• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
HP Recommended
OMEN 30L Desktop PC GT13-1000a (207P7AV)

I have an HP OMEN 30L GT13-1074 (Product 399T3AA) with motherboard SSID 8876.

I updated the BIOS from F.19 to F.24 to address the AMD TPM firmware/attestation issue affecting newer games. The BIOS update successfully updated the AMD TPM firmware to 3.94.2.5, and Windows now reports that the TPM is fully ready for attestation.

However, after installing F.24, Secure Boot no longer works.

Current status:

  • BIOS: F.24
  • Motherboard/SSID: 8876
  • BIOS Mode: UEFI
  • TPM: 2.0
  • AMD TPM firmware: 3.94.2.5
  • TPM Ready for Attestation: True
  • TPM Capable for Attestation: True
  • Secure Boot State in Windows: Off
  • BIOS Platform Key: Not Enrolled
  • BIOS Pending Action: None
  • KEK and db Secure Boot variables are present

In PowerShell:

Confirm-SecureBootUEFI

returns:

False

And:

Get-SecureBootUEFI -Name PK

returns:

Variable is currently undefined: 0xC0000100

I have already attempted Load HP Factory Default Keys in BIOS. The BIOS showed the factory keys as a pending action for the next boot, but after rebooting, the Platform Key was still Not Enrolled.

I also performed the official Windows+B HP BIOS Recovery procedure. The recovery completed, but the system remained on F.24 and the Platform Key is still not enrolled.

I attempted to use HP's official F.19 BIOS package, but the HP BIOS utility prevents the downgrade because F.19 is older than F.24.

I do not want to manually clear or inject Secure Boot keys or force-flash an older BIOS.

This appears to be a BIOS F.24 firmware issue involving Platform Key enrollment on SSID 8876. Other users also appear to be experiencing Secure Boot problems with F.24.

Can an HP representative please escalate this to the BIOS/firmware team?

I am looking for either:

  1. An updated BIOS that fixes Platform Key enrollment/Secure Boot on SSID 8876, or
  2. An HP-supported method of rolling back from F.24 to a BIOS version where Secure Boot functions correctly.

Secure Boot is now preventing software/games that require hardware security attestation from functioning correctly.

1 REPLY 1
HP Recommended

Please see this discussion:

 

Re: Need help with BIOS update for OMEN desktop 30L 2MO1333H... - HP Support Community - 9701835

 

Unless you understand the risks and are willing to take the steps in the last reply on the above link to get the F.24 BIOS update to work, I would wait until HP releases an update to update the BIOS without any unpleasant surprises.

 

My understanding is that the HP system engineers are now working on a future BIOS update to fix this problem, but I have no idea on when that update will be available.

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->