How To Enable Secure Boot Windows 11 (detailed Guide)

To enable Secure Boot on Windows 11, open Settings > System > Recovery, select Restart now next to Advanced startup, choose Troubleshoot > Advanced options > UEFI Firmware Settings, then set Secure Boot to Enabled and save.

Advertisement

This guide covers the pre-checks that stop a failed boot (UEFI mode, GPT disk, BitLocker key), brand pointers, how to confirm the change, and fixes for a greyed-out option, boot errors and the 2023 certificate update status.

How to Enable Secure Boot in Windows 11 (Step-by-Step)

Secure Boot is a firmware setting, so Windows can only restart you into the firmware menu; the switch itself lives there. Save open work first, because the PC restarts.

  1. Open Settings, select System, then select Recovery.
  2. Next to Advanced startup, select Restart now, and confirm with Restart now if a save prompt appears.
  3. On the blue screen, select Troubleshoot, then Advanced options.
  4. Select UEFI Firmware Settings, then Restart. The PC opens its firmware (UEFI/BIOS) menu.
  5. Make sure the boot mode is UEFI, not Legacy or CSM. If both are offered, make UEFI the first or only option.
  6. Open the Security, Boot or Authentication tab and find Secure Boot.
  7. Set Secure Boot to Enabled. On some PCs you must first choose Custom and load the Secure Boot keys built into the PC.
  8. Save changes and exit. Windows starts with Secure Boot on.

If Windows fails to start afterwards, go back into the firmware, set Secure Boot to Disabled again, and read the boot fixes further down before retrying.

Quick Summary

Use this as a quick checklist before and after the change. Each row links to the section with the full steps.

Check What you want to see Where to look
Secure Boot State On System Information (msinfo32) > System Summary
BIOS Mode UEFI (not Legacy) System Information > System Summary
System disk partition style GPT Get-Disk in PowerShell or Disk Management > disk Properties > Volumes
BitLocker recovery key Saved somewhere you can reach from another device https://aka.ms/myrecoverykey
Firmware setting Secure Boot: Enabled, CSM/Legacy off Security, Boot or Authentication tab
Result in Windows Confirm-SecureBootUEFI returns True PowerShell run as administrator

Which Method Should You Use?

Every route ends in the same firmware menu. The difference is how you get there, and whether Windows still starts.

Your situation Use this route Why
Windows 11 starts normally Settings > System > Recovery > Advanced startup No key timing needed; works on every brand
You are at the sign-in screen or Start menu Hold Shift while selecting Power > Restart, then Troubleshoot > Advanced options > UEFI Firmware Settings Same result without opening Settings
Windows does not start, or the PC is off Press the manufacturer's firmware key at power-on (commonly Esc, Delete, F1, F2, F10, F11 or F12) Needs no working Windows; the key is often shown briefly at startup
Microsoft Surface Hold Volume Up, press and release Power, keep holding Volume Up until the UEFI screen appears Surface has no keyboard firmware key; Secure Boot is on the Security page
Disk is MBR or BIOS Mode reads Legacy Convert the disk with MBR2GPT first, then switch to UEFI and enable Secure Boot Enabling Secure Boot on a Legacy install leaves Windows unbootable

What Secure Boot Actually Does (And Why Windows 11 Demands It)

Secure Boot lets only trusted, digitally signed software run while the PC starts. That blocks rootkits, which load before Windows and can hide from it.

Question Answer
What does it check? The signature of every piece of boot software: UEFI firmware drivers (Option ROMs), EFI applications and the operating system loader
What happens to unsigned code? The firmware refuses to run it, so the PC will not start that software
Where are the trusted keys kept? In firmware databases: db (allowed), dbx (revoked) and KEK (keys that may update db and dbx), locked by the manufacturer's Platform Key
What does Windows 11 require? UEFI firmware that is Secure Boot capable, plus TPM 2.0. Turning Secure Boot on is recommended rather than required for the upgrade
Why is it in the news in 2026? Microsoft's Secure Boot certificates from 2011 begin expiring in June 2026; the 2023 replacements arrive through Windows Update
Does it need TPM? They are separate features; Windows 11 requires both a TPM 2.0 chip and Secure Boot capable firmware

For how the TPM and Secure Boot work together, see TPM 2.0 and Secure Boot Explained.

Advertisement
TPM Management console showing Specification Version 2.0 highlighted
Windows 11 requires a TPM with this Specification Version of 2.0 alongside Secure Boot capable firmware. (Image: Microsoft)

Before You Start: Important Things To Check

Two checks decide whether the switch is a two-minute job or a boot failure: the firmware mode and the disk's partition style. The rest protects you if something goes wrong.

Check Why it matters If it fails
BIOS Mode is UEFI Secure Boot only works in UEFI mode; Windows keeps booting in the mode it was installed with Convert the disk to GPT, then switch the firmware to UEFI
System disk is GPT UEFI boots Windows from a GPT disk; an MBR system disk will not start in UEFI-only mode Run mbr2gpt /validate, then /convert
BitLocker recovery key is saved Firmware and boot changes can trigger the BitLocker recovery screen Sign in at https://aka.ms/myrecoverykey from another device and note the key
Windows Update is current Your manufacturer may update the list of trusted hardware and drivers Install pending updates and restart
Old graphics card, Linux or older Windows installed Unsigned hardware and loaders can stop the PC starting with Secure Boot on Check the maker's support site before you enable it

First, Check Whether Secure Boot Is Already On

Many PCs ship with Secure Boot already enabled. Check whether Secure Boot is already enabled before you touch the firmware.

  1. Press Win + R, type msinfo32 and press Enter to open System Information.
  2. Select System Summary in the left pane.
  3. Read Secure Boot State: On means you are done; Off means it is supported but disabled; Unsupported usually means the PC is running in Legacy mode.
  4. Read BIOS Mode on the same page: it must say UEFI before Secure Boot can be turned on.
  5. For a one-line check, open PowerShell as administrator and run Confirm-SecureBootUEFI. True means on, False means off, and "Cmdlet not supported on this platform" means a BIOS (non-UEFI) boot.

Check Whether Your System Disk Uses GPT Or MBR

Run this in PowerShell or Terminal. The disk that holds Windows is usually disk 0.

Get-Disk | ft -Auto

Lists every disk with its number, size and Partition Style column. Without a terminal, right-click Start, open Disk Management, right-click the disk number, choose Properties, and read Partition style on the Volumes tab. In DiskPart, list disk marks GPT disks with an asterisk in the Gpt column.

Advertisement

You should see: The Windows disk shows GPT. If it shows MBR, convert it before you switch the firmware to UEFI.

If Needed: Convert MBR To GPT Safely

Microsoft's MBR2GPT tool converts the system disk without deleting data. It refuses to run if the disk has more than three primary partitions, an extended partition, or no room for the GPT tables.

If the drive is BitLocker-encrypted, suspend protection first; the tool will not convert an encrypted volume while protection is active. Validate first, then convert.

mbr2gpt /validate /disk:0 /allowFullOS
mbr2gpt /convert /disk:0 /allowFullOS

Run both from an elevated Command Prompt. /validate only checks whether disk 0 can be converted; /convert checks again and converts. /allowFullOS lets the tool run inside Windows instead of Windows PE, where it creates a new EFI system partition by shrinking the Windows partition.

Advertisement

You should see: "Validation completed successfully" after the first line, and a successful conversion message after the second. Then restart into the firmware, switch the boot mode to UEFI, and enable Secure Boot; the converted disk will not boot in Legacy mode.

Return code 6 means an encrypted volume blocked the conversion, and 7 means the disk layout does not meet the requirements. Logs are written to %windir% as setupact.log and setuperr.log.

How To Enter UEFI Firmware Settings From Windows 11

This is the route to use when you cannot catch the startup key. It works on every brand of PC that boots in UEFI mode.

  1. Select Start, then the Power button.
  2. Hold Shift and select Restart. Keep holding until the blue Choose an option screen appears.
  3. Select Troubleshoot.
  4. Select Advanced options.
  5. Select UEFI Firmware Settings, then Restart.

If UEFI Firmware Settings is missing from Advanced options, Windows is running in Legacy BIOS mode. Use the manufacturer's startup key instead, and convert the disk before switching to UEFI.

Brand-Specific Pointers

Menu names differ by manufacturer, and Microsoft links to each maker's own instructions. Where the table lists only the link, follow the maker's page for the exact menu.

Brand How to open the firmware Where Secure Boot is
ASUS motherboards Press Delete at power-on, then switch to Advanced Mode Boot > Secure Boot: set OS Type to Windows UEFI mode (the default Other OS leaves Secure Boot off)
Microsoft Surface Hold Volume Up, press and release Power Security page > Secure Boot (Surface UEFI guide)
Dell Settings route above, or the startup key Dell: enable Secure Boot
HP Settings route above, or the startup key HP: Secure Boot
Lenovo Settings route above, or the startup key Lenovo: Secure Boot
GIGABYTE motherboards Settings route above, or the startup key GIGABYTE FAQ 3918
MSI, Acer and others Settings route above, or the key shown at startup Usually the Security, Boot or Authentication tab; check the maker's support site

On ASUS boards, Secure Boot State is greyed out by design: it simply reports whether keys are installed. User means keys are present; Setup means no keys, so Secure Boot stays off until you restore the default keys.

Confirm Secure Boot Is Enabled In Windows 11

Check from inside Windows after the restart. The firmware menu saying Enabled is not proof on its own, because missing keys can keep it inactive.

  1. Open System Information (msinfo32) and confirm Secure Boot State reads On and BIOS Mode reads UEFI.
  2. Open an elevated PowerShell and run Confirm-SecureBootUEFI; it should return True.
  3. Open Windows Security, select Device security, and look for the Secure Boot section.
  4. Read the text next to the badge. Green with "Secure Boot is on and all required certificate updates have been applied" means fully updated; yellow or red means an action is recommended or needed.

A green checkmark alone does not confirm the 2023 certificates are installed; the text beside it does.

Windows Security app Device security page with Secure boot status
This message confirms Secure boot is on and blocking unsigned software during startup. (Image: Microsoft)

Secure Boot And Gaming Anti-Cheat Requirements

Some kernel-level anti-cheat systems check Secure Boot before a game will launch. The fix is the same firmware change described above.

Game or system What you see What it means
Valorant (Riot Vanguard) Error VAN 9003 Riot states that Secure Boot is not enabled and Vanguard requires it
Riot Vanguard, other errors VAN 9001 or VAN: STATUS_SB_POLICY Look up the exact code on Riot's Vanguard error page before changing firmware
Any game that reports Secure Boot is off A launch error naming Secure Boot Check msinfo32 first; if Secure Boot State is Off, enable it in the firmware

Secure Boot And Dual-Boot Systems

Microsoft notes that Linux, earlier versions of Windows and some graphics cards may need Secure Boot turned off. Plan the boot order before you flip the switch.

Setup What to expect with Secure Boot on What to do
Windows 11 plus a Linux distribution with a signed boot loader Both can start Check your distribution's documentation for Secure Boot support
Windows 11 plus Linux with an unsigned loader Linux fails to start Keep Secure Boot off only while you need that system, or switch to a signed loader
Windows 11 plus Windows 7 or another Legacy/MBR install The Legacy install will not start in UEFI mode Choose one mode; Secure Boot requires UEFI
Windows 11 virtual machine in Hyper-V Windows 11 VMs need Secure Boot and TPM enabled in the VM settings Enable both on the VM, not on the host firmware

More on the VM side: Windows 11 virtual machines now require TPM 2.0 and Secure Boot.

How to disable Secure Boot in Windows 11

Turn it off only for a specific reason, such as installing hardware or an operating system that is not compatible, and turn it back on afterwards.

  1. Check Windows Update and your manufacturer's site first; updated trust lists may make disabling unnecessary.
  2. Hold Shift and select Restart, then go to Troubleshoot > Advanced options > UEFI Firmware Settings.
  3. Find Secure Boot on the Security, Boot or Authentication tab.
  4. Set it to Disabled.
  5. Save changes and exit. The PC restarts.

Microsoft warns that after disabling Secure Boot and installing other software or hardware, you may need to restore the PC to its factory state before Secure Boot can be turned on again.

Things to Do Before Touching BIOS

The firmware menu is built for advanced users, and one wrong setting can stop the PC starting. These habits make every change reversible.

  1. Save your BitLocker recovery key and confirm you can open https://aka.ms/myrecoverykey from a phone or another PC.
  2. Photograph the current Boot and Security pages so you can put every value back.
  3. Change one setting at a time, save, and test that Windows starts before changing the next.
  4. Note the firmware key for your PC, so you can get back in if Windows will not start.
  5. Follow your manufacturer's instructions exactly for anything beyond the Secure Boot and boot-mode switches.

What to Do When Secure Boot Is Greyed Out

The Secure Boot option cannot be selected

The firmware is in Legacy or CSM mode, which cannot use Secure Boot.

  1. Confirm the Windows disk is GPT; convert it with mbr2gpt if it is MBR.
  2. In the firmware, set boot mode to UEFI and disable CSM (Compatibility Support Module).
  3. Save, re-enter the firmware, and set Secure Boot to Enabled.

Secure Boot State is grey and shows Setup

No Secure Boot keys are installed, so the firmware is in setup mode.

  1. On the Secure Boot page, choose Custom (or key management) and load the factory default keys.
  2. On ASUS boards, set OS Type to Windows UEFI mode; the grey Secure Boot State then changes to User.
  3. If no key option exists, reset the firmware to factory settings and try again.

Fix: Windows Will Not Boot After Enabling Secure Boot

The PC loops, shows a boot error or stops at the firmware logo

A boot loader, graphics card or driver is not signed with a trusted key.

  1. Open the firmware menu with the startup key.
  2. Set Secure Boot to Disabled, save, and confirm Windows starts.
  3. Remove or update the incompatible hardware or operating system.
  4. Re-enable Secure Boot and test again.

Windows asks for a BitLocker recovery key

BitLocker saw the boot configuration change.

  1. Note the first 8 digits of the recovery key ID on the screen.
  2. On another device, open https://aka.ms/myrecoverykey and sign in with the Microsoft account used on the PC.
  3. Type the 48-digit key that matches the ID. Work devices store it with the organization's IT team.

No bootable devices found in Windows 11

"No bootable device" right after switching to UEFI or enabling Secure Boot

Windows was installed in Legacy mode on an MBR disk, and a UEFI-only firmware cannot start it.

  1. Enter the firmware and switch back to Legacy/CSM so Windows starts again.
  2. In Windows, run mbr2gpt /validate /disk:0 /allowFullOS from an elevated Command Prompt.
  3. If validation passes, run mbr2gpt /convert /disk:0 /allowFullOS.
  4. Restart into the firmware, set boot mode to UEFI, then enable Secure Boot.

Acer Security Boot Fail error in Windows 11

A Secure Boot failure or violation message at power-on

The firmware blocked a boot loader or device that is not signed with a trusted key, or the key databases were changed.

  1. Disconnect USB drives and recently added hardware, then restart.
  2. Open the firmware with the startup key and confirm the boot mode is UEFI.
  3. If another operating system caused it, set Secure Boot to Disabled, start the system, and remove or update that loader.
  4. Load the factory default Secure Boot keys or reset the firmware to defaults, then enable Secure Boot again.
  5. If the error remains, contact Acer support; the firmware may need an update.

UEFI2023Status stuck at In Progress or Not Started

This value tracks Microsoft's 2023 Secure Boot certificate update. It lives under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing as UEFICA2023Status, with the values NotStarted, InProgress and Updated.

UEFICA2023Status stays NotStarted

The device is not eligible yet: Secure Boot is off, updates are missing, or the update task is not running.

  1. Confirm Secure Boot is on with Confirm-SecureBootUEFI.
  2. Install all pending updates from Windows Update and restart.
  3. In an elevated PowerShell, run schtasks.exe /Query /TN "\Microsoft\Windows\PI\Secure-Boot-Update" /FO LIST /V and confirm Status reads Ready.
  4. Leave the PC on; the task runs at startup and every 12 hours.

UEFICA2023Status stays InProgress

A step failed and is being retried, or the boot manager update is waiting for a restart.

  1. Restart the PC; the boot manager step may not finish until after a restart.
  2. Check UEFICA2023Error in the same key. A non-zero value means a step failed.
  3. In Event Viewer, check the System log for Secure Boot events. Events 1032, 1795, 1796 and 1802 point to firmware limits; 1803 means the manufacturer's signed key is missing.
  4. Install the latest firmware (BIOS/UEFI) update from your PC maker, then let the task retry.
  5. Check Windows Security > Device security > Secure Boot for a paused or hardware-limitation message.

Still Not Working?

Why can't I enable Secure Boot on Windows 11?

The firmware refuses the setting, often because of old firmware, cleared keys or a changed configuration.

  1. Reset the firmware to factory settings and try again.
  2. Update the firmware from your PC maker's support site.
  3. As a last resort, Microsoft suggests a refresh or Remove everything reset to return the PC to its original state.
  4. If none of that works, contact the manufacturer.

Frequently Asked Questions

How do I enable Secure Boot on Windows 10?

The process matches Windows 11. Hold Shift while selecting Restart, go to Troubleshoot > Advanced options > UEFI Firmware Settings, and set Secure Boot to Enabled on the firmware's Security, Boot or Authentication tab. The PC must boot in UEFI mode from a GPT disk.

Is enabling Secure Boot different on Windows 11 Pro?

No. Secure Boot is a firmware setting, so the steps are identical on Windows 11 Home and Pro. Windows only restarts you into the firmware menu through Advanced startup; the switch itself belongs to the PC's UEFI firmware on either edition.

How do I enable Secure Boot on an ASUS motherboard?

Press Delete at power-on, switch to Advanced Mode, and open Boot > Secure Boot. Change OS Type from Other OS to Windows UEFI mode, then save and exit. The greyed-out Secure Boot State line only reports status and cannot be changed directly.

How do I enable Secure Boot on Gigabyte, MSI, HP or Lenovo PCs?

Use Settings > System > Recovery > Advanced startup > Restart now, then Troubleshoot > Advanced options > UEFI Firmware Settings. Look for Secure Boot on the Security, Boot or Authentication tab. Menu names vary, so follow the maker's own support page for the exact labels.

How do I enable Secure Boot for Valorant?

Riot's error VAN 9003 means Secure Boot is not enabled, and Vanguard requires it. Confirm the PC boots in UEFI mode from a GPT disk, enable Secure Boot in the firmware, restart, and check that msinfo32 shows Secure Boot State: On before launching the game.

A game like Fortnite says Secure Boot is off. What do I do?

Open msinfo32 and read Secure Boot State. If it says Off, enable it in the firmware with the steps in this guide. If it says Unsupported, the PC is in Legacy mode, so convert the disk to GPT and switch to UEFI first.

Why can't I enable Secure Boot on Windows 11?

The usual causes are Legacy/CSM boot mode, an MBR system disk, or missing Secure Boot keys. Switch the firmware to UEFI, convert the disk with MBR2GPT, and load the factory default keys. If the option stays locked, reset the firmware to defaults or update it.

Can I enable Secure Boot without entering the BIOS?

No. Secure Boot is switched on only in the UEFI firmware menu. Windows can restart you straight into that menu through Advanced startup, and PowerShell's Confirm-SecureBootUEFI can check the state, but neither turns it on for you.

Can I disable Secure Boot in Windows 11?

Yes. Open UEFI Firmware Settings through Advanced startup, set Secure Boot to Disabled, and save. Microsoft recommends turning it back on once the issue is solved, and warns that turning it back on later may require a factory reset.

Will enabling Secure Boot delete my files?

No. Turning Secure Boot on changes a firmware setting and does not touch your files. Converting the disk with MBR2GPT also keeps data, but back up first and save your BitLocker recovery key in case the change triggers the recovery screen.

Do I need TPM 2.0 as well as Secure Boot for Windows 11?

Yes. Windows 11 requires TPM 2.0 and UEFI firmware that is Secure Boot capable. Secure Boot capability is the hard requirement for the upgrade; turning it on is recommended for protection against boot-level malware.

Should You Leave Secure Boot Enabled?

Yes. Leave Secure Boot on permanently unless a specific piece of hardware or another operating system needs it off, and switch it back on when that need ends. Secure Boot blocks rootkits that load before Windows, and Microsoft's own guidance says disabling it leaves a device less secure than keeping it on, even when the 2023 certificate update cannot be installed.

Philip Celasco

Philip is a Texas-based technology writer and IT administrator at Techdows.com with more than 10 years of experience creating practical content for everyday users and professionals. He specializes in web browsers, particularly Chromium-based platforms such as Google Chrome, Microsoft Edge, Brave, and Opera. Through his work as an IT administrator, Philip has hands-on experience managing devices, configuring browser policies, troubleshooting software and network issues, and helping people resolve problems that affect productivity and security. His articles are based on practical testing and real-world technical experience. He covers browser settings, extensions, performance problems, privacy controls, security features, and Windows troubleshooting. Outside work, Philip enjoys the quieter side of life in Texas and stepping away from the screen when he can. He has two kids, two cats and loves to play golf with his mother during the weekends.

Leave a Reply

Your email address will not be published. Required fields are marked *