As this is a very common ‘issue’ I am just going to post the quick-fix:

If you have internet:

Install from install media:

 

Need to set pics in AD, here a quick way to do it with #powershell

If you are more comfortable with a GUI, codetwo.com has a free tool that will give you the same functionality.

It’s True — There is no such backdoor that only its creator can access.
Microsoft has accidentally leaked the Secret keys that allow hackers to unlock devices protected by UEFI (Unified Extensible Firmware Interface) Secure Boot feature.
What’s even worse?
It will be impossible for Microsoft to undo its leak.
Secure Boot is a security feature that protects your device from certain types of malware, such as a rootkit, which can hijack your system bootloader, as well as, Secure Boot restricts you from running any non-Microsoft operating system on your device.
In other words, when Secure Boot is enabled, you will only be able to boot Microsoft approved (cryptographically signature checking) operating systems.

https://thehackernews.com/2016/08/uefi-secure-boot-hack.html