• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
HP Recommended
Pro Mini 400 G9

I want to modify the BIOS settings on an HP Pro Mini 400 G9 PC.
I am trying to use BiosConfigUtility64.exe to configure the various settings.
I am unable to "enable" or "disable" the Secure Boot setting; I receive error code 4.
The command line provided in the manual is `BiosConfigUtility64 /setvalue:"Secure Boot","Enable"` to enable it, but this is unsuccessful.
Are there any prerequisites or a specific sequence required to perform this operation? I cannot access the computer directly; I am working remotely.
Thanks for any help.

 

Below, extract from the BIOS Configuratio:

Product Family
103C_53307F HP ProDesk
TPM Specification Version
2.0
TPM Device
Hidden
*Available
TPM State
Disable
*Enable
Clear TPM
*No
On next boot
TPM Activation Policy
F1 to Boot
*Allow user to reject
No prompts
Verify Boot Block on every boot
Disable
*Enable
Sure Start BIOS Settings Protection
*Disable
Enable
Sure Start Secure Boot Keys Protection
Disable
*Enable
Enhanced HP Firmware Runtime Intrusion Prevention and Detection
Disable
*Enable
Sure Start Security Event Boot Notification
Time out after 15 seconds
*Require Acknowledgment
Sure Start Security Event Policy
Log Event Only
*Log Event and notify user
Log Event and power off system
Secure Boot
*Disable
Enable
Import Custom Secure Boot keys
*Do Nothing
On next boot
Clear Secure Boot keys
*Disable
Enable
Reset Secure Boot keys to factory defaults
*Disable
Enable
Enable MS UEFI CA key
*No
Yes
Ready to disable MS UEFI CA Key
Not Ready
*Ready
Custom Keys Image Verification State
*No Custom Keys
Fail
Success
Ready BIOS for Device Guard Use
*Do Nothing
Configure on Next Boot
Clear Configuration on Next Boot
Secure Boot Platform Key
HP
Secure Platform Management Key Endorsement Certificate
 
Secure Platform Management Signing Key
 
Secure Platform Management Current State
Not provisioned
Secure Platform Management Version
1.00
Secure Platform Management Usage Bitmask
0x0000
Secure Platform Management Counter
0
Secure Platform Management Key Endorsement Key
 
Enhanced BIOS Authentication Mode
*Disable
Enable
Enhanced BIOS Authentication Mode Version
1.01
Enhanced BIOS Authentication Mode Local Access Key 1
 
Enhanced BIOS Authentication Mode Settings Anti-Replay Counter
0
Enhanced BIOS Authentication Mode Actions Anti-Replay Counter

 

 

1 REPLY 1
HP Recommended

Hi @HM31100 

 

Welcome to the HP Support Community.

 

Thank you for posting your query.

 

Thank you for the detailed information. I understand you've already attempted to enable Secure Boot using HP BIOS Configuration Utility (BCU) and are receiving WMI Result Code 4 (Operation Failed). This error typically indicates that the BIOS has rejected the requested change due to unmet prerequisite, a BIOS security restriction, or a platform limitation. Let's verify the required BIOS conditions and configuration to determine why the setting cannot be modified and identify the appropriate next steps.

 

Yes, Secure Boot is a security-sensitive BIOS setting, and certain prerequisites may need to be met before it can be modified remotely using BCU. Please verify the following:

  • Ensure the system is configured to boot in UEFI mode and that Legacy Support is disabled.
  • Confirm that the BIOS administrator (Setup) password is provided if one is configured, as some security settings cannot be changed without authentication.
  • Verify that the system is running the latest BIOS version and that you are using a BCU version supported for the HP Pro Mini 400 G9.
  • Check whether BIOS protection features such as HP Sure Start BIOS Settings Protection or Enhanced BIOS Authentication Mode are preventing remote modifications.
  • Export the BIOS configuration (/GetConfig) and confirm that Secure Boot is exposed as a configurable setting for your platform.
  • If related settings (such as boot mode or Secure Boot keys) have recently been changed, reboot the system before attempting to modify Secure Boot.

If all prerequisites are satisfied and WMI Result Code 4 (Operation Failed) continues to occur, the platform may not allow Secure Boot to be changed remotely through BCU.

 

Click Here for Detailed information

 

Take care and have an amazing day!

I'm an HP Employee.


If this reply helped resolve your issue, please select the Accept as Solution as it helps others in the community quickly find the answer they’re looking for.


And if you found this reply helpful, clicking Yes below is a great way to let us know we’re providing the support you need, as it encourages us to keep improving and sharing helpful guidance.

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->