Tech Support Guy banner

Device Security Issues

1 reading
8K views 29 replies 2 participants last post by  Macboatmaster  
#1 · (Edited)
Afternoon All,

Im having some issues with the device security section in settings all drivers and windows updates are to date it used to have core isolation tpm etc in there but now it has nothing at all and just says "Standard Hardware Security Not Supported" when i open it.

I have the following enabled:

TPM 2.0
Secure Boot
DEP
UEFI

Nothing i do is working, i need to turn off memory integrity also but as nothing is showing up in settings i cant do anything at all.

I was using AI Suite 3 which requires memory integrity to be off so i cant even use that anymore as it wont open with integrity on and theres no way of turning it off in settings.

PC Spec`s:

TUF GAMING H670-PRO WIFI D4
Intel® Core™ i7-12700K Processor
Corsair CMW16GX4M2C3200C16 Vengeance RGB PRO 16 GB (2 x 8 GB) DDR4 3200 MHz C16 XMP 2.0
ASUS Dual GeForce RTX 2060 OC EVO Edition 6GB GDDR6

BIOS Ver: 1720
Edition - Windows 11 Pro
Version - 22H2
Installed on - ‎03/‎10/‎2022
OS build - 22621.608
Experience - Windows Feature Experience Pack 1000.22634.1000.0
64-bit operating system, x64-based processor

Image


Any Help is much appreciated, from bios settings hw they should be/look anything as im exhausted with what google is telling me to do etc as none of it is making a difference.

Thank You,

Phil
 
#2 ·
Before actually selecting device security on left pane of secttins
what is shown on - settings
windows security under the icon - device security

1. Go to this link
TUF GAMING H670-PRO WIFI D4|Motherboards|ASUS United Kingdom
download the
Version 1.00.04
2022/02/15 135.01 KBytes
AI Suite 3 Cleaner
Use the uninstall tool to remove AI Suite 3 and its related service files.

and run that.

2. RESTART the computer not shut down as on 11 that is not of course a complete shutdown.

3. Check now if the standard hardware security is now OK and does not display the not supported message.

4. If so go back to the link and download
Version 3.01.06
2022/01/04 154.67 MBytes
ASUS AI Suite 3 V3.01.06 Install Program for Windows 10 64-bit, Windows 11 64-bit.
-Performance and Power Saving Utilities V2.00.88 for Windows 10 64-bit, Windows 11 64-bit.
-ASUS System Information V2.00.18 for Windows 10 64-bit, Windows 11 64-bit.

install
and check again IF the first step did show all in order with hardware security under device security

IF that does not work when you reply I will give you further advice.
 
#4 ·
1. Are you absolutely certain
PTT is enabled in firmware
Advanced Screen

Section 6.6. BIOS manual
PRIME_PROART_TUF_GAMING_Intel_600_Series_BIOS_EM_WEB_EN.pdf (asus.com)

If you are
cmd prompt admin arights and
type
sfc /scannow
press enter

if all is in order leave the prompt
if errors could not be fixed
run
Dism /Online /Cleanup-Image /RestoreHealth

please report result of DISM if it was needed
If errors still could not be fixed
send DISM log please as an attachment
Windows
Logs
DISM
 
#5 ·
PTT 100% enabled, TPM 2.0 all setup, UEFI Mode set in Bios

C:\Windows\System32>sfc /scannow

Beginning system scan. This process will take some time.

Beginning verification phase of system scan.
Verification 100% complete.

Windows Resource Protection did not find any integrity violations.

C:\Windows\System32>
 
#6 ·
Please see if you have this folder in bold in the
C:\Windows\System32\SecurityHealth\
1.0.2109.27002-0

Would I be correct in thinking that the problem only occured after the upgrade to 22H2

The folowing only applies IF the problem arose AFTER you system upgraded to 22H2
If you do have that folder
1. create a restore point
check it has been created

2. Copy that folder and save it to the desktop
THEN delete the folder

RESTART and try again
 
#8 ·
#15 ·
I resume after setting standard and save and exit and then you restarted system
Without the restart the changes will not take effect

If it still does not work I can only suggest the repair install

A number of such problems as you are having - have been reported, but a roll back, has cured the issue
OR the deletion of that folder

What puzzles me and I must admit I do not know the answer is why you do nt have any entries in that

C:\Windows\System32\SecurityHealth is there but its contents are empty
I do not have 2H22 but I have four entries in that folder on my 11
 
#11 ·
Goodnight
signing off
I am in UK - back approx 1800 hrs UK time
 
#13 ·
I suggest
Section 8
BIOS manual
set secure boot mode
STANDARD not custom
 
#16 ·
#18 ·
I honestly do not know
Have you got a system image of the whole drive on an external drive
The reason I ask is that if you do a clean install and it does not work, you can at least then go back to the system image to save you reinstalling all the apps and indeed your personal data will be preserved.

