Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Secure Boot is turned on in your PC’s UEFI firmware, not in a regular Windows setting. First check msinfo32: if BIOS Mode is UEFI and Secure Boot State is Off, you can usually enable it in firmware. If BIOS Mode says Legacy, do not switch to UEFI blindly—your existing Windows installation may stop booting.

Check Secure Boot before changing anything

  1. Press the Windows key, type msinfo32, and open System Information.
  2. In System Summary, check BIOS Mode and Secure Boot State.
BIOS Mode Secure Boot State What to do
UEFI On Secure Boot is already active.
UEFI Off Firmware is using the right boot mode; proceed to enable Secure Boot.
Legacy Off or unavailable Pause. Determine whether Windows can be converted safely or needs reinstalling before changing boot mode.
UEFI Unsupported or unavailable Check firmware settings, device support, and available BIOS/UEFI updates.

Secure Boot validates boot-time software against cryptographic keys trusted by UEFI firmware. It helps prevent unauthorized bootloaders and other untrusted code from running before the operating system starts; it does not encrypt your drive, replace antivirus, or stop all malware. Microsoft explains Secure Boot and its relationship to Windows.

Before enabling it: protect access to your PC

  • Save your work and back up important files.
  • If BitLocker or Windows Device Encryption is enabled, locate and save your recovery key somewhere you can access without this PC. Firmware or boot changes can trigger a recovery prompt. Follow your manufacturer’s instructions about suspending protection; do not disable encryption automatically without a reason.
  • Note the current boot mode and any nonstandard firmware settings. If you dual-boot, use custom boot software, or rely on unsigned kernels or drivers, check compatibility first.
  • Check Windows Update and your PC or motherboard manufacturer’s support page for relevant firmware updates. Install only firmware intended for your exact model.

The risk that matters most is switching an existing Legacy installation to UEFI without preparation. That can make Windows unbootable; what is needed to recover depends on the installation and disk layout. Dell warns of this risk, and Microsoft discusses the Legacy/CSM and UEFI considerations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Open UEFI firmware settings from Windows

On Windows 11, open Settings > System > Recovery. Under Advanced startup, select Restart now. Then choose:

#1 Best Overall
Sale
GIGABYTE B550 Eagle WIFI6 AMD AM4 ATX Motherboard, Supports Ryzen 5000/4000/3000 Processors, DDR4, 10+3 Power Phase, 2X M.2, PCIe 4.0, USB-C, WIFI6, GbE LAN, PCIe EZ-Latch, EZ-Latch, RGB Fusion
  • AMD Socket AM4: Ready to support AMD Ryzen 5000 / Ryzen 4000 / Ryzen 3000 Series processors
  • Enhanced Power Solution: Digital twin 10 plus3 phases VRM solution with premium chokes and capacitors for steady power delivery.
  • Advanced Thermal Armor: Enlarged VRM heatsinks layered with 5 W/mk thermal pads for better heat dissipation. Pre-Installed I/O Armor for quicker PC DIY assembly.
  • Boost Your Memory Performance: Compatible with DDR4 memory and supports 4 x DIMMs with AMD EXPO Memory Module Support.
  • Comprehensive Connectivity: WIFI 6, PCIe 4.0, 2x M.2 Slots, 1GbE LAN, USB 3.2 Gen 2, USB 3.2 Gen 1 Type-C

Troubleshoot > Advanced options > UEFI Firmware Settings > Restart

You can also hold Shift while selecting Restart, then follow the same Troubleshoot path. If Windows cannot reach these settings, restart the PC and immediately press the firmware setup key shown by the manufacturer. Common examples include F1, F2, F12, or Esc, but the correct key varies by model. Microsoft’s Windows instructions note that firmware labels and layouts differ.

