• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
HP Recommended
Microsoft Windows 11

Hi, I’m having a Secure Boot firmware issue with my HP Pavilion Gaming Desktop TG01-2xxx (motherboard 8906).

My BIOS is currently F.40. Windows is installed in UEFI mode and TPM is enabled. BIOS shows Secure Boot enabled, but Platform Key (PK) says “Not Enrolled.” Windows shows Secure Boot State: Off.

I checked through PowerShell:

* Confirm-SecureBootUEFI → False
* Get-SecureBootUEFI -Name PK → “Variable is currently undefined”

I have already updated from BIOS F.38 to F.40, loaded HP Factory Default Secure Boot Keys, loaded BIOS defaults, cleared/re-enabled TPM, toggled Secure Boot, and attempted HP BIOS recovery. None of this has enrolled the PK.

I believe the Platform Key/Secure Boot variables are not being properly written to the firmware/NVRAM.

Please escalate this as a BIOS/firmware issue and check whether there is a firmware fix, deeper HP BIOS recovery/reflash procedure, or whether the motherboard needs service. I do not want to repeat the standard factory-key/TPM troubleshooting because I have already completed it multiple times.

1 REPLY 1
HP Recommended

Greetings,

 

Opinions or troubleshooting suggestions in this response are provided independently. I am not employed by: HP, Inc. or the HP Forum.

 

Check your PC's Secure Boot status in Windows Security>Device security.

 

Your PC's problem sounds like a Windows 2023 security certificate/ HP firmware PK database problem.

 

HP has decided to forego updating TG01-2xxxa series PCs to the latest TPM 2.0 version (3.92.5.5). Your PC's 8906 MB is an AMD MB

 

It's possible your PC may not see a future PK database update. I don't know?

 

Or BIOS version F.40 needs a future BIOS revision to fix an unintended F.40 compiling/debugging error.

 

Regards

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->