Skip to content

Secure Boot#

Secure Boot

System Mode

Display only


  1. Deployed Mode - Default.
  2. Audit Mode
  3. User Mode
  4. Setup Mode
Secure Boot
  1. Enabled - BIOS will prevent unauthorized OS from loading.
  2. Disabled - disables Secure Boot.
WMI Setting name Values Locked by SVP
SecureBoot Disabled, Enabled yes
Restore Factory Keys

Restore Factory Keys resets secure boot to factory defaults.

Press Yes to proceed, or No to cancel.

Reset Platform to Setup Mode
Reset to setup mode will change secure boot to setup mode.
Enter Audit Mode

Enter Audit Mode workflow.

  • Transition from user to Audit Mode will result in erasing PK (Platform Key) variable.
  • Removing PK (Platform Key) will reset the system to setup / audit mode.
Enter Deployed Mode
Transition between Deployment and User Modes.
Allow Microsoft 3rd Party UEFI CA


  1. Enabled - Install Microsoft 3rd Party UEFI CA, and trust it in secure boot. Default.
  2. Disabled. Remove Microsoft 3rd Party UEFI CA in secure boot BD.
WMI Setting name Values Locked by SVP
AllowMicrosoft3rdPartyUEFICA Enabled, Disabled yes

If add-on cards are supported, Microsoft 3rd Party UEFI CA will not be removed until the boot loader is loaded.