ASUS mobo wont boot unless secure boot is off suddenly


Recommended Posts

So I have an ASUS ROG Strix Z890-E motherboard with a 285K, it's worked perfectly until last night... I went to reinstall windows

Did a secure erase of the SSD which I've done before to blank them out, except this time I could not get the windows 11 installer USB drive to boot from.. it would just go right back to the UEFI BIOS screen... tried that multiple times no luck, tried other boot drives no luck, they all worked in the past, they are all UEFI boot devices too.. ok can't do anything

messed with it for an hour last night nothing, cleared bios settings, nothing, reflashed the bios nothing... the BIOS is the latest version ASUS has available also.

This morning disabled secure boot and bingo it works..

Turn secure boot back on and nope nothing... cleared the keys loaded defaults nothing... turn off works again

This makes no sense secure boot was working fine until I erased the SSD to do a reinstall..

 

anyone have any ideas? I'm stumped, the secure boot keys shouldn't be expired it's the latest BIOS update that was just pushed last month and apparently they added new keys months ago to it.

Posted (edited)

This sounds very much like the new secure boot certificates Microsoft has been busy rolling out which install in the certificate database on your UEFI.

The installer probably has the UEFI 2023 secure boot certificates. You'll need to update the BIOS on your motherboard to recognise the new certificates. Failing that it could be your machine already updated to the 2023 certs and no longer accepts the 2011 ones on the older versions of install media. If that's the case you'll just need updated install media.

 

Having re-read your original post the second scenario seems way more likely, so you'll just need new install media such as a 25H2 Iso.

One thing I did to fix a system that wouldn't boot with secure boot enabled is go to C:\Windows\Boot\EFI

and an copy SecureBootRecovery.efi to a flash drive into the folder EFI / Boot

Then boot off the flash drive. After it repairs try turning it back on.

Posted (edited)
On 20/05/2026 at 05:05, Ixion said:

This sounds very much like the new secure boot certificates Microsoft has been busy rolling out which install in the certificate database on your UEFI.

The installer probably has the UEFI 2023 secure boot certificates. You'll need to update the BIOS on your motherboard to recognise the new certificates. Failing that it could be your machine already updated to the 2023 certs and no longer accepts the 2011 ones on the older versions of install media. If that's the case you'll just need updated install media.

 

Having re-read your original post the second scenario seems way more likely, so you'll just need new install media such as a 25H2 Iso.

But OP said they flashed the most recent bios and it is up to date. Do we need to wait for ASUS to publish another new version?

 

NVM i misunderstood what you were trying to say.

On 20/05/2026 at 08:05, Ixion said:

This sounds very much like the new secure boot certificates Microsoft has been busy rolling out which install in the certificate database on your UEFI.

The installer probably has the UEFI 2023 secure boot certificates. You'll need to update the BIOS on your motherboard to recognise the new certificates. Failing that it could be your machine already updated to the 2023 certs and no longer accepts the 2011 ones on the older versions of install media. If that's the case you'll just need updated install media.

 

Having re-read your original post the second scenario seems way more likely, so you'll just need new install media such as a 25H2 Iso.

it wont even boot like this with the newest win 11 iso images just goes right to the bios screen when told to boot from it

Posted (edited)

On another forum, I used a PS script to update my Secure Boot keys.  I've seen people use this when their bios is too old and the maker is not going to update their bios.

Here is the link to the thread on ElevenForum -- Please read carefully (the entire thread is over 70pgs and growing) as I am not responsible for any damage or you ending up with a non-bootable device should things go wrong.  I'm just sharing information that may help someone out:

https://www.elevenforum.com/t/garlins-powershell-scripts-for-updating-secure-boot-ca-2023.43423/

Hello,

Did you create your Windows 11 installation media using the Windows Media Creation Tool, Rufus or some other tool?  If you did not use the Windows Media Creation tool, try using it instead to (re)create your media and see if using it makes any difference.

