reported a BitLocker recovery loop that kept happening. Rolling back to an older BIOS fixed the problem, but that’s not a realistic option for large fleets. Neither HP nor Microsoft had a follow-up answer.
According to a different user, HP silently removed older devices from its list of supported devices after figuring the NVRAM wouldn't accommodate the updated certificates, thus leaving those PCs stranded.
Dell was not exempt either. An admin stated that OptiPlex 5000 machines refused to update the registry entry when commanded, and no Dell agent responded during the session.
The Root Cause: Fragmented Firmware
This isn’t a Microsoft problem alone, it’s an industry-wide firmware fragmentation issue. A normal certificate modification became a stress test for the entire ecosystem due to inconsistent UEFI implementations among manufacturers. Occasionally, ASUS boards might not apply the revocation list unless Secure Boot was momentarily disabled. While displaying Secure Boot as enabled in the user interface, MSI boards disregarded updates on certain models. On nearly all systems, ASRock required manual key resets. Eventually, one IT administrator gave up and completely rebuilt the motherboard.
What This Means for You
If you're using Windows 11 on an older computer, particularly one made by HP or Dell, you might be experiencing:
- Recovery loops for BitLocker that start with each reboot
- KEK changes that are inapplicable while adhering to official guidelines
- Readings for the Secure Boot status that don't correspond to the certificate state of your device
- Devices in "Under Observation" with no obvious way out
- Instead of allowing a known-to-be-broken update to continue, Microsoft has started to halt the distribution on particular device and firmware combinations. However, the pause might be permanent for a lot of older PCs.
Your Action Plan
Before making any changes:
- Back up BitLocker recovery keys before modifying registry keys or BIOS settings
- Pilot changes on representative hardware before pushing broadly
- Check your OEM’s specific advisory instead of relying only on Microsoft’s general guidance
- Run the detection script (Detect-SecureBootCertUpdateStatus.ps1) to verify your device’s status
How Bayon Technologies Group Can Help
Deploying Secure Boot certificates is a difficult, vendor-specific task that needs careful preparation. We at Bayon Technologies Group assist businesses in navigating these firmware mazes by providing:
- Hardware compatibility evaluations to determine which devices are vulnerable and which may be updated
- Pilot program design to test changes on representative hardware before full deployment
- To make sure you can recover in the event that a BIOS update starts a recovery loop, use BitLocker recovery key management.
- Vendor-specific information customized to your OEM's unique requirements
Avoid making your fleet unusable with a Secure Boot update. Contact Bayon Technologies Group today to design a safe, phased implementation strategy.
‹ Back


