Forum Discussion
SurfaceHub Gen1 violation error at several devices
Following Error occured 2 day's ago on several SurfaceHub Gen1 in our company:
SurfaceHub error: secure boot violation invalid signature detected. Check secure boot policy in setup.
Solution could be to disable Secure Boot and other UEFI details.
But following process to enter UEFI / Bios is not working at all:
- Shut down the Surface Hub completely.
- Press and hold the volume up button on the side of the device.
- While holding the volume up button, press and release the power button.
- Continue holding the volume up button until the Surface logo appears.
- The device should now boot into the UEFI (BIOS) settings menu.
We did test with several different SurfaceHub devices and all kind of pressing and holding these buttons, even with external cabled Keyboard. Not able to enter UEFI.
Does anybody have same issue?
Know in detail how to enter UEFI at Surface Hub Generation 1.
thx for any hints Bruno
32 Replies
- p-s-sCopper Contributor
Caution: Use this procedure at your own risk. I’m not responsible for any failures or data loss that may occur.
We got our Surface Hub v1 working again. It took some back and forth with Microsoft because we were receiving errors running the recovery USB. After a while we found out the NVRAMTool.exe was being quarantined by our Antivirus.
In my case this is basically what we dit to get our HUB working again:- Disconnect all cables except the power cable.
- Power-off using the rocker switch beside the power cable.
- Remove the internal SSD.
- Prepare USB #1 (“BOOTME”):
- Format a USB 2.0 stick as FAT32.
- Rename its volume label to BOOTME.
- Insert the BOOTME USB in the bottom USB port under the Microsoft logo.
- Power-on using the rocker switch beside the power cable.
- Retreive the automatically generated Manufacturing.bin from the USB after booting the HUB once.
- Submit to Microsoft Support:
- Open a support ticket and upload that Manufacturing.bin.
- Provide the Hub’s serial number.
- Receive & apply signed binary:
- When Microsoft sends back the signed .bin, copy it (no renaming) to the same BOOTME USB.
- You will also receive any additional information you need. (If not, ask at least for the instruction video).
- Boot Hub to unlock:
- Insert the BOOTME USB.
- Power-on using the rocker switch beside the power cable.
- Wait for on-screen confirmation that the unlock completed. (it will go into manufacturing mode)
- Reinsert SSD & initial boot:
- Shut down via the power rocker.
- Reinstall the SSD.
- Power on once—no need to fully load Windows—then shut down again.
- Prepare USB #2 (“PPI-INSTALL”):
- Format a second USB 2.0 stick as FAT32.
- Rename it PPI-INSTALL.
- Copy the region-specific recovery files (provided by Microsoft Support) directly onto it.
- Recovery USB boot:
- Remove the internal SSD again.
- Insert the PPI-INSTALL USB.
- Power on via the rocker switch.
- (If prompted, enter the serial number.)
- Run the on-screen PowerShell steps exactly—deviating risks bricking the device.
- Finalize & reboot:
- After recovery completes, reinstall the SSD.
- Power on.
- If asked, re-enter the serial number.
Watchouts:
- Make sure your antivirus isn’t quarantining NVRAMTool.exe.
- USB sticks must be USB 2.0 and FAT32-formatted.
- Recovery files are region-specific—use the set provided for your region.
- pmarsh508Copper Contributor
MS is/has dropped the ball.
I uploaded the required file and wait for days.
I have to ping them back asking for an update and they state we've uploaded the signed files. WOULD HAVE BEEN NICE IF YOU NOTIFED ME YOU'VE DONE THAT.
I have to ping them back to asking now what do I do with the signed files?
They ping me back stating they have provided the download of scripts and a pdf with detailed steps.
SORRY MS there is NO Surface_Hub_v1_Recovery_Procedure_Customer_Steps.pdf anywhere
Now I have to ping them back for the .pdf
WHY ARE WE CHASING THEM.
YOU BROKE IT!!!!!!!!!
SO frustrating
- pmarsh508Copper Contributor
After opening a ticket and uploading the requested files how long is it taking MS to get back to people? I uploaded two days ago and have not heard anything from MS as what is happening and what to do.... TICK, TICK, TICK my hubs are still bricks
- phhuberCopper Contributor
So how were your Surface Hub V1 devices repaired? BrunoK1874 Please state a detailed description of the steps taken to repair the devices, so other people with the same issue can fix it too.
As of now there is still no official solution provided by Microsoft, considering that Microsoft themself actually broke the devices and caused this problem.
