-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
- HP Community
- Notebooks
- Business Notebooks
- What HP Device do I own?

Create an account on the HP Community to personalize your profile and ask a question
06-16-2026 10:44 AM
I purchased the device -- HP Laptop PC 17-by4000 (18B36AV) -- on which I'm writing this Problem Description in June 2024 from Amazon Renewed. The device that was subsequently delivered to me is labeled as an HP ZBook 15u G5 Mobile Workstation according to the information printed on the case. However, when HP scans the device online, it is reported as an HP Elite Book X360 1030 G2. ???
To date, I've been very satisfied with the device, but am now struggling with Secure Boot Certificate updates primarily because the HP System Information app tells me that it is using BIOS Q78 V.01.31.00 whereas HP's online scan says the BIOS in use is HPNotebookSystemBIOS (P80) Update 01.51 REV A, 4/3/25.
The machine, of course, is out of warranty. I'm at a complete loss what to do here.
Appreciate any assistance. Thanks.
Solved! Go to Solution.
Accepted Solutions
06-20-2026 09:57 AM - edited 06-20-2026 09:58 AM
You're very welcome.
Yes, your PC fully meets Microsoft's minimum W11 requirements.
Regarding the 2018 date...I wouldn't know. I'm thinking by now your PC should have gotten the automatic secure boot 2023 certificate updates.
I have two PCs that got those updates. One in January 2026 and the other PC got the updates in March of 2026
Unless there is a reason you want to stay on W10, even with the extended OS security support, that will end in October of this year, so you may want to take advantage of the free upgrade period to W11 because that may not last indefinitely.
As far as the notice on the top of the support page, that does not seem related to the secure boot certificate updates and one of the steps to resolve the issue was to update the BIOS to the latest version, which you already did.
The Microsoft guidance for applying Secure Boot DBX update (KB4575994) is no longer applicable.
Microsoft guidance for applying Secure Boot DBX update (KB4575994) - Microsoft Support
I would imagine that since your notebook did not present the error, that it probably will not happen at this time.
Another thing you can check before trying to manually update the secure boot certificates is to see if there is a known problem that is preventing the secure boot certificates from updating.
I have two HP PC's that are presenting the 3rd message down on the list I posted below, and 3 PCs that are presenting the 5th message down on the list.
The 3 that are presenting the 5th message on the list have the 2023 secure boot certificates installed in Windows, but are not installed in the BIOS.
I'm not surprised by that since none of the PCs are supported to run W11, but I run W11 on them anyway.
Go to Settings>Privacy and Security>Windows Security>Device Security and check the Secure Boot Status.
It should show one of the following messages:
If you see this message in the Secure Boot sectionWhat you should do
Secure Boot is on and all required certificate updates have been applied. No further certificate changes are needed. | No action is needed. |
Secure Boot is on, but your device is using an older boot trust configuration that should be updated. | Make sure your device has the latest Windows updates installed. Restart if prompted. |
Secure Boot is on, but your device is affected by a known issue. To reduce risk, Secure Boot certificate updates are temporarily paused while Microsoft and partners work toward a supported resolution. The update will resume automatically once resolved. | No action is needed. The certificates update will resume automatically once the issue is resolved. |
Secure Boot is on, but your device is using an older boot trust configuration that should be updated. There is not yet enough data to classify your device for automatic update. Visit the link below for more information. | Your device might need additional validation before the update can proceed automatically. Visit aka.ms/getsecureboot for more information. |
Secure Boot is on, but your device does not support the automated Secure Boot certificate update due to hardware or firmware limitations. Contact your device manufacturer for assistance. | Contact your device manufacturer for assistance. |
Secure Boot is on, but this device can no longer receive required updates for the Windows boot experience. | Your device is still using an old certificate after the expiration dates. Visit aka.ms/getsecureboot for guidance. |
06-16-2026 12:17 PM - edited 06-16-2026 12:21 PM
I suggest that you enter the PC's serial number in the search window at the link below to see what the HP PartSurfer database describes your PC as.
The ZBook 15u G5 Mobile Workstation is newer than the HP Elite Book X360 1030 G2.
The ZBook 15u G5 Mobile Workstation is supported by HP and Microsoft to run Windows 11 if it has an Intel 8th gen core processor. Some of the models came with Intel 7th gen core processors.
The HP Elite Book X360 1030 G2 is not supported by HP or Microsoft to run W11 because the Intel 7th gen core processors offered in the model series do not meet Microsoft's minimum W11 Intel processor requirements of an Intel 8th gen core or newer processor.
The ZBook 15u G5 Mobile Workstation has a 15.6" display and the HP Elite Book X360 1030 G2 has a 13.3" display.
06-19-2026 04:53 PM - edited 06-19-2026 04:56 PM
Thank you for your reply.
Using the information listed on the bottom of the device, which identifies it as an HP ZBook 15u G5, I entered the serial number in HP PartSurfer's Generic Search and it identified the device as an HP EliteBook x360 1030 G2.
I then went to the HP ZBook 15u G5 Mobile Workstation product support page and ran the HP System Information app on the same device and it returned an entirely different serial number. I then entered this different serial number in HP PartSurfer's Generic Search and it identified the device as an HP ZBook 15u G5.
However, it also reported "Multiple Products associated for above Serial Number" and suggested "Please Select a Product Number" from a list of two Devices: one General (Product Family) and one Advance (Unique Product S/N).
