• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines

Featured blog article:

HP Recommended
HP ENVY All-in-One - 32-a1035

Hello,

I’m looking for guidance on restoring Secure Boot and safely updating my BIOS.

System details:

  • HP ENVY All-in-One 32-a1035

  • Motherboard/ROM family SSID: 86C7

  • Windows 11 Home, build 26200

  • Current BIOS: AMI F.22, dated February 5, 2021

  • BIOS mode: UEFI

The PC initially displayed “Boot Device Not Found—Hard Disk (3F0).” All the drive diagnostics I ran passed, including SMART, Short DST and the extended tests.

During troubleshooting, I also received “Secure Boot Violation—Invalid signature detected. Check Secure Boot Policy in Setup.”

After disabling Secure Boot and entering my BitLocker recovery key, Windows booted successfully and is currently working normally. Secure Boot remains disabled as a temporary workaround.

HP’s download page for my exact model lists BIOS F.32 Rev.A, dated December 4, 2024 (sp156058.exe). However, its supported operating systems list includes only Windows 10. HP Support Assistant also removed a BIOS update as “no longer applicable.” I have not installed F.32.

Could someone please clarify:

  1. Is sp156058.exe supported for installation on this model running Windows 11? An official HP reference would be appreciated.

  2. Can I update directly from F.22 to F.32, and what BitLocker precautions or alternative update method are required?

  3. Is there a documented fix for the Secure Boot signature error, and how can I safely re-enable Secure Boot?

The download page warns that the BIOS cannot be downgraded afterward, so I would like to verify compatibility before proceeding. Thank you.

1 REPLY 1
HP Recommended

Hi @kawai9999 

 

Welcome to the HP Support Community! We're here to help you get back up and running.

 

Thank you for providing the detailed information. We understand your concern regarding the Secure Boot violation message, BIOS compatibility, and the importance of confirming update support before proceeding.

 

Based on the information available for the HP ENVY All-in-One 32-a1035 (SSID 86C7):

 

BIOS F.32 Rev.A (sp156058.exe) is the latest BIOS released by HP for this platform. HP BIOS packages are designed for the system board and SSID, not solely the Windows version listed on the download page. If the SoftPaq specifically matches your model and SSID 86C7, it can be installed on a supported Windows 11 system. The operating system listing on the download page does not necessarily indicate incompatibility with Windows 11.

 

Updating directly from BIOS F.22 to F.32 is supported. Before performing the update:

  • Back up important data.
  • Suspend BitLocker protection from Windows Security before starting the BIOS update.
  • Keep AC power connected throughout the process.
  • Allow the BIOS update to complete without interruption.
  • Re-enable BitLocker protection after the update is finished and Windows starts normally.

 

The "Secure Boot Violation - Invalid signature detected" message can occur when the Secure Boot keys or signature databases become out of sync. Since Windows boots normally with Secure Boot disabled and all storage diagnostics have passed, updating to the latest HP BIOS is a reasonable first step because BIOS updates commonly include Secure Boot, UEFI, and platform security improvements.

 

After updating to F.32:

  • Enter BIOS Setup.
  • Load BIOS defaults.
  • Verify UEFI Boot Mode is enabled.
  • Re-enable Secure Boot.
  • Save changes and restart.

 

If the Secure Boot message returns after the BIOS update, please share whether the system is using the factory-installed Windows image or a customized installation, as that can help determine whether the issue is related to Secure Boot key enrollment or bootloader validation.

 

Given your current BIOS is F.22 from 2021 and HP has released F.32 in 2024 for the same platform, updating the BIOS first is the safest and most appropriate path before attempting additional Secure Boot remediation. 

 

This approach also aligns with HP's guidance to maintain the latest BIOS revision for security, stability, and Windows 11 compatibility.

 

 

Take care, and have an amazing day!

 

Regards, 

Hawks_Eye

I'm an HP Employee.


If this reply helped resolve your issue, please select the Accept as Solution as it helps others in the community quickly find the answer they’re looking for.


And if you found this reply helpful, clicking Yes below is a great way to let us know we’re providing the support you need, as it encourages us to keep improving and sharing helpful guidance.

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->