Running Windows and Linux on the same machine leaves your setup open to Windows breaking it without warning. Windows may move its own boot manager back to the top of the boot order, leave its drives locked because of Fast Startup, change which bootloaders Secure Boot will trust, or shut you out entirely with BitLocker. Every one of these problems can be fixed, and with some preparation before you make changes, you can avoid most of them.
Why Windows keeps getting in the way
On UEFI systems, both operating systems store their bootloaders on the EFI system partition, a small partition holding the startup files for each OS. To decide which one to launch, your firmware reads a boot order kept in NVRAM, its own small block of memory.
Windows behaves as though no other system shares the disk. Major feature updates, repairs and reinstalls can all rewrite the boot order. Security updates can change what Secure Boot will accept. Its default power and encryption settings assume nothing else will ever touch the drive. None of this targets Linux on purpose, but your Linux install is what takes the damage.
Check the firmware boot menu when Linux seems to be gone
If a big Windows update, a repair or a reinstall moves Windows Boot Manager back to first place, the next restart bypasses the GRUB menu and loads Windows directly. GRUB, the Linux bootloader, is usually still on the disk. It has just been pushed further down the list.
- Reboot the PC and bring up the firmware boot menu.
- Find your Linux entry among the boot options.
- Choose it to start Linux, or move it back above Windows Boot Manager in the boot order.
Older BIOS machines with MBR partitioning work differently. On those, the Windows installer writes its own code to the master boot record and erases GRUB entirely, so you’ll have to reinstall GRUB using the steps in the next section.
Reinstall GRUB from a Linux live USB
If your Linux entry is missing from the boot menu, or GRUB has been wiped, a live USB lets you bring it back. This requires a bootable Linux USB stick. If Windows is the only system that will start, create one before you need it.
- Start the PC from a Linux live USB.
- Mount the Linux system you installed.
- Use
grub-installto reinstall the bootloader. - Run
update-grubto rebuild the boot menu.
If GRUB survived and was only moved down the order, you can run efibootmgr from Linux to put the Linux entry back on top.
Stop it happening again
- Install Windows before Linux, so the Linux installer can spot the existing setup and work around it.
- Give Linux a separate drive with its own EFI partition. That keeps your bootloader files out of reach of Windows updates.
- Store a Linux live USB somewhere you’ll be able to find it.
Turn off Fast Startup so Linux can open your Windows drives
Fast Startup helps Windows boot faster by writing the state of its kernel to a hibernation file rather than shutting down completely. So when you press Shut Down, Windows is actually hibernating. Its NTFS partitions are left suspended in an unclean state, as if Windows could resume where it stopped at any moment.
When you start Linux and try to access those partitions, the driver will typically decline to mount them read-write, or it will mount them read-only and warn you about the hibernated session.
Don’t force the mount. Writing to a filesystem that Windows plans to resume can corrupt data. The ntfs-3g option that discards the hibernation file also wipes out whatever Windows was holding in memory, and any files you edit from Linux may conflict with what Windows expects to see when it returns.
To turn off Fast Startup:
- Open the Windows power settings.
- Go to Choose what the power buttons do.
- Click the link that unlocks the setting. This requires administrator rights.
- Disable Fast Startup.
To get rid of hibernation altogether, which also frees up several gigabytes of disk space:
- Open an elevated command prompt (one running as administrator).
- Enter
powercfg /h offand press Enter.
If you want to keep Fast Startup, pick Restart rather than Shut Down any time you plan to switch to Linux. Restarting fully shuts down the Windows kernel, which leaves your drives in a clean state.
Prepare for BitLocker before installing Linux
BitLocker poses the biggest risk of the four because it can lock you out of your own data. Recent Windows 11 versions enable device encryption on many new PCs, frequently without asking when you sign in with a Microsoft account. The recovery key is saved to that account, not anywhere you would think to check.
BitLocker links its encryption key to the PC’s TPM, a security chip that records measurements of the boot process. When something in that chain changes, such as a new bootloader being installed, Secure Boot settings being altered or firmware being updated, the TPM can refuse to hand over the key. You’ll then get a blue recovery screen demanding a 48-digit key you may never have seen before.
Installing Linux raises the odds of this happening. You normally need to shrink the Windows partition, and Linux tools usually can’t resize a BitLocker volume without the key. Even if they can, modifying an encrypted partition from outside Windows is a quick way to lose it.
Before you change anything:
- Locate your BitLocker recovery key.
- Keep it somewhere apart from the PC.
- Suspend BitLocker protection, or decrypt the drive.
- Shrink the Windows partition from within Windows.
- Only after that, begin the Linux installation.
Some users switch encryption off entirely to sidestep the hassle. That’s simpler, but it means giving up the protection BitLocker offers. Whichever route you take, don’t begin a dual-boot install until you know where your key is.
Linux can read BitLocker drives using tools like cryptsetup or dislocker, but only when you can provide the recovery key or password.
Fix Secure Boot problems and SBAT errors
Secure Boot allows your PC to run only bootloaders signed with keys that its firmware trusts. Most PC firmware trusts Microsoft’s certificates, which is why most Linux distributions rely on a small loader called shim that Microsoft signs on their behalf.
Microsoft’s 2011 certificates are reaching expiry. The certificate that signs Linux shims expires on June 27, and the one behind the Windows bootloader follows on October 19. Because firmware doesn’t check expiry dates, a Linux install that boots today should continue to boot.
The problems arrive later. New shims carry only the newer 2023 certificate, and a PC whose firmware has never been given that certificate may reject them. On dual-boot machines, Windows Update is supposed to push the new certificates to the firmware. Older computers that no longer receive firmware updates from their manufacturer may never get them, and a new distro installer might fail to launch with Secure Boot enabled.
This has happened with Windows updates before. In August 2024, a Windows security update targeting a bootkit vulnerability left some dual-boot systems unable to start Linux, displaying an error about SBAT verification.
The standard workaround:
- Disable Secure Boot temporarily in your firmware settings.
- Start Linux and update your distro’s shim and GRUB packages.
- Re-enable Secure Boot.
Another option is fwupd, which can update the firmware’s key databases from within Linux. How effective it is depends on how well your hardware manufacturer supports it.
Frequently asked questions
Why does my PC boot straight into Windows after an update?
Most likely a major Windows update, repair or reinstall has moved Windows Boot Manager back to the top of the boot order. GRUB is usually still present, and you can select it from the firmware boot menu or move it back up using efibootmgr.
Why can’t Linux write to my Windows drive?
When you shut down Windows, Fast Startup leaves your NTFS partitions in a hibernated state. Disable Fast Startup, or use Restart rather than Shut Down before switching to Linux.
Will Linux stop booting when Microsoft’s Secure Boot certificate expires?
Since firmware doesn’t check expiry dates, an install that boots now should keep doing so. The risk lies with newer shims signed only with the 2023 certificate, which firmware that never received that certificate may reject.
Can Linux read a BitLocker-encrypted drive?
Yes, using tools like cryptsetup or dislocker, but only if you have the recovery key or password.

















STAY ALWAYS UP TO DATE