Returning to the custom or standard for the secure boot
Standard takes the keys from the TPM trusted platform in the firmware and the various hardware and then from boot devices etc.and eventually from the OS for the successful result on the windows security - devices etc.

As I understand it, and I am by no means an expert in this issue, custom is only used when the user wishes to configure the keys
That seems to be the general theme of the BIOS operating manual for your board.

My recommendation is
1. System image I always use Macrium Reflect free edition
It has never failed me on my personal use or in my use for solving problems on relatives and friends computers.
It is very highly regarded, simple to use and has none of the complexity of Acronis for example.

2. Reset BIOS to optimal defaults.
CHECK settings for secure boot and UEFI but I am sure they will be correct

3. Clean install from USB using Microsoft download media
Download Windows 11 (microsoft.com)
second option.
Ensure you delete all partitions on the drive
UNLESS of course you have partitions other than the four for the UEFI install
eg a partition containing such as other personal data - games etc,
See link for excellent guide
(13) Clean Install Windows 11 Tutorial | Windows 11 Forum (elevenforum.com)

4. If that works, then the next step is of course up to you.
If it does not, I am sorry to say I do not know the answer.
 
#19 ·
I honestly do not know
Have you got a system image of the whole drive on an external drive
The reason I ask is that if you do a clean install and it does not work, you can at least then go back to the system image to save you reinstalling all the apps and indeed your personal data will be preserved.

Returning to the custom or standard for the secure boot
Standard takes the keys from the TPM trusted platform in the firmware and the various hardware and then from boot devices etc.and eventually from the OS for the successful result on the windows security - devices etc.

As I understand it, and I am by no means an expert in this issue, custom is only used when the user wishes to configure the keys
That seems to be the general theme of the BIOS operating manual for your board.

My recommendation is
1. System image I always use Macrium Reflect free edition
It has never failed me on my personal use or in my use for solving problems on relatives and friends computers.
It is very highly regarded, simple to use and has none of the complexity of Acronis for example.

2. Reset BIOS to optimal defaults.
CHECK settings for secure boot and UEFI but I am sure they will be correct

3. Clean install from USB using Microsoft download media
Download Windows 11 (microsoft.com)
second option.
Ensure you delete all partitions on the drive
UNLESS of course you have partitions other than the four for the UEFI install
eg a partition containing such as other personal data - games etc,
See link for excellent guide
(13) Clean Install Windows 11 Tutorial | Windows 11 Forum (elevenforum.com)

4. If that works, then the next step is of course up to you.
If it does not, I am sorry to say I do not know the answer.
cool thanks for the help, i dont store anything on my m.2 its all on externals only have 4 games installed on it. everything is backed up so ill just fresh install and see what happens. ill let you know.
 
#22 ·
Cheers
Will wait to hear from you
 
#23 ·
just a quick update, not had time to complete a full wipe but ive received a number of updates titled 2H22 and still noting is changing, bios is still all enabled so untill i can get a minute im hoping the updates will fix it, if there are any other things you have seen regarding this then please share.

thanks for your help so far
 
#24 ·
f there are any other things you have seen regarding this then please share.
I have nothing further to suggest
However 2H22 is more or less a complete fresh install of windows as it is a new version of 11
and you will notice that you have on C drive a windows old folder whioch is for the purpose of rollng back to 21H2

Are you aware that a number of people have had issues with 2H22 which was I think an optional update
That is not to mean that you will - but you may wish to see this

If you google 2H22 problems you can see the many reports
2h22 problems - Google Search

although the official microsoft problems do not show most of them
Windows 11, version 22H2 known issues and notifications | Microsoft Learn
I suspect like many other version updates many of those reported on google - will be peculiar to certaion setups and certain third party software
 
#26 ·
#27 ·
I understand its importance but turning it off is the only way to overclock using the ai program, I can't see how in bios to switch it off switching off from device security saves it and forces a restart then login and it's back on, same with the ai app open that says do you want to turn off memory integrity, click yes and forces reboot to make changes, comes back on and it's still not off.

It is a frustrating thing it is
 
#28 ·
Have you tried the reg file on the link
 
#30 ·
I would think you would have to re-run the reg file.
That said depending on what OC you are making the easier way - surely is turn off memory integrity - run A1
and then turn on memory integrity
It is not, as I see it, a repeated exercise with A1 suite
OR OC in firmware without using A1