Regards,

Aryeh Goretsky


 

Posted (edited)
On 20/05/2026 at 22:07, neufuse said:

it wont even boot like this with the newest win 11 iso images just goes right to the bios screen when told to boot from it

I've seen similar things on some of our work machines, where I've ended up in a catch-22 of the BIOS supports the new keys, Windows will only boot with secure boot turned off. None of the scripts work to update the certificates database because without secure boot enabled they can't access the certs.

There are ways of fixing it from a UEFI prompt but they look horrendous. On those machines I ended up booting from an old windows install using the 2011 certificates, doing the secure boot updates then putting the new image back on but I appreciate this isn't an option for the average home user!

You can check the current status by doing the following:

Step 1: Open PowerShell as administrator

Right-click the Start button and choose Windows PowerShell (Admin) or Terminal (Admin).

Step 2: Run this command exactly as shown

([System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match ‘Windows UEFI CA 2023’)

If it returns true then you have the 2023 cert installed in the UEFI, if it returns false you still have the 2011 version.

Edited by Ixion
Added what response to expect
  • Like 1
Posted (edited)
On 20/05/2026 at 23:20, goretsky said:

Hello,

Did you create your Windows 11 installation media using the Windows Media Creation Tool, Rufus or some other tool?  If you did not use the Windows Media Creation tool, try using it instead to (re)create your media and see if using it makes any difference.

Regards,

Aryeh Goretsky


 

no it's the actual windows ISO downloaded as an ISO from the download site, not through the media creation tool. I also did try making a USB flash stick with the tool and same result.

On 21/05/2026 at 07:19, Ixion said:

I've seen similar things on some of our work machines, where I've ended up in a catch-22 of the BIOS supports the new keys, Windows will only boot with secure boot turned off. None of the scripts work to update the certificates database because without secure boot enabled they can't access the certs.

There are ways of fixing it from a UEFI prompt but they look horrendous. On those machines I ended up booting from an old windows install using the 2011 certificates, doing the secure boot updates then putting the new image back on but I appreciate this isn't an option for the average home user!

You can check the current status by doing the following:

Step 1: Open PowerShell as administrator

Right-click the Start button and choose Windows PowerShell (Admin) or Terminal (Admin).

Step 2: Run this command exactly as shown

([System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match ‘Windows UEFI CA 2023’)

If it returns true then you have the 2023 cert installed in the UEFI, if it returns false you still have the 2011 version.

done that already, it returns true, that was back before this started when I checked to make sure the latest bios did have the new keys already

Posted (edited)
On 21/05/2026 at 10:33, Ixion said:

If you used a tool like Rufus did you tick the use 2023 UEFI certificate signed bootloader box on the Windows customizations? It's off by default.

As I've said, this is the Microsoft ISO image for windows, the direct download of it... I also tried the medica creation tool same result.. booting directly from a ISO image using  a media emulator with my JetKVM.

Posted (edited)
On 23/05/2026 at 01:24, binaryzero said:

Sounds like pebkac

BS, why would this only happen when I set it to a specific date.

This issue was only noticed when I went to reinstall the OS, wiping the SSD to do a reinstall shouldn't make secure boot not work, using the latest ISO's isn't a user issue, they have the the latest keys, so that's still not a a user issue, the BIOS was update still not a user issue... the only thing that changed was the date...

This sounds like a calendar bug you know since keys are date based too.....

Edited by neufuse
On 24/05/2026 at 22:21, neufuse said:

BS, why would this only happen when I set it to a specific date.

This issue was only noticed when I went to reinstall the OS, wiping the SSD to do a reinstall shouldn't make secure boot not work, using the latest ISO's isn't a user issue, they have the the latest keys, so that's still not a a user issue, the BIOS was update still not a user issue... the only thing that changed was the date...

This sounds like a calendar bug you know since keys are date based too.....

