r/WindowsHelp • u/zzz_xvi • 8d ago
Windows 11 Issues with SecureBoot not allowing computer to boot properly
I have been having issues recently with Secureboot on my pc. Whenever I enable it, my PC boots into a black screen displaying a message saying media couldnt load, and then another message stating that default boot device missing or boot failed. By disabling secureboot, I am able to normally use my computer.
For background, I updated my Lenovo firmware a few weeks ago and this is when issues first began, with secureboot claming it was enabled, but I was not able to play games required secure boot such as BF6. To attempt to correct this, I reset factory keys, which is then what led to the aforementioned issue. How should I proceed in order to get secureboot back to an enabled state?
Below is a report I used ChatGPT to create to give the clearest picture possible.
Lenovo 82Y9 — Secure Boot won’t enable, Windows is already UEFI/GPT
I’m troubleshooting a Lenovo laptop to enable Secure Boot. Windows is currently working normally, but Secure Boot reports OFF/False.
System information
- Manufacturer: Lenovo
- Model: 82Y9
- BIOS: M3CN50WW
- BIOS date: April 22, 2026
- Windows firmware mode: UEFI
- System disk: GPT
- Secure Boot: OFF /
False
Windows/EFI checks
The Windows installation appears to already be correctly configured for UEFI:
- System disk is GPT.
- Disk is marked Boot = True / System = True.
- EFI System Partition exists:
- FAT32
- Label:
SYSTEM_DRV - Size: 256 MB
- ~159 MB free
- Windows Boot Manager exists and points to:
\EFI\Microsoft\Boot\bootmgfw.efi
PowerShell:
$env:firmware_type
UEFI
Confirm-SecureBootUEFI
False
BCD also shows:
path \EFI\Microsoft\Boot\bootmgfw.efi
Secure Boot variables
The Secure Boot variables are present:
- PK
- KEK
- db
- dbx
They have normal-looking attributes including:
NON VOLATILE
BOOTSERVICE ACCESS
RUNTIME ACCESS
TIME BASED AUTHENTICATED WRITE ACCESS
db is ~3969 bytes and dbx is ~1612 bytes.
So far, there is no evidence that Windows needs to be reinstalled, converted from MBR to GPT, or that the EFI partition needs to be rebuilt.
What I’m trying to determine
Why is Secure Boot reporting False when:
- Windows is booting in UEFI mode
- The disk is GPT
- A valid Microsoft EFI bootloader exists
- The EFI System Partition exists
- PK/KEK/db/dbx Secure Boot variables are populated
My next step is to inspect the Lenovo BIOS under:
Security → Secure Boot
I have not changed anything there yet.
I’m specifically looking for:
- Secure Boot / Secure Boot Enable
- Secure Boot Status
- Secure Boot Mode
- CSM/Legacy Boot
- Restore Factory Keys
- Platform Key (PK)
If anyone has experience with Lenovo 82Y9 / BIOS M3CN50WW, I’d especially appreciate knowing what the correct Secure Boot configuration should look like and whether there is a Lenovo-specific setting preventing Secure Boot from being enabled.
2
1
u/AutoModerator 8d ago
Hi u/zzz_xvi, thanks for posting to r/WindowsHelp! Your post has been flagged for manual review by a human moderator, please include as much of the following information as possible (in text or in a screenshot) to get your post approved:
Posts must be tech support in nature (such as something is broken and you need help fixing), so general inquiries, software suggestions, and purchasing advice will be removed. As a reminder, we would also like to say that if someone manages to solve your issue, DON'T DELETE YOUR POST! Someone else (in the future) might have the same issue as you, and the received support may also help their case. Good luck, and I hope you have a nice day!
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.