• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
Check out our WINDOWS 11 Support Center info about: OPTIMIZATION, KNOWN ISSUES, FAQs, VIDEOS AND MORE.
HP Recommended

ZBook Studio G5

Windows 11 25H2 (26200.8039)

All latest Windows updates (as of March 24, 2026)

BIOS is latest (01.33.00)

Secure Boot is Enabled

 

I am consistently seeing the following two ERRORs in Windows Event Viewer:

TPM-WMI Event ID 1801:

Updated Secure Boot certificates are available on this device but have not yet been applied to the firmware. Review the published guidance to complete the update and maintain full protection. This device signature information is included here.
DeviceAttributes: FirmwareManufacturer:HP;FirmwareVersion:Q71 Ver. 01.33.00;OEMModelBaseBoard:8427;OEMManufacturerName:HP;OSArchitecture:amd64;
BucketId: 49ef97185eea44c27ac824a36988b185c4fb95ff5b24297ab200bca9e316ccd7
BucketConfidenceLevel: Under Observation - More Data Needed
UpdateType:
For more information, please see https://go.microsoft.com/fwlink/?linkid=2301018.

 

TPM-WMI Event ID 1796:

The Secure Boot update failed to update SBAT with error Unknown HResult Error code: 0x800700c1. For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931

 

Based on some online research, I have done the following steps, but so far no joy:

  • Re-installed latest BIOS
  • Established Admin password for BIOS
  • Turned off Windows Fast Startup (Control Panel -> Power Options)
  • Ensured Legacy Boot is disabled ("Legacy Boot disabled; Secure Boot Enabled")
  • Turned off all HP SureStart options in BIOS so that Secure Boot Configuration options in BIOS would be available
  • Did "Reset Secure Boot Keys to Factory Defaults" in BIOS
  • Ran sfc /scannow and dism /online /cleanup-image /restorehealth
  • Confirmed TPM and Secure Boot were still active
  • Disabled Secure Boot, and booted into Windows
  • Disabled "Use MS CA/UEFI keys" option
  • Re-enabled Secure Boot
  • Re-enabled "Use MS CA/UEFI keys" and did "Clear Secure Boot Keys" (this turns off Secure Boot)
  • Re-enabled Secure Boot
  • Re-enabled HP Sure Start options previously disabled
  • Re-enabled Fast Startup in Windows
  • PROBLEM STILL NOT SOLVED

 

At each step above, I continue to get the same errors in the Windows event log.  I have seen some references to using Powershell (Remove-SecureBootPolicy) to clear pending Secure Boot updates, but this does not sound like a solution to the real problem.  I have read this is basically an issue that the OS and the firmware are not "in sync" regarding Secure Boot  configuration, and it seems it is perhaps unique to HP systems and firmware with HP SureStart features.  

 

How can this be resolved?  So far, none of the Google wisdom is helping.  Is this going to require a BIOS update from HP?

 

 

 

 

 

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.