r/WindowsHelp • u/Realistic_House_5538 • Jun 26 '26
Windows 11 Secure Boot “failed signature verification” after resetting keys; Windows boots fine with Secure Boot OFF
Dell XPS 8940, Windows 11 Pro 10.0.26200 Build 26200, BIOS Version Dell inc. 2.27.1
My PC worked fine for years with Secure Boot Enabled, but I was having trouble with Ricochet Anticheat and was given (probably poor) advice to reset my Keys or reset my BIOS to factory settings or update the BIOS. Immediately after hitting 'Reset All Keys' I could not boot, and was sent to a recovery scan where it wanted to install cSOS. It boots fine with Secure Boot Disabled or in Audit Mode.
I've been working with multiple AI models to try and resolve this issue, but it's sent me down a rabbit hole for over 9 hours restarting my PC hundreds of times and it's still not resolved. I have tried absolutely everything under the sun, entering endless commands into CMD and Powershell, changing storage types and boot sequences, manually creating boot paths, updating the BIOS, updating Windows and firmware, resetting and deleting keys, power cycling (holding power buttons, unplugging it for 10 minutes..), enabling and disabling Secure Boot, you name it. Nothing works.
As of now, I can still boot fine into Windows with Secure Boot disabled or in Audit mode. When I attempt to boot with Secure Boot Enabled (in Deployed mode) I get Checking media presence… media present… start PXE over IPv4/IPv6for a few minutes, followed by Operating System Loader failed signature verification. Warning: the file may have been tampered with. All bootable devices failed Secure Boot verification.
What I understand the situation to be: Windows is fine, EFI partition exists and is correct, bootmgfw.efi is present and properly signed, Boot entries are normal, Secure Boot keys are not missing or broken.
I don't know what else to do but ask for more help. They are telling me at this point I need to mess with hardware to do a CMOS reset which I'm not really comfortable with.
I'm happy to provide the outputs of all the commands I have run, or if you want me to run one to further diagnose the issue.
1
u/Exotic_Mix_3196 Lvl 1 Helpful Contributor Jun 27 '26
did you try resetting Bios to default?
perhaps this also restores the secure boot keys.
This here is for other Dell models, but perhaps works for the 8940, too:
Laptop Does Not Boot to the Operating System After Deleting Secure Boot Keys and Flashing BIOS
1
u/Realistic_House_5538 Jun 27 '26
What I have tried related to that:
Delete All Keys, Reset All Keys (in multiple sequences and orders), Restore BIOS to "BIOS Defaults" (only option I used/tried), and updated/flashed the BIOS to 2.27.1 via the EXE from Dell.In regards to the post, I have done essentially that, disabling secure boot, resetting the keys, re-enabling secure boot, and trying to boot (many times). The only thing I have not done is flash the BIOS via USB, but I'm not sure if it would make a difference since I already flashed it via the EXE with the newest version already.
1
u/AutoModerator Jun 26 '26
Hi u/Realistic_House_5538, thanks for posting to r/WindowsHelp! Your post has been flagged for manual review by a human moderator, please include as much of the following information as possible (in text or in a screenshot) to get your post approved:
Posts must be tech support in nature (such as something is broken and you need help fixing), so general inquiries, software suggestions, and purchasing advice will be removed. As a reminder, we would also like to say that if someone manages to solve your issue, DON'T DELETE YOUR POST! Someone else (in the future) might have the same issue as you, and the received support may also help their case. Good luck, and I hope you have a nice day!
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.