MSI Prestige 16 AI+ A3HGM-016US laptop cannot dual-boot Fedora & Windows 11 in Secure Boot mode

The MSI BIOS on this laptop, a Prestige 16 AI+ A3HMG-016US (AMD Ryzen 9 AI 365 CPU, 32Gb DDR5), does NOT support any Advanced Mode as far as I can tell. Pressing F7 while in the BIOS has NO effect nor is there any menu option to load any “Advanced Options.” Also the modified “secret key press” for the MSI AI/Co-Pilot+ PCs has no effect as well. I cannot boot Fedora with Secure Boot turned on because of the way in which MSI locks the user out from loading any third-party keys. Can’t boot Ventoy either because it won’t allow me to load the Ventoy key. Thus I CANNOT dual-boot Fedora and Windows 11 unless I leave the machine with Secure Boot turned OFF. Now, the reason I got into this whole MESS to begin with is that I wanted to run Windows 11’s controversial “Recall” feature which will NOT load unless Windows 11 is started with Secure Boot on. If I leave Secure Boot OFF I can easily dual-boot Windows 11 and Fedora V44 Workstation KDE Plasma 6 but when running Windows 11 using the “Recall” feature is no longer an option. I am 65 years old, I worked for the US Army for 35 years in Information Technology, I have spent HOURS on this problem to no avail. In the end my conclusion is that the MSI BIOS will only accept a Microsoft-certified key and will not allow for third-party keys to be loaded into the BIOS, Fedora simply will not boot in Secure Mode. I have spent HOURS on this problem. Another laptop I have a new HP OmniBook X 17-inch model running an Intel CPU has NO problem running dual-boot in Secure Mode, it’s only the new MSI laptop that has this problem. Any new MSI Co-Pilot+ laptop users out there confirm my findings??? Tell me where I am wrong, if I am wrong..

AMI bios I presume - is it fully up-to-date?

MSI firmware sometimes refuses to enable Secure Boot until either one or all of the following are performed.

  • an administrator/supervisor password is set in the BIOS,
  • factory Secure Boot keys are enrolled,
  • CSM/Legacy boot is disabled.

Done any/all of these yet?

I don’t know about “Advanced Mode” but what you need is to enable 3rd party CA under the Secure Boot settings.
On Surface devices for example, the option looks like this:


There should be something similar for MSI.
Some business-focused PCs are locked down and prevent 3rd party CA support, but even Microsoft’s secured-core PCs only do this by default and allow the enabling of 3rd party CA.

I have reset to factory keys more than once. I’m not setting an Admin password on this machine because I got burned doing that when it had the original Samsung SSD in it..long story.. BIOS is the latest.. Also, Steve, the problem isn’t that it can’t enable Secure Boot, it can, it’s just once I turn on Secure Boot I have no access to Fedora 44 only Windows 11 will boot with Secure Boot enabled. Thank you for taking the time to reply!

Yuri: That’s the exact problem, this MSI BIOS has NO option to change the Secure Boot configuration. None. No “Advanced” menus, etcetera. It’s basically Secure Boot on-or-off and that’s about it. Thank you though for your time.

I read the user manual and no mention of BIOS at all.

I think you need to ask MSI how to change the BIOS to allow linux to be installed.

Before retiring I worked for a “large enterprise”. We were issued laptops running Windows “Enterprise”. Management required that we have Windows running (no excuses for not responding immediately to requests from managers!), so mission critical Linux apps had to be run in WSL or on linux servers in data centres. Since retiring it appears that Microsoft has been improving WSL, so you may find that a viable alternative to dual booting.

George thanks! I’ve never really gotten into running VMs despite their immense popularity among enthusiasts. Thank you for the suggestion though! Much appreciated! Chris R.

Barry: I didn’t find out until purchasing this laptop second-hand (eBay) that the Prestige Series is MSI’s business line so it kind of make sense that they lock them down like this. Also I have just today submitted a Tech Support ticket to MSI. We’ll see what they say but I don’t really hold out much hope that they will do anything but say “Too bad, so sad..” and walk away.