Turned Secure Boot off and now it will not turn back on.
I've walked thru all the steps with Copilot and here is the summary......
Surface Book Secure Boot Case Summary
Device
- Original Surface Book (1st Generation)
- Windows 10 22H2
- BIOS Mode: UEFI
- Disk Partition Style: GPT
Problem
Surface boots normally when Secure Boot is disabled.
Enabling either:
- Microsoft Only
- Microsoft & 3rd Party CA
Plain Text
No bootable device
- Device returns to UEFI settings screen.
BitLocker Status
Plain Text
Protection Status: Protection Off
Conversion Status: Used Space Only Encrypted
``
- BitLocker recovery key is available and was successfully retrieved.
Secure Boot Status
Plain Text
Secure Boot State: Off
``
When Secure Boot is enabled:
Plain Text
No bootable device
Secure Boot Certificate Update Status
Registry:
Plain Text
HKLM\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing
WindowsUEFICA2023Capable : 0
UEFICA2023Status : InProgress
UEFICA2023Error : 0
UEFICA2023ErrorEvent : 0
TaskState : 13
Observed event log entries:
Plain Text
Event ID 1044
Secure Boot DB update to install Microsoft Option ROM UEFI CA 2023 certificate
Event ID 1045
Secure Boot DB update to install Microsoft UEFI CA 2023 certificate
Secure Boot Update Task
Plain Text
Task Name: Secure-Boot-Update
Location: \Microsoft\Windows\PI\
LastRunTime : 10/2/2026 7:25:25 PM
LastTaskResult : 0
State : Ready
EFI System Partition Verification
EFI partition present:
Plain Text
Volume 1
Label: SYSTEM
FAT32
260 MB
Healthy
System
EFI boot files present:
Plain Text
S:\EFI\Microsoft\Boot\bootmgfw.efi
S:\EFI\Microsoft\Boot\bootmgr.efi
S:\EFI\Microsoft\Boot\BCD
S:\EFI\Microsoft\Boot\SecureBootRecovery.efi
Signature Verification
PowerShell:
PowerShell
Get-AuthenticodeSignature "S:\EFI\Microsoft\Boot\bootmgfw.efi"
Result:
Plain Text
Status : Valid
PowerShell:
PowerShell
Get-AuthenticodeSignature "S:\EFI\Microsoft\Boot\bootmgr.efi"
Result:
Plain Text
Status : Valid
BCD Verification
Firmware Boot Manager:
Plain Text
Windows Boot Manager
device partition=\Device\HarddiskVolume1
path \EFI\Microsoft\Boot\bootmgfw.efi
Windows Boot Loader:
Plain Text
path \WINDOWS\system32\winload.efi
Windows Recovery Environment
Plain Text
Windows RE status: Enabled
Operation Successful
Firmware
Plain Text
SMBIOSBIOSVersion
92.3748.768
Windows Update history shows:
Plain Text
Surface - Firmware - 92.3748.768.0
Surface - Firmware - 11.8.86.3877
Support Request
Please investigate why Secure Boot validation fails on this Surface Book.
Observations:
- Windows installation appears healthy.
- EFI partition exists and contains valid Microsoft boot files.
- Microsoft boot files validate successfully with Authenticode.
- Secure Boot servicing reports no errors.
- Secure Boot certificate update events are present.
- Enabling Secure Boot causes firmware to report "No bootable device."
Looking for guidance on whether this is:
- a Surface firmware issue,
- a Secure Boot database issue,
- a UEFI CA 2023 transition issue,
- or a known limitation of the 1st-generation Surface Book.