Save open work and back up important files. Note any recent driver or hardware changes. If Windows cannot start, use the startup guide first.
Work through these checks
0 of 3 complete01Update UEFI Secure Boot database via Windows Update
Update UEFI Secure Boot database via Windows Update.
Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.
02Regenerate Secure Boot keys in BIOS
Regenerate Secure Boot keys in BIOS.
Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.
03Update or recreate bootable USB media
Update or recreate bootable USB media.
Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.
Possible causes
- Microsoft Secure Boot certificate revocation (KB5025885)
- Outdated dual-boot Linux EFI bootloader
- Old USB recovery media with expired signatures
Was this helpful?
Your progress is saved on this device.