How to Fix the “Restart Surface to Modify Security Settings” Loop Safely (2026)

2026 maintenance note. The original article is a substantive 2017 first-person account, attributed in its body to Chen Miao, about a Surface Pro 4 whose UEFI Security page disappeared after an attempt to boot a USB PE environment. Its “turn Devices off, then on” workaround was an observation, not an explained or Microsoft-documented repair. This edition preserves the complete export at the end and adds a separate evidence-first recovery guide based only on current Microsoft documentation. The export contains no trailing whitespace, so no normalization was necessary.

The message “The security settings on Surface cannot be modified at this time. A restart is required…” does not by itself identify the cause. It might be a Windows restart workflow, a Surface UEFI state, a BitLocker response to changed boot measurements, or an organization-enforced firmware policy. Repeating restarts or changing more firmware settings can erase useful evidence and may trigger BitLocker recovery.

1. Preserve data and BitLocker recovery first

Before changing Secure Boot, TPM, boot order, UEFI devices, or firmware:

  1. If Windows starts, copy irreplaceable files to a separate, verified destination.
  2. Check whether Device encryption or BitLocker Drive Encryption is on.
  3. From another trusted device, verify that you can actually retrieve the correct 48-digit BitLocker recovery key. Match it by the first eight digits of the recovery key ID shown on the recovery screen.
  4. Keep the key somewhere other than the Surface. Do not put the recovery key, full serial number, Microsoft-account address, or organization identifiers in public screenshots or support posts.
  5. If the device belongs to work or school, ask IT to confirm the recovery key and authorize any firmware action.

Microsoft explains that hardware, firmware, software, Secure Boot, or boot-flow changes can make BitLocker require recovery. Microsoft Support cannot recreate a lost recovery key. If the only remaining recovery choice is a reset, files can be removed. Therefore:

No accessible key plus no verified backup means stop. Do not experiment in UEFI.

Device encryption can have been enabled automatically and its key saved to a Microsoft or work/school account. Do not assume the drive is unencrypted because you never manually enabled BitLocker.

2. Identify the exact Surface and software state

“Surface Pro” is not specific enough. Menu layout, supported controls, force-restart buttons, and management features vary by model and commercial/consumer SKU.

Record these facts before attempting a fix:

Fact Supported place to find it Privacy note
Exact Surface model Surface app → Device information, or Windows System InformationSystem Model/System SKU Model is usually safe to share
Windows edition, version, build Settings → System → About Do not publish device or product IDs
UEFI/firmware version Surface UEFI → PC information Redact serial number and system UUID
Secure Boot state Windows System Information Record only; do not toggle it yet
Encryption state Settings → Privacy & security → Device encryption, or Manage BitLocker Never publish the recovery key
Management state Settings → Accounts → Access work or school; also note a UEFI password, locked/grey controls, or a Management page Do not disconnect an organization
Trigger and exact location Photograph the complete message and note whether it appeared before Windows, in Settings, during update, or at BitLocker recovery Redact identifiers

The archived machine was a Surface Pro 4. Do not apply its buttons, screenshots, or menu expectations to a different model. Also note that Windows 10 support ended on October 14, 2025; if this Surface still runs Windows 10, plan a supported migration separately after data recovery rather than combining an OS migration with firmware troubleshooting.

3. Classify the screen before acting

What you see What it establishes Safe next move
A prompt inside Windows Settings or Windows Security Windows has requested a restart; it does not prove UEFI is broken Save work and perform one normal Windows restart
The Surface UEFI interface before Windows loads You are in firmware; available pages depend on model/SKU/management Record PC information and menu availability; make no security change
A blue BitLocker recovery screen with a key ID The encrypted drive did not auto-unlock Stop and retrieve the matching key; do not guess
A Surface firmware-update screen with progress bars Firmware is actively being applied on reboot Keep approved power connected and do not force shutdown
Grey/locked controls, a UEFI password, SEMM, DFCI, or organization text Policy or firmware management may own the setting Stop and contact the authorized administrator
Windows fails to start but Windows Recovery Environment appears Windows recovery tools are available; some require the BitLocker key Prefer diagnostic/repair tools before reset

If you cannot identify where the message appears, do not label it a “UEFI loop” yet. Capture the screen and exact sequence first.

