Hello Beelink Support,
I’m troubleshooting two firmware-related security issues on a Beelink GTi system.
System details
Model: Beelink/AZW GTi V3.0
CPU: Intel Core Ultra 9 285H
BIOS: GTiAT302
BIOS date: March 31, 2026
OS: Windows 11 Enterprise, build 26200
TPM: Intel PTT / TPM 2.0, initialized and attestation-ready
Secure Boot: enabled
VBS, Credential Guard, and Memory Integrity/HVCI: running
- Windows System Guard Secure Launch does not run
Windows has Secure Launch enabled and configured, but it does not enter the running state:
SecurityServicesConfigured: 1, 2, 3
SecurityServicesRunning: 1, 2, 7
SmmIsolationLevel: 0
Service 3 is System Guard Secure Launch. It is configured but absent from the running list.
The following BIOS options are enabled:
Intel TXT
Intel VT-d
Pre-Boot DMA Protection
DMA Control Guarantee
Intel PTT / TPM 2.0
Secure Boot
CPU virtualization
Initially, Windows logged:
System Guard enabled but not supported.
Reason: The system does not support DMA remapping in the DMAR table.
After enabling Pre-Boot DMA Protection and DMA Control Guarantee, that DMAR error disappeared. Windows now reports:
System Guard enabled but not supported. Reason: None
Hyper-V confirms that I/O remapping is functioning:
Hypervisor initialized I/O remapping.
Hardware present: true
Hardware enabled: true
Problems: 0×0
TPM SHA-256 PCRs 17-22 also remain FF…FF after a full shutdown and cold power-on, which suggests that the expected TXT/DRTM measured-launch path is not being exercised.
The Intel Core Ultra 9 285H supports Intel TXT. Could you confirm whether BIOS GTiAT302 includes and correctly provisions all firmware components required for Windows System Guard Secure Launch, including:
Compatible production Intel SINIT ACM
Required Intel TXT TPM AUX/PS/NV provisioning
Intel System Resources Defense / SMM protections
Intel System Security Report support
Complete Windows DRTM / Secured-core firmware support
Specifically:
Is Windows System Guard Secure Launch officially supported on this GTi model?
If yes, is there an additional BIOS setting required?
Is there a newer BIOS than GTiAT302 that addresses Secure Launch or TXT/DRTM support?
- SBAT firmware variable update failure
Every boot also produces Windows Kernel-Boot Event ID 292:
Failed to update the SBAT value in FW.
Secure Boot remains enabled, PCR7 is bound, and Windows reports the Windows UEFI CA 2023 transition as updated. However, the firmware appears unable to complete the SBAT authenticated-variable update.
Could you confirm whether GTiAT302 has a known issue with SBAT or authenticated Secure Boot variable updates, and whether a firmware update is available?
These may be separate issues, but both appear related to advanced UEFI platform-security support.
Thank you.