I've tried nearly every suggested fix for Secure Boot, but I still get the error: "Unauthorized changes have been detected on the firmware, operating system, or UEFI drivers." I've reset the Secure Boot keys, disabled CSM, enabled TPM 2.0, switched Windows to UEFI mode, and confirmed that the drive uses GPT. I'm using an ASUS motherboard and can't figure out what I'm missing. I'm also not sure how to check whether the BIOS needs an update.
2 Answers
It’s also worth checking the BIOS version and comparing it with the latest version listed on ASUS’s support page for your exact motherboard model. The version is usually shown on the BIOS main screen or in the system-information section. Update only with the file intended for that exact model, and don’t interrupt power during the update.
On ASUS motherboards, resetting or clearing the Secure Boot keys can leave the firmware in Setup Mode. Secure Boot won’t work properly in that state because the default keys are missing. Enter the BIOS and check the Secure Boot section for the Secure Boot State. If it says “Setup,” open Key Management and choose “Install Default Secure Boot Keys,” then save and restart. The state should change to “User.”

I’ll check the Secure Boot State and look through Key Management for the default-key option. I hadn’t realized clearing the keys could leave the system in Setup Mode.