Macrium Secure boot


man00

Well-known member
Member
Local time
10:12 PM
Posts
319
OS
windows 11
I updated my system for the June thing that MS id suppose to do
now my macrium usb rescue disk won't boot. Is it safe to disable secure boot in bios
without screwing up everything and turning it back on when needed. I can not find how to update the rescue disk

 

My Computer

System One

  • OS
    windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Antec/Case
    CPU
    Intel i5-10600kf
    Motherboard
    GIGABYTE Z590 UD AC
    Memory
    32gb corsair vengerance pro
    Graphics Card(s)
    AMD RX 6500XT
    Sound Card
    onboard
    Monitor(s) Displays
    40" Hisense
    Hard Drives
    Samsung 850
    Samsung 870
    Seagate 2TB
    PSU
    EVGA GQ 750
You can fix your macrium boot drive:

In an Administrator powershell window, mount your system partition and replace the necessary in the macrium boot builder area with the system partitions:

mountvol s: /s
copy s:\EFI\Boot\bootx64.efi C:\boot\macrium\WinREFiles\media\EFI\Boot\bootx64.efi
copy S:\EFI\Microsoft\Boot\bootmgfw.efi C:\boot\macrium\WinREFiles\media\EFI\Boot\bootx64.efi

Then rebuild your rescue media in macrium and try it
 

My Computers

System One System Two

  • OS
    Windows 11 Pro x64
    Computer type
    PC/Desktop
    Manufacturer/Model
    📷🔈🎧 🪛 DIY Photoshop/Audio/Game/tinker
    CPU
    i9 14900K P/E 5.8/4.5 GHz, cache 5.0 GHz
    Motherboard
    Asus ROG Maximus Z790 Dark Hero
    Memory
    🐏 96GB (2x48) G.skill Ripjaws 6800 MT/s
    Graphics Card(s)
    Asus ROG Strix 4070 Ti OC
    Sound Card
    🔊Bowers & Wilkins 606 S3 speakers; Audiolabs 7000a integrated amp; RSL 10S Mk2 sub; Creative Pebble Pro Minimilist
    Monitor(s) Displays
    🖥️🖥️ Eizo CG2730 ColorEdge, ViewSonic VP2768
    Screen Resolution
    🖥️🖥️ 2560 x 1440p x 2
    Hard Drives
    💾 WDC SN850X 4TB nvme, SN850 1TB nvme, SK-Hynix 2 TB P41 nvme,. Sabrent USB-C DS-SC5B 5-bay docking station: 6TB WDC Black, 6TB Ironwolf Pro; 2x 2TB WDC Black HDD
    PSU
    ⚡️ 850W Seasonic Vertex PX-850 ATX 3.0/PCI-E 5.0
    Case
    Fractal Design North XL Mesh, Black Walnut
    Cooling
    ❄️ EK Nucleus black 360 AIO w/Phanteks T30-120 fans, 2 Noctua NF-A14 Chromax case fan, 1 T30-120 fan cooling memory
    Keyboard
    ⌨️ Keychron Q3 Max TKL with custom GMK Redsuns Red Samuri keycaps, TX Stabs
    Mouse
    🖱️ Logitech G305 wireless gaming
    Internet Speed
    ⬇️ 500 Mb/s ⬆️ 12 Mb/s
    Browser
    🔥🦊 Firefox
    Antivirus
    🦺 Defender, Macrium Reflect X 🏆
    Other Info
    Phangkey Amaterasu V2 Desk Mat
  • Computer type
    Laptop
    Manufacturer/Model
    💻 Apple 13" Macbook Pro 2020 (m1)
    CPU
    Apple M1
    Screen Resolution
    2560x1600
    Browser
    Firefox
Instead of copying the files from the EFI partition (mountvol S:), the same files live under "\Windows\Boot\EFI_EX".

You should push files outward from "\Windows\Boot\EFI_EX", instead of pulling them from the EFI. Newer versions of the boot files will be installed by Windows Update under "\Windows\Boot".
Code:
copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi C:\boot\macrium\WinREFiles\media\bootmgfw.efi
copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi C:\boot\macrium\WinREFiles\media\EFI\Boot\bootx64.efi
copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi C:\boot\macrium\WinREFiles\media\EFI\Microsoft\Boot\bootmgfw.efi
 

My Computer

System One

  • OS
    Windows 7
Is it safe to disable secure boot in bios
without screwing up everything and turning it back on when needed.
To answer your question. Yes it is safe to temporarily disable secure boot in order to boot from Macrium rescue usb.

