-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
- HP Community
- Notebooks
- Notebook Boot and Lockup
- Secure Boot Violation

Create an account on the HP Community to personalize your profile and ask a question
08-25-2026 01:47 PM
On booting my HP computer, I get a message: "Secure Boot Violation. Invalid signature detected. Check secure boot policy. However, if I disable secure boot in BIOS computer boots just fine. I have tried to remove security keys and restore factory defaults, but nothing seems to help. I need to add that, prior to that, a virus visited my computer. So I ran McAfee, and as of now, all scans are clean.
Any suggestions?
08-25-2026 11:46 PM
Hi,
Since the computer boots when Secure Boot is disabled, the hardware is probably not the main problem. The issue is more likely that Secure Boot is detecting an invalid or untrusted boot component.
Because you mentioned that the computer had a virus recently, I would treat this carefully. A clean antivirus scan inside Windows is good, but it does not always prove that the boot path is clean.
Please try this order:
- Back up your important files first.
- Disconnect all external devices:
- USB drives
- External hard drives
- Memory cards
- Docks
- Printers
- Enter BIOS Setup:
- Turn on the computer and press Esc repeatedly.
- Press F10 for BIOS Setup.
- Load BIOS Setup Defaults.
- Save and restart.
- Go back into BIOS and check:
- OS Boot Manager is first in the boot order.
- Secure Boot is enabled.
- If available, restore/load the default Secure Boot keys.
HP Secure Boot information:
https://support.hp.com/us-en/document/ish_6930187-6931079-16
- If Windows still gives the same Secure Boot Violation, disable Secure Boot only temporarily so you can boot into Windows and run an offline security scan.
Run Microsoft Defender Offline scan:
Windows Security > Virus & threat protection > Scan options > Microsoft Defender Antivirus Offline scan
Microsoft Defender Offline scan:
- After the offline scan, run Windows repair.
Open Command Prompt as Administrator and run:
sfc /scannow
DISM /Online /Cleanup-Image /RestoreHealth
- If Secure Boot still fails, boot from a clean Windows 11 installation USB and choose:
Repair your computer > Troubleshoot > Advanced options > Startup Repair
Do not choose Install now unless you plan to reinstall Windows.
Microsoft Startup Repair:
https://support.microsoft.com/en-us/windows/experience/startup-boot/startup-repair
- If the issue started after the virus and Secure Boot still fails after restoring BIOS defaults, restoring Secure Boot keys, running an offline scan, and using Startup Repair, the safest solution may be to back up your files and perform a clean Windows installation from official Microsoft installation media.
I would not recommend leaving Secure Boot disabled permanently. Secure Boot is there to protect the boot process, and this error means something in the startup path is not trusted or not signed correctly.
Regards,
Haytham