• ×
    Information
    Windows update impacting certain printer icons and names. Microsoft is working on a solution.
    Click here to learn more
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Windows update impacting certain printer icons and names. Microsoft is working on a solution.
    Click here to learn more
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Any failures related to Hotkey UWP service? Click here for tips.
HP Recommended
Z230
Microsoft Windows 10 (64-bit)

Hi,

 

We are testing Windows 10 1809 deployment in our environment. I have come across an issue when rebooting \ restarting the Z230. The workstations shuts down instead of restarting. So far I have tried

 

1) Installing all the latest drivers from the HP support site

2) Updating the BIOS to latest firmware and resetting the BIOS to default settings

3) Disabling fast start-up in Windows 10

 

Howeever the issue remains, have also tried in 3 additional Z230s with the same issue. Any help will be appreciated.

 

Thanks

1 ACCEPTED SOLUTION

Accepted Solutions
HP Recommended

I managed to workaround the issue so thought it would be good to share it here. The issue seems to be when you have Windows Device\Credential guard Virtualisation Based Security enabled. This was turned on in GPO https://docs.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-gu...

 

Removing the GPO does not disable DG\CG, have to use the Device Guard and Credential Guard hardware readiness tool to properly disable DG\CG https://www.microsoft.com/en-us/download/details.aspx?id=53337 

 

Once disabled the Z230 was rebooting correctly again. So although the readiness tool reports that DG\CG can be enabled with some caveats (see pic), there is a bug (either HP drivers\BIOS or Windows) which is causing the issue. So at this moment, disabling DG\CG allows the Z230 to restart correctly. I believe this impacts the EliteDesk 800 G1s (maybe G2s) as well but need further testing. For now unfortunatley I cant take advantage of platform security features in Windows 10 of secure boot and virtualization based security with the Z230.

DeviceGuard.png

 

UPDATE

After further testing I was able to get secure boot & credential guard working with these GPO settings. Note - Virtualization Secure launch Configuration set to Not Configured - TPM attestation issue if enabled on Z230/G1. Virtualization Based Protection of Code Integrity set to Not Configured - Restart will shutdown if configured on Z230/G1.

 

Annotation 2019-05-20 191536.png

View solution in original post

6 REPLIES 6
HP Recommended

Did you perform clean Windows 10 installation or just update?

 

I would recommend clean install, it commonly solves numerous ussies.

HP Recommended

Thanks, however these are all fresh installs of Windows 10 1809 with the drivers made availbe on HP's drivers page for Windows 10 64-bit. We are having problems with every single Z230 workstations unable to restart properly. The PC would shutdown instead of restart and requires manual intervention.

HP Recommended

Sorry to hear that. Unfortunately I have no experience with your computer model, so it could be just wild guess from my side. Probably somebody else at this forum could provide you with better advice.

 

The problems you described commonly are related to BIOS and/or power issues. But according to your description, it happens right after your systems upgrade. So it might be either OS or... BIOS issue.

 

Did you try your system after OS upgrade but before BIOS upgrade? For example, there was a new BIOS revision issue with my computer model, so I waited long time while they fix the problem. As I understand, there is no simple way to downgrade your BIOS revision. It is common with HP workstations.

 

BTW. Did you try to disable Embedded security device? It is a standard source of different kind of problems.

HP Recommended

We need TPM so disabling Embeded Security Device is not an option for us. I did try diabling Intel AMT as suggested by others in a different forum but still no joy. I've tested on an Elite Desk 800 G1 and that is also having the same issue. 😞 

HP Recommended

If you have an option to temporarily disable Embeded Security Device and then enable again, it could give you a hint.

 

If you discover your power-up problem fixed after disabling Embeded Security Device, the most probably you could lay the blame on the newest BIOS update.

HP Recommended

I managed to workaround the issue so thought it would be good to share it here. The issue seems to be when you have Windows Device\Credential guard Virtualisation Based Security enabled. This was turned on in GPO https://docs.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-gu...

 

Removing the GPO does not disable DG\CG, have to use the Device Guard and Credential Guard hardware readiness tool to properly disable DG\CG https://www.microsoft.com/en-us/download/details.aspx?id=53337 

 

Once disabled the Z230 was rebooting correctly again. So although the readiness tool reports that DG\CG can be enabled with some caveats (see pic), there is a bug (either HP drivers\BIOS or Windows) which is causing the issue. So at this moment, disabling DG\CG allows the Z230 to restart correctly. I believe this impacts the EliteDesk 800 G1s (maybe G2s) as well but need further testing. For now unfortunatley I cant take advantage of platform security features in Windows 10 of secure boot and virtualization based security with the Z230.

DeviceGuard.png

 

UPDATE

After further testing I was able to get secure boot & credential guard working with these GPO settings. Note - Virtualization Secure launch Configuration set to Not Configured - TPM attestation issue if enabled on Z230/G1. Virtualization Based Protection of Code Integrity set to Not Configured - Restart will shutdown if configured on Z230/G1.

 

Annotation 2019-05-20 191536.png

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.