Rank #2
Sale
MSI PRO B760-P WiFi DDR4 ProSeries Motherboard - Supports 12th/13th/14th Gen Intel Processors, LGA 1700, DDR4, PCIe 4.0, M.2, 2.5Gbps LAN, USB 3.2 Gen2, HDMI/DP, Wi-Fi 6E, Bluetooth 5.3, ATX
  • Supports 12th/13th Gen Intel Core, Pentium Gold and Celeron processors for LGA 1700 socket
  • Supports DDR4 Memory, Dual Channel DDR4 5333+MHz (OC)
  • Enhanced Power Design: 12+1 Duet Rail Power System with P-PAK, 8-pin + 4-pin CPU power connectors, Core Boost, Memory Boost
  • Premium Thermal Solution: Extended Heatsink, MOSFET thermal pads rated for 7W/mK, additional choke thermal pads and M.2 Shield Frozr are built for high performance system and non-stop gaming experience
  • High Quality PCB: 6-layer PCB made by 2oz thickened copper and server grade level material

Enable Secure Boot in UEFI

Firmware menus vary, so treat these as the general steps rather than a universal menu path:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Look under Boot, Security, or Authentication for boot mode and Secure Boot controls.
  2. If Windows is already installed in UEFI mode, make sure boot mode is set to UEFI. If Legacy or CSM is enabled, do not change it until you have established that the existing Windows installation supports the change.
  3. Set Secure Boot to Enabled. The setting may instead be named Secure Boot Control, or depend on choosing Windows UEFI Mode or an equivalent operating-system type.
  4. If the firmware says Secure Boot keys are missing, look for an option such as Install default Secure Boot keys or Restore factory keys. Use it only when the manufacturer’s instructions call for it. Do not clear keys as a routine enabling step.
  5. Save changes and exit, using the on-screen Save, Apply, or Save and Exit command.

Common labels include OS Type, Legacy Support, CSM, and Key Management. If a setting is missing or greyed out, see the troubleshooting section below rather than guessing at key-management options.

Rank #3
Sale
GIGABYTE B550M K AMD AM4 Micro-ATX Motherboard, Supports Ryzen 5000/4000/3000 Series Processors, DDR4, 3+3 Power Phase, 2X M.2, PCIe 4.0, USB 3.2 Gen 1, GbE LAN, Q-Flash
  • AMD Socket AM4: Ready to support AMD Ryzen 5000/4000/3000 Series Processors
  • Enhanced Power Solution: Digital 3+3 VRM Design and premium chokes and capacitors for steady power delivery.
  • Advanced Thermal Armor: Chipset heatsinks for better heat dissipation.
  • Boost Your Memory: Compatible with DDR4 and supports 4 DIMMS with Extreme Memory Profile support.
  • Comprehensive Connectivity: 1x Ultra Durable PCIe 4.0 x16 slot, 1x PCIe 4.0 M.2 slot, 1x PCIe 3.0 M.2 slot, 4x USB 3.2 Gen 1 ports for hassle-free setup.

Examples from common manufacturers

  • Dell: Restart and tap F2 at the Dell logo. Boot mode and Secure Boot controls are commonly found under Boot or Boot Sequence. Select UEFI only when appropriate for the installed operating system; save changes. Exact screens vary. See Dell’s model guidance.
  • HP: Windows Advanced Startup can open firmware settings. In firmware, look for UEFI and Legacy Support options; labels and startup keys vary. See HP’s support guidance.
  • Lenovo: BIOS menus differ among models. Follow the instructions for your exact model in Lenovo’s Secure Boot support information.
  • ASUS: A common location resembles Advanced > Boot > Secure Boot, but the layout varies. See ASUS’s instructions, especially before changing keys or certificates.

Verify that it is on

After Windows restarts, open msinfo32 again. In System Summary, confirm:

  • BIOS Mode: UEFI
  • Secure Boot State: On

Secure Boot capability, Secure Boot being enabled, and meeting every Windows 11 requirement are not the same thing. Turning this setting on does not by itself establish that a PC meets all Windows 11 eligibility requirements.

