Secure Boot fails to enable in VM after "Restore Factory Keys"

Hello,

I am trying to enable Secure Boot for a new Windows 10 VM on my fresh install/update of TrueNAS SCALE [25.04.2.1].

I have followed all the standard procedures, but I am stuck. Here is what I did:

  1. I created a brand new VM.
  2. In the VM settings, I selected Boot Method: UEFI. (Secure boot and TPM chcked)
  3. I started the VM and entered the TianoCore UEFI setup by pressing Esc.
  4. Inside the UEFI menu, I navigated to Device Manager -> Secure Boot Configuration.
  5. The Secure Boot option was [Disabled] and greyed out.
  6. I selected the option Restore Factory Keys and confirmed it.

The main problem: Even after successfully executing “Restore Factory Keys”, the Secure Boot status remains [Disabled] and the system stays in “Setup Mode”. It does not automatically enable.

I have confirmed this on a clean test VM with no passthrough devices attached. It seems like the “Restore Factory Keys” function is not working as expected in the OVMF firmware provided with this version of SCALE.

Has anyone else experienced this? Is this a known bug or is there a workaround?

Thank you very much, so far Im enjoying truenas expirience very much!

Hello,

Is there any update on this? I’m facing the same issue with IncusOS and Truenas (25.04.2.6)