Secure Boot Violation - Invalid Signature Detected. Check Secure Boot Policy in Setup

amriison1156e02e0

New member
Joined
Apr 4, 2026
Messages
1
I am currently dealing with a frustrating BIOS issue on my MSI Modern 14 B4MW. It all started because I was concerned about my laptop's performance, it had been crashing occasionally, and Valorant was acting up. I opened the BIOS just to see if anything looked out of place, but I didn't actually change any settings. However, when I hit F10 to save and exit, I was immediately blocked by an error message 'Secure Boot Violation - Invalid Signature Detected. Check Secure Boot Policy in Setup.'

To try and bypass this, I experimented with the boot settings by switching from UEFI to 'UEFI with CSM.' When that didn't work and the 'Invalid Signature' error persisted, I reverted everything to the original settings. After researching the issue on YouTube and Google, I went into the Security tab and disabled 'Secure Boot Support.' This finally allowed me to boot into Windows, but it created a new problem: Valorant refused to launch. Since the game's anti-cheat (Vanguard) strictly requires Secure Boot to be enabled on Windows 11, I was stuck in a loop.

I went back into the BIOS to try a specific fix I found online. The tutorial suggested changing the Secure Boot Mode to [Custom] so I could manually reset the security signatures. According to the guide, I was supposed to see an option to 'Enroll All Factory Default Keys' once I switched to Custom mode, but that option is completely missing from my menu. Now, I’m at a dead end, I have to keep Secure Boot disabled just to use my laptop at all, which unfortunately means I still can't play Valorant. Can you please help me figure out how to fix this?
 

Attachments

  • a9d3ee25-f6f7-4f91-ba93-0254d34a1826.jpg
    a9d3ee25-f6f7-4f91-ba93-0254d34a1826.jpg
    61.8 KB · Views: 2,413
  • 86740f4a-3978-4da6-b386-6327483bb1a4.jpg
    86740f4a-3978-4da6-b386-6327483bb1a4.jpg
    130.5 KB · Views: 2,596
  • cdd25646-2af8-493c-90f1-32655a62c328.jpg
    cdd25646-2af8-493c-90f1-32655a62c328.jpg
    178.8 KB · Views: 1,963
  • f9be3d69-7732-4340-af89-1f0879724330.jpg
    f9be3d69-7732-4340-af89-1f0879724330.jpg
    95.7 KB · Views: 1,915
  • 3c49c52b-da1b-4c3d-8367-af712f360d19.jpg
    3c49c52b-da1b-4c3d-8367-af712f360d19.jpg
    113.6 KB · Views: 2,175
I'm having the same issue, except I do have "Install all factory default keys" but selecting this has still not allowed me to boot without disabling secure boot.

This started after updating my BIOS on a Crosshair 15 A11UEK. Though the cause of our problems might be different, hopefully someone might have some insight that can help
 
Thank you for your response. That Microsoft Learn step was one I had come across and hadn't yet tried but MSI support was able to point me to the below link, which resolved this issue for me: https://www.msi.com/faq/faq-11370 .

OP, I hope this might help your situation as well.

One thing to note, is to make sure the boot64.exe file is saved to your flash drive in the EFI>Boot folder. Probably an obvious thing, but it didn't work for me originally because I had the boot64 file dropped directly into my USB drive, not within the EFI folder as downloaded.
 
Thank you for your response. That Microsoft Learn step was one I had come across and hadn't yet tried but MSI support was able to point me to the below link, which resolved this issue for me: https://www.msi.com/faq/faq-11370 .

OP, I hope this might help your situation as well.

One thing to note, is to make sure the boot64.exe file is saved to your flash drive in the EFI>Boot folder. Probably an obvious thing, but it didn't work for me originally because I had the boot64 file dropped directly into my USB drive, not within the EFI folder as downloaded.
Hey, thanks a ton --
that fix definitely works in the moment. However, I’m still having a weird recurring problem. My laptop often refuses to boot normally, so I have to flush the charge by holding the power button. Every time I do that, the 'Invalid signature' error pops back up. Any idea why my system keeps resetting or failing to boot in the first place?
 
First, try reinstalling the BIOS update.
That should automatically reset Secure Boot
to its default settings.

 
I am currently dealing with a frustrating BIOS issue on my MSI Modern 14 B4MW. It all started because I was concerned about my laptop's performance, it had been crashing occasionally, and Valorant was acting up. I opened the BIOS just to see if anything looked out of place, but I didn't actually change any settings. However, when I hit F10 to save and exit, I was immediately blocked by an error message 'Secure Boot Violation - Invalid Signature Detected. Check Secure Boot Policy in Setup.'

To try and bypass this, I experimented with the boot settings by switching from UEFI to 'UEFI with CSM.' When that didn't work and the 'Invalid Signature' error persisted, I reverted everything to the original settings. After researching the issue on YouTube and Google, I went into the Security tab and disabled 'Secure Boot Support.' This finally allowed me to boot into Windows, but it created a new problem: Valorant refused to launch. Since the game's anti-cheat (Vanguard) strictly requires Secure Boot to be enabled on Windows 11, I was stuck in a loop.

