How can I fix Secure Boot on an HP OMEN 25L without breaking Windows?

0
0
Asked By MellowCedar42 On

I have an HP OMEN 25L GT15-0xxx with an i5-12400F, RTX 4060, 16GB of RAM, a 2TB NVMe SSD, and Windows 11. I disabled Secure Boot previously because the computer was having boot problems, and Windows now starts normally with it disabled. However, I need Secure Boot enabled for Valorant/Vanguard. When I turn it back on, I get a "Secure Boot Violation" and "Boot Device Not Found" error and cannot reach Windows.

I found instructions saying to clear the Secure Boot keys, restore the factory keys, and use the BIOS option "Boot from EFI File" to launch securebootrecovery.efi, but I cannot find that file. I also have not been able to locate a useful BIOS update for this discontinued OMEN model. As far as I know, Windows is installed in UEFI mode and works correctly when Secure Boot is disabled.

Could this be caused by missing or corrupted Secure Boot keys, an incorrectly configured Windows installation, or something specific to the HP BIOS? I would prefer not to keep changing BIOS settings without knowing what is safe. What should I check or try first?

3 Answers

Answered By QuietOrbit88 On

The “Boot Device Not Found” message with Secure Boot enabled often means the firmware cannot validate the bootloader, not necessarily that the SSD has failed. In the BIOS, make sure Windows Boot Manager for the NVMe drive is the first boot entry, legacy/CSM boot is disabled, and the factory Secure Boot keys are installed. Do not repeatedly clear the keys unless you have a recovery plan, since that can make the system harder to boot until the correct keys are restored.

Answered By NorthwindLark19 On

Do not use a BIOS update or recovery file intended for a different OMEN 25L variant. GT15 models can have different motherboard and firmware revisions, even when the case and product name look similar. Find the complete product number and current BIOS version in the BIOS setup or Windows System Information, then use HP’s support page for that exact identifier. If HP provides no matching update, leave the BIOS alone rather than forcing a file from another model.

CopperVale6 -

The exact model and BIOS version are important here. A hardware-specification report or a clear photo of the BIOS information screen can help identify whether the firmware is outdated, but avoid downloading anything until the model matches exactly.

Answered By PixelHarbor7 On

First verify that Windows is actually installed for UEFI booting. In Windows, open System Information and check that BIOS Mode says UEFI. Also check Disk Management or a partition utility to confirm the system disk uses GPT rather than MBR. Secure Boot generally will not work with a legacy/MBR installation.

If those checks are correct, the usual recovery path is to restore the HP factory Secure Boot keys and use a USB drive containing the Secure Boot recovery file. The file will not normally be present somewhere on your existing Windows installation, so not finding it in the BIOS file browser is expected. Back up important data before changing keys or boot settings, and make sure the USB recovery files match the instructions for the exact OMEN model and BIOS version.

MellowCedar42 -

I have not tried the USB method yet because I do not currently have a USB drive. I was hoping there might be another option, but I will check the UEFI and GPT settings before changing anything else.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.