Windows won’t start

'Secure Boot Violation' error prevents Windows from starting

The screen shows a message like 'Secure Boot Violation' or 'Invalid signature detected, check Secure Boot Policy,' and Windows refuses to start as a security precaution.

Difficulty
Advanced
Time
20–60 minutes
DIY cost
$0
Pro cost
$80–$180

Symptoms

  • Error text specifically mentions Secure Boot Violation
  • Appears right after the BIOS logo, before Windows loads
  • May follow a BIOS update, installing another OS, or a bootable USB left connected
  • PC previously booted fine before this appeared

Likely causes

  • CommonBoot loader or bootable USB not signed for Secure BootCertain Linux installers or older bootable tools aren't Secure Boot compatible by default.
  • CommonBIOS/UEFI firmware update changed Secure Boot keys or settingsUpdates can occasionally reset or alter Secure Boot's trusted key database.
  • PossibleMalware attempting to modify the boot processSecure Boot is specifically designed to catch and block this kind of tampering.
  • PossibleDual-boot setup with a non-Secure-Boot-compliant OS installedInstalling certain other operating systems can trip this check.
  • Less commonCorrupted UEFI firmware settingsRare firmware corruption can cause false violation detections.

What to do

  1. Remove any USB drives or discs and restart, since a non-compliant bootable USB is a very common trigger.
  2. If it persists, enter BIOS/UEFI setup and check the Secure Boot section for any pending key or policy update prompts.
  3. If you recently updated BIOS firmware, check the manufacturer's site for known Secure Boot issues with that specific firmware version.
  4. As a temporary test, you can disable Secure Boot in BIOS to confirm Windows boots normally without it, which confirms Secure Boot is the specific blocker.
  5. If disabling it works, re-enable Secure Boot afterward once the underlying cause (like a bad USB or dual-boot OS) is addressed, since leaving it off reduces security.
  6. If a dual-boot OS caused this, check that OS's documentation for Secure Boot compatible boot loader setup, such as using a signed shim.
  7. If you suspect malware rather than a hardware/software change, run a full antivirus/anti-malware scan from a bootable rescue disk before re-enabling Secure Boot.

Tools and parts

  • Bootable antivirus rescue USB, if malware is suspected

When to call a pro

If you're not comfortable adjusting Secure Boot or firmware settings, or if malware tampering is suspected, a technician can safely diagnose and resolve this without weakening your PC's security.

Safety

Generally low risk

Generally low risk for a careful person. Stop if anything looks different from what this guide describes.

Related guides

Operator provides AI-generated troubleshooting information. It can be wrong. For safety-critical, electrical, gas, structural, medical, automotive safety, or other high-risk problems, consult a qualified professional.