Overwhelmed - Macrium Reflect


I was tinkering and discovered something that may be obvious to others but was a surprise to me. I never realized I could simply turn off Memory Intergity in Windows Security which then allowed me to switch off Microsoft Vulnerable Driver Blocklist. Off course that come with it's own implications and requires a reboot for it to apply, but seems like an easy way to gain access to browsing saved images. Turning Memory Integrity back on is one click and a reboot which turns on the Microsoft Vulnerable Driver Blocklist on its own and locks it by greying out the switch.
I have rarely needed to mount an image to recover individual files since I have separate data file backups, but I knew this workaround existed if needed (Macrium 8 Free v8.0.7783). Full backup and restore still work fine as long as I keep using the update script @garlin created so my Rescue boot drive stays bootable when MS makes changes.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 25H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo T490 (2020 Hardware)
    CPU
    i7-8565U
    Motherboard
    20N20028US
    Memory
    16GB
    Graphics Card(s)
    Intel UHD Graphics 620
    Sound Card
    Realtec Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 970 PRO 512GB NVMe
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Supported hardware, upgraded from Windows 10 Pro to Windows 11 Pro version 24H2 on 06/01/2025 using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/07/2025. Secure boot enabled. Secure Boot CA 2023 updated.
  • Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Lenovo ThinkCentre M83 (2014 Hardware)
    CPU
    i7-4770 (with SSE4.2, and POPCNT)
    Motherboard
    10AL000GUS
    Memory
    16GB
    Graphics card(s)
    Intel HD Graphics 4600
    Sound Card
    Realtec High Definition Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 860 PRO 1TB SATA
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Unsupported hardware, upgraded from Windows 10 Pro (TPM 1.2 & unsupported CPU, but does have SSE4.2, and POPCNT) to Windows 11 Pro version 24H2 on 06/15/2025. Added Registry Key HKEY_LOCAL_MACHINE\SYSTEM\Setup\MoSetup – AllowUpgradesWithUnsupportedTPMOrCPU=1 to allow installation using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/08/2025. Secure boot enabled. Secure Boot CA 2023 updated.
I believe most of the v8 users on this thread don't want to upgrade to X. Even if it properly supports CA 2023.
No, I paid the price for X on my imprtant desktop PC but not my less important laptops.
 

My Computer

System One

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self build
    CPU
    Core i7-13700K
    Motherboard
    Asus TUF Gaming Plus WiFi Z790
    Memory
    64 GB Kingston Fury Beast DDR5
    Graphics Card(s)
    Gigabyte GeForce RTX 2060 Super Gaming OC 8G
    Sound Card
    Realtek S1200A
    Monitor(s) Displays
    Viewsonic VP2770 & Dell (secondary)
    Screen Resolution
    2560 x 1440
    Hard Drives
    Kingston KC3000 2TB NVME SSD & SATA HDDs & SSD
    PSU
    EVGA SuperNova G2 850W
    Case
    Nanoxia Deep Silence 1
    Cooling
    Noctua NH-D14
    Keyboard
    Microsoft Digital Media Pro
    Mouse
    Logitech Wireless
    Internet Speed
    80 Mb / s
    Browser
    Chrome
    Antivirus
    Defender, Malwarebytes Free & AdwCleaner
I believe most of the v8 users on this thread don't want to upgrade to X. Even if it properly supports CA 2023.

But it still does not.

Last WU updated SVN to 9 and I recreated the macrium PE thinking it would pickup the change.

It would not boot as there was a SVN mismatch so got a secure boot violation error.
 

My Computer

System One

  • OS
    Windows 11 Pro
June 2026 both introduces a new boot manager (SVN 9.0) and a new SkuSiPolicy (3.0.0.15). If you're using SkuSiPolicy, this restricts using the previous winload.efi in the boot.wim, requiring a newer updated image.
 

My Computer

System One

  • OS
    Windows 7
Still using Macrium v8.0.7783 Free and with the updated (SVN 9.0) and a new SkuSiPolicy (3.0.0.15), I create a new Bootable PE, like in april also and all work well, boots up fine with c2023.
 

My Computer

System One

  • OS
    Win11 24H2 IOT LTSC / Win11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Gigabyte / Asus Home build
    CPU
    AMD Ryzen 7 8700G / AMD Ryzen 7 8700G
    Motherboard
    Gigabyte B650 AORUS ELITE AX V2 / ASUS TUF GAMING B650-PLUS
    Memory
    F5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB LD5BU016G-R6000GDLA 32GB
    Graphics Card(s)
    internal
    Sound Card
    Realtek
    Monitor(s) Displays
    BenQ 27 L EW2780
    Screen Resolution
    1920x1080
    Hard Drives
    Many M.2's
    Internet Speed
    400 mbs
    Browser
    Vivaldi
    Antivirus
    Eset
June 2026 both introduces a new boot manager (SVN 9.0) and a new SkuSiPolicy (3.0.0.15). If you're using SkuSiPolicy, this restricts using the previous winload.efi in the boot.wim, requiring a newer updated image.
Macrium Reflect + WinPE 26100(2024/12) creates a MacriumResque.iso(BOOT ISO) with bootx64.efi Bootloader(CA2023 certificate) ver. 10.0.26100.30227
WinPE 28000
(2025/11) has bootx64.efi bootloader(CA2023 certificate) ver. 10.0.27954.300

Questions:
1. What version of bootx64.efi should you have in order for Macrium BOOT ISO (UEFI CA2023; WinPE) to work with all versions of Windows 10 / 11?
2. Is it enough to replace only the bootx64.efi file in the MacriumResque.iso\EFI\Boot\bootx64.efi folder? ... Or do I need to replace any other files?
 
Last edited:

My Computer

System One

  • OS
    Windows 10/11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Windows 10 21H2 LTSC x64 [MSDN]; Windows 11 24H2 LTSC; m/b Z77-HD3(BIOS-MBR/UEFI); HDD WD 500Gb
Macrium Reflect + WinPE 26100(2024/12) creates a MacriumResque.iso(BOOT ISO) with bootx64.efi Bootloader(CA2023 certificate) ver. 10.0.26100.30227
WinPE 28000
(2025/11) has bootx64.efi bootloader(CA2023 certificate) ver. 10.0.27954.300

Questions:
1. What version of bootx64.efi should you have in order for Macrium BOOT ISO (UEFI CA2023; WinPE) to work with all versions of Windows 10 / 11?
2. Is it enough to replace only the bootx64.efi file in the MacriumResque.iso\EFI\Boot\bootx64.efi folder? ... Or do I need to replace any other files?
Have you looked at the entry at

How to "fix" Secure Boot violation due to certificate revocations. - (Page 2)

There is an entry from jimrf97 at the end with a .bat file that looks promising and might help.

You run it on your system targeting the USB boot-able drive.

As I understand it, it sounds like the MS changes involve a series of steps over time starting with adding the new certificates to your windows and ultimately (possibly) removing the old certificates from both Windows and the BIOS.

I tried this .bat file a few months back and it seemed to work on a boot-able USB. But I don't think my system was (is?) yet 'all the way through' the complete MS process.
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Asus
    CPU
    9950X3D
    Motherboard
    X870E
Back
Top Bottom