Macrium Secure boot


man00

Well-known member
Member
Local time
3:17 PM
Posts
330
OS
windows 11
I updated my system for the June thing that MS id suppose to do
now my macrium usb rescue disk won't boot. Is it safe to disable secure boot in bios
without screwing up everything and turning it back on when needed. I can not find how to update the rescue disk

 

My Computer My Computer

At a glance

windows 11Intel i5-10600kf32gb corsair vengerance proAMD RX 6500XT
OS
windows 11
Computer type
PC/Desktop
Manufacturer/Model
Antec/Case
CPU
Intel i5-10600kf
Motherboard
GIGABYTE Z590 UD AC
Memory
32gb corsair vengerance pro
Graphics Card(s)
AMD RX 6500XT
Sound Card
onboard
Monitor(s) Displays
40" Hisense
Hard Drives
Samsung 850
Samsung 870
Seagate 2TB
PSU
EVGA GQ 750
You can fix your macrium boot drive:

In an Administrator powershell window, mount your system partition and replace the necessary in the macrium boot builder area with the system partitions:

mountvol s: /s
copy s:\EFI\Boot\bootx64.efi C:\boot\macrium\WinREFiles\media\EFI\Boot\bootx64.efi
copy S:\EFI\Microsoft\Boot\bootmgfw.efi C:\boot\macrium\WinREFiles\media\EFI\Boot\bootx64.efi

Then rebuild your rescue media in macrium and try it
 

My Computers My Computers

  • At a glance

    Windows 11 ProIntel Core i9 14900K 5800/4500 P/E all core96GB (2x48) G.skill Ripjaws 6800 MT/s DDR5Asus ROG Strix 4070 Ti OC
    OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY Photoshop/Audio/Game/tinker
    CPU
    Intel Core i9 14900K 5800/4500 P/E all core
    Motherboard
    Asus ROG Maximus Z790 Dark Hero
    Memory
    96GB (2x48) G.skill Ripjaws 6800 MT/s DDR5
    Graphics Card(s)
    Asus ROG Strix 4070 Ti OC
    Sound Card
    Bowers & Wilkins 606 S3 speakers; Audiolabs 7000a integrated amp; RSL 10S Mk2 sub; Creative Pebble Pro Minimilist
    Monitor(s) Displays
    Eizo CG2730 ColorEdge, ViewSonic VP2768, i1 Display Pro calibration puck
    Screen Resolution
    2560 x 1440p x 2
    Hard Drives
    WDC SN850X 4TB nvme, SN850 1TB nvme, SK-Hynix 2 TB P41 nvme,. Sabrent USB-C DS-SC5B 5-bay docking station: 6TB WDC Black, 6TB Ironwolf Pro; 2x 2TB WDC Black HDD
    PSU
    850W Seasonic Vertex PX-850 ATX 3.0/PCI-E 5.0
    Case
    Fractal Design North XL Mesh, Black Walnut
    Cooling
    EK Nucleus black 360 AIO w/Phanteks T30-120 fans, 2 Noctua NF-A14 Chromax case fan, 1 T30-120 fan cooling memory
    Keyboard
    Keychron Q3 Max TKL with custom GMK Redsuns Red Samuri keycaps, TX Stabs
    Mouse
    Logitech G305 wireless gaming
    Internet Speed
    575 Mb/s down | 25 Mb/s up
    Browser
    Firefox
    Antivirus
    Defender, Macrium Reflect X
    Other Info
    Phangkey Amaterasu V2 Desk Mat
  • At a glance

    Apple M1
    Computer type
    Laptop
    Manufacturer/Model
    💻 Apple 13" Macbook Pro 2020 (m1)
    CPU
    Apple M1
    Screen Resolution
    2560x1600
    Browser
    Firefox
Instead of copying the files from the EFI partition (mountvol S:), the same files live under "\Windows\Boot\EFI_EX".

