Workaround For Stonebook Edge-R (ECS SP41MD) Secure Boot Violation Failure After BIOS Update

This is a temporary fix until we receive a new BIOS from ECS

Purpose
To restore bootability on SP41MD units that fail to boot with a Secure Boot violation after applying Windows 11 25H2 updates followed by a BIOS update.

Root Cause (Summary)
Windows Update installs the 2023 Secure Boot keyset, but the SP41MD BIOS resets the firmware back to 2011 keys, causing the firmware to reject the updated Windows bootloader. This guide provides the required workaround until a BIOS containing the 2023 keyset is released.

1. Scope
This procedure applies to:
  •     SP41MD units running Windows 11 25H2
  •     Systems that have received cumulative updates enabling the 2023 Secure Boot key update
  •     Systems that fail to boot after a BIOS update with a Secure Boot violation

2. Symptoms
Technicians may observe:
  •     Secure Boot error on POST
  •     “Invalid signature” or “Secure Boot violation”
  •     System loops back to BIOS
  •     Windows will not boot unless Secure Boot is disabled

3. Required Conditions
This workaround applies when:
  •     BIOS has just been updated
  •     Windows was fully updated before the BIOS flash
  •     Secure Boot is enabled

4. Workaround Procedure


Step 1 - Enter BIOS Setup
  1.     Power on the device
  2.     Press DEL to enter BIOS

Step 2 - Navigate to Secure Boot Menu

  1.     Navigate to the Security tab
  2.     Change Secure Boot Mode to Custom

Step 3 - Enter the Key Management sub menu.

Step 4 - From within the Key Management sub menu, select Enroll Efi Image

Step 5 - Manually Enrol the Windows Bootloader. Select the file system, this will usually be the top option. Ensure all removable drives are removed before undertaking this task! 

 Step 6 - Select File. Select the EFI directory,

Step 7 - Select Boot directory.

Step 8 - Finally select bootx64.efi

Step 9 - This will then give you the option to Enroll the Efi image, select yes.

Step 10 - Once this is done save and exit the BIOS menu.

The machine will now boot to the OS as normal, providing the steps have been undertaken correctly.



Article ID: 987
Last updated: 11 May, 2026
Revision: 4
Stone Branded Products -> Laptops, Netbooks and Tablets -> Troubleshooting -> Workaround For Stonebook Edge-R (ECS SP41MD) Secure Boot Violation Failure After BIOS Update
https://kb.stonegroup.co.uk/index.php?View=entry&EntryID=987