If you dual-boot Windows and Linux, Windows can quietly break your setup. It can push its own boot manager back to the top of the boot order, leave your Windows drives locked through Fast Startup, change which bootloaders Secure Boot trusts, or lock you out with BitLocker. Each problem has a fix, and most of them can be avoided if you prepare before you make changes.
Why Windows keeps getting in the way
On UEFI systems, Windows and Linux both keep their bootloaders on the EFI system partition (a small partition that holds the startup files for each operating system). Your firmware chooses which one to launch from a boot order stored in NVRAM, the firmware’s own small memory.
Windows acts as if it’s the only system on the disk. Big feature updates, repair operations and reinstalls can rewrite that boot order. Security updates can change what Secure Boot accepts. Its default power and encryption settings assume nothing else will ever touch the drive. Nothing here is aimed at Linux, but your Linux install is the one that suffers.
Check the firmware boot menu when Linux seems to be gone
When a major Windows update, a repair or a reinstall puts Windows Boot Manager back in first place, your next restart skips the GRUB menu and goes straight to Windows. GRUB, the Linux bootloader, usually hasn’t been deleted. It’s been moved down the list.
- Restart your PC and open the firmware boot menu.
- Look for your Linux entry in the list of boot options.
- Select it to boot Linux, or move it back above Windows Boot Manager in the boot order.
Older BIOS machines that use MBR partitioning are a different story. There, the Windows installer writes its own code to the master boot record and wipes GRUB completely, so you’ll need to reinstall GRUB as described in the next section.
Reinstall GRUB from a Linux live USB
If the boot menu doesn’t show your Linux entry, or GRUB has been erased, you can restore it from a live USB. You’ll need a bootable Linux USB stick for this. If Windows is the only system that starts, make one before you need it.
- Boot your PC from a Linux live USB.
- Mount your installed Linux system.
- Reinstall the bootloader with
grub-install. - Run
update-grubto rebuild the boot menu.
If GRUB is still there and has only been pushed down the order, you can use efibootmgr from Linux to move the Linux entry back to the top.
Stop it happening again
- Install Windows first, then Linux, so the Linux installer can detect your existing setup and work around it.
- Put Linux on its own drive with its own EFI partition. That keeps Windows updates away from your bootloader files.
- Keep a Linux live USB somewhere you can find it.
Turn off Fast Startup so Linux can open your Windows drives
Fast Startup makes Windows boot faster by saving the state of its kernel to a hibernation file instead of shutting down fully. That means when you click Shut Down, Windows is really hibernating. Its NTFS partitions stay in a suspended, unclean state, as though Windows might pick up where it left off at any moment.
When you boot Linux and try to open those partitions, the driver will usually refuse to mount them read-write, or mount them read-only and warn you about the hibernated session.
Don’t force the mount. Writing to a filesystem that Windows expects to resume can corrupt data. The ntfs-3g option that discards the hibernation file also throws away whatever Windows had saved in memory, and files you change from Linux may clash with what Windows expects to find when it comes back.
To turn off Fast Startup:
- Open the Windows power settings.
- Go to Choose what the power buttons do.
- Click the link that unlocks the option. You’ll need administrator rights for this.
- Turn off Fast Startup.
To remove hibernation completely, which also frees several gigabytes of disk space:
- Open an elevated command prompt (one run as administrator).
- Type
powercfg /h offand press Enter.
If you’d rather keep Fast Startup, choose Restart instead of Shut Down whenever you want to switch to Linux. A restart fully shuts down the Windows kernel, so your drives are left in a clean state.
Prepare for BitLocker before installing Linux
BitLocker is the most serious risk here because it can lock you out of your own data. Recent versions of Windows 11 turn on device encryption on many new PCs, often automatically when you sign in with a Microsoft account. The recovery key is stored with that account, not anywhere you’d expect to look.
BitLocker ties its encryption key to the PC’s TPM, a security chip that records measurements of the boot process. If something in that chain changes, such as installing a new bootloader, changing Secure Boot settings or updating firmware, the TPM may refuse to release the key. You’ll then see a blue recovery screen asking for a 48-digit key you may never have seen.
Installing Linux makes this more likely. You usually have to shrink the Windows partition, and Linux tools generally can’t resize a BitLocker volume without the key. Even if you can, changing an encrypted partition from outside Windows is a fast way to lose it.
Before you touch anything:
- Find your BitLocker recovery key.
- Store it somewhere separate from the PC.
- Suspend BitLocker protection, or decrypt the drive.
- Shrink the Windows partition from inside Windows.
- Only then start the Linux installation.
Some people turn encryption off completely to avoid the trouble. That’s easier, but you give up the security BitLocker provides. Whichever you choose, don’t start a dual-boot install until you know where your key is.
Linux can read BitLocker drives with tools such as cryptsetup or dislocker, but only if you can supply the recovery key or password.
Fix Secure Boot problems and SBAT errors
Secure Boot only lets your PC run bootloaders signed with keys its firmware trusts. Most PC firmware trusts Microsoft’s certificates, so most Linux distributions use a small loader called shim, which Microsoft signs for them.
Microsoft’s 2011 certificates are expiring. The one that signs Linux shims expires on June 27, and the one behind the Windows bootloader follows on October 19. Firmware doesn’t check expiry dates, so a Linux install that boots today should keep booting.
The trouble comes later. New shims are signed only with the newer 2023 certificate, and a PC whose firmware has never received that certificate may refuse them. On dual-boot machines, Windows Update is meant to deliver the new certificates to the firmware. Older computers that no longer get firmware updates from their maker may never receive them, and a new distro installer could fail to start with Secure Boot turned on.
Windows updates have caused this before. In August 2024, a Windows security update aimed at a bootkit vulnerability left some dual-boot systems unable to start Linux, showing an error about SBAT verification.
The usual workaround:
- Temporarily turn off Secure Boot in your firmware settings.
- Boot Linux and update your distro’s shim and GRUB packages.
- Turn Secure Boot back on.
You can also try fwupd, which can update the firmware’s key databases from inside Linux. How well that works depends on how well your hardware maker supports it.
Frequently asked questions
Why does my PC boot straight into Windows after an update?
A major Windows update, repair or reinstall has probably put Windows Boot Manager back at the top of the boot order. GRUB is usually still there, and you can pick it from the firmware boot menu or move it back up with efibootmgr.
Why can’t Linux write to my Windows drive?
Fast Startup leaves your NTFS partitions in a hibernated state when you shut down Windows. Turn off Fast Startup, or choose Restart instead of Shut Down before you switch to Linux.
Will Linux stop booting when Microsoft’s Secure Boot certificate expires?
Firmware doesn’t check expiry dates, so an install that boots now should keep booting. The risk is with newer shims signed only with the 2023 certificate, which firmware that never received that certificate may refuse.
Can Linux read a BitLocker-encrypted drive?
Yes, with tools such as cryptsetup or dislocker, but only if you have the recovery key or password.