4. Check ownership and management policy

Surface firmware can be managed below Windows:

  • Surface Enterprise Management Mode (SEMM) uses a certificate to protect a UEFI configuration. Microsoft says the approved certificate is required to modify or remove management; if it is lost or corrupt, SEMM cannot simply be reset.
  • On eligible commercial models, Device Firmware Configuration Interface (DFCI) lets Intune manage UEFI security, boot, camera, microphone, and other settings.
  • A UEFI password may restrict pages or changes. Microsoft states that a forgotten Surface UEFI password cannot be reset or retrieved by Microsoft.

If the Surface is or was owned by an organization, do not disconnect the work/school account, clear the TPM, reinstall Windows, or attempt to unenroll firmware management to defeat the restriction. Contact the current authorized administrator. For a second-hand device that still has an organization lock, ask the seller or originating organization to release it through its supported management process.

The presence or absence of a Security or Devices page is not proof of a fault by itself; Microsoft says visible UEFI options vary by model and whether the unit is a home or commercial device.

5. Enter Surface UEFI only by supported methods

After the backup/key/management gates pass, use one of Microsoft’s documented entry paths.

From a working Windows 11 installation:

  1. Open Start → Settings → System → Recovery.
  2. Next to Advanced startup, select Restart now.
  3. Select Troubleshoot → Advanced options → UEFI Firmware Settings → Restart.

On Windows 10, Recovery is under Settings → Update & Security → Recovery.

Or use the Surface hardware method:

  1. Shut down normally and wait about 10 seconds.
  2. Hold Volume Up.
  3. While holding it, press and release Power.
  4. Keep holding Volume Up until Surface UEFI appears, then release it.

On this first entry, observe only: record the model, firmware version, menu names, any lock/management indicator, and the exact prompt. Use Exit → Restart now without changing Secure Boot, TPM, boot order, or Devices.

6. Follow one bounded, low-risk recovery sequence

Do not restart indefinitely. Use this sequence once:

  1. Complete the BitLocker, backup, model, and management checks above.
  2. Disconnect nonessential USB storage, PE media, hubs, docks, and network-boot adapters. Keep the approved power supply attached. Removable boot media or a changed boot path can alter BitLocker measurements.
  3. If Windows is responsive, perform one normal Start → Power → Restart.
  4. If the prompt persists, enter UEFI once by a supported method, collect evidence, change nothing, and exit with Restart now.
  5. If the Surface is unresponsive—not merely showing the same prompt—perform at most one model-correct forced restart from the next section.
  6. When Windows is stable, apply supported Windows and Surface firmware updates as described below.
  7. If the same loop remains, stop. Escalate with the evidence package in section 13 rather than trying unrelated toggles.

A loop that survives one normal restart, one read-only UEFI visit, and one appropriate force restart is not made safer by ten more cycles.

7. Use the model-correct force restart only when unresponsive

A forced restart is for a frozen or unresponsive Surface, not for interrupting a firmware update and not as a repeated UEFI repair.

For the Surface Pro 4 in the original article, Microsoft’s current “earlier Surface models” procedure is:

  1. Hold Volume Up + Power together until the screen turns off, continuing for at least 15 seconds even if the logo flashes.
  2. Release both buttons and wait 10 seconds.
  3. Press and release Power to start the Surface.

Newer Surface families generally use a different procedure—holding Power until shutdown/restart and the Windows logo appears, about 20 seconds—and Microsoft lists the applicable models on its support page. Confirm the exact model before touching buttons. Perform the matching sequence once. Never force power off while firmware-update progress is visible.

