Turned Secure Boot off and now it will not turn back on.

Ed Dery 0 Reputation points
2026-10-03T02:15:51.8933333+00:00

I've walked thru all the steps with Copilot and here is the summary......

Surface Book Secure Boot Case Summary

Device

  • Original Surface Book (1st Generation)
  • Windows 10 22H2
  • BIOS Mode: UEFI
  • Disk Partition Style: GPT

Problem

Surface boots normally when Secure Boot is disabled.

Enabling either:

  • Microsoft Only
    • Microsoft & 3rd Party CA
    results in:

Plain Text

No bootable device

  • Device returns to UEFI settings screen.

BitLocker Status

Plain Text

Protection Status: Protection Off

Conversion Status: Used Space Only Encrypted

``

  • BitLocker recovery key is available and was successfully retrieved.

Secure Boot Status

Plain Text

Secure Boot State: Off

``

When Secure Boot is enabled:

Plain Text

No bootable device


Secure Boot Certificate Update Status

Registry:

Plain Text

HKLM\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing

 

WindowsUEFICA2023Capable : 0

UEFICA2023Status : InProgress

UEFICA2023Error : 0

UEFICA2023ErrorEvent : 0

TaskState : 13

Observed event log entries:

Plain Text

Event ID 1044

Secure Boot DB update to install Microsoft Option ROM UEFI CA 2023 certificate

 

Event ID 1045

Secure Boot DB update to install Microsoft UEFI CA 2023 certificate

 


Secure Boot Update Task

Plain Text

Task Name: Secure-Boot-Update

Location: \Microsoft\Windows\PI\

 

LastRunTime : 10/2/2026 7:25:25 PM

LastTaskResult : 0

State : Ready


EFI System Partition Verification

EFI partition present:

Plain Text

Volume 1

Label: SYSTEM

FAT32

260 MB

Healthy

System

 

EFI boot files present:

Plain Text

S:\EFI\Microsoft\Boot\bootmgfw.efi

S:\EFI\Microsoft\Boot\bootmgr.efi

S:\EFI\Microsoft\Boot\BCD

S:\EFI\Microsoft\Boot\SecureBootRecovery.efi


Signature Verification

PowerShell:

PowerShell

Get-AuthenticodeSignature "S:\EFI\Microsoft\Boot\bootmgfw.efi"

Result:

Plain Text

Status : Valid

PowerShell:

PowerShell

Get-AuthenticodeSignature "S:\EFI\Microsoft\Boot\bootmgr.efi"

Result:

Plain Text

Status : Valid


BCD Verification

Firmware Boot Manager:

Plain Text

Windows Boot Manager

device partition=\Device\HarddiskVolume1

path \EFI\Microsoft\Boot\bootmgfw.efi

Windows Boot Loader:

Plain Text

path \WINDOWS\system32\winload.efi


Windows Recovery Environment

Plain Text

Windows RE status: Enabled

Operation Successful


Firmware

Plain Text

SMBIOSBIOSVersion

92.3748.768

Windows Update history shows:

Plain Text

Surface - Firmware - 92.3748.768.0

Surface - Firmware - 11.8.86.3877


Support Request

Please investigate why Secure Boot validation fails on this Surface Book.

Observations:

  • Windows installation appears healthy.
  • EFI partition exists and contains valid Microsoft boot files.
  • Microsoft boot files validate successfully with Authenticode.
  • Secure Boot servicing reports no errors.
  • Secure Boot certificate update events are present.
  • Enabling Secure Boot causes firmware to report "No bootable device."

Looking for guidance on whether this is:

  • a Surface firmware issue,
  • a Secure Boot database issue,
  • a UEFI CA 2023 transition issue,
  • or a known limitation of the 1st-generation Surface Book.
Surface | Surface Book | Safety and security

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.