-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
- HP Community
- Notebooks
- Notebook Operating System and Recovery
- Wrong value for SecureBoot's AvailableUpdates in Windows 11:...

Create an account on the HP Community to personalize your profile and ask a question
07-28-2025 02:07 AM - edited 07-28-2025 02:18 AM
In Windows 11 Version 24H2 Build 26100.4770,
I noticed that under Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot the key "AvailableUpdates" has the wrong value of 0x400 instead of 0x40.
Should I change it to 0x40?
In the Event viewer I see many errors like:
The Secure Boot update failed to update a Secure Boot variable
Error Unknown HResult Error code: 0x800700c1
Origin: TPM-WMI, Event ID: 1796
The first error occurred on May 13th, 2025, after the installation of the KB5058411 update (OS Build 26100.4061) released on Windows Update at the same date
10-14-2025 09:36 AM
Hello AndreaMarc,
Thank you for reaching out to the Hp community. I would be delighted to assist you. Superb description and terrific troubleshooting. Kudos to you for that.
The value 0x40 or 0x400 represents bit flags that correspond to available secure boot updates or update stages.
Secure Boot variables are stored in firmware (UEFI), not just Windows registry.
The registry merely reflects or caches state information. Editing it will not fix the underlying issue and may desync registry and firmware data.
The error 0x800700c1 (“Invalid image format”) in Event ID 1796 (TPM-WMI) occurs when the firmware rejects a Secure Boot variable update payload — usually due to a mismatch between UEFI implementation and the update content (often from KB5058411 in this case).
Microsoft is aware of this behavior in 24H2 Insider and production builds — it’s benign in most cases and does not disable Secure Boot or affect TPM integrity.
Do not manually modify registry values under SecureBoot.
Ensure your UEFI firmware is updated to the latest version for your HP model (HP releases firmware microcode updates that improve Secure Boot handling).
If the TPM-WMI 1796 errors persist after future cumulative updates (e.g., November 2025 Patch Tuesday), they will likely be resolved automatically once Microsoft syncs the Secure Boot DBX update pipeline.
Optionally, you can clear and re-enroll Secure Boot keys via BIOS/UEFI (only if you’re comfortable and have recovery media).
Keep AvailableUpdates as 0x400.
Do not manually edit it.
The Event ID 1796 TPM-WMI errors after KB5058411 are a known cosmetic issue not a functional fault. Secure Boot still works fine.
speaking for myself and not for
HP.
Click Helpful = Yes to
say Thank You.
Question /
Concern Answered, Click
"Accept as Solution"