2 Intern
•
29 Posts
2
883
February 20th, 2026 11:55
Aurora R10, Secure boot is on but windows says its not
So i have alienware aurora r10 ryzen edition bios 2.10.0 and in bios secure boot is set to Enabled. In windows msinfo32 it shows secure boot state is off.
Ive had it enabled for awhile now been playing Battlefield just fine and out of no where its now showing that its off and i cant play any game that needs it enabled.
Ive tried disabling it and re-enabling it. Everything is up to date. Not sure why its not working now.
No Events found!


thekiller199365
2 Intern
•
29 Posts
2
February 25th, 2026 06:02
So i was told by dell tech support to downgrade to the previous version of bios which would be 2.9.1 to see if that would fix it. It did, its in deployed mode and msinfo32 says secure boot state is On. Thank you guys for helping.
(edited)
it-at-tridauto
2 Intern
•
16 Posts
•
2 Points
0
February 20th, 2026 16:30
I don't have any Alienware devices but I have Dell desktops and laptops that have a similar looking BIOS Setup. Your BIOS might have its Secure Boot set to "Audit" mode instead of "Deployed" mode, which is still "enabled" but the Audit mode does not enforce Secure Boot rules.
Hopefully these screens look similar to your screens from your Alienware BIOS.
If you need to, make sure you save a backup of your settings before you change them. You can undo them if your machine doesn't boot afterward. Switching between Audit mode and Deployed mode is an effective on/off switch for Secure Boot, at least on Precision 76xx laptops.
See if this helps.
thekiller199365
2 Intern
•
29 Posts
0
February 21st, 2026 04:56
For some reason it won't let me change it. It gives me a warning that says
" changing the secure boot mode will enroll the default dell platform key. If you wish to enroll a custom key, use expert key management." So I press okay. And it stays on audit mode.
thekiller199365
2 Intern
•
29 Posts
0
February 21st, 2026 07:17
yeah it wont change to deployed mode. it switches back to audit. Sorry for the sideways pitcures lol
(edited)
Tesla1856
10 Wizard
•
17.9K Posts
•
71.4K Points
0
February 21st, 2026 18:05
@thekiller199365 ,
Yeah, looks like someone (Dell ?) left it in Audit-Mode (or you had "some event" and it got switched to that). That's for BIOS and driver testing ... Experimental stuff. Deployed-Mode is what you want when you are using the computer "for real".
The default Dell Platform-Key (PK) is what we are all using on our machines now. But yeah, that is not something you would want in Audit-Mode.
(edited)
thekiller199365
2 Intern
•
29 Posts
0
February 22nd, 2026 00:55
@Tesla1856 when it came out that you had to have secure boot on for battlefield and call of duty I think sometime last year. I remember going into the bios and it was already enabled and I was able to play. It just recently started saying it wasn't enabled.
Then went into bios and seen it was enabled but in audit mode and Microsoft support said I needed dells platform key which I don't know how to get. Can't talk to dell chat support all it is, is an AI. And my support service thing ended like a couple years ago.
Tesla1856
10 Wizard
•
17.9K Posts
•
71.4K Points
0
February 22nd, 2026 02:13
@thekiller199365 ,
1. nice
2. cool
3. bummer
4. I don't think you can in Audit-Mode. Re-read my post above.
5. Really?! But I thought AI was all-knowing and everything they say is golden (at least that is how many people act now-days).
Problem is ... I don't really "do AMD" or know about AMD-chipset motherboards. But hopefully what I already told you pushes you in the correct direction to resolve your issue.
(edited)
thekiller199365
2 Intern
•
29 Posts
0
February 22nd, 2026 03:32
@Tesla1856 so should I be talking to amd support or dell. Microsoft support said I need dells default product key don't know where to go to get it.
Tesla1856
10 Wizard
•
17.9K Posts
•
71.4K Points
0
February 22nd, 2026 04:48
@thekiller199365 ,
AFAIK, the Default Product Key is in the BIOS-Firmware, waiting to be used. Once the motherboard is successfully shifted into Deployed-Mode (aka normal-use Mode) the Product-Key (normally called PK) will be automatically available when you are in Windows using SecureBoot Mode.
I think Dell/Alienware is support for all the Alienware Auroras ... aren't they?
Were you messing with the Keys in Custom-Key-Management ... like back when it was still working?
(edited)
thekiller199365
2 Intern
•
29 Posts
1
February 22nd, 2026 05:45
@Tesla1856 no, never touched it. Only went to the bios to enable it for the games but it was already enabled so I never messed with it.
thekiller199365
2 Intern
•
29 Posts
0
February 23rd, 2026 07:17
I sent tech support an email. Not sure how long it'll take for them to respond but hope I can get it fixed eventually.
it-at-tridauto
2 Intern
•
16 Posts
•
2 Points
1
February 23rd, 2026 15:05
If what I'm seeing (after straining my neck!) is correct, you should just be able to switch it back to Deployed mode and it should start working again. I'm surprised you can't switch it though.
I've only had to start looking at Secure Boot problems recently, so I'm no expert. What I do know is you want the machine's default Platform Key (PK) because all of the other keys and certificates chain off of this one.
