What does HRESULT 0x803100BB (FVE_E_SECUREBOOT_CONFIGURATION_INVALID) mean?

 
Previous Next
FVE_E_SECUREBOOT_DISABLED FVE_E_EDRIVE_DRY_RUN_FAILED

FVE_E_SECUREBOOT_CONFIGURATION_INVALID

Enabled does not necessarily mean measurable

FVE_E_SECUREBOOT_CONFIGURATION_INVALID indicates that BitLocker cannot rely on the current Secure Boot configuration for platform integrity even though Secure Boot may appear enabled. PCR 7 use depends on correctly formed UEFI variables, authenticated boot policy, and corresponding TCG event-log entries.

Microsoft’s validation guidance lists failures such as unreadable Secure Boot variables, missing or malformed authority events, an invalid signature-database relationship, or a boot loader whose certificate chain cannot be matched to the recorded authority.

Evidence to collect

  • The PCR profile from manage-bde, Secure Boot state from system information, and BitLocker-API Management events.
  • Event IDs associated with PCR 7 sealing and unexpected Secure Boot changes.
  • Firmware version, trust-database updates, custom Secure Boot keys, and recent boot-loader servicing.
  • Do not clear the TPM as a first step; that removes sealed state without correcting malformed firmware measurements.

References


Looking for a different code? Search another status or error code.