| Previous | Next |
| FVE_E_SECUREBOOT_DISABLED | FVE_E_EDRIVE_DRY_RUN_FAILED |
FVE_E_SECUREBOOT_CONFIGURATION_INVALID
Enabled does not necessarily mean measurable
FVE_E_SECUREBOOT_CONFIGURATION_INVALID indicates that BitLocker cannot rely on the current Secure Boot configuration for platform integrity even though Secure Boot may appear enabled. PCR 7 use depends on correctly formed UEFI variables, authenticated boot policy, and corresponding TCG event-log entries.
Microsoft’s validation guidance lists failures such as unreadable Secure Boot variables, missing or malformed authority events, an invalid signature-database relationship, or a boot loader whose certificate chain cannot be matched to the recorded authority.
Evidence to collect
- The PCR profile from
manage-bde, Secure Boot state from system information, and BitLocker-API Management events. - Event IDs associated with PCR 7 sealing and unexpected Secure Boot changes.
- Firmware version, trust-database updates, custom Secure Boot keys, and recent boot-loader servicing.
- Do not clear the TPM as a first step; that removes sealed state without correcting malformed firmware measurements.
References
- Microsoft: BitLocker check after firmware update
- TCG: EFI platform event measurements
- UEFI: Secure Boot and driver signing
Looking for a different code? Search another status or error code.