Rank #4
Asus ROG Strix B550-F Gaming WiFi II AMD AM4 (3rd Gen Ryzen) ATX DDR4 Gaming Motherboard (PCIe 4.0,WiFi 6E, 2.5Gb LAN, BIOS Flashback, HDMI 2.1, Addressable Gen 2 RGB Header and Aura Sync)
  • AM4 socket: Ready for AMD Ryzen 3000 and 5000 series, plus 5000 and 4000 G-series desktop processors.Bluetooth v5.2
  • Best gaming connectivity: PCIe 4.0-ready, dual M.2 slots, USB 3.2 Gen 2 Type-C, plus HDMI 2.1 and DisplayPort 1.2 output
  • Smooth networking: On-board WiFi 6E (802.11ax) and Intel 2.5 Gb Ethernet with ASUS LANGuard
  • Robust power solution: 12+2 teamed power stages with ProCool power connector, high-quality alloy chokes and durable capacitors
  • Renowned software: Bundled 60 days AIDA64 Extreme subscription and intuitive UEFI BIOS dashboard

If Secure Boot is missing, unavailable, or still off

  1. Check BIOS Mode again. If it says Legacy, stop before changing modes; investigate the installation and disk layout or consult the PC manufacturer.
  2. Look for CSM or Legacy Support. These compatibility modes can prevent Secure Boot from being available. Do not disable them until you know the installed system can boot in UEFI mode.
  3. Check the operating-system mode. Some firmware requires a setting such as Windows UEFI Mode rather than a generic or custom OS mode.
  4. Check whether standard keys are enrolled. If the firmware reports that keys are missing, follow the manufacturer’s directions for restoring default keys. Key changes can affect a custom trust setup.
  5. Check model support and firmware updates. Some older systems do not support Secure Boot, while others need a firmware update. Use the support page for the exact PC or motherboard.
  6. Save and verify again. Confirm the firmware change was saved, restart, and check the state in msinfo32.

If a work or school administrator manages the PC, firmware settings may be locked by policy; contact the administrator rather than trying to bypass the controls.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If Windows will not boot after enabling it

Use this as a temporary recovery step, not as the final fix:

Best Value
Sale
GIGABYTE B650 Eagle AX AM5 LGA 1718 ATX Motherboard, DDR5, Triple M.2 Slots (1x PCIe 5.0, 2X PCIe 4.0), USB 3.2 Gen2x2 Type-C, WiFi 6E, Realtek GbE LAN
  • AMD Socket AM5: Supports AMD Ryzen 9000/Ryzen 8000/Ryzen 7000 Series Processors
  • DDR5 Compatible: 4 SMD DIMMs with AMD EXPO and Intel XMP Memory Module Support
  • Unparalleled Performance: 12 plus2 plus2 Phases Digital VRM Solution
  • Advanced Thermal Design and M.2 Thermal Guard: To Ensure VRM Power Stability and M.2 SSD Performance
  • Stable Connectivity: 1 x PCIe 5.0 plus 2 x PCIe 4.0 M.2, USB 3.2 Gen 2x2 Type-C
  1. Power on and re-enter UEFI firmware.
  2. Temporarily set Secure Boot to Disabled, then save and restart.
  3. If Windows starts, check the installation’s boot mode and investigate incompatible or unsigned boot components. Update firmware and compatible boot software before trying to enable Secure Boot again.
  4. If the PC still will not boot, or asks for a BitLocker recovery key, use the recovery key or contact the manufacturer or your organization’s support team.

Microsoft recommends disabling Secure Boot again if a system cannot boot after the change, then contacting the manufacturer if the problem continues. See its Secure Boot guidance.

Linux, dual boot, and custom kernels

Secure Boot does not automatically rule out Linux. Ubuntu documents a signed boot chain using a Microsoft-signed shim, Canonical-signed GRUB, signed kernels, and signed kernel modules. Compatibility and procedures vary by distribution and release. See Ubuntu’s Secure Boot documentation.

Custom