8. Update through Microsoft, with power and recovery ready

For most users, Microsoft recommends the Surface app and Windows Update:

  1. Connect the approved charger; Microsoft specifies at least 40% battery for Surface firmware updates.
  2. In the Surface app, open Help & support and check update status.
  3. Open Windows Update and install applicable Windows, optional, and Surface-named driver/firmware updates.
  4. Allow the next reboot to complete; Surface firmware is applied during reboot, and progress screens must not be interrupted.

If a manual package is genuinely needed, select the exact model and Windows build through Microsoft’s Surface driver/firmware page and follow its link to the Microsoft Download Center. Do not use a driver site, forum attachment, mirror, or firmware package for a “close enough” Surface.

Ordinary Microsoft updates normally coordinate with BitLocker. For a separately planned manual firmware or boot-security change, first verify the recovery key and follow the authorized Microsoft/IT BitLocker suspend-and-resume procedure. Suspending protection reduces protection temporarily; do not do it casually or leave it suspended.

9. Understand Secure Boot, TPM, and BitLocker consequences

  • Secure Boot protects the startup chain. Changing its state, keys, certificates, or boot order can change TPM measurements and trigger BitLocker recovery.
  • TPM clear is not a restart. Microsoft warns that clearing the TPM removes TPM-created keys and can invalidate Windows Hello PIN/biometric sign-in and data protected only by those keys.
  • Do not clear TPM on a device you do not own, and never do so on a work/school Surface without IT instruction.
  • Do not disable Secure Boot merely to make a warning disappear or to boot an unverified PE/Linux image.
  • Do not delete or replace Secure Boot keys, bypass a UEFI password, or use “unlock” tools.
  • If BitLocker recovery appears after an authorized change, match the recovery key ID, unlock with the correct key, then determine the root cause. Repeated recovery needs diagnosis; it is not solved by repeatedly entering the key.

This guide intentionally provides no Secure Boot/TPM bypass or credential-evasion procedure.

10. Treat the 2017 Devices toggle as history, not a default fix

The original author reported that disabling UEFI Devices entries made the missing Security page return, after which the devices were re-enabled. The author also explicitly said the reason was unknown.

Microsoft’s current Surface UEFI documentation describes device controls and notes that SEMM can even control whether the Security and Devices pages are displayed. It does not document “toggle every device to refresh Security” as a general repair. Disabling devices can remove Wi-Fi, Bluetooth, cameras, microphones, USB, the Type Cover, or other hardware, and an organization may own those settings.

Accordingly, this maintained guide does not recommend reproducing the workaround. If Microsoft Surface Support or an authorized administrator requests a specific setting test on an owned, unmanaged device, first secure the recovery key and backup, change only the named setting, record before/after state, and restore it exactly as instructed.

11. If Windows does not start

If Windows Recovery Environment (Windows RE) appears automatically, note that encrypted devices can require the BitLocker key for some tools. Prefer bounded, reversible diagnosis:

  1. Startup Repair for a startup failure.
  2. Uninstall Updates only when the failure immediately followed an update and the recovery UI offers it.
  3. System Restore when a known restore point exists and you understand which system changes it will undo.

Do not select Reset this PC merely to make a UEFI prompt disappear. A reset is not the first step, and Microsoft warns that recovery/reset paths can remove files. If the internal recovery environment is unavailable, use only the official Surface recovery image for the exact model and understand that creating the recovery USB erases that USB drive.

If data is not backed up, the recovery key is unavailable, the drive may be failing, or the recovery choices differ from Microsoft’s current page, stop and seek Microsoft/qualified data-recovery help before writing to the disk.

12. Stop and escalate when any gate fails

Stop immediately if:

  • there is no verified backup or accessible BitLocker recovery key;
  • the device is organization-owned, enrolled in management, password-protected, or shows locked firmware controls;
  • a firmware update progress screen is active;
  • a prompt asks to clear TPM, delete Secure Boot keys, reset factory keys, or remove management;
  • BitLocker recovery starts unexpectedly or repeats;
  • the charger/battery is unreliable, the Surface overheats, the battery is swollen, or storage errors appear;
  • one normal restart, one read-only UEFI visit, and one model-correct forced restart do not change the behavior;
  • the screen or menu does not match the documented model.