Not checking the date is correct is the pebkac... ;)

  • Facepalm 3
Posted (edited)
On 24/05/2026 at 09:25, binaryzero said:

Not checking the date is correct is the pebkac... ;)

apparently you didn't understand what is going on..

the DATE WAS CORRECT, secure boot would not work on one day... the next day it just worked... I swapped the date back to the previous day and secure boot wouldn't work again... that's not PEBKAC that's verification of an issue

Edited by neufuse
  • Like 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Slight change of pace for me! Gunnar & the Grizzly Boys - Standard American (Official)  
    • draw.io Desktop 30.2.4 by Razvan Serea draw.io desktop is a downloadable security-first diagramming application that runs on Windows, MacOS and Linux. Creating diagrams in the desktop app doesn’t need an internet connection. This is useful when you are disconnected or when you must create diagrams in a highly secure environment, where data protection is of the utmost importance. When you use the draw.io desktop app, your diagrams will be stored on your local device. Because this is a stand-alone application, also designed to run offline, there are no interfaces to cloud storage platforms available. Of course, you can still store your diagrams in folders that are synchronised to your cloud storage if you wish. Easy-to-use diagram editor The draw.io apps work just like the office and drawing tools you are used to using. Drag and drop shapes from the shape libraries and drag to draw connectors between them. Drag connectors to add waypoints and set a precise shape and position, or let them reroute automatically. Double click and start typing to add a label to anything. Create tables and swimlane flows with a familiar tool. Style shapes and connectors with customisable palettes, sketch options, fonts and text formatting tools. Search for shapes, including in open-source icon libraries. Use our vast libraries of shapes and templates, organised into logical categories, to create a range of diagrams and infographics. Generate diagrams from text descriptions using our smart templates. Diagram faster with keyboard shortcuts. draw.io Desktop 30.2.4 changelog: Uses electron 42.4.1 Updates to draw.io core 30.2.4. Download: draw.io 64-bit | Standalone ~100.0 MB (Open Source) Download: draw.io 32-bit | ARM64 | ARM64 Standalone Links: draw.io Home Page | Project page @GitHub | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Microsoft will soon allow some users to block Copilot from analyzing their Office files by Usama Jawad Microsoft Purview is a pretty useful data governance, security, and management service that allows customers to gain enhanced visibility and control over their content. It's meant for commercial customers, such as organizations that are storing data at scale. As AI continues to expand and infiltrate every corner of a firm, many are a bit conscious about the technology gaining access to their confidential data. Microsoft is now making a configuration change that will allow such customers to rest easy. Right now, users within an organization have the option to apply Purview sensitivity labels (when available) to secure certain files and label them as such. For example, if you apply the "Confidential" label on an Excel file, the file will be encrypted, and a "confidential" watermark will be applied to it. So, if this file is shared with anyone, they are aware that its access is supposed to be restricted. Up until now, Microsoft was allowing some connected experiences, like its AI services, to analyze files, regardless of their sensitivity label. This is of major concern to most organizations, as a recent example highlighted how confidential emails with data loss prevention (DLP) policies like privacy labels were being uploaded to Copilot for analysis. As such, Microsoft is updating an existing Purview data label sensitivity setting that prevents "some connected experiences that analyze content", from being blocked completely from doing this. The label isn't changing, but the blocking is now being enforced across all connected services (including Copilot and other AI tools), and now extends to Microsoft Word, Excel, and PowerPoint. Files with the label applied already will get this enhancement automatically too once it becomes available. Microsoft has urged IT admins to inform their respective helpdesk and compliance teams, update internal documentation, and review sensitivity labels to ensure that they meet their respective compliance needs. This change is tagged as MC1297982 in the Message Center. General availability is scheduled to begin in a phased manner soon and will complete by the end of next month. That said, it is important to note that this only applies to commercial customers who have a license that allows them to use Purview.
