Aller au contenu principal

UEFI - Windows 11 - Custom WinPE-based Media Builder

Thread solved

Hi Paul,
hello Steve

Both of you kindly helped me at the end of last year to create a USB stick that can handle Bitlocker.
Thank you again for that.

The upcoming Windows 11 requires Secure boot. And if I activate Secure boot in the BIOS, I can no longer boot with this stick. Could you please set your Custom WinPE-based Media Builder so that you can also create a UEFI-capable stick with it? Would that be possible?

By the way, I installed TI 2021, version 2021, build 39216.

Best and grateful regards,
wisch

0 Users found this helpful

wisch, all Acronis rescue media is capable of booting on both Legacy / MBR and UEFI / GPT secure boot systems with no changes needed to the media itself.

KB 59877: Acronis True Image: how to distinguish between UEFI and Legacy BIOS boot modes of Acronis Bootable Media

So if your rescue media boots in UEFI boot mode without Secure Boot enabled, then it should also boot with it enabled as far as I understand.  This works for me on my own system which has always had UEFI Secure Boot enabled since I got it.

What happens when you attempt to boot from your rescue media with secure boot enabled? Are you shown any error message etc?

As Steve mentioned above, the media should be able to boot in UEFI mode with secure Boot enabled. There are two reasons I can think of that could cause it to fail. It can happen if one of the custom drivers you added doesn't have a Microsoft approved digital signature. This will cause a BSOD with the driver sys file mentioned. Take a digital picture of the screen that shows the boot failure and post it here. It's also possible that your motherboard won't allow booting from USB media with Secure Boot enabled. In that case it may help to update the BIOS to the latest version.

There is a trick to get an unsigned driver to work with Secure Boot enabled. You can build with the 10240 (early Windows 10) ADK. That has a nice feature that lets you hit F8 and F7 to override digital signatures. Later ADK's and WinRE's don't have this nice feature.

 

Hi Paul,
hello Steve

Thank you very much for your support 🙏
It's going well now, all right! And that was my fault 🤢 I overlooked the displayed stick in the UEFI area in the BIOS because it was described differently there than in the LEGACY area, sorry 🤷‍♂️

With hanging ears and with best regards,
wisch