Per Macrium "In the event that a disaster has occurred meaning that a rescue media restore is needed, we recommend temporarily disabling Secure Boot to enable the system to boot the rescue media and then performing a restore.
reference Managing the Boot Media Signing Certificate for Macrium Reflect Rescue Media
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    2x1tb Solidigm m.2 nvme /External drives 512gb Samsung m.2 sata+2tb Kingston m2.nvme
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    #1 Edge #2 Firefox
    Antivirus
    Defender+MWB Premium
  • Operating System
    Windows 11 Pro 24H2 26200.8457
    Computer type
    PC/Desktop
    Manufacturer/Model
    Beelink Mini PC SER5
    CPU
    AMD Ryzen 7 6800U
    Memory
    32 gb
    Graphics card(s)
    integrated
    Sound Card
    integrated
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Crucial nvme
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    still too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender
    Other Info
    System 3 is non compliant Dell 9020 i7-4770/24gb ram Win11 PRO 26200.8457
Per Macrium "In the event that a disaster has occurred meaning that a rescue media restore is needed, we recommend temporarily disabling Secure Boot to enable the system to boot the rescue media and then performing a restore.
reference Managing the Boot Media Signing Certificate for Macrium Reflect Rescue Media
That's really nice that Macrium X supports the option to pick a version of the Secure Boot files, but unfortunately you don't get that for Macrium v8.

You got to copy files by hand, or use a script.
 

My Computer

System One

  • OS
    Windows 7
Thanks folks, got it
 

My Computer

System One

  • OS
    windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Antec/Case
    CPU
    Intel i5-10600kf
    Motherboard
    GIGABYTE Z590 UD AC
    Memory
    32gb corsair vengerance pro
    Graphics Card(s)
    AMD RX 6500XT
    Sound Card
    onboard
    Monitor(s) Displays
    40" Hisense
    Hard Drives
    Samsung 850
    Samsung 870
    Seagate 2TB
    PSU
    EVGA GQ 750
That's really nice that Macrium X supports the option to pick a version of the Secure Boot files, but unfortunately you don't get that for Macrium v8.
Thanks for the correction. I just assumed he was on X. My bad for assuming.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    2x1tb Solidigm m.2 nvme /External drives 512gb Samsung m.2 sata+2tb Kingston m2.nvme
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    #1 Edge #2 Firefox
    Antivirus
    Defender+MWB Premium
  • Operating System
    Windows 11 Pro 24H2 26200.8457
    Computer type
    PC/Desktop
    Manufacturer/Model
    Beelink Mini PC SER5
    CPU
    AMD Ryzen 7 6800U
    Memory
    32 gb
    Graphics card(s)
    integrated
    Sound Card
    integrated
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Crucial nvme
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    still too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender
    Other Info
    System 3 is non compliant Dell 9020 i7-4770/24gb ram Win11 PRO 26200.8457
The validity period of the PCA 2011 certificate for the Windows Bootloader ends in June-October 2026..
The new UEFI CA 2023 certificate will expire in 2035.…

What is the difference between the old MacriumRescue.iso(PCA 2011) vs the new MacriumRescue.iso(UEFI CA 2023)?
You can check it yourself.
You just need to make MacriumRescue.iso(PCA 2011) and MacriumRescue.iso(UEFI CA 2023) for version 10.0.8750 (or for version 10.0.8731), then unpack the ISO archives and compare all the files of these two archives by checksum.
It will take about 30 minutes.
MacriumRescue.iso should be done on the basis of pe11Dec24x64.zip (WinPE ver. 26100)

A checksum comparison of the unpacked ISO archives v.10.0.8750(PCA 2011) vs 10.0.8750(UEFI CA 2023) shows that these archives differ in files:
MacriumRescue.iso\Boot\efisys_noprompt.bin
MacriumRescue.iso\Boot\efisys_prompt.bin
MacriumRescue.iso\EFI\Boot\bootx64.efi
MacriumRescue.iso\EFI\Microsoft\Boot\
bootmgfw.efi
NOTE:
1. For MacriumRescue.iso ver. 10.0.8750(PCA 2011), these files have the old PCA 2011 certificate.
2. For MacriumRescue.iso ver. 10.0.8750(UEFI CA 2023), these files have a new UEFI CA 2023 certificate.
3. The files "efisys_noprompt.bin" and "efisys_prompt.bin" are archives containing the file "bootx64.efi"

How to use these files when creating MacriumRescue.iso ver. 8.0 – 8.1 ?
Unfortunately, pe11Dec24x64.zip was created for Macrium Reflect v10, and it is incompatible with Macrium Reflect ver. 8.0 – 8.1
However, you can try to create MacriumRescue.iso ver. 8.0 – 8.1 based on WinPE ADK 26100
... and then replace the old BootLoader files (PCA 2011) in them with the corresponding BootLoader files of the new version (UEFI CA 2023) from this Archive:
Macrium_bootloader_PCA2011_CA2023.zip (7,8Mb)
NOTE
The Archive contains files of the old and new versions of the BootLoader from MacriumRescue 10.0.8750 based on pe11Dec24x64.zip
 
Last edited:

My Computer

System One

  • OS
    Windows 10/11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Windows 10 21H2 LTSC x64 [MSDN]; Windows 11 24H2 LTSC; m/b Z77-HD3(BIOS-MBR/UEFI); HDD WD 500Gb
The latest boot files are already provided under "C:\Windows\Boot", if you've updated to the current W11 Monthly Update (April 2026 or later). You don't need to download a ZIP file.

