{"id":7354,"date":"2026-05-03T22:25:18","date_gmt":"2026-05-04T05:25:18","guid":{"rendered":"https:\/\/www.terabyteunlimited.com\/kb\/?post_type=lsvr_kba&#038;p=7354"},"modified":"2026-05-03T23:04:48","modified_gmt":"2026-05-04T06:04:48","slug":"impacts-of-changing-uefi-secure-boot-settings","status":"publish","type":"lsvr_kba","link":"https:\/\/www.terabyteunlimited.com\/kb\/kb-articles\/impacts-of-changing-uefi-secure-boot-settings\/","title":{"rendered":"Impacts of Changing UEFI Secure Boot Settings"},"content":{"rendered":"<p>Modifying UEFI Secure Boot settings can affect Windows security features and sign-in methods. This includes changes such as entering Setup Mode, clearing Secure Boot keys, installing custom certificates, restoring default keys, or simply enabling or disabling Secure Boot.<\/p>\r\n<p>This article explains the most common impacts and how to prepare for them.<\/p>\r\n<p><span style=\"color: #005858;\"><strong>Overview<\/strong><\/span><\/p>\r\n<p>Secure Boot changes may involve one or more of the following:<\/p>\r\n<ul>\r\n\t<li>Platform Key (PK)<\/li>\r\n\t<li>Key Exchange Keys (KEK)<\/li>\r\n\t<li>Allowed database (DB)<\/li>\r\n\t<li>Revoked database (DBX)<\/li>\r\n\t<li>Secure Boot state, such as enabled or disabled<\/li>\r\n\t<li>Secure Boot operating mode, such as Setup Mode, User Mode, or Deployed Mode<\/li>\r\n<\/ul>\r\n<p>Not all systems handle Secure Boot changes the same way. Some systems allow Secure Boot to be enabled or disabled without clearing keys. Other systems require keys to be cleared or changed before certain options are available.<\/p>\r\n<p><span style=\"color: #005858;\"><strong>BitLocker Recovery May Be Required<\/strong><\/span><\/p>\r\n<p>If BitLocker is enabled with TPM-based protection, changes to Secure Boot settings may cause BitLocker to require a recovery key before Windows will boot.<\/p>\r\n<p>This can happen because Windows uses TPM measurements to verify that the boot environment has not changed unexpectedly. Secure Boot state and related firmware settings can be included in those measurements.<\/p>\r\n<p>Examples of changes that may trigger BitLocker recovery include:<\/p>\r\n<ul>\r\n\t<li>Entering Secure Boot Setup Mode.<\/li>\r\n\t<li>Clearing Secure Boot keys or variables.<\/li>\r\n\t<li>Installing or removing Secure Boot certificates.<\/li>\r\n\t<li>Restoring default Secure Boot keys.<\/li>\r\n\t<li>Enabling or disabling Secure Boot.<\/li>\r\n\t<li>Changing related BIOS\/UEFI boot security settings.<\/li>\r\n<\/ul>\r\n<p><span style=\"color: #005858;\"><strong>How to Avoid BitLocker Recovery Prompts<\/strong><\/span><\/p>\r\n<p>Before making Secure Boot or BIOS\/UEFI changes, make sure the BitLocker recovery key is available.<\/p>\r\n<p>If you are using the TeraByte Secure Boot Certificate Wizard, BitLocker should automatically be suspended as needed during the process.<\/p>\r\n<p>If you are making changes manually, suspend BitLocker protection before making the changes. For example, to suspend BitLocker protection on <strong>C:<\/strong> for one reboot, run the following command from an administrator command prompt:<\/p>\r\n<p><span style=\"color: #008800; font-family: Courier New, Courier, monospace;\"><strong>manage-bde -protectors -disable C: -rc 1<\/strong><\/span><\/p>\r\n<p>After the process is complete, BitLocker protection should resume automatically. If it does not, protection can be manually re-enabled.<\/p>\r\n<p><span style=\"color: #005858;\"><strong>Windows Hello May Need to Be Reset<\/strong><\/span><\/p>\r\n<p>Changing Secure Boot or related TPM-measured boot settings may cause Windows Hello sign-in methods to stop working.