At this point, I feel reassured that this device is in fact an HP ZBook 15u G5 running BIOS Q78 Ver. 01.31.00, 3/10/25, which appears to be the most recent BIOS available. But I'm still struggling with Secure Boot Certificate updates.
I've sifted thru the Bulletins and Alerts available for the device and installed a few of the updates to no avail. I'm concerned that having two serial numbers associated with this device may be preventing any firmware containing the certificate updates from reaching this device. Hope that I'm wrong about that.
06-19-2026 05:15 PM
You're very welcome.
The serial numbers or model numbers won't affect whether or not your PC gets the 2023 secure boot certificate updates.
Your PC may be on the border of getting or not getting an automatic 2023 secure boot certificate updates based on the date of manufacture as set forth in the link below:
HP Business PCs - Prepare for new Windows Secure Boot certificates | HP® Support
All Secure Boot-enabled HP Commercial PCs released in 2019 and later, in addition to select 2018 products, are supported with new certificates. To be supported, systems (a) must be able to run Windows 11 or Windows 10 IoT LTSC, and (b) meet Windows processor requirements for Windows 11.
Intel PC's meeting Windows processor requirements for W11 must be Intel 8th gen or newer Core processors.
Check the 4th character of your PC's serial number.
If it is an 8, then it was made in 2018 and if it is a 9, then it was made in 2019.
Have you tried manually updating the secure boot certificates?
06-20-2026 09:22 AM
Thank you for the advice and information. Before I try manually updating the secure boot certificates, let me confirm a few things that you've noted.
The 4th character of my device's serial number IS an 8 indicating a 2018 birthday. As such, the HP ZBook 15u G5 does NOT appear to be included in the 'Supported HP Commercial platforms and minimum BIOS versions list' as either a Business Notebook or a Mobile Workstation. Should I take this to mean it is NOT likely one of the "select 2018 products" that may eventually be supported with new certificates?
Regarding the Windows processor requirements, the PC has a Intel® Core™ i7-8650U with Intel® UHD Graphics 620. According to Intel, this is an 8th Generation Intel® Core™ i7 Processor.
With respect to the operating system, the device is currently running Windows 10 Pro 64 Version 22H2 ESU. Further, Windows Update notes that "Your PC meets the minimum system requirements for Windows 11".
Lastly, on the HP ZBook 15u G5 product support page, there is an alert advising "Product may experience a HP Secure Boot error after installing a cumulative Microsoft Security Update." Can I safely assume that this should be resolved before manually updating the secure boot certificates?
Thanks again.
06-20-2026 09:57 AM - edited 06-20-2026 09:58 AM
You're very welcome.
Yes, your PC fully meets Microsoft's minimum W11 requirements.
Regarding the 2018 date...I wouldn't know. I'm thinking by now your PC should have gotten the automatic secure boot 2023 certificate updates.
I have two PCs that got those updates. One in January 2026 and the other PC got the updates in March of 2026
Unless there is a reason you want to stay on W10, even with the extended OS security support, that will end in October of this year, so you may want to take advantage of the free upgrade period to W11 because that may not last indefinitely.
As far as the notice on the top of the support page, that does not seem related to the secure boot certificate updates and one of the steps to resolve the issue was to update the BIOS to the latest version, which you already did.
The Microsoft guidance for applying Secure Boot DBX update (KB4575994) is no longer applicable.
Microsoft guidance for applying Secure Boot DBX update (KB4575994) - Microsoft Support
I would imagine that since your notebook did not present the error, that it probably will not happen at this time.
Another thing you can check before trying to manually update the secure boot certificates is to see if there is a known problem that is preventing the secure boot certificates from updating.
I have two HP PC's that are presenting the 3rd message down on the list I posted below, and 3 PCs that are presenting the 5th message down on the list.
The 3 that are presenting the 5th message on the list have the 2023 secure boot certificates installed in Windows, but are not installed in the BIOS.
I'm not surprised by that since none of the PCs are supported to run W11, but I run W11 on them anyway.
Go to Settings>Privacy and Security>Windows Security>Device Security and check the Secure Boot Status.
It should show one of the following messages:
If you see this message in the Secure Boot sectionWhat you should do
Secure Boot is on and all required certificate updates have been applied. No further certificate changes are needed. | No action is needed. |
Secure Boot is on, but your device is using an older boot trust configuration that should be updated. | Make sure your device has the latest Windows updates installed. Restart if prompted. |
Secure Boot is on, but your device is affected by a known issue. To reduce risk, Secure Boot certificate updates are temporarily paused while Microsoft and partners work toward a supported resolution. The update will resume automatically once resolved. | No action is needed. The certificates update will resume automatically once the issue is resolved. |
Secure Boot is on, but your device is using an older boot trust configuration that should be updated. There is not yet enough data to classify your device for automatic update. Visit the link below for more information. | Your device might need additional validation before the update can proceed automatically. Visit aka.ms/getsecureboot for more information. |
Secure Boot is on, but your device does not support the automated Secure Boot certificate update due to hardware or firmware limitations. Contact your device manufacturer for assistance. | Contact your device manufacturer for assistance. |
Secure Boot is on, but this device can no longer receive required updates for the Windows boot experience. | Your device is still using an old certificate after the expiration dates. Visit aka.ms/getsecureboot for guidance. |
06-23-2026 08:12 AM
Yes, I have the "Secure Boot is on, but your device is affected by a known issue." message under Device Security Secure Boot. Apparently 'Take a number and have a seat' is my only option at this point.
Thank you for for your advice and guidance.