-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
- HP Community
- Desktops
- Desktop Hardware and Upgrade Questions
- Re: I can't get secure boot to activate

Create an account on the HP Community to personalize your profile and ask a question
06-14-2026 06:35 AM - edited 06-14-2026 06:36 AM
Secure boot cannot be enabled because all UEFI secure boot key variables are missing. In windows powershell, "Get-SecureBootUEFI" returns as "Variable is currently undefined" for PK, KEK, and db. In BIOS, platform key shows "Not Enrolled" and secure boot cannot be properly activated. Using "Load HP Factory Default Keys" completes and clears pending action, but doesn't populate any secure boot keys and platform key remains not enrolled after reboot.
System Details :
HP Omen 40L GT21 series
Motherboard - 8949
BIOS - F.38 (updated/reflashed, no change)
TPM 2.0 - enabled, functional
Secure boot state - off (can't be turned on due to missing keys)
I've been up all night trying to fix this and i genuinely have no clue what to do anymore. My sanity is low. Please help.
Solved! Go to Solution.
Accepted Solutions
06-14-2026 06:59 AM
Greetings,
I don't work for HP.
I have been seeing many folks in this Forum, using various HP MBs, having the same Secure Boot data base problem you are having.
My guess is: the HP team responsible for firmware updates erroneously removed Secure Boot data when preparing the latest BIOS updates for the affected MBs.
I would say you'll have to check for a future BIOS update which, hopefully, fixes this problem. There is nothing you can personally do to solve the problem.
Regards
06-14-2026 06:59 AM
Greetings,
I don't work for HP.
I have been seeing many folks in this Forum, using various HP MBs, having the same Secure Boot data base problem you are having.
My guess is: the HP team responsible for firmware updates erroneously removed Secure Boot data when preparing the latest BIOS updates for the affected MBs.
I would say you'll have to check for a future BIOS update which, hopefully, fixes this problem. There is nothing you can personally do to solve the problem.
Regards