You should push files outward from "\Windows\Boot\EFI_EX", instead of pulling them from the EFI. Newer versions of the boot files will be installed by Windows Update under "\Windows\Boot".
Code:
copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi C:\boot\macrium\WinREFiles\media\bootmgfw.efi
copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi C:\boot\macrium\WinREFiles\media\EFI\Boot\bootx64.efi
copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi C:\boot\macrium\WinREFiles\media\EFI\Microsoft\Boot\bootmgfw.efi
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Is it safe to disable secure boot in bios
without screwing up everything and turning it back on when needed.
To answer your question. Yes it is safe to temporarily disable secure boot in order to boot from Macrium rescue usb.

Per Macrium "In the event that a disaster has occurred meaning that a rescue media restore is needed, we recommend temporarily disabling Secure Boot to enable the system to boot the rescue media and then performing a restore.
reference Managing the Boot Media Signing Certificate for Macrium Reflect Rescue Media
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.8875i9-10900 10 core 20 threads32 gbnone-Intel UHD Graphics 630
    OS
    Windows 11 Pro 25H2 26200.8875
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    2x1tb Solidigm m.2 nvme /External drives 512gb Samsung m.2 sata+2tb Kingston m2.nvme
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    #1 Edge #2 Firefox
    Antivirus
    Defender+MWB Premium
  • At a glance

    Windows 11 Pro 24H2 26200.8875AMD Ryzen 7 6800U32 gbintegrated
    Operating System
    Windows 11 Pro 24H2 26200.8875
    Computer type
    PC/Desktop
    Manufacturer/Model
    Beelink Mini PC SER5
    CPU
    AMD Ryzen 7 6800U
    Memory
    32 gb
    Graphics card(s)
    integrated
    Sound Card
    integrated
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Crucial nvme
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    still too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender
    Other Info
    System 3 is non compliant Dell 9020 i7-4770/24gb ram Win11 PRO 26200.8875
Per Macrium "In the event that a disaster has occurred meaning that a rescue media restore is needed, we recommend temporarily disabling Secure Boot to enable the system to boot the rescue media and then performing a restore.
reference Managing the Boot Media Signing Certificate for Macrium Reflect Rescue Media
That's really nice that Macrium X supports the option to pick a version of the Secure Boot files, but unfortunately you don't get that for Macrium v8.

You got to copy files by hand, or use a script.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Thanks folks, got it
 

My Computer My Computer

At a glance

windows 11Intel i5-10600kf32gb corsair vengerance proAMD RX 6500XT
OS
windows 11
Computer type
PC/Desktop
Manufacturer/Model
Antec/Case
CPU
Intel i5-10600kf
Motherboard
GIGABYTE Z590 UD AC
Memory
32gb corsair vengerance pro
Graphics Card(s)
AMD RX 6500XT
Sound Card
onboard
Monitor(s) Displays
40" Hisense
Hard Drives
Samsung 850
Samsung 870
Seagate 2TB
PSU
EVGA GQ 750
That's really nice that Macrium X supports the option to pick a version of the Secure Boot files, but unfortunately you don't get that for Macrium v8.
Thanks for the correction. I just assumed he was on X. My bad for assuming.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.8875i9-10900 10 core 20 threads32 gbnone-Intel UHD Graphics 630
    OS
    Windows 11 Pro 25H2 26200.8875
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    2x1tb Solidigm m.2 nvme /External drives 512gb Samsung m.2 sata+2tb Kingston m2.nvme
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    #1 Edge #2 Firefox
    Antivirus
    Defender+MWB Premium
  • At a glance

    Windows 11 Pro 24H2 26200.8875AMD Ryzen 7 6800U32 gbintegrated
    Operating System
    Windows 11 Pro 24H2 26200.8875
    Computer type
    PC/Desktop
    Manufacturer/Model
    Beelink Mini PC SER5
    CPU
    AMD Ryzen 7 6800U
    Memory
    32 gb
    Graphics card(s)
    integrated
    Sound Card
    integrated
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Crucial nvme
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    still too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender
    Other Info
    System 3 is non compliant Dell 9020 i7-4770/24gb ram Win11 PRO 26200.8875
The validity period of the PCA 2011 certificate for the Windows Bootloader ends in June-October 2026..
The new UEFI CA 2023 certificate will expire in 2035.…