If your machine is still getting BIOS updates, the update should contain the PK and all of the subordinate keys and certificates, including the Microsoft-supplied KEK and DB certs. If the machine is too old to get these, it should at least be able to load these into the machine's NVRAM like other BIOS settings.
If you have local admin access on your PC, would you try running the Secure Boot check script from this GitHub repository, and copy / paste the text result?
https://github.com/cjee21/Check-UEFISecureBootVariables
Download and extract the entire repository (it's only 264 KB), run the "Check UEFI PK, KEK, DB and DBX.cmd" script as an admin, and report the output to here. If Secure Boot is disabled, it should still retrieve what keys and certificates are present, both in the BIOS firmware (Default) and in the NVRAM (Current).
There are some tools in that repository that can force updating the keys and certs, but don't use those yet. If your machine doesn't have the updated certs in the Default sections, you risk messing up Secure Boot by using those tools without advice. You can always put the machine back into Audit mode to at least boot if you do get stuck.
(edited)
thekiller199365
2 Intern
•
29 Posts
1
February 24th, 2026 05:58
@it-at-tridauto
Checking for Administrator permission...
Running as administrator - continuing execution...
24 February 2026
Manufacturer: Alienware
Model: Alienware Aurora Ryzen Edition
BIOS: Alienware, 2.10.0, 2.10.0, ALWARE - 1072009
Windows version: 25H2 (Build 26200.7840)
Detected x64 UEFI architecture. Ensure that this is correct for valid DBX results.
Secure Boot status: Disabled
Current UEFI PK
WARNING: Failed to query UEFI variable PK
Default UEFI PK
WARNING: Failed to query UEFI variable PKDefault
Current UEFI KEK
WARNING: Failed to query UEFI variable 'kek' for cert 'Microsoft Corporation KEK CA 2011'
WARNING: Failed to query UEFI variable 'kek' for cert 'Microsoft Corporation KEK 2K CA 2023'
WARNING: Failed to query UEFI variable 'kek'
Default UEFI KEK
WARNING: Failed to query UEFI variable 'KEKDefault' for cert 'Microsoft Corporation KEK CA 2011'
WARNING: Failed to query UEFI variable 'KEKDefault' for cert 'Microsoft Corporation KEK 2K CA 2023'
WARNING: Failed to query UEFI variable 'KEKDefault'
Current UEFI DB
√ Microsoft Windows Production PCA 2011 (revoked: False)
√ Microsoft Corporation UEFI CA 2011 (revoked: False)
X Windows UEFI CA 2023
X Microsoft UEFI CA 2023
X Microsoft Option ROM UEFI CA 2023
√ Microsoft Windows UEFI Driver Publisher (revoked: False)
√ Microsoft Windows (revoked: False)
Default UEFI DB
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Microsoft Windows Production PCA 2011'
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Microsoft Corporation UEFI CA 2011'
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Windows UEFI CA 2023'
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Microsoft UEFI CA 2023'
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Microsoft Option ROM UEFI CA 2023'
WARNING: Failed to query UEFI variable 'DBDefault'
Current UEFI DBX
2025-10-14 (v1.6.0) [x64] : ERROR: An exception has occurred while checking DBX
Get-SecureBootUEFI : Variable is currently undefined: 0xC0000100
At C:\Users\(redact)\Downloads\Check-UEFISecureBootVariables-main\Check-UEFISecureBootVariables-main\ps\Check UEFI PK,
KEK, DB and DBX.ps1:270 char:15
+ $dbx_bytes = (Get-SecureBootUEFI dbx).Bytes
+ ~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : ResourceUnavailable: (Microsoft.Secur...BootUefiCommand:GetSecureBootUefiCommand) [Get-S
ecureBootUEFI], StatusException
+ FullyQualifiedErrorId : GetFWVarFailed,Microsoft.SecureBoot.Commands.GetSecureBootUefiCommand
Windows Bootmgr SVN : None
Windows cdboot SVN : None
Windows wdsmgfw SVN : None
(edited)
it-at-tridauto
2 Intern
•
16 Posts
•
2 Points
0
February 24th, 2026 14:03
Thanks for sending this. This and several other warning lines don't look good:
Having worked on a few Dell PCs now, the failure of the scripts to query the PK and KEK sections is concerning. There's something else going on that's messing with Secure Boot on this machine. I wonder if you have some other kernel level shenanigans blocking access to this.
If I had physical access to this PC, I would have tried booting it from a Windows Preinstall Environment USB device and checking the Secure Boot keys and certs that way. That is getting way too involved for remote troubleshooting.
Before searching for shenanigans though, there appears to be another thread referencing a similar problem with Aurora R10 machines not being able to get Secure Boot working. There's an out of band BIOS update to address it apparently. @DELL-Nat M replied to that thread specifying the Dell KB (000387773) referencing the problem.
See if you can get that updated first. If that doesn't let you properly enable Secure Boot and run the Check scripts, then it needs to be serviced by someone in person.
thekiller199365
2 Intern
•
29 Posts
0
February 24th, 2026 14:33
I mean as weird as it sounds, i've been wanting to reset my pc like im starting over. If i were to reinstall windows would that fix the issue? and that thread i think is more to do with tpm. when i run tpm.msc it shows that its working. I can still check it out and see if it'll work.