[Warning] BIOS manipulation can make your PC unbootable? Three measures to prepare for Secure Boot updates

One day, when I turned on my PC as usual, a warning message appeared and Windows 11 wouldn't start up at all.

Such a nightmare could soon happen to your PC, not due to a virus or malfunction, but due to a legitimate security update.

In this article, we will explain, based on actual testing, what the update to the "Secure Boot Certificate (2023 version)" currently underway for Windows 11 is and why, when combined with a "BIOS reset," it becomes a time bomb that can render a PC unable to boot.

And to prepare for that "what if" moment, we'll introduce you to three ironclad measures you should take right now (creating a dedicated repair tool, backing up, and setting up emergency systems).

table of contents

What's happening? Generational change in "Secure Boot Certificates"

First, let's briefly understand what's going on in the background.

There is a mechanism called "Secure Boot" that protects the safety of your PC when it starts up. This is like a tough "gatekeeper" for the OS, watching over the PC from when it is turned on until Windows starts up, to prevent any malicious programs from interfering.

This gatekeeper judges security by looking at the "digital signature (certificate)" that serves as a pass, but there are vulnerabilities in old certificates (CVE-2023-24932) was found. Therefore, the entire industry is aiming for 2026,Complete transition to the new "2023 version" certificatePreparations are underway to do so.

Here's the catch: In the Windows 11 preview update released on January 29, 2026 (KB5074105 and later),For devices that already have the "Windows UEFI CA 2023" certificate in the BIOS (DB)In 2023, the Windows boot system (boot manager) will be replaced with the "2023 version."

In other words, Windows will present a new "pass." The biggest risk here is:BIOS OperationIf the 2023 version information is deleted from the "gatekeeper's list (DB)" that accepts the bill due to a reset or other operation, the bill will be deemed "not on the list" even though it is a legitimate bill, and will be refused activation.

The purpose of this article is not to stop updates. It is to help you understand the mechanisms of problems specific to this "transitional period" and prepare to reissue a "new promissory note (key)" yourself in case of an emergency. That is the main purpose.

[Important] Is your BIOS being updated "without your knowledge"?

Many people may think, "I don't remember updating the BIOS," but do you have a dedicated support app provided by your PC manufacturer, such as Dell's "SupportAssist" or HP's "Support Assistant," installed?

These tools are:Updating your BIOS without you realizing itThere is a possibility.

In particular, when the tool notifies you that there is an important update,You hit the "Update All" button without realizing that the list includes a BIOS update.It is a case.

Even if you don't intend to do so, the "Secure Boot Certificate," which is the core of your PC's security, may have already been updated.

How to check the BIOS update date

1. Press Windows key + R to open Run, type "msinfo32" and press Enter.

Run
Run

2. Check the "BIOS Version/Date" in the right column.

BIOS Version/Date
BIOS Version/Date

[Supplementary Information] Manual BIOS update may be required

Of course, not all PCs update their BIOS automatically.

If you are using a self-built PC (BTO computer) or if you have a manufacturer-made PC but have disabled the support app, you may need to periodically check the official website of your PC manufacturer (or motherboard manufacturer) and manually download and update the BIOS yourself.

We recommend searching for your PC's manufacturer and model number and checking the support page to see if the latest BIOS has been released (check all updates for versions newer than your current BIOS version).

*For the author's PC motherboard (model number: B550M-P4), a BIOS including an update to the Secure Boot Key (2023 KEK/DB/PK) was released on 2025/10/09.

B550M-P4 BIOS download page

ASRock B550M Pro4 Motherboard BIOS Update Method and Notes

This has serious implications for your PC

This "gatekeeper rule update" is essential for strengthening security, but after Windows Update replaces the boot manager (startup system), if you perform certain operations,The PC won't start at allThis poses a fatal risk.