<\/p>\r\n<p>This may affect:<\/p>\r\n<ul>\r\n\t<li>Windows Hello PIN<\/li>\r\n\t<li>Fingerprint sign-in<\/li>\r\n\t<li>Facial recognition<\/li>\r\n\t<li>Other TPM-protected sign-in credentials<\/li>\r\n<\/ul>\r\n<p>Possible symptoms include:<\/p>\r\n<ul>\r\n\t<li>PIN sign-in fails.<\/li>\r\n\t<li>Fingerprint or facial recognition is unavailable.<\/li>\r\n\t<li>Windows prompts you to reset Windows Hello.<\/li>\r\n\t<li>Windows requires another sign-in method before Windows Hello can be configured again.<\/li>\r\n<\/ul>\r\n<p>If this happens, sign in using your normal sign-in method, such as your account password or verification code, and then reset or reconfigure Windows Hello.<\/p>\r\n<p><span style=\"color: #005858;\"><strong>Secure Boot May Be Disabled or Enter Setup Mode<\/strong><\/span><\/p>\r\n<p>Depending on the firmware and the change performed, the system may either disable Secure Boot or enter Secure Boot Setup Mode.<\/p>\r\n<p>These are not always the same thing:<\/p>\r\n<ul>\r\n\t<li>Disabling Secure Boot usually turns off Secure Boot enforcement while leaving the Secure Boot keys intact.<\/li>\r\n\t<li>Clearing Secure Boot keys generally places the system into Setup Mode.<\/li>\r\n\t<li>Some systems provide a direct option to enter Setup Mode.<\/li>\r\n\t<li>Some systems provide only key-clearing options to enter Setup Mode.<\/li>\r\n<\/ul>\r\n<p>When Secure Boot is disabled or the system is in Setup Mode, boot verification may not be enforced.<\/p>\r\n<p>To restore normal Secure Boot protection, you may need to:<\/p>\r\n<ul>\r\n\t<li>Re-enable Secure Boot, if it was disabled.<\/li>\r\n\t<li>Restore or install the required Secure Boot keys.<\/li>\r\n\t<li>Return the system to User Mode or Deployed Mode, depending on the firmware.<\/li>\r\n<\/ul>\r\n<p><span style=\"color: #005858;\"><strong>Custom Keys May Change Boot Behavior<\/strong><\/span><\/p>\r\n<p>Installing or modifying Secure Boot keys can affect which bootloaders, operating systems, and recovery environments are allowed to start.<\/p>\r\n<p>Possible effects include:<\/p>\r\n<ul>\r\n\t<li>A previously bootable operating system may no longer boot.<\/li>\r\n\t<li>Boot media may fail to start if it is not signed by a trusted certificate.<\/li>\r\n\t<li>Custom bootloaders may need to be signed with a trusted certificate.<\/li>\r\n\t<li>Restoring factory keys may remove trust for custom certificates.<\/li>\r\n\t<li>Replacing default keys may remove trust for boot components signed by Microsoft or the system vendor.<\/li>\r\n<\/ul>\r\n<p>This is especially important on systems that boot multiple operating systems or use custom recovery, imaging, or maintenance media.<\/p>\r\n<p><span style=\"color: #005858;\"><strong>Firmware May Automatically Restore Keys<\/strong><\/span><\/p>\r\n<p>Some systems have firmware options that automatically reload factory Secure Boot keys or variables.<\/p>\r\n<p>An example of this type of option on an MSI board is <strong>Provision Factory Default Keys<\/strong>.<\/p>\r\n<p>If this type of option is enabled, the system may automatically reload the default Secure Boot keys during restart and leave Setup Mode.<\/p>\r\n<p>Before attempting to remain in Setup Mode, disable automatic key provisioning options if the firmware provides them.<\/p>\r\n<p><span style=\"color: #005858;\"><strong>Secure Boot Tools May Use Multiple Stages<\/strong><\/span><\/p>\r\n<p>Tools that modify Secure Boot configuration may require more than one reboot or more than one firmware state.