Secure Boot worked normally until I cleared the CMOS last week. Since then, my Windows installation will boot with UEFI and CSM enabled, or with CSM disabled while Secure Boot is off, but enabling Secure Boot causes the computer to restart straight back into the BIOS instead of loading Windows. The system drive is GPT and BIOS mode is set to UEFI. I have already tried repairing the EFI boot files with bootrec and bcdboot, clearing and reinstalling the Secure Boot keys, and switching Secure Boot to Standard mode. The BIOS reports Secure Boot as enabled, but Windows still will not start with it active. The motherboard is an ASRock B450M-HDV, and I am trying to figure out what changed after the CMOS reset.
2 Answers
The CMOS reset probably removed or reverted the Secure Boot databases. Update the motherboard BIOS to a recent version that includes the current Secure Boot certificates, then enter the firmware settings and use the option to load or install the default Secure Boot keys. After that, leave the system in UEFI mode, disable CSM, and try enabling Secure Boot again.
It is also worth checking whether the graphics card needs a VBIOS update. UEFI and Secure Boot initialization involve the GPU firmware too, and some older cards have compatibility problems when CSM is disabled. Updating both the motherboard BIOS and, if available, the GPU VBIOS would be the next step.

Related Questions
Lenovo Thinkpad Stuck In Update Loop Install FilterDriverU2_Reload