1. Biggest risk: "Secure Boot violation" due to BIOS manipulation

This is the most alarming point this time. Windows Update (KB5074105 or later) rewrites the PC's boot file to require the "2023 version key." However, resetting the motherboard (BIOS) settings or running out of battery can cause theAn accident in which the "2023 version key" was lost from the permission list (DB)can occur.

As a result, the PC mistakenly identifies genuine Windows as a "malicious program" andThe OS itself loses its startup privilegesIt may lead to a serious situation.

2. Peripherals or old cards stop working (Option ROM)

Another risk is that signatures (Option ROMs) of older graphics cards, network cards, etc. may be deemed "untrusted" under the new rules, which could result in certain hardware not being recognized or the screen going blank.

3. Risk of having to disable Secure Boot

If your PC won't boot, disabling Secure Boot may be a temporary solution. However, this comes with significant risks. Removing the "checkpoint" allows malicious malware, such as rootkits, to infect the OS boot process (its deepest part).

2."Second disaster" after recovery: PIN is broken and you can no longer sign in可能性

Another thing to be careful about is "PIN (personal identification number) corruption" .

When you reset or update the BIOS to resolve Secure Boot issues, it often also resets the TPM chip that manages Windows Hello security information. This can lead to a secondary disaster: after struggling to start your PC, you're locked out because you're told your PIN isn't available.

If you are in an environment without an internet connection and this happens, you will be stuck and unable to reset your Microsoft account password. To avoid this risk, we strongly recommend changing the following settings.

  1. Right-click the Start button > Settings > Accounts > Sign-in options.
  2. Under "Additional Settings," turn off the switch for "For better security, only allow Windows Hello sign-in for Microsoft accounts on this device (recommended)."
Settings > Accounts > Sign-in options - additional settings
Settings > Accounts > Sign-in options – Additional settings

As of October 9, 2025, we have confirmed an issue where the PIN becomes unusable after performing a Windows Update or BIOS update, and the message "Could not verify credentials" is displayed.

Reasons why you can't sign in even after entering your PIN on the Windows 11 sign-in screen and how to fix it

Why turn this setting off?

By turning off this setting, even if there is any problem with your PIN or fingerprint authentication (Windows Hello), you will be given the option to sign in with your Microsoft account password as usual.

When you first create a PIN for your Microsoft account, it securely links your account to your PC's TPM (Trusted Platform Module).Internet connection requiredIn other words, a PIN is like a "key that you set online once and can be used conveniently offline," while a password is like a "key that is primarily used online but can also be used offline."

If you turn this setting off, you can sign in with your Microsoft account password even if you are not connected to the Internet or if your PIN has been deleted. This is a very important "escape route" in an emergency.

【Related Links】

Recommended Preparation

To prevent such "unable to boot" problems, we strongly recommend that you take the following precautions:

Check for BIOS updates

Motherboard manufacturers may provide new BIOS versions that support the 2023 signature. By updating, the key may not be erased even after resetting. (Please be careful with the update procedure.)

[Most important] Create "Secure Boot recovery media"

Instead of using a regular recovery drive, create a "Secure Boot recovery media" that can restore the lost key (DB). With this, you can recover in just a few seconds even if a BIOS reset accident occurs.

I want to read it together
Windows 11 won't boot? "Secure Boot 2023 Signature" issue and how to create a repair tool The Windows 11 preview update KB5074105, released on January 29, 2026, and the next official update will complete the preparation phase and include Secure Boot...

Backing up your OS

We strongly recommend that you back up your entire current environment in case of system damage.

Use backup software such as Acronis True Image to save the entire state of your PC at this very moment when it is operating normally to an external hard drive or similar.

To avoid panicking if your PC suddenly breaks down, it's a good idea to have a standard backup software to protect your important photos and data.

of course,If the "2023 key" is lost, which is the biggest risk,Secure Boot Recovery MediaIt will not start unless you use ". However, if you experience any other problems (such as Windows corruption due to a failed update, operating error, or driver malfunction), you can always restore your PC to its current state with this backup.