What is the difference between the old MacriumRescue.iso(PCA 2011) vs the new MacriumRescue.iso(UEFI CA 2023)?
You can check it yourself.
You just need to make MacriumRescue.iso(PCA 2011) and MacriumRescue.iso(UEFI CA 2023) for version 10.0.8750 (or for version 10.0.8731), then unpack the ISO archives and compare all the files of these two archives by checksum.
It will take about 30 minutes.
MacriumRescue.iso should be done on the basis of pe11Dec24x64.zip (WinPE ver. 26100)

A checksum comparison of the unpacked ISO archives v.10.0.8750(PCA 2011) vs 10.0.8750(UEFI CA 2023) shows that these archives differ in files:
MacriumRescue.iso\Boot\efisys_noprompt.bin
MacriumRescue.iso\Boot\efisys_prompt.bin
MacriumRescue.iso\EFI\Boot\bootx64.efi
MacriumRescue.iso\EFI\Microsoft\Boot\
bootmgfw.efi
NOTE:
1. For MacriumRescue.iso ver. 10.0.8750(PCA 2011), these files have the old PCA 2011 certificate.
2. For MacriumRescue.iso ver. 10.0.8750(UEFI CA 2023), these files have a new UEFI CA 2023 certificate.
3. The files "efisys_noprompt.bin" and "efisys_prompt.bin" are archives containing the file "bootx64.efi"

How to use these files when creating MacriumRescue.iso ver. 8.0 – 8.1 ?
Unfortunately, pe11Dec24x64.zip was created for Macrium Reflect v10, and it is incompatible with Macrium Reflect ver. 8.0 – 8.1
However, you can try to create MacriumRescue.iso ver. 8.0 – 8.1 based on WinPE ADK 26100
... and then replace the old BootLoader files (PCA 2011) in them with the corresponding BootLoader files of the new version (UEFI CA 2023) from this Archive:
Macrium_bootloader_PCA2011_CA2023.zip (7,8Mb)
NOTE
The Archive contains files of the old and new versions of the BootLoader from MacriumRescue 10.0.8750 based on pe11Dec24x64.zip
 
Last edited:

My Computer My Computer

At a glance

Windows 10/11
OS
Windows 10/11
Computer type
PC/Desktop
Manufacturer/Model
Windows 10 21H2 LTSC x64 [MSDN]; Windows 11 24H2 LTSC; m/b Z77-HD3(BIOS-MBR/UEFI); HDD WD 500Gb
The latest boot files are already provided under "C:\Windows\Boot", if you've updated to the current W11 Monthly Update (April 2026 or later). You don't need to download a ZIP file.

Replace en-US with your local language. ie. de-DE, fr-FR, es-ES

Code:
copy C:\Windows\Boot\DVD_EX\EFI\en-US\efisys_EX.bin E:\Boot\efisys_prompt.bin /y
copy C:\Windows\Boot\DVD_EX\EFI\en-US\efisys_noprompt_EX.bin E:\Boot\efisys_noprompt.bin /y
copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi E:\EFI\Boot\bootx64.efi /y
copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi E:\EFI\Microsoft\Boot\bootmgfw.efi /y
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
You don't need to download a ZIP file.
We create MacriumRescue.iso (BOOT ISO) based on WinPE
Each version of WinPE has its own set of original files of certain versions.
Currently, there is only one version of the "new" BootLoader for WinPE with the UEFI CA2023 certificate - WinPE 10.1.26100.2454 (December 2024) i.e. pe11Dec24x64.zip (official file from Macrium)

This version of WinPE contains this BootLoad kit (UEFI CA2023 certificate) :
bootx64.efi ( "Boot Manager") 10.0.26100.30227
bootmgfw.efi ( "Boot Manager") 10.0.26089.1001
efisys_prompt.bin ("CD bootstrap application") 10.0.26100.1061
efisys_noprompt.bin ("CD bootstrap application") 10.0.26100.1061

If you replace these original files with "newer versions" then you are acting at your own risk.
..We only received problems from the "new" Microsoft update for April 2026...
 
