2 Intern

 • 

29 Posts

883

February 20th, 2026 11:55

Aurora R10, Secure boot is on but windows says its not

So i have alienware aurora r10 ryzen edition bios 2.10.0 and in bios secure boot is set to Enabled. In windows msinfo32 it shows secure boot state is off. 

Ive had it enabled for awhile now been playing Battlefield just fine and out of no where its now showing that its off and i cant play any game that needs it enabled. 

Ive tried disabling it and re-enabling it. Everything is up to date. Not sure why its not working now.

2 Intern

 • 

29 Posts

February 25th, 2026 06:02

So i was told by dell tech support to downgrade to the previous version of bios which would be 2.9.1 to see if that would fix it. It did, its in deployed mode and msinfo32 says secure boot state is On. Thank you guys for helping.

(edited)

2 Intern

 • 

16 Posts

 • 

2 Points

February 20th, 2026 16:30

I don't have any Alienware devices but I have Dell desktops and laptops that have a similar looking BIOS Setup. Your BIOS might have its Secure Boot set to "Audit" mode instead of "Deployed" mode, which is still "enabled" but the Audit mode does not enforce Secure Boot rules.

Hopefully these screens look similar to your screens from your Alienware BIOS.

If you need to, make sure you save a backup of your settings before you change them. You can undo them if your machine doesn't boot afterward. Switching between Audit mode and Deployed mode is an effective on/off switch for Secure Boot, at least on Precision 76xx laptops.

See if this helps.

2 Intern

 • 

29 Posts

February 21st, 2026 04:56

For some reason it won't let me change it. It gives me a warning that says

" changing the secure boot mode will enroll the default dell platform key. If you wish to enroll a custom key, use expert key management." So I press okay. And it stays on audit mode.

2 Intern

 • 

29 Posts

February 21st, 2026 07:17

yeah it wont change to deployed mode. it switches back to audit. Sorry for the sideways pitcures lol

(edited)

10 Wizard

 • 

17.9K Posts

 • 

71.4K Points

February 21st, 2026 18:05

@thekiller199365​ ,

 

Yeah, looks like someone (Dell ?) left it in Audit-Mode (or you had "some event" and it got switched to that). That's for BIOS and driver testing ... Experimental stuff. Deployed-Mode is what you want when you are using the computer "for real".

 

The default Dell Platform-Key (PK) is what we are all using on our machines now. But yeah, that is not something you would want in Audit-Mode.

(edited)

2 Intern

 • 

29 Posts

February 22nd, 2026 00:55

@Tesla1856​ when it came out that you had to have secure boot on for battlefield and call of duty I think sometime last year. I remember going into the bios and it was already enabled and I was able to play. It just recently started saying it wasn't enabled.

Then went into bios and seen it was enabled but in audit mode and Microsoft support said I needed dells platform key which I don't know how to get. Can't talk to dell chat support all it is, is an AI. And my support service thing ended like a couple years ago.

10 Wizard

 • 

17.9K Posts

 • 

71.4K Points

February 22nd, 2026 02:13

@thekiller199365​ ,

1. when it came out that you had to have secure boot on for battlefield and call of duty I think sometime last year. I remember going into the bios and it was already enabled

2. and I was able to play.

3. It just recently started saying it wasn't enabled.

4. Then went into bios and seen it was enabled but in audit mode and Microsoft support said I needed dells platform key which I don't know how to get.

5. Can't talk to dell chat support all it is, is an AI. 

1. nice

2. cool

3. bummer

4. I don't think you can in Audit-Mode. Re-read my post above.

5. Really?! But I thought AI was all-knowing and everything they say is golden (at least that is how many people act now-days).

 

Problem is ... I don't really "do AMD" or know about AMD-chipset motherboards. But hopefully what I already told you pushes you in the correct direction to resolve your issue.

(edited)

2 Intern

 • 

29 Posts

February 22nd, 2026 03:32

@Tesla1856​ so should I be talking to amd support or dell. Microsoft support said I need dells default product key don't know where to go to get it. 

10 Wizard

 • 

17.9K Posts

 • 

71.4K Points

February 22nd, 2026 04:48

@thekiller199365​ ,

 

AFAIK, the Default Product Key is in the BIOS-Firmware, waiting to be used. Once the motherboard is successfully shifted into Deployed-Mode (aka normal-use Mode) the Product-Key (normally called PK) will be automatically available when you are in Windows using SecureBoot Mode. 

 

I think Dell/Alienware is support for all the Alienware Auroras ... aren't they?

 

Were you messing with the Keys in Custom-Key-Management ... like back when it was still working?

(edited)

2 Intern

 • 

29 Posts

February 22nd, 2026 05:45

@Tesla1856​ no, never touched it. Only went to the bios to enable it for the games but it was already enabled so I never messed with it.

2 Intern

 • 

29 Posts

February 23rd, 2026 07:17

I sent tech support an email. Not sure how long it'll take for them to respond but hope I can get it fixed eventually.

2 Intern

 • 

16 Posts

 • 

2 Points

February 23rd, 2026 15:05

If what I'm seeing (after straining my neck!) is correct, you should just be able to switch it back to Deployed mode and it should start working again. I'm surprised you can't switch it though.

I've only had to start looking at Secure Boot problems recently, so I'm no expert. What I do know is you want the machine's default Platform Key (PK) because all of the other keys and certificates chain off of this one.

