-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
- HP Community
- Notebooks
- Notebook Operating System and Recovery
- Issues with secure boot on Omen 17` an123nm, cannot enable n...

Create an account on the HP Community to personalize your profile and ask a question
04-20-2024 07:15 AM - edited 04-20-2024 07:22 AM
So basically since i have recently acquired this laptop and i am sharing it with a younger person i have never notice before if secure boot was enabled because bios does not show this option other then TPM and UEFI/Legacy which can be disabled respectively. And because we were using windows 10 64 initially on an mbr partition setup. So it was not an issue in the domain of certain programs. Now my younger siblings cannot play certain games because their anti cheat programs deem win11 installation innapropriate because of lack of secure boot enabled. It is official win11 so TPM 2.0 is presently active and i have checked that in msinfo. I would add that i have properly flashed Bios to newest version F.19-11/15/2022 from official HP driver site for this model and i have noticed for this 2020 omen model 8th gen intel that there is lack of support for windows 11.. (it still expects that you download driver for win10 1909 as the latest)
I now presently have installed dual boot configuration with debian in UEFI where in bios it says Primary OS - non windows. Which is expected because first layer before OS is well known Grub Bootloader. I have heard i need to enroll keys through either terminal or edit them on secure boot menu in txt file, but i have no clue if there is a way to access that, i have also heard that in certain situation just rebooting laptop can auto-reset secure boot feature https://www.reddit.com/r/archlinux/comments/1aw8r6l/sbctl_and_grub_how_do_i_properly_enroll_secure/
Running this command in terminal I`ve got one green flag:
Sudo mokutil --sb-state
SecureBoot disabled
Platform is in Setup Mode
(which is nececary to enroll linux keys CA which i am still preparing to so that i do not mess up whole configuration and render it unsable)
I do not mind to reinstall whole setup all over again but first i would like to try that manually, because it seems that i just have to assign/enroll grub bootloader and debian keys so that this feature (SB) enable it self and i want to get clearer picture of what is going on in here...
Is it the only regular and approved way to have this wiping my whole drive with windows system only, i respect new features and would like to run latest OS, but if there is no obvious workaround i may revert to and older configuration. I am also open to flash custom bios since mine is very limited for workstation like this...
04-20-2024 10:05 AM - edited 04-20-2024 10:05 AM
Hi:
You cannot enable secure boot with Windows installed with the MBR partition table.
You can only enable secure boot if Windows is installed with the GPT partition table.
To do that, you must boot the windows installation media from the EFI USB boot source not the legacy one.
Me...I'd be clean installing W11 in EFI mode but there is a way to convert from MBR to GPT.
I've never tried it before so I cannot confirm that it is guaranteed to work.
m s p h - c h v 2 - p t (youtube.com)
There are other videos like this out there.