<\/p>\r\n<p>For example, a tool may use stages such as:<\/p>\r\n<ol>\r\n\t<li>Prepare the system.<\/li>\r\n\t<li>Reboot into BIOS\/UEFI firmware.<\/li>\r\n\t<li>Enter Setup Mode.<\/li>\r\n\t<li>Apply the Secure Boot certificate change.<\/li>\r\n\t<li>Restore or finalize the Secure Boot state.<\/li>\r\n<\/ol>\r\n<p>Interrupting the process may leave the system in a partially configured state. Follow the tool\u2019s prompts and complete all required stages.<\/p>\r\n<p><span style=\"color: #005858;\"><strong>Recommendations Before Making Changes<\/strong><\/span><\/p>\r\n<p>Before changing Secure Boot settings:<\/p>\r\n<ul>\r\n\t<li>Back up or confirm access to BitLocker recovery keys.<\/li>\r\n\t<li>Ensure you can use your normal Windows sign-in method.<\/li>\r\n\t<li>Suspend BitLocker protection if making changes manually.<\/li>\r\n\t<li>Understand how to restore default Secure Boot keys on the system.<\/li>\r\n\t<li>Check whether the firmware has automatic key provisioning enabled.<\/li>\r\n\t<li>Keep required recovery or boot media available.<\/li>\r\n<\/ul>\r\n<p><span style=\"color: #005858;\"><strong>Recommendations After Making Changes<\/strong><\/span><\/p>\r\n<p>After changing Secure Boot settings:<\/p>\r\n<ul>\r\n\t<li>Confirm Windows boots normally.<\/li>\r\n\t<li>Confirm the expected Secure Boot state.<\/li>\r\n\t<li>Confirm whether the system is in Setup Mode, User Mode, or Deployed Mode.<\/li>\r\n\t<li>Re-enable Secure Boot if it was intentionally disabled only temporarily.<\/li>\r\n\t<li>Reconfigure Windows Hello if required.<\/li>\r\n\t<li>Re-enable BitLocker protection if it did not resume automatically.<\/li>\r\n<\/ul>\r\n<p><span style=\"color: #005858;\"><strong>Related Articles<\/strong><\/span><\/p>\r\n<ul>\r\n\t<li><a href=\"https:\/\/www.terabyteunlimited.com\/kb\/?p=7336\">How to Enable UEFI Secure Boot Setup Mode<\/a><\/li>\r\n\t<li><a href=\"https:\/\/www.terabyteunlimited.com\/kb\/?p=7347\">How to Access BIOS\/UEFI Settings to Configure Your System<\/a><\/li>\r\n<\/ul>\r\n<p>&nbsp;<\/p>","protected":false},"excerpt":{"rendered":"<p>Modifying UEFI Secure Boot settings can affect Windows security features and sign-in methods. This includes changes such as entering Setup Mode, clearing Secure Boot keys, installing custom certificates, restoring default keys, or simply enabling or disabling Secure Boot. This article explains the most common impacts and how to prepare for them. Overview Secure Boot changes [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"lsvr_kba_cat":[1808],"lsvr_kba_tag":[],"class_list":["post-7354","lsvr_kba","type-lsvr_kba","status-publish","hentry","lsvr_kba_cat-hardware-or-bios"],"_links":{"self":[{"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/lsvr_kba\/7354","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/lsvr_kba"}],"about":[{"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/types\/lsvr_kba"}],"author":[{"embeddable":true,"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/comments?post=7354"}],"version-history":[{"count":3,"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/lsvr_kba\/7354\/revisions"}],"predecessor-version":[{"id":7358,"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/lsvr_kba\/7354\/revisions\/7358"}],"wp:attachment":[{"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/media?parent=7354"}],"wp:term":[{"taxonomy":"lsvr_kba_cat","embeddable":true,"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/lsvr_kba_cat?post=7354"},{"taxonomy":"lsvr_kba_tag","embeddable":true,"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/lsvr_kba_tag?post=7354"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}