If your machine is still getting BIOS updates, the update should contain the PK and all of the subordinate keys and certificates, including the Microsoft-supplied KEK and DB certs. If the machine is too old to get these, it should at least be able to load these into the machine's NVRAM like other BIOS settings.

If you have local admin access on your PC, would you try running the Secure Boot check script from this GitHub repository, and copy / paste the text result?

https://github.com/cjee21/Check-UEFISecureBootVariables

Download and extract the entire repository (it's only 264 KB), run the "Check UEFI PK, KEK, DB and DBX.cmd" script as an admin, and report the output to here. If Secure Boot is disabled, it should still retrieve what keys and certificates are present, both in the BIOS firmware (Default) and in the NVRAM (Current).

There are some tools in that repository that can force updating the keys and certs, but don't use those yet. If your machine doesn't have the updated certs in the Default sections, you risk messing up Secure Boot by using those tools without advice. You can always put the machine back into Audit mode to at least boot if you do get stuck.

(edited)

2 Intern

 • 

29 Posts

February 24th, 2026 05:58

@it-at-tridauto​ 

Checking for Administrator permission...
Running as administrator - continuing execution...

24 February 2026
Manufacturer: Alienware
Model: Alienware Aurora Ryzen Edition
BIOS: Alienware, 2.10.0, 2.10.0, ALWARE - 1072009
Windows version: 25H2 (Build 26200.7840)

Detected x64 UEFI architecture. Ensure that this is correct for valid DBX results.

Secure Boot status: Disabled

Current UEFI PK
WARNING: Failed to query UEFI variable PK

Default UEFI PK
WARNING: Failed to query UEFI variable PKDefault

Current UEFI KEK
WARNING: Failed to query UEFI variable 'kek' for cert 'Microsoft Corporation KEK CA 2011'
WARNING: Failed to query UEFI variable 'kek' for cert 'Microsoft Corporation KEK 2K CA 2023'
WARNING: Failed to query UEFI variable 'kek'

Default UEFI KEK
WARNING: Failed to query UEFI variable 'KEKDefault' for cert 'Microsoft Corporation KEK CA 2011'
WARNING: Failed to query UEFI variable 'KEKDefault' for cert 'Microsoft Corporation KEK 2K CA 2023'
WARNING: Failed to query UEFI variable 'KEKDefault'

Current UEFI DB
√ Microsoft Windows Production PCA 2011 (revoked: False)
√ Microsoft Corporation UEFI CA 2011 (revoked: False)
X Windows UEFI CA 2023
X Microsoft UEFI CA 2023
X Microsoft Option ROM UEFI CA 2023
√ Microsoft Windows UEFI Driver Publisher (revoked: False)
√ Microsoft Windows (revoked: False)

Default UEFI DB
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Microsoft Windows Production PCA 2011'
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Microsoft Corporation UEFI CA 2011'
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Windows UEFI CA 2023'
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Microsoft UEFI CA 2023'
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Microsoft Option ROM UEFI CA 2023'
WARNING: Failed to query UEFI variable 'DBDefault'

Current UEFI DBX
2025-10-14 (v1.6.0) [x64]   : ERROR: An exception has occurred while checking DBX
Get-SecureBootUEFI : Variable is currently undefined: 0xC0000100
At C:\Users\(redact)\Downloads\Check-UEFISecureBootVariables-main\Check-UEFISecureBootVariables-main\ps\Check UEFI PK,
KEK, DB and DBX.ps1:270 char:15
+ $dbx_bytes = (Get-SecureBootUEFI dbx).Bytes
+               ~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : ResourceUnavailable: (Microsoft.Secur...BootUefiCommand:GetSecureBootUefiCommand) [Get-S
   ecureBootUEFI], StatusException
    + FullyQualifiedErrorId : GetFWVarFailed,Microsoft.SecureBoot.Commands.GetSecureBootUefiCommand

Windows Bootmgr SVN         : None
Windows cdboot SVN          : None
Windows wdsmgfw SVN         : None

(edited)

2 Intern

 • 

16 Posts

 • 

2 Points

February 24th, 2026 14:03

Thanks for sending this. This and several other warning lines don't look good:

WARNING: Failed to query UEFI variable 'kek' for cert 'Microsoft Corporation KEK 2K CA 2023'

Having worked on a few Dell PCs now, the failure of the scripts to query the PK and KEK sections is concerning. There's something else going on that's messing with Secure Boot on this machine. I wonder if you have some other kernel level shenanigans blocking access to this.

If I had physical access to this PC, I would have tried booting it from a Windows Preinstall Environment USB device and checking the Secure Boot keys and certs that way. That is getting way too involved for remote troubleshooting.

Before searching for shenanigans though, there appears to be another thread referencing a similar problem with Aurora R10 machines not being able to get Secure Boot working. There's an out of band BIOS update to address it apparently. @DELL-Nat M replied to that thread specifying the Dell KB (000387773) referencing the problem.

See if you can get that updated first. If that doesn't let you properly enable Secure Boot and run the Check scripts, then it needs to be serviced by someone in person.

2 Intern

 • 

29 Posts

February 24th, 2026 14:33

I mean as weird as it sounds, i've been wanting to reset my pc like im starting over. If i were to reinstall windows would that fix the issue? and that thread i think is more to do with tpm. when i run tpm.msc it shows that its working. I can still check it out and see if it'll work.

No Events found!

Top