UMC Security Advisory: WARNING: Windows Boot Manager has been blocked by the current security policy.
Windows Boot Manager has been blocked by the current security policy.
Recently, some of the BIOS and/or Windows updates are causing issues related to Secure Boot. We already have a guide on how to prevent and mitigate Secure Boot issues before June by updating certificates yourself.
However, if you have an issue where Secure Boot set to On/Enabled causes you to not be able to boot into Windows, here is a guide.
- Create a FAT32 USB/SD card.
- Download SecureBootRecovery.zip - https://github.com/user-attachments/files/24540206/SecureBootRecovery.zip
- Create a folder called efi and inside it a folder called boot
- Extract the zip and put the file as \efi\boot\bootx64.efi (rename SecureBootRecovery.efi to bootx64.efi) on a FAT32 USB/SD card.
- Boot from that USB once. You can now boot to Windows with Secure Boot set to On/Enabled.
sources: Unable to update Default UEFI DB #15 - https://github.com/cjee21/Check-UEFISecureBootVariables/issues/15#issuecomment-3732066463 (Closed on Issue #15 on Jan 10, 2026)
Windows only boots when Secure Boot is disabled - https://www.reddit.com/r/Lenovo/comments/1rsr283/loq_15aph8_secure_boot_issue_windows_only_boots/oakc8vp/ (published on March 13, 2026 | retrieved on April 1, 2026)
reddit link above but different approach -https://www.reddit.com/r/Lenovo/comments/1rsr283/loq_15aph8_secure_boot_issue_windows_only_boots/obxn98b/ (published on March 13, 2026 | retrieved on April 1, 2026)
comment pointing out that updating Secure Boot certificates beforehand can help - https://www.reddit.com/r/LenovoLegion/comments/1rfvwo9/secure_boot_problem_whens_the_next_bios_update/o7ndgty/ (published on February 23, 2026 | retrieved on April 1, 2026)
This came from the Legion Series Discord in #warnings.
Comments
Post a Comment