I went back into the BIOS to try a specific fix I found online. The tutorial suggested changing the Secure Boot Mode to [Custom] so I could manually reset the security signatures. According to the guide, I was supposed to see an option to 'Enroll All Factory Default Keys' once I switched to Custom mode, but that option is completely missing from my menu. Now, I’m at a dead end, I have to keep Secure Boot disabled just to use my laptop at all, which unfortunately means I still can't play Valorant. Can you please help me figure out how to fix this?
Just press left alt+fn+right ctrl+ right shift+ F2, this expands the bios into advanced mode from user friendly mode. After this you will see all of the hidden options which were missing. It will include restore factory default keys option just below the secure boot mode when you set it to custom.

I am also facing the Secure Boot Violation issue on my Modern 14 B5M but it happened after I tried to do EC reset by pressing power button. I found that this process drains the battery from the motherboard and can cause corruption in secure boot key. I tried to restore factory default keys but it didn't help me. I am thinking about updating the bios. I hope this will solve the Secure Boot Violation issue. For now I am using my pc with Secure Boot Support option set to disabled.

If Restoring default keys doesn't work, I would suggest to update the BIOS. Just download the BIOS from the official MSI product support page and you are good to go. You can find tutorials for updating the bios on YouTube. It is simple and secure if done properly.
 
Hello,

I am experiencing a persistent Secure Boot activation issue on an MSI GF75 Thin 10UEK laptop (model MS-17F5).

System information:

- Model: MSI GF75 Thin 10UEK
- BIOS Vendor: American Megatrends
- BIOS Version: 17F50 1.05 x64
- BIOS Build Date: June 1, 2021
- Operating System: Windows 11
- Boot Mode: UEFI

Issue description:

When Secure Boot is enabled in the BIOS, Windows fails to start and the system displays an "Invalid Signature" error immediately after the MSI splash screen.

When Secure Boot is disabled, Windows boots normally without any issues.

Troubleshooting steps already performed:

1. UEFI verification

- BIOS is configured in UEFI mode.
- Windows boots correctly in UEFI mode.

2. Boot Manager verification

- Windows Boot Manager is set as the first boot option in the boot order.

3. Secure Boot key restoration

- Executed "Install All Factory Default Keys".
- Verified that PK, KEK, DB, and DBX keys are present.
- Secure Boot keys appear to be properly installed.

4. Manual EFI image enrollment

- Located and selected:
EFI\Microsoft\Boot\bootmgfw.efi
- Successfully completed the "Enroll EFI Image" procedure.

5. Secure Boot status in BIOS

- Secure Boot Support: Enabled
- System Mode: User
- Secure Boot: Active
- Secure Boot Mode: Custom

6. Windows verification

- The file EFI\Microsoft\Boot\bootmgfw.efi is present and accessible.
- PowerShell confirms that the Platform Key (PK) exists:
Get-SecureBootUEFI PK
- However:
Confirm-SecureBootUEFI returns False
- And:
Get-SecureBootPolicy returns:
"Secure Boot policy is not enabled on this computer."

Current situation:

Even after restoring the factory Secure Boot keys and manually enrolling bootmgfw.efi, enabling Secure Boot consistently results in the "Invalid Signature" error during startup.

I would appreciate your assistance regarding:

- Whether this is a known issue with BIOS version 17F50 1.05.
- Whether a newer BIOS or EC firmware update is recommended.
- Whether MSI provides an official procedure to completely rebuild or reset the Secure Boot database on this model.

I can provide BIOS screenshots, photographs, and PowerShell outputs if required.

Thank you for your assistance.

Kind regards,

Laurent
 
Make sure you've put all of the files into the USB key, including the EFI folder, not just the boot file.
 
Hey, thanks a ton --
that fix definitely works in the moment. However, I’m still having a weird recurring problem. My laptop often refuses to boot normally, so I have to flush the charge by holding the power button. Every time I do that, the 'Invalid signature' error pops back up. Any idea why my system keeps resetting or failing to boot in the first place?
I've had the booting problem for the last year. Still happening but now it's degraded further to whatever this issue is. I have noticed my Bios date is 1/1/23, so I'm guessing a CMOS battery dying could also have been a factor, but who knows. Time to figure out a BIOS flash I guess...MSI is a trip
 
I've just fixed the above issue with help from MSI support team. No BIOS flash nor fresh Windows Install was required.
I tried the https://www.msi.com/faq/faq-11370 and saved the file to USB but the file didn't work somehow. I contacted MSI about the problem I was having on my GS66 Stealth Gaming Laptop and they sent me detailed instructions on how to fix the invalid key problem. Maybe took an hour to fix.

One tip is not to use a USB adaptor and card reader as the drivers aren't loaded and use a normal USB drive. USB Drive also needs clean formatted to FAT32 and only the key file added to it and not in a folder. Check your USB ports on your computer as I had to find one that would work on start up.
 
Whenever I get the Secure boot violation screen and try to change anything in the secure boot menu it’s all greyed out. I don’t know what to do
 
Back
Top