-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
- HP Community
- Desktops
- Desktop Boot and Lockup
- Secure Boot signature error—BIOS F.32 compatible with Window...

Create an account on the HP Community to personalize your profile and ask a question
10-04-2026 12:22 PM
Hello,
I’m looking for guidance on restoring Secure Boot and safely updating my BIOS.
System details:
HP ENVY All-in-One 32-a1035
Motherboard/ROM family SSID: 86C7
Windows 11 Home, build 26200
Current BIOS: AMI F.22, dated February 5, 2021
BIOS mode: UEFI
The PC initially displayed “Boot Device Not Found—Hard Disk (3F0).” All the drive diagnostics I ran passed, including SMART, Short DST and the extended tests.
During troubleshooting, I also received “Secure Boot Violation—Invalid signature detected. Check Secure Boot Policy in Setup.”
After disabling Secure Boot and entering my BitLocker recovery key, Windows booted successfully and is currently working normally. Secure Boot remains disabled as a temporary workaround.
HP’s download page for my exact model lists BIOS F.32 Rev.A, dated December 4, 2024 (sp156058.exe). However, its supported operating systems list includes only Windows 10. HP Support Assistant also removed a BIOS update as “no longer applicable.” I have not installed F.32.
Could someone please clarify:
Is sp156058.exe supported for installation on this model running Windows 11? An official HP reference would be appreciated.
Can I update directly from F.22 to F.32, and what BitLocker precautions or alternative update method are required?
Is there a documented fix for the Secure Boot signature error, and how can I safely re-enable Secure Boot?
The download page warns that the BIOS cannot be downgraded afterward, so I would like to verify compatibility before proceeding. Thank you.
10-06-2026 04:26 AM
Hi @kawai9999
Welcome to the HP Support Community! We're here to help you get back up and running.
Thank you for providing the detailed information. We understand your concern regarding the Secure Boot violation message, BIOS compatibility, and the importance of confirming update support before proceeding.
Based on the information available for the HP ENVY All-in-One 32-a1035 (SSID 86C7):
BIOS F.32 Rev.A (sp156058.exe) is the latest BIOS released by HP for this platform. HP BIOS packages are designed for the system board and SSID, not solely the Windows version listed on the download page. If the SoftPaq specifically matches your model and SSID 86C7, it can be installed on a supported Windows 11 system. The operating system listing on the download page does not necessarily indicate incompatibility with Windows 11.
Updating directly from BIOS F.22 to F.32 is supported. Before performing the update:
- Back up important data.
- Suspend BitLocker protection from Windows Security before starting the BIOS update.
- Keep AC power connected throughout the process.
- Allow the BIOS update to complete without interruption.
- Re-enable BitLocker protection after the update is finished and Windows starts normally.
The "Secure Boot Violation - Invalid signature detected" message can occur when the Secure Boot keys or signature databases become out of sync. Since Windows boots normally with Secure Boot disabled and all storage diagnostics have passed, updating to the latest HP BIOS is a reasonable first step because BIOS updates commonly include Secure Boot, UEFI, and platform security improvements.
After updating to F.32:
- Enter BIOS Setup.
- Load BIOS defaults.
- Verify UEFI Boot Mode is enabled.
- Re-enable Secure Boot.
- Save changes and restart.
If the Secure Boot message returns after the BIOS update, please share whether the system is using the factory-installed Windows image or a customized installation, as that can help determine whether the issue is related to Secure Boot key enrollment or bootloader validation.
Given your current BIOS is F.22 from 2021 and HP has released F.32 in 2024 for the same platform, updating the BIOS first is the safest and most appropriate path before attempting additional Secure Boot remediation.
This approach also aligns with HP's guidance to maintain the latest BIOS revision for security, stability, and Windows 11 compatibility.
Take care, and have an amazing day!
Regards,
Hawks_Eye
I'm an HP Employee.
If this reply helped resolve your issue, please select the Accept as Solution as it helps others in the community quickly find the answer they’re looking for.
And if you found this reply helpful, clicking Yes below is a great way to let us know we’re providing the support you need, as it encourages us to keep improving and sharing helpful guidance.