| Previous | Next |
| STATUS_FVE_SECUREBOOT_DISABLED | STATUS_FVE_DEVICE_LOCKEDOUT |
STATUS_FVE_SECUREBOOT_CONFIG_CHANGE
The key point is policy change, not merely whether Secure Boot is on. BitLocker detected that the Secure Boot configuration no longer matches the expected protected-startup environment, so this status should be investigated as a boot-trust change.
Collect the previous and current firmware settings, key enrollment or policy updates, boot-manager changes, and the time of the first recovery or failure. Keep the approved recovery path available while validating whether the change was an authorized firmware maintenance event.
Do not collapse this with STATUS_FVE_SECUREBOOT_DISABLED. A platform can have Secure Boot enabled yet still present a changed policy that affects the measured or verified boot conditions used for BitLocker protection.
UEFI Secure Boot | UEFI Boot Manager | BitLocker recovery overview
Looking for a different code? Search another status or error code.