    • llamas are unruly going haywire in New Guinea.
    • The Persuasion Engine: How Any Business Can Use AI-Powered Neuromarketing —was $28 now free by Steven Parker Claim your complimentary copy (worth $35) of "The Persuasion Engine: How Any Business Can Use AI-Powered Neuromarketing to Understand and Win Customers" for free, before the offer ends on June 24. Description The Persuasion Engine, by neuromarketing and behavioral science expert Roger Dooley, solves the most pressing challenge faced by every marketer: how to figure out why customers make the decisions they do when 95% of their thought processes occur at an unconscious level. Dooley explains how artificial intelligence democratizes sophisticated neuromarketing tools that were once available only to Fortune 500 companies, making powerful customer insight and persuasion techniques accessible to businesses of any size. The book walks you through the evolution of traditional neuromarketing into ”Neuromarketing 2.0,” where AI-powered tools eliminate the need for expensive lab studies and human behavioral science experts. It offers a comprehensive roadmap for implementing eye tracking, facial coding, biometrics, implicit testing, and advanced AI behavioral techniques that dramatically improve marketing effectiveness while reducing costs and time investment. Inside the book, you’ll find: Revolutionary AI prompting strategies that bring world-class behavioral science expertise to your desktop Practical frameworks for leveraging attention, emotion, credibility, and decision architecture to boost conversions Step-by-step guidance for implementing biometric tools and implicit testing without laboratory resources Advanced techniques for creating scarcity, urgency, and FOMO that drive immediate customer action Comprehensive methods for auditing and enhancing empathy in customer communications Perfect for marketing professionals, business owners, entrepreneurs, and anyone with a stake in customer acquisition and retention, The Persuasion Engine provides actionable strategies that will transform your approach to marketing. Whether you're working on a shoestring or managing enterprise campaigns, you'll discover how to use your customers' non-conscious motivations and create compelling marketing that work on real people in the real world. How to download for free Please ensure you read the terms and conditions to claim this offer. Complete and verifiable information is required in order to receive this free offer. If you have previously made use of these offers, you will not need to re-register. Was $28, but is now FREE | Below free offer link expires on June 24. The Persuasion Engine: How Any Business Can Use AI-Powered Neuromarketing to Understand and Win Customers The below offers are also available for free in exchange for your (work) email: The Vibe Coding Playbook: Building Your Tech Business with AI ($35 Value) FREE - Expires 6/23 The Persuasion Engine: How Any Business Can Use AI-Powered Neuromarketing to Understand and Win Customers ($28 Value) FREE - Expires 6/24 How to Do More with Less: Future-Proofing Yourself in an AI-driven Economy ($28 Value) FREE - Expires 6/30 Cloud Security Fundamentals: Building the Foundations for Secure Cloud Platforms ($131.95 Value) FREE - Expires 7/1 The Complete Free AI Learning: Master ChatGPT, Claude, Gemini & More ($21 Value) FREE How to Build an AI Design Workflow with Gamma ($21 Value) FREE The Ultimate Linux Newbie Guide – Featured Free content Python Notes for Professionals – Featured Free content Learn Linux in 5 Days – Featured Free content Quick Reference Guide for Cybersecurity – Featured Free content We post these because we earn commission on each lead so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. Other ways to support Neowin The above deal not doing it for you, but still want to help? Check out the links below. Check out our partner software in the Neowin Store Buy a T-shirt at Neowin's Threadsquad Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: An account at Neowin Deals is required to participate in any deals powered by our affiliate, StackCommerce. For a full description of StackCommerce's privacy guidelines, go here. Neowin benefits from shared revenue of each sale made through the branded deals site.
  • Recent Achievements

    • Week One Done
      Eurosoft10 earned a badge
      Week One Done
    • One Month Later
      Eurosoft10 earned a badge
      One Month Later
    • One Year In
      Skeet Campbell earned a badge
      One Year In
    • One Month Later
      Sharbel earned a badge
      One Month Later
    • First Post
      BizSAR earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      589
    2. 2
      +Edouard
      190
    3. 3
      Michael Scrip
      76
    4. 4
      PsYcHoKiLLa
      75
    5. 5
      neufuse
      72
  • Tell a friend

    Love Neowin? Tell a friend!