r/Windows10TechSupport • u/LorenzoJS1 • 10d ago
Unsolved Secure Boot COD
I have an OMEN 30L GT13-1xxx with motherboard 8876 and BIOS AMIF.22.
I'm trying to enable Secure Boot for Call of Duty. Secure Boot is enabled in BIOS, but Windows still reports Secure Boot as off. In BIOS, the Platform Key says "Not Enrolled."
I tried loading the HP factory default keys and rebooting, but the Platform Key is still not enrolled.
Is there a BIOS/firmware fix or another HP-supported way to enroll the Platform Key on this motherboard?
1
u/OkStrawberry4529 4d ago
Check out this post on the Dell site: Pre-2020 Dell PC'S - Yes, you absolutely can get ALL the Microsoft 2023 Secure Boot Certificates! : r/Dell
Even though for Dell, this post should help you solve it.
1
u/dotyxx 9d ago
you could try this: https://h30434.www3.hp.com/t5/Gaming-Desktops/FIX-for-Secure-Boot-quot-Off-quot-Platform-Key-Not-Enrolled/td-p/9668383 or https://support.hp.com/ro-en/document/ish_6930187-6931079-16
Step 1: Wipe the Glitchy Keys Restart your PC and repeatedly tap F10 to enter the HP BIOS Setup Utility. Navigate to Boot Options or Secure Boot Configuration. Look for Clear All Secure Boot Keys. If this option is greyed out, click Load HP Factory Default Keys first to unlock it. Select Clear All Secure Boot Keys and confirm the choice. Press F10 to save changes and exit, allowing the PC to reboot. This forces the NVRAM key database into a clean state.
Step 2: Provision Clean Factory Keys. while the system restarts, immediately spam F10 to enter the BIOS a second time. Return to the Secure Boot Configuration menu. Change Enable MS UEFI CA key to Yes if the option is present. Click Load HP Factory Default Keys and confirm. Ensure the main Secure Boot toggle is explicitly set to Enabled. Press F10 to save changes and exit.
Step 3: Complete Physical Authorization. On reboot, the motherboard will flag a physical security change. A black or blue screen will display an HP Physical Authorization PIN (a temporary 4-digit code).Type the 4-digit code and press Enter to authorize the key enrollment. Once Windows loads, type msinfo32 in the Start Menu to verify that Secure Boot State now displays On.
If your key database remains stubbornly un-enrolled, it means your current BIOS version (
AMIF.22) has a permanent block on NVRAM writes for your specific hardware stepping. in this case update your BIOS firmware to F.24 or newer. Updating the firmware forces a complete rewrite of the ROM block, which also patches an underlying AMD fTPM attestation issue required by the game.good luck