• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Seize the moment! nominate yourself or a tech enthusiast you admire & join the HP Community Experts!
Check out our WINDOWS 11 Support Center info about: OPTIMIZATION, KNOWN ISSUES, FAQs, VIDEOS AND MORE.
HP Recommended
Microsoft Windows 11

In Windows 11 Version 24H2 Build 26100.4770,
I noticed that under Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot the key "AvailableUpdates" has the wrong value of 0x400 instead of 0x40.

 

Should I change it to 0x40?

 

In the Event viewer I see many errors like:

The Secure Boot update failed to update a Secure Boot variable

Error Unknown HResult Error code: 0x800700c1

Origin: TPM-WMI, Event ID: 1796

 

The first error occurred on May 13th, 2025, after the installation of the KB5058411 update (OS Build 26100.4061) released on Windows Update at the same date

1 REPLY 1
HP Recommended

Hello AndreaMarc,
Thank you for reaching out to the Hp community. I would be delighted to assist you. Superb description and terrific troubleshooting. Kudos to you for that. 

The value 0x40 or 0x400 represents bit flags that correspond to available secure boot updates or update stages.

 

Secure Boot variables are stored in firmware (UEFI), not just Windows registry.
The registry merely reflects or caches state information. Editing it will not fix the underlying issue and may desync registry and firmware data.

 

The error 0x800700c1 (“Invalid image format”) in Event ID 1796 (TPM-WMI) occurs when the firmware rejects a Secure Boot variable update payload — usually due to a mismatch between UEFI implementation and the update content (often from KB5058411 in this case).

 

Microsoft is aware of this behavior in 24H2 Insider and production builds — it’s benign in most cases and does not disable Secure Boot or affect TPM integrity.

 

Do not manually modify registry values under SecureBoot.

 

Ensure your UEFI firmware is updated to the latest version for your HP model (HP releases firmware microcode updates that improve Secure Boot handling).

 

If the TPM-WMI 1796 errors persist after future cumulative updates (e.g., November 2025 Patch Tuesday), they will likely be resolved automatically once Microsoft syncs the Secure Boot DBX update pipeline.

 

Optionally, you can clear and re-enroll Secure Boot keys via BIOS/UEFI (only if you’re comfortable and have recovery media).

 

Keep AvailableUpdates as 0x400.

 

Do not manually edit it.

 

The Event ID 1796 TPM-WMI errors after KB5058411 are a known cosmetic issue not a functional fault. Secure Boot still works fine.

I am an HP Employee. Although I am
speaking for myself and not for
HP.
Click Helpful = Yes to
say Thank You.
Question /
Concern Answered, Click
"Accept as Solution"

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.