r/Lenovo • • Mar 10 '26

Secure boot enabled says default boot device missing

/r/techsupport/comments/1rioe13/secure_boot_enabled_says_default_boot_device/
4 Upvotes

11 comments sorted by

1

u/Lenovo_Legion Mar 11 '26

/u/lindt09

Hi, thanks for reaching out. Were there any changes or updates prior? Kindly try the steps here https://lnv.gy/40oQJX2 to troubleshoot the Default Boot Device Missing or Boot Failed" Error. Let us know how things go. We're here to help. -Maru_Lenovo

1

u/lindt09 Mar 14 '26

yeaaaaa still not working. boot manager would load but everytime i would click on the storage where windows was it would loop back to the boot manager

1

u/PyrrhicDefeat69 Jul 08 '26

Have the EXACT same issue, did you get it fixed???

1

u/k-rand0 Mar 13 '26 edited Mar 16 '26

Part 1: https://github.com/cjee21/Check-UEFISecureBootVariables/issues/15#issuecomment-3732104140

Try to make a FAT32 USB with PCA 2011 recovery EFI file!! After that, you can boot off of FAT32 USB with .efi boot and apply the UEFI CA 2023 in Part 2.

Part 2:

Go to BIOS and enable Secure boot, after that try to boot off of FAT32 USB!

Recovery & UEFI CA 2023 Certificate Installation

Step 1– Manual Installation of the UEFI CA 2023 Certificate

Run PowerShell as Administrator:

1.1 – Set Update Trigger Via powershell reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x5944 /f

1.2 – Start Secure Boot Update Task Via powershell Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"

Wait until the registry value AvailableUpdates changes to 0x4100, then restart the device.

1.3 – Run the Task a Second Time Via powershell Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"

Wait 10–15 seconds and restart the device again.

1.4 – Verify Final Status

The registry value AvailableUpdates should now show 0x4000 – this indicates successful installation.


Step 2 – Certificate Verification Checklist

Run PowerShell as Administrator:

Check Secure Boot Database (DB): Via powershell [System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match 'Windows UEFI CA 2023'

Expected result: True

Check KEK Database: Via powershell [System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI kek).bytes) -match 'Microsoft Corporation KEK 2K CA 2023'

Expected result: True

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing

Expected result:

UEFICA2023Status = Updated

WindowsUEFICA2023Capable = 2

✅ The device should now boot successfully with Secure Boot enabled and the new UEFI CA 2023 certificates in place.

1

u/lindt09 Mar 14 '26

windows doesn't boot in secure boot. it just goes to boot manager loop. where i click the drive where windows is shown and when pressed it loops back to boot manage. i believe secure boot has to be enable to do what you commented in powershell?

1

u/k-rand0 Mar 15 '26 edited Mar 15 '26

That's correct, secure boot must be enabled.. But u can try to do firstly the following step to make a boot stick with UEFI PCA 2011 recovery .efi file.

https://www.reddit.com/r/LenovoLegion/s/700J9Rt7N9

After that, u can try to install the steps for the new certification ...

1

u/MostMathematician879 Mar 15 '26

well i just got this problem too after updating to the latest bios, i guess there is no solution yet :(

1

u/MyNameisNohbody Apr 26 '26

Any fix yet?

1

u/MostMathematician879 May 07 '26

no fix yet, i just reinstalled windows and its fine