Replace en-US with your local language. ie. de-DE, fr-FR, es-ES

Code:
copy C:\Windows\Boot\DVD_EX\EFI\en-US\efisys_EX.bin E:\Boot\efisys_prompt.bin /y
copy C:\Windows\Boot\DVD_EX\EFI\en-US\efisys_noprompt_EX.bin E:\Boot\efisys_noprompt.bin /y
copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi E:\EFI\Boot\bootx64.efi /y
copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi E:\EFI\Microsoft\Boot\bootmgfw.efi /y
 

My Computer

System One

  • OS
    Windows 7
You don't need to download a ZIP file.
We create MacriumRescue.iso (BOOT ISO) based on WinPE
Each version of WinPE has its own set of original files of certain versions.
Currently, there is only one version of the "new" BootLoader for WinPE with the UEFI CA2023 certificate - WinPE 10.1.26100.2454 (December 2024) i.e. pe11Dec24x64.zip (official file from Macrium)

This version of WinPE contains this BootLoad kit (UEFI CA2023 certificate) :
bootx64.efi ( "Boot Manager") 10.0.26100.30227
bootmgfw.efi ( "Boot Manager") 10.0.26089.1001
efisys_prompt.bin ("CD bootstrap application") 10.0.26100.1061
efisys_noprompt.bin ("CD bootstrap application") 10.0.26100.1061

If you replace these original files with "newer versions" then you are acting at your own risk.
..We only received problems from the "new" Microsoft update for April 2026...
 
Last edited:

My Computer

System One

  • OS
    Windows 10/11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Windows 10 21H2 LTSC x64 [MSDN]; Windows 11 24H2 LTSC; m/b Z77-HD3(BIOS-MBR/UEFI); HDD WD 500Gb
I revoke this once but for some reason it returned, is it okay to just leave it

Secure Boot: ON
Virtualization Based Security: OFF
BitLocker on (C:) OFF

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023

UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023

UEFI DBX Certs
--------------
Microsoft Windows Production PCA 2011
Windows BootMgr SVN 7.0

EFI Files
---------
Disk 3: Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.

Registry: WindowsUEFICA2023Capable = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.


REQUIRED ACTION
===============

To revoke the [PCA 2011] cert, run the commands, run the commands:

reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x200 /f
powershell Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"
 

My Computer

System One

  • OS
    windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Antec/Case
    CPU
    Intel i5-10600kf
    Motherboard
    GIGABYTE Z590 UD AC
    Memory
    32gb corsair vengerance pro
    Graphics Card(s)
    AMD RX 6500XT
    Sound Card
    onboard
    Monitor(s) Displays
    40" Hisense
    Hard Drives
    Samsung 850
    Samsung 870
    Seagate 2TB
    PSU
    EVGA GQ 750
I revoke this once but for some reason it returned, is it okay to just leave it
If you don't know what to do, then don't do anything. ;-)
... For testing, I made the Free version of Macrium 8.0.7175 based on ADK WinPE 10.1.26100.2454 .. and then replaced the bootloaders with the UEFI CA2023
I did not install Secure Boot, so this version is untested.
If you want, you can check this MacriumRescue.iso at your own risk.
MR_Free_8_0_7175_pe11_26100_UEFI_CA2023_x64_en.zip (383Mb)
 

My Computer

System One

  • OS
    Windows 10/11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Windows 10 21H2 LTSC x64 [MSDN]; Windows 11 24H2 LTSC; m/b Z77-HD3(BIOS-MBR/UEFI); HDD WD 500Gb
Thanks my MacriumRescue works fine I just noticed I made this post in the wrong place....Sorry
 

My Computer

System One

  • OS
    windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Antec/Case
    CPU
    Intel i5-10600kf
    Motherboard
    GIGABYTE Z590 UD AC
    Memory
    32gb corsair vengerance pro
    Graphics Card(s)
    AMD RX 6500XT
    Sound Card
    onboard
    Monitor(s) Displays
    40" Hisense
    Hard Drives
    Samsung 850
    Samsung 870
    Seagate 2TB
    PSU
    EVGA GQ 750
Thanks my MacriumRescue works fine I just noticed I made this post in the wrong place
Thanks for checking it out. It's hard to be the first. ;-)
Did you probably make a Backup, but didn't make a Recovery?
The final conclusion can be made only after a full check, in the "total System crash" mode, i.e., on a TEST disk.:
WARNING:
if you've never done a "Total System Crash", then do it only on the
TEST disk!
Do not do a "Total System Crash" on your laptop, as you may lose your factory copy of Windows!

1. Backup all Windows partitions
100Mb(Active Service Partition)
16Mb(Service Partition)
40-100Gb(Windows File, Data, and Programs section)
500Mb(Service Recovery Partition)
Save the backup to disk D (or E, F, etc.)
2. Run the Windows 11 installation from a Windows bootable flash drive, and delete all four Windows partitions during the dialog.
Then abort the Windows installation and turn off the computer.
3. Download from a USB flash drive MacriumRescue.iso (UEFI CA2023) and restore Backup(item 1)
 
Last edited:

My Computer

System One

  • OS
    Windows 10/11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Windows 10 21H2 LTSC x64 [MSDN]; Windows 11 24H2 LTSC; m/b Z77-HD3(BIOS-MBR/UEFI); HDD WD 500Gb
Back
Top Bottom