Last edited:

My Computer My Computer

At a glance

Windows 10/11
OS
Windows 10/11
Computer type
PC/Desktop
Manufacturer/Model
Windows 10 21H2 LTSC x64 [MSDN]; Windows 11 24H2 LTSC; m/b Z77-HD3(BIOS-MBR/UEFI); HDD WD 500Gb
I revoke this once but for some reason it returned, is it okay to just leave it

Secure Boot: ON
Virtualization Based Security: OFF
BitLocker on (C:) OFF

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023

UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023

UEFI DBX Certs
--------------
Microsoft Windows Production PCA 2011
Windows BootMgr SVN 7.0

EFI Files
---------
Disk 3: Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.

Registry: WindowsUEFICA2023Capable = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.


REQUIRED ACTION
===============

To revoke the [PCA 2011] cert, run the commands, run the commands:

reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x200 /f
powershell Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"
 

My Computer My Computer

At a glance

windows 11Intel i5-10600kf32gb corsair vengerance proAMD RX 6500XT
OS
windows 11
Computer type
PC/Desktop
Manufacturer/Model
Antec/Case
CPU
Intel i5-10600kf
Motherboard
GIGABYTE Z590 UD AC
Memory
32gb corsair vengerance pro
Graphics Card(s)
AMD RX 6500XT
Sound Card
onboard
Monitor(s) Displays
40" Hisense
Hard Drives
Samsung 850
Samsung 870
Seagate 2TB
PSU
EVGA GQ 750
I revoke this once but for some reason it returned, is it okay to just leave it
If you don't know what to do, then don't do anything. ;-)
... For testing, I made the Free version of Macrium 8.0.7175 based on ADK WinPE 10.1.26100.2454 .. and then replaced the bootloaders with the UEFI CA2023
I did not install Secure Boot, so this version is untested.
If you want, you can check this MacriumRescue.iso at your own risk.
MR_Free_8_0_7175_pe11_26100_UEFI_CA2023_x64_en.zip (383Mb)
 

My Computer My Computer

At a glance

Windows 10/11
OS
Windows 10/11
Computer type
PC/Desktop
Manufacturer/Model
Windows 10 21H2 LTSC x64 [MSDN]; Windows 11 24H2 LTSC; m/b Z77-HD3(BIOS-MBR/UEFI); HDD WD 500Gb
Thanks my MacriumRescue works fine I just noticed I made this post in the wrong place....Sorry
 

My Computer My Computer

At a glance

windows 11Intel i5-10600kf32gb corsair vengerance proAMD RX 6500XT
OS
windows 11
Computer type
PC/Desktop
Manufacturer/Model
Antec/Case
CPU
Intel i5-10600kf
Motherboard
GIGABYTE Z590 UD AC
Memory
32gb corsair vengerance pro
Graphics Card(s)
AMD RX 6500XT
Sound Card
onboard
Monitor(s) Displays
40" Hisense
Hard Drives
Samsung 850
Samsung 870
Seagate 2TB
PSU
EVGA GQ 750
Thanks my MacriumRescue works fine I just noticed I made this post in the wrong place
Thanks for checking it out. It's hard to be the first. ;-)
Did you probably make a Backup, but didn't make a Recovery?
The final conclusion can be made only after a full check, in the "total System crash" mode, i.e., on a TEST disk.:
WARNING:
if you've never done a "Total System Crash", then do it only on the
TEST disk!
Do not do a "Total System Crash" on your laptop, as you may lose your factory copy of Windows!

1. Backup all Windows partitions
100Mb(Active Service Partition)
16Mb(Service Partition)
40-100Gb(Windows File, Data, and Programs section)
500Mb(Service Recovery Partition)
Save the backup to disk D (or E, F, etc.)
2. Run the Windows 11 installation from a Windows bootable flash drive, and delete all four Windows partitions during the dialog.
Then abort the Windows installation and turn off the computer.
3. Download from a USB flash drive MacriumRescue.iso (UEFI CA2023) and restore Backup(item 1)
 
Last edited:

My Computer My Computer

At a glance

Windows 10/11
OS
Windows 10/11
Computer type
PC/Desktop
Manufacturer/Model
Windows 10 21H2 LTSC x64 [MSDN]; Windows 11 24H2 LTSC; m/b Z77-HD3(BIOS-MBR/UEFI); HDD WD 500Gb

Latest Support Threads

Back
Top Bottom