# Invalid Signature Detected Secure Boot Policy: Fix

Source: https://srvscripts.com/guides/invalid-signature-detected-secure-boot/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

The message “Invalid Signature Detected. Check Secure Boot Policy in Setup” comes from the system firmware, not from Windows. It means Secure Boot is enabled and the firmware refused to run a boot component whose signature is missing, untrusted or has been added to the revocation database (DBX). It can appear on Windows 10, Windows 11 (25H2 and 26H1 alike), Windows Server 2019/2022/2025, dual-boot machines and virtual machines with a UEFI firmware. The fix depends on which component failed, so the first job is to find out.

In short: Boot into the UEFI setup, check whether Secure Boot is in “Standard” mode with the Microsoft Windows and UEFI CA keys, and confirm the boot entry points to the Windows Boot Manager on the EFI partition.

**Short answer:** Boot into the UEFI setup, check whether Secure Boot is in “Standard” mode with the Microsoft Windows and UEFI CA keys, and confirm the boot entry points to the Windows Boot Manager on the EFI partition. If a third-party loader (older Linux shim, a recovery tool or a vendor imaging utility) is first in the boot order, move Windows first or update that loader. If the Windows Boot Manager itself is rejected, the DBX has revoked it: boot from current installation media, rebuild the EFI boot files with `bcdboot`, and apply the 2023 Secure Boot certificate update through Windows Update.

## Identify what the firmware rejected

The dialog rarely names the file. Enter the firmware setup (usually F2, Del or F12 at power-on) and look at the boot order. Common culprits:

- A Linux distribution’s shim or GRUB from a dual-boot setup, revoked by a DBX update pushed through Windows Update.

- Bootable USB or PXE images built with an old bootmgfw.efi that has since been revoked.

- Windows itself after the EFI partition was restored from a backup that predates the certificate rollover, or after a firmware update reset the key store.

- Hypervisors: a VMware or Hyper-V VM whose virtual firmware has only the older Microsoft UEFI CA 2011 trusted.

On a machine that still boots, examine the Secure Boot state from an elevated PowerShell prompt:

```
Confirm-SecureBootUEFI
Get-SecureBootUEFI -Name PK | Format-List
Get-SecureBootUEFI -Name db | Format-List Bytes
reg query HKLM\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing /v UEFICA2023Status
```

`UEFICA2023Status` reports whether the new Windows UEFI CA 2023 certificate has been added to the db and the boot manager updated to one signed by it; a value other than “Updated” or the equivalent means the rollover has not completed.

## Fix a third-party loader in the boot order

If the rejected item is a Linux or vendor loader, simply select the Windows Boot Manager entry in the firmware boot menu and make it first. Update the other loader from within its own operating system afterwards. Do not disable Secure Boot as the first move; Windows 11 devices under Intune compliance and BitLocker with TPM+PIN can flag or require recovery keys when Secure Boot state changes.

## Repair the Windows boot files

When the Windows Boot Manager itself is refused, boot from installation media that is at least the 2024 build (which carries the newer signed boot manager), open a command prompt from Repair your computer » Troubleshoot » Command Prompt, and rebuild the EFI files:

```
diskpart
list vol
select vol
assign letter=S
exit
bcdboot C:\Windows /s S: /f UEFI
```

Reboot. If the error persists, the firmware’s db lacks the Windows UEFI CA 2023 certificate. Enter setup, look for a “Restore factory keys” or “Install default Secure Boot keys” option, apply it and retry. Firmware from 2024 onward ships the 2023 CA; older systems need a BIOS update from the vendor.

## Virtual machines

On ESXi 8 and 9, a Windows VM that suddenly fails with this message after a boot manager update needs the virtual firmware’s certificate store refreshed. Power the VM off, edit settings » VM Options » Boot Options, and ensure Secure Boot is enabled with the current EFI firmware. On ESXi 8.0 U3 and later the NVRAM can be reset by removing the VM’s .nvram file from the datastore while powered off; the host recreates it with the current default key set on next power-on. Hyper-V uses the “Microsoft UEFI Certificate Authority” template for non-Windows guests and “Microsoft Windows” for Windows; pick the right one under Settings » Security.

## Verify

After repair, the machine should boot straight to Windows with Secure Boot still on:

```
Confirm-SecureBootUEFI
msinfo32
```

System Information should show BIOS Mode: UEFI and Secure Boot State: On. Then run Windows Update to let the certificate servicing task complete, and check the `UEFICA2023Status` value again a day later.

## Common pitfall

Disabling Secure Boot to make the error go away leaves BitLocker prompting for the recovery key at every boot (because PCR 7 changed) and, under Intune compliance, can mark the device non-compliant so conditional access blocks it. Fix the trust store or the loader instead, and if you must toggle Secure Boot temporarily, suspend BitLocker first with `manage-bde -protectors -disable C:`.

## Invalid Signature Detected Secure Boot at a glance

**Official documentation:** [Windows client documentation](https://learn.microsoft.com/en-us/windows/), [Windows Server documentation](https://learn.microsoft.com/en-us/windows-server/).

**Related guides:** [Offboarding an employee: checklist for Active Directory, Microsoft 365, Google Workspace and Zoho](https://srvscripts.com/guides/employee-offboarding-checklist/) · [Disable RDP drive, clipboard and USB redirection with Group Policy](https://srvscripts.com/guides/disable-rdp-drive-redirection-gpo/) · [Set up Windows LAPS on Windows Server 2025 and Windows 11](https://srvscripts.com/guides/windows-laps-setup/).

## Frequently asked questions

### Does this error also appear on Windows Server 2025?

Yes. Windows Server 2025 on UEFI hardware uses the same Secure Boot chain, and the 2023 certificate rollover applies to it. The bcdboot and firmware steps are identical; the main difference is that servers often run older firmware that needs a vendor update to carry the new CA.

### How long does the Secure Boot certificate update take to apply?

Once the firmware trusts the 2023 CA, the Windows servicing task updates the boot manager on the next reboot after the relevant cumulative update, so allow two reboots. Fleet-wide, expect the rollover to be gradual because Microsoft gates it on firmware readiness.

### Can I undo the bcdboot repair?

bcdboot only rewrites the boot files on the EFI partition; it does not touch Windows itself. Rerunning it, or restoring the EFI partition from backup, reverts the change, though restoring an old boot manager will bring the signature error back on a firmware with an updated DBX.
