laurentvicario15dd02eb
New member
- Joined
- Jun 5, 2026
- Messages
- 5
Hello,
I am experiencing a persistent Secure Boot activation issue on an MSI GF75 Thin 10UEK laptop (model MS-17F5).
System information:
- Model: MSI GF75 Thin 10UEK
- BIOS Vendor: American Megatrends
- BIOS Version: 17F50 1.05 x64
- BIOS Build Date: June 1, 2021
- Operating System: Windows 11
- Boot Mode: UEFI
Issue description:
When Secure Boot is enabled in the BIOS, Windows fails to start and the system displays an "Invalid Signature" error immediately after the MSI splash screen.
When Secure Boot is disabled, Windows boots normally without any issues.
Troubleshooting steps already performed:
1. UEFI verification
- BIOS is configured in UEFI mode.
- Windows boots correctly in UEFI mode.
2. Boot Manager verification
- Windows Boot Manager is set as the first boot option in the boot order.
3. Secure Boot key restoration
- Executed "Install All Factory Default Keys".
- Verified that PK, KEK, DB, and DBX keys are present.
- Secure Boot keys appear to be properly installed.
4. Manual EFI image enrollment
- Located and selected:
EFI\Microsoft\Boot\bootmgfw.efi
- Successfully completed the "Enroll EFI Image" procedure.
5. Secure Boot status in BIOS
- Secure Boot Support: Enabled
- System Mode: User
- Secure Boot: Active
- Secure Boot Mode: Custom
6. Windows verification
- The file EFI\Microsoft\Boot\bootmgfw.efi is present and accessible.
- PowerShell confirms that the Platform Key (PK) exists:
Get-SecureBootUEFI PK
- However:
Confirm-SecureBootUEFI returns False
- And:
Get-SecureBootPolicy returns:
"Secure Boot policy is not enabled on this computer."
Current situation:
Even after restoring the factory Secure Boot keys and manually enrolling bootmgfw.efi, enabling Secure Boot consistently results in the "Invalid Signature" error during startup.
I would appreciate your assistance regarding:
- Whether this is a known issue with BIOS version 17F50 1.05.
- Whether a newer BIOS or EC firmware update is recommended.
- Whether MSI provides an official procedure to completely rebuild or reset the Secure Boot database on this model.
I can provide BIOS screenshots, photographs, and PowerShell outputs if required.
Thank you for your assistance.
Laurent
I am experiencing a persistent Secure Boot activation issue on an MSI GF75 Thin 10UEK laptop (model MS-17F5).
System information:
- Model: MSI GF75 Thin 10UEK
- BIOS Vendor: American Megatrends
- BIOS Version: 17F50 1.05 x64
- BIOS Build Date: June 1, 2021
- Operating System: Windows 11
- Boot Mode: UEFI
Issue description:
When Secure Boot is enabled in the BIOS, Windows fails to start and the system displays an "Invalid Signature" error immediately after the MSI splash screen.
When Secure Boot is disabled, Windows boots normally without any issues.
Troubleshooting steps already performed:
1. UEFI verification
- BIOS is configured in UEFI mode.
- Windows boots correctly in UEFI mode.
2. Boot Manager verification
- Windows Boot Manager is set as the first boot option in the boot order.
3. Secure Boot key restoration
- Executed "Install All Factory Default Keys".
- Verified that PK, KEK, DB, and DBX keys are present.
- Secure Boot keys appear to be properly installed.
4. Manual EFI image enrollment
- Located and selected:
EFI\Microsoft\Boot\bootmgfw.efi
- Successfully completed the "Enroll EFI Image" procedure.
5. Secure Boot status in BIOS
- Secure Boot Support: Enabled
- System Mode: User
- Secure Boot: Active
- Secure Boot Mode: Custom
6. Windows verification
- The file EFI\Microsoft\Boot\bootmgfw.efi is present and accessible.
- PowerShell confirms that the Platform Key (PK) exists:
Get-SecureBootUEFI PK
- However:
Confirm-SecureBootUEFI returns False
- And:
Get-SecureBootPolicy returns:
"Secure Boot policy is not enabled on this computer."
Current situation:
Even after restoring the factory Secure Boot keys and manually enrolling bootmgfw.efi, enabling Secure Boot consistently results in the "Invalid Signature" error during startup.
I would appreciate your assistance regarding:
- Whether this is a known issue with BIOS version 17F50 1.05.
- Whether a newer BIOS or EC firmware update is recommended.
- Whether MSI provides an official procedure to completely rebuild or reset the Secure Boot database on this model.
I can provide BIOS screenshots, photographs, and PowerShell outputs if required.
Thank you for your assistance.
Laurent