These are authorization, data-recovery, policy, or hardware-support problems—not invitations to bypass security.

13. Prepare a useful support evidence package

Give Microsoft Surface Support or your administrator:

  • exact Surface model and consumer/commercial SKU;
  • Windows edition, version, and build;
  • UEFI/firmware version;
  • encryption status and whether the matching recovery key is retrievable;
  • management state: work/school connection, DFCI/SEMM indication, UEFI password, grey controls;
  • the exact text and location of the prompt;
  • what immediately preceded it: update, USB/PE boot, Linux attempt, boot-order change, or unexplained restart;
  • one redacted photo of each relevant screen;
  • the bounded steps already attempted and their outcomes.

Share only the first eight digits of the BitLocker key ID when matching records with authorized support—not the 48-digit recovery key. Send the serial number only through Microsoft’s or your organization’s private support channel.

14. Quick decision table

Condition Continue locally? Next action
Windows starts; data and key verified; personal unmanaged device Yes, bounded Normal restart → read-only UEFI check → official updates
BitLocker recovery screen No firmware changes Retrieve the matching key and diagnose the trigger
Work/school management, DFCI, SEMM, UEFI password, grey control No Authorized IT/admin
Firmware update progress No interruption Keep power attached and wait
Windows does not start, but key and backup are available Carefully Windows RE repair tools before reset
No key or no backup No Data-recovery/authorized support
Still looping after the bounded sequence No Microsoft Surface Support with evidence

15. Primary Microsoft documentation

16. Original 2017 export (verbatim)

The block below preserves the complete source export byte-for-byte, including its wording, attribution, historical links, relative image references, and unexplained workaround. No trailing whitespace was present, so none was normalized. It is evidence of the 2017 report, not current Microsoft guidance.

---
id: 26
title: '(SOLVED)HOW TO BREAK THE LOOP “RESTART SURFACE TO MODIFY SECURITY SETTINGS”'
slug: 'solvedhow-to-break-the-loop-restart-surface-to-modify-security-settings-2'
date: '2017-05-09T15:08:23'
modified: '2023-09-30T13:57:00'
status: 'publish'
link: 'https://blog.lazying.art/en/html/computer_internet/hardware_system/26/solvedhow-to-break-the-loop-restart-surface-to-modify-security-settings-2.html'
author: 'Lachlan Chen'
categories:
  - 'Hardware & System'
---

Reference Link:

http://earnfs.sinaapp.com/html/1237.htm

Handing on my new Surface Pro 4,I try to install ubuntu on it. But I lost my “Security” menu in UEFI while I try to boot from a PE in my USB stick.Then I get stuck in the “Restart to Surface UEFI” loop with a message ‘The security settings on Surface cannot be modified at this time. A restart is required to make changes to the security settings’. The default security settings menu no longer appear no matter how many times I restart. I googled as many as I can, but I still cannot find a way to fix this.

[![1](images/11.jpg)](http://earnfs.files.wordpress.com/2016/04/11.jpg)

Though I nearly give up this, but as a geek I have to know what’s the ball in it. It still lingered in my mind luring me. And most important I feel I lost my control on my computer, which is unacceptable!

I have to know!!! Or I can’t stop to ponder this.

Last night, an idea occured in my mind. I try to turn off the ‘Devices’ to trigger the settings to fix this. The result is amazing. I didn’t believe it worked. The pity is I still don’t know the reason why this happend.

Turn off the Devices:

[![2](images/2.jpg)](http://earnfs.files.wordpress.com/2016/04/2.jpg)

The Security settings come back again:

[![3](images/31.jpg)](http://earnfs.files.wordpress.com/2016/04/31.jpg)

Turn on all the Devices, you don’t expect a computer without camera, WIFI, and bluetooth…

[![4](images/41.jpg)](http://earnfs.files.wordpress.com/2016/04/41.jpg)

Enjoy your full-controled computer again!

—-

by Chen Miao

Leave a Reply