⚠️ Important
If BitLocker Drive Encryption is enabled on your system, resetting Secure Boot keys may trigger a BitLocker recovery prompt the next time Windows starts.
Before continuing, either:
- Suspend BitLocker protection, or
- Ensure you have access to your BitLocker recovery key
If you don't have your recovery key available, you may be unable to access Windows after restarting your PC.
In some cases, Secure Boot may be enabled but still not function correctly due to corrupted or outdated Secure Boot keys. In that case, check reset your secure boot keys.
Step 1: Access the BIOS or UEFI firmware
You can enter BIOS in a few ways:
- Windows 11: Start > Settings > System > Recovery > Advanced startup > Restart Now
- Windows 10: Start > Settings > Update and Security > Recovery > Advanced startup > Restart Now
- Or press Del, F2, or F10 during boot (this varies by motherboard)
Step 2: Locate the Security/Boot setting
Once you're inside BIOS or UEFI:
- Open the Boot tab or Security tab
- This may also be under Advanced or Startup, depending on your manufacturer
- Look for a setting named Key Management
Step 3: Restore Factory Keys
In the Key Management setting:
- Choose Restore Factory Keys to clear custom keys
- This could also be called Reset to Setup Mode or Install Default Secure Boot Keys depending on your manufacturer
- Ensure the default factory keys are installed
- Save and exit
Step 4: Ensure Secure Boot is enabled
To turn it on:
- Go to the Security or Boot tab
- Find Secure Boot and set it to Enabled
If Secure Boot is greyed out, make sure:
- Boot Mode is set to UEFI
- Then save, reboot into BIOS again, and check the setting once more
Step 5: Save Changes and Exit
- Use the Save and Exit tab or press the save hotkey (usually F10)
- Choose Save Changes and Exit > Yes
- Your system will reboot