  • Secure Boot Recovery Media : Insurance to repair your front door lock
  • backup: Insurance to protect your household goods (data and OS)

Having these two is truly the "strongest insurance" that allows you to perform important BIOS and Windows updates "at any time" without any fear.

[Windows 11] Back up your entire OS for free! Completely restore your PC with your own "custom installation media"

Summary

  • background: With the Windows 11 update (KB5074105 and later), the Secure Boot certificate is being replaced with the 2023 version.
  • Biggest risks: If you reset or operate the BIOS, the key may be lost, resulting in a "Secure Boot Violation (unable to boot)." Also, if the TPM is cleared during recovery, a secondary disaster may occur, resulting in "unable to sign in."

[Three preparations you should make now]

  1. Key Repair: Create a "Secure Boot Recovery Media" in case your computer won't boot. (This is the only solution.)
  2. System Protection: Take a complete backup of the entire system in case of problems such as update failure.
  3. Secure an escape route: To prevent being locked out (PIN corruption) by clearing the TPM, enable the "Emergency Escape Route" in the sign-in settings.

As the saying goes, "prevention is better than cure," so in this case, you'll need three things: a USB stick, a hard hat (backup), and a duplicate house key (PIN code). We hope this article helps protect your PC from future problems.

If you found this article helpful, please share it on social media.

Person who wrote this article

Driven by questions arising from my daily PC use and the desire to "do more," I have been pursuing self-study in Windows since around 2008. I am sharing the "aha!" techniques and solutions I discovered through trial and error with the sole purpose of helping you in your PC life.

View profile

Comment:

Comment list (4)

  • Thank you. When I checked the system information, the BIOS version/date was American Megatrends Inc. FA506IU.320, 2022/06/01 (Wed), and it seems that no new BIOS versions have been released since then.

    What would happen if the manufacturer (ASUS) did not release a new one? Are there any cases where it turns out to be okay?

    • Dear Siden,

      Even if the manufacturer (ASUS) doesn't update the BIOS, there's no need to worry as Microsoft will take care of it through Windows Update as long as your PC is supported.

  • I'm even more worried now, but I'm wondering what it's really like. I upgraded to Windows 11 properly, and Secure Boot was disabled, so I tried enabling it.
    Should I just disable it again?
    I have "To improve security, only allow Windows Hello sign-in for Microsoft accounts on this device (recommended)" turned off.
    I thought the issue would be resolved if the certificate was updated. But I was wondering whether the certificate update was handled by the manufacturer or Windows Update. Since it's an ASUS gaming laptop from 2020, I don't think there's much hope for a BIOS update.

    • Thank you for your comment, Siden.

      Should I disable Secure Boot again?
      No, the safest and correct way to do this is to leave Secure Boot enabled.
      If you've successfully enabled Secure Boot, you can rest assured that your PC meets the security standards of Windows 11.

      The purpose of this article is not to tell you to "disable Secure Boot," but rather to call for advance "preparation" by saying, "The mechanism of Secure Boot may change in the future, so let's prepare now."

      We recommend leaving "For increased security, only allow Windows Hello sign-in for Microsoft accounts on this device (recommended)" unchecked.

      Is the certificate updated by the manufacturer or by Windows Update?
      The answer is both. They work together to keep your PC's security up to date.

      Gaming laptops manufactured in 2020 are still in good working order as PCs, and it's entirely possible that manufacturers will provide BIOS updates for older models, especially for important security updates that affect the industry as a whole.

To comment

[About submissions]
We welcome any questions or information regarding the content of the article.
However, please note that content unrelated to the purpose of the article, criticism of specific individuals or organizations, offensive language,Inappropriate wordsComments containing the above may be deleted or made private without notice at the discretion of the administrator.
Please note that spam may be automatically deleted by anti-spam measures.

CAPTCHA


table of contents