- ChristophCopper Contributor
There is currently no self-service solution from Microsoft. Please open a ticket with Microsoft including the serial numbers of the devices, and you will receive information on the next steps (specifically: collect BIN files from the devices and then upload them via an individual link provided by Microsoft for each case). After that, Microsoft will get back to you with further information and steps (to my understanding, this is what everyone with open tickets is currently waiting for).
- BrunoK1874Brass Contributor
The repair was only possible together with MS support. Need was to create a manufacturing.bin send to MS and then receive a signed manufacturing-SIGNED.bin file. With this signed file unlock was possible and with a then follwo bios update all is running fine again. Please get in contact with MS about.
- Chris_1Copper Contributor
Good luck to everybody.
- p-s-sCopper Contributor
Hi, phhuber
In my case, yesterday I opened a ticket with Microsoft through our Microsoft admin center. There i posted the link to this thread, also I used the instruction given by flamurK on the 23 of june to get the maintenance.bin file from the hub, along with that i included a file with the serial number and packed it in a zip file, and added it to my ticket.
Just this morning i received a reply from Microsoft with detailed instructions for my case.
hope this helps.- pmarsh508Copper Contributor
Did they include the Surface_Hub_v1_Recovery_Procedure_Customer_Steps.pdf
That is all I need
- p-s-sCopper Contributor
Is this link intended for use by everyone? And what steps should be taken after uploading the file?
- ChristophCopper Contributor
The link is not intended for everyone and is actually assigned to a specific support case. Please do not upload any files there, as you will not receive a response.
- p-s-sCopper Contributor
Is this link intended for use by everyone? And what steps should be taken after uploading the file?
- BrunoK1874Brass Contributor
The solution provided by MS, with creating BIN file, get this signed, unlock system, update bios... is working for us. Already several Surface Hubs we did repair. good job (finally ;-) ) MS
- pmarsh508Copper Contributor
I'm seeing that MS is recommending leaving the hub in the state with red error "Invalid signature detected" while they work on a plan for recovery. I see no other information on what to do to get out of this error other than what Adam posted above. Anyone else hearing or seeing solutions?
- flamurKCopper Contributor
hey Pmarsh i posted some instructions that will need to be sent over to microsoft
- Vic_GatchCopper Contributor
Hi, I'm having the same problem of "Secure Booth Violation". Any fix yet that can be done? Thanks
- flamurKCopper Contributor
Hello Everyone,
I truly appreciate your continued patience and understanding as we work through this issue together. I know how important this is to you, and we’re committed to resolving it as quickly and smoothly as possible.
To help us move forward with the necessary fix, could you please follow the steps outlined below?
Prerequisites:
- A USB 2.0/3.0 flash drive, formatted as FAT32, re-named to “BOOTME”
- A computer to send and receive files from Microsoft
- Keyboard, wired or USB-wireless (later in the process)
Collect the Manufacturing.bin file
- Connect the formatted USB to the bottom port of the device, located just below the display panel.
- Power the unit on, using the power rocker switch. Approximately three seconds later the following message will appear in the upper left corner of the display. A file called Manufacturing.bin will be placed on the USB.
- Note: The HUB will display “Secureboot Violation” again after approximately two minutes. This is expected and is not a concern.
- Record the serial number from the unit. The Serial Number can be found on the side of the device, underneath the button panel.
- Upload the Manufacturing.bin file inside of a .zip folder and the device serial number to the DTM file, using the link provided below.
https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsupport.microsoft.com%2Ffiles%3Fworkspace%3DeyJhbGciOiJSUzI1NiIsImtpZCI6IjUwNjQwRTE0NEREODg5MzE5NzYzRTBFNjM5RjMzNjdFQUNDNzlBRDAiLCJ0eXAiOiJKV1QifQ.eyJ3c2lkIjoiYWExOTkwYWYtZGU2NS00ODUwLWJmMzUtY2E1ZWFjMWEzMThkIiwic3IiOiIyNTA2MTEwMDQwMDA4MzAzIiwic3YiOiJ2MSIsInJzIjoiRXh0ZXJuYWwiLCJ3dGlkIjoiZThhMDZjNGEtNjc0MS00NzM2LWIwMzMtMDA2MzM0N2MwYzg2IiwiYXBwaWQiOiI0ZTc2ODkxZC04NDUwLTRlNWUtYmUzOC1lYTNiZDZlZjIxZTUiLCJuYmYiOjE3NTA1MjI5OTUsImV4cCI6MTc1ODI5ODk5NCwiaWF0IjoxNzUwNTIyOTk1LCJpc3MiOiJodHRwczovL2FwaS5kdG1uZWJ1bGEubWljcm9zb2Z0LmNvbSIsImF1ZCI6Imh0dHA6Ly9zbWMifQ.fcR8HhcrYZrYDPg1ouEk3V3FI9dP8M-BK0NZUqRD22wEFkkYWQJwyq3imQlFJADhxRqUUb1yXJ8LZIprJwHQG5EtIG8D0aEYDWZrUsvyBHWGykEbKwHFEecN8jcyjIJ_6nF5O-icntzc9pY7Z_XEVULtItno1yFuGkZpaCq0PY4vqw7Kr68t-GCIuUAeVZx35RfjEoD6t4TvJ9GK76BZrFcyw80VwAxdEbW3nKs36cXJa9OpiZmljvNXtyl-S-Ykg_qa_nzNca5YKVX-fDEUxCmD6j2_6kOon0rvSdQXx9-Mo4xXR5SVjYRiIB7HFtDrHn-__57FBvt-JNDzvuP4ZA%26wid%3Daa1990af-de65-4850-bf35-ca5eac1a318d&data=05%7C02%7Cflamur.kaba.ext%40boehringer-ingelheim.com%7C97e240a7e6bc422199c908ddb0e01c37%7Ce1f8af86ee954718bd0d375b37366c83%7C0%7C0%7C638861198797441840%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=GLwBdIBAsp%2BvYmLxH1OG%2BZPcc1javQ%2BmLEHRgrV%2BQ%2BM%3D&reserved=0
- Adam_CollinsworthCopper Contributor
This is what Microsoft gave to us.
For the Serial Issue:
I was told you can press the backspace button and then you can enter the s/n. (Not tested)
I had to get the BitLocker (Recovery) keys from Active Directory.
Once you enter in the recovery key, the unit will work until it is rebooted.
It will go back into an errored state anytime the unit reboots but simply press the ESC on your external keyboard and it will boot back up without the recovery key.
edit I was just told the reason this happens is because were did not enter in the serial number but rather pressed ESC to enter the recovery key. Be sure to enter the Serial Number.
We have not identified a fix for the boot error. We currently have over 300 units effected.Surface Hub v1 Boot Issue After June 2025 Windows Update (KB5060533)
[Last Updated: June 12, 2025]We are currently investigating a known issue impacting Surface Hub v1 devices following the June 2025 “6B” Windows Update (KB5060533). After installing this update, some Surface Hub v1 units may no longer boot into Windows and display one of two error messages.
Affected Devices:
- Only Surface Hub v1 is affected.
- Surface Hub 2S and Surface Hub 3 are not impacted.
What You Might See
🔴 Secure Boot Violation (Red Screen)
You may encounter the following error message on boot:
Secure Boot Violation
Invalid signature detected. Check Secure Boot Policy in SetupThis is the primary error blocking startup of affected devices. It is caused by a Secure Boot DBX update included in the June “6B” cumulative update. The Surface and Windows engineering teams have identified this as a conflict between the update and the AMI BIOS used in Hub v1 devices. A fix is actively being developed.
🔵 Invalid Serial Number (Blue Screen)
Some customers may also see this message:
Invalid Serial Number
New Serial Number: [System Serial]This is a separate issue and not directly related to Secure Boot, but may appear if the BIOS has been fully reset to defaults. In this case, you can re-enter the correct serial number for your device and it will proceed to boot to Bitlocker recovery. If the Bitlocker key is not available, SHRT can be used to re-image the device at that point.
To locate your Surface Hub v1 serial number, refer to the label underneath the power and volume control panel, as shown below:
What Microsoft Is Doing
- As of June 11, 2025, Microsoft has blocked the 6B update from installing on additional Surface Hub v1 devices.
- Engineering teams are developing a 6B update to prevent future DBX updates from being applied to Hub v1, while still allowing all other security patches through the end of Windows 10 support in October 2025.
- We are investigating recovery options for devices already affected and will share validated recovery instructions as soon as they are available.
What You Can Do Now
- If your device is displaying the red Secure Boot error, please retain the device in its current state. We will share step-by-step recovery instructions once a fix is confirmed.
- If you see the blue Invalid Serial Number screen, manually re-enter the serial number found on the label near the control buttons.
- Stay connected with your Microsoft representative for direct updates and we will also soon be releasing a Surface IT Pro Blog post around this issue.
We understand how critical Surface Hub is to your organization, and we are working urgently across engineering teams to resolve this issue. We appreciate your patience and partnership.
If you have questions or need to report affected devices, please reach out to your Microsoft support contact.