Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Secure Boot is turned on in your PC’s UEFI firmware, not in a regular Windows setting. First check msinfo32: if BIOS Mode is UEFI and Secure Boot State is Off, you can usually enable it in firmware. If BIOS Mode says Legacy, do not switch to UEFI blindly—your existing Windows installation may stop booting.
Check Secure Boot before changing anything
- Press the Windows key, type
msinfo32, and open System Information. - In System Summary, check BIOS Mode and Secure Boot State.
| BIOS Mode | Secure Boot State | What to do |
|---|---|---|
| UEFI | On | Secure Boot is already active. |
| UEFI | Off | Firmware is using the right boot mode; proceed to enable Secure Boot. |
| Legacy | Off or unavailable | Pause. Determine whether Windows can be converted safely or needs reinstalling before changing boot mode. |
| UEFI | Unsupported or unavailable | Check firmware settings, device support, and available BIOS/UEFI updates. |
Secure Boot validates boot-time software against cryptographic keys trusted by UEFI firmware. It helps prevent unauthorized bootloaders and other untrusted code from running before the operating system starts; it does not encrypt your drive, replace antivirus, or stop all malware. Microsoft explains Secure Boot and its relationship to Windows.
Before enabling it: protect access to your PC
- Save your work and back up important files.
- If BitLocker or Windows Device Encryption is enabled, locate and save your recovery key somewhere you can access without this PC. Firmware or boot changes can trigger a recovery prompt. Follow your manufacturer’s instructions about suspending protection; do not disable encryption automatically without a reason.
- Note the current boot mode and any nonstandard firmware settings. If you dual-boot, use custom boot software, or rely on unsigned kernels or drivers, check compatibility first.
- Check Windows Update and your PC or motherboard manufacturer’s support page for relevant firmware updates. Install only firmware intended for your exact model.
The risk that matters most is switching an existing Legacy installation to UEFI without preparation. That can make Windows unbootable; what is needed to recover depends on the installation and disk layout. Dell warns of this risk, and Microsoft discusses the Legacy/CSM and UEFI considerations.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Open UEFI firmware settings from Windows
On Windows 11, open Settings > System > Recovery. Under Advanced startup, select Restart now. Then choose:
#1 Best Overall
- AMD Socket AM4: Ready to support AMD Ryzen 5000 / Ryzen 4000 / Ryzen 3000 Series processors
- Enhanced Power Solution: Digital twin 10 plus3 phases VRM solution with premium chokes and capacitors for steady power delivery.
- Advanced Thermal Armor: Enlarged VRM heatsinks layered with 5 W/mk thermal pads for better heat dissipation. Pre-Installed I/O Armor for quicker PC DIY assembly.
- Boost Your Memory Performance: Compatible with DDR4 memory and supports 4 x DIMMs with AMD EXPO Memory Module Support.
- Comprehensive Connectivity: WIFI 6, PCIe 4.0, 2x M.2 Slots, 1GbE LAN, USB 3.2 Gen 2, USB 3.2 Gen 1 Type-C
Troubleshoot > Advanced options > UEFI Firmware Settings > Restart
You can also hold Shift while selecting Restart, then follow the same Troubleshoot path. If Windows cannot reach these settings, restart the PC and immediately press the firmware setup key shown by the manufacturer. Common examples include F1, F2, F12, or Esc, but the correct key varies by model. Microsoft’s Windows instructions note that firmware labels and layouts differ.
Rank #2
- Supports 12th/13th Gen Intel Core, Pentium Gold and Celeron processors for LGA 1700 socket
- Supports DDR4 Memory, Dual Channel DDR4 5333+MHz (OC)
- Enhanced Power Design: 12+1 Duet Rail Power System with P-PAK, 8-pin + 4-pin CPU power connectors, Core Boost, Memory Boost
- Premium Thermal Solution: Extended Heatsink, MOSFET thermal pads rated for 7W/mK, additional choke thermal pads and M.2 Shield Frozr are built for high performance system and non-stop gaming experience
- High Quality PCB: 6-layer PCB made by 2oz thickened copper and server grade level material
Enable Secure Boot in UEFI
Firmware menus vary, so treat these as the general steps rather than a universal menu path:
Free tools Windows power users keep installed
One-click scans. No signup required.
- Look under Boot, Security, or Authentication for boot mode and Secure Boot controls.
- If Windows is already installed in UEFI mode, make sure boot mode is set to UEFI. If Legacy or CSM is enabled, do not change it until you have established that the existing Windows installation supports the change.
- Set Secure Boot to Enabled. The setting may instead be named Secure Boot Control, or depend on choosing Windows UEFI Mode or an equivalent operating-system type.
- If the firmware says Secure Boot keys are missing, look for an option such as Install default Secure Boot keys or Restore factory keys. Use it only when the manufacturer’s instructions call for it. Do not clear keys as a routine enabling step.
- Save changes and exit, using the on-screen Save, Apply, or Save and Exit command.
Common labels include OS Type, Legacy Support, CSM, and Key Management. If a setting is missing or greyed out, see the troubleshooting section below rather than guessing at key-management options.
Rank #3
- AMD Socket AM4: Ready to support AMD Ryzen 5000/4000/3000 Series Processors
- Enhanced Power Solution: Digital 3+3 VRM Design and premium chokes and capacitors for steady power delivery.
- Advanced Thermal Armor: Chipset heatsinks for better heat dissipation.
- Boost Your Memory: Compatible with DDR4 and supports 4 DIMMS with Extreme Memory Profile support.
- Comprehensive Connectivity: 1x Ultra Durable PCIe 4.0 x16 slot, 1x PCIe 4.0 M.2 slot, 1x PCIe 3.0 M.2 slot, 4x USB 3.2 Gen 1 ports for hassle-free setup.
Examples from common manufacturers
- Dell: Restart and tap F2 at the Dell logo. Boot mode and Secure Boot controls are commonly found under Boot or Boot Sequence. Select UEFI only when appropriate for the installed operating system; save changes. Exact screens vary. See Dell’s model guidance.
- HP: Windows Advanced Startup can open firmware settings. In firmware, look for UEFI and Legacy Support options; labels and startup keys vary. See HP’s support guidance.
- Lenovo: BIOS menus differ among models. Follow the instructions for your exact model in Lenovo’s Secure Boot support information.
- ASUS: A common location resembles Advanced > Boot > Secure Boot, but the layout varies. See ASUS’s instructions, especially before changing keys or certificates.
Verify that it is on
After Windows restarts, open msinfo32 again. In System Summary, confirm:
- BIOS Mode: UEFI
- Secure Boot State: On
Secure Boot capability, Secure Boot being enabled, and meeting every Windows 11 requirement are not the same thing. Turning this setting on does not by itself establish that a PC meets all Windows 11 eligibility requirements.
Rank #4
- AM4 socket: Ready for AMD Ryzen 3000 and 5000 series, plus 5000 and 4000 G-series desktop processors.Bluetooth v5.2
- Best gaming connectivity: PCIe 4.0-ready, dual M.2 slots, USB 3.2 Gen 2 Type-C, plus HDMI 2.1 and DisplayPort 1.2 output
- Smooth networking: On-board WiFi 6E (802.11ax) and Intel 2.5 Gb Ethernet with ASUS LANGuard
- Robust power solution: 12+2 teamed power stages with ProCool power connector, high-quality alloy chokes and durable capacitors
- Renowned software: Bundled 60 days AIDA64 Extreme subscription and intuitive UEFI BIOS dashboard
If Secure Boot is missing, unavailable, or still off
- Check BIOS Mode again. If it says Legacy, stop before changing modes; investigate the installation and disk layout or consult the PC manufacturer.
- Look for CSM or Legacy Support. These compatibility modes can prevent Secure Boot from being available. Do not disable them until you know the installed system can boot in UEFI mode.
- Check the operating-system mode. Some firmware requires a setting such as Windows UEFI Mode rather than a generic or custom OS mode.
- Check whether standard keys are enrolled. If the firmware reports that keys are missing, follow the manufacturer’s directions for restoring default keys. Key changes can affect a custom trust setup.
- Check model support and firmware updates. Some older systems do not support Secure Boot, while others need a firmware update. Use the support page for the exact PC or motherboard.
- Save and verify again. Confirm the firmware change was saved, restart, and check the state in
msinfo32.
If a work or school administrator manages the PC, firmware settings may be locked by policy; contact the administrator rather than trying to bypass the controls.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →If Windows will not boot after enabling it
Use this as a temporary recovery step, not as the final fix:
Best Value
- AMD Socket AM5: Supports AMD Ryzen 9000/Ryzen 8000/Ryzen 7000 Series Processors
- DDR5 Compatible: 4 SMD DIMMs with AMD EXPO and Intel XMP Memory Module Support
- Unparalleled Performance: 12 plus2 plus2 Phases Digital VRM Solution
- Advanced Thermal Design and M.2 Thermal Guard: To Ensure VRM Power Stability and M.2 SSD Performance
- Stable Connectivity: 1 x PCIe 5.0 plus 2 x PCIe 4.0 M.2, USB 3.2 Gen 2x2 Type-C
- Power on and re-enter UEFI firmware.
- Temporarily set Secure Boot to Disabled, then save and restart.
- If Windows starts, check the installation’s boot mode and investigate incompatible or unsigned boot components. Update firmware and compatible boot software before trying to enable Secure Boot again.
- If the PC still will not boot, or asks for a BitLocker recovery key, use the recovery key or contact the manufacturer or your organization’s support team.
Microsoft recommends disabling Secure Boot again if a system cannot boot after the change, then contacting the manufacturer if the problem continues. See its Secure Boot guidance.
Linux, dual boot, and custom kernels
Secure Boot does not automatically rule out Linux. Ubuntu documents a signed boot chain using a Microsoft-signed shim, Canonical-signed GRUB, signed kernels, and signed kernel modules. Compatibility and procedures vary by distribution and release. See Ubuntu’s Secure Boot documentation.
Custom kernels and some third-party modules may need signing. Ubuntu’s Machine Owner Key (MOK) process can enroll a key used to sign modules, but enrolling a key changes what the machine trusts. Understand the source and purpose of a key before enrolling it. If a dual-boot system uses an unsigned or otherwise unsupported bootloader, enabling Secure Boot may prevent that system from starting. Check the distribution’s documentation before changing firmware settings.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Secure Boot certificates: a 2026 consideration
Microsoft says certificates issued in 2011 begin expiring from June 2026. Supported systems may receive updated Secure Boot certificates through Windows updates, while some devices may also need an OEM firmware update. Keep Windows and manufacturer firmware updates current, and consult your PC maker’s guidance for your model. ASUS describes its supported-device certificate update process and warns that firmware or certificate changes can trigger a BitLocker recovery prompt. This is separate from the basic task of switching Secure Boot on; do not run vendor-specific key or PowerShell procedures unless the manufacturer says they apply to your device.
Quick Recap
Quick decision guide
| Your situation | Recommended next step |
|---|---|
| UEFI mode; Secure Boot is Off | Enable it in firmware, save, restart, and verify in msinfo32. |
| Legacy mode | Do not switch blindly. Assess a safe conversion or reinstall path for this installation. |
| Secure Boot setting missing or greyed out | Check CSM, OS mode, keys, firmware updates, and device support using the exact-model manual. |
| Windows will not boot after enabling | Temporarily disable Secure Boot in firmware, then investigate the incompatible boot component or boot mode. |
| Ubuntu or another supported Linux distribution | Check that distribution’s Secure Boot and signing guidance; Secure Boot may be usable without disabling it. |
| Custom kernel, bootloader, or unsigned module | Confirm signing and trust-key requirements before enabling Secure Boot. |
| BitLocker or Device Encryption is active | Locate the recovery key before firmware changes and follow the manufacturer’s update guidance. |
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

