A new ThinkPad T460 - Secure Boot and UEFI help

gunjan

Junior Member
Dec 3, 2016
8
0
6
So my cousin got a new ThinkPad T460, but without an OS. I had a spare Windows 8.1 Pro key, so I installed 8.1 using a live USB drive after converting the ISO using Windows 7 USB/DVD download tool. It installed without any problems, but I ensured that Windows couldn't install any updates or device drivers (during the setup I didn't go for express settings). So just after connecting to the internet and activation, I started the upgrade to Windows 10 using the assistive technology upgrade route (I know it's a bit unfair). Windows 10 also installed without any problems and is running fine. But I don't think it's making use of the Secure Boot and UEFI properly. I mean I still see the Lenovo splash screen, the Windows Logo splash screen, a no-logo-but-rotation-animation splash screen and then the account login screen. Shouldn't I be seeing just the Lenovo splash screen if secure boot and UEFI work properly? Any help in the regard would be appreciated. I'm not trying to implement security measures, just trying to reduce the boot time. Thanks :blush:
 

JeffMD

Platinum Member
Feb 15, 2002
2,026
19
81
Well unfortunately now is too late. Unless you want to install from square one you can't go into secure boot. To make sure you can install in secure boot you make sure everything for secure boot is enabled in bios. So no legacy modes and such. The method you used to create the usb stick is fine.
 
  • Like
Reactions: gunjan

ch33zw1z

Lifer
Nov 4, 2004
39,040
19,732
146
In lenovo products, uEFI "on/off" switch is under the restart menu in the BIOS. Lenovo calls it "OS Optimized" and you either enable (uEFI mode) or disable (non uEFI mode). check it out...
 
  • Like
Reactions: gunjan

gunjan

Junior Member
Dec 3, 2016
8
0
6
Thanks for replying Jeff and ch33zw1z :)
Well unfortunately now is too late. Unless you want to install from square one you can't go into secure boot.
I have no problem in doing a clean install, probably will do when the Creator's update rolls out.
To make sure you can install in secure boot you make sure everything for secure boot is enabled in bios. So no legacy modes and such.
Can you/someone please elaborate more about this. What all do I need to do and what are the legacy modes?
The method you used to create the usb stick is fine.
Is the method explained here not the best way to go about it?
Thanks again.
 

gunjan

Junior Member
Dec 3, 2016
8
0
6
In lenovo products, uEFI "on/off" switch is under the restart menu in the BIOS. Lenovo calls it "OS Optimized" and you either enable (uEFI mode) or disable (non uEFI mode). check it out...
Wouldn't I need to do a clean install before I can turn on Secure boot properly?
 

ch33zw1z

Lifer
Nov 4, 2004
39,040
19,732
146
Yup (to my knowledge), since you have the Win10 license, just build the windows 10 installer media and reinstall.

Turn on the secure boot, make sure OS Optimized is set to enabled, and have at it.
 
  • Like
Reactions: gunjan

fire400

Diamond Member
Nov 21, 2005
5,204
21
81
secure boot generally shouldn't matter if you're booting into a flash drive with a genuine installation of Windows; restart PC into UEFI settings, and in the next menu after a restart it usually allows you to boot from a flash drive, especially if generally the current BIOS settings make it difficult to access a flash drive when the computer starts up very quickly.

splash screen(s) shouldn't really matter at all, either. of course some gaming desktop motherboard manufacturers, force end users to look at a logo for a few seconds before launching boot priorities, even on expensive rigs (my guess is the BIOS software needs to load and be fancy and offer "elaborate or fun looking features" with the color schemes and mouse cursor support, or just terrible planning from upper management).

before we get to the bread and butter, windows 10 totally blows with all the upgrade packages, ads (which can somewhat be turned off) hidden telemetry (enterprise edition can disable telemetry) being forced down 10 home and 10 pro (upgrade deferment possible for pro) end users, recommend just leaving 8.1 on it for now, 'cuz it's flatter and has fewer ads like windows 7, and also has far fewer modding-customization restrictions unlike windows 10. but win10 has great support for virtual desktops, which is hard to beat with how well it's integrated into the GUI.

for the motherboard signature of Microsoft Windows 10 activation, that t460 should have activated by itself without having to use spare keys:

https://www.nextofwindows.com/how-to-retrieve-windows-8-oem-product-key-from-bios
https://support.microsoft.com/en-us/help/12440/windows-10-activation

unless of course the issue at hand was a banned key, or if the key was tampered with in the BIOS, or other reasons untold like Lenovo skipped BIOS key implementation, etc.

--

anyway, here's what I would look at,

check RAM against faults first. bad memory can put delays in the system and no one will ever know it.
make sure the system is on an SSD and no HDD or SSHD, and is not faulty at all, and if the t460 specific model can take PCI-e NVMe, then replace it with that type of storage type SSD technology instead.

back up important data, save drivers folder if you want to make it a bit easier with finding missing drivers later
do a fresh install of microsoft.com's version of Win10 pro x64, delete all partions before you install;
TURN ON: UEFI, secure boot, quickboot, speedstep, multi-core, performance mode on AC power
TURN OFF: legacy boot, intel mangement technology, passwords, advanced 3rd party security enhancements, any interface devices that will not be used such as for example: bluetooth, LAN ROM boot, WWAN, etc.

PRIORITY BOOT: SSD ONLY, disable everything except USB so you can reload OS's later, and set USB as priority #2, whereas #1 would be the SSD.

bypass anything that requires external internalization or virtual network environment locating in BIOS.

if the RAM is 8gb - 32gb, and it's on a great branded SSD with clean install of Windows, then a t460 should be loading in less than fifteen seconds, easily, but literally seconds on the cleanest OS environment and unrestricted BIOS settings, and even faster on NVMe SSD's.

--

to help with boot times, you can also try under windows 8.1 and windows 10; control panel / power options / system settings / +turn on fast startup (does not help with restarts).

if the SSD needs to be optimized, use SSD/HDD software kits to write 1's and 0's across the entire drive, to give it as fresh a slate as possible, for the install of a new OS.
 

gunjan

Junior Member
Dec 3, 2016
8
0
6
Yup (to my knowledge), since you have the Win10 license, just build the windows 10 installer media and reinstall.

Turn on the secure boot, make sure OS Optimized is set to enabled, and have at it.
Yeah, didn't work without reinstalling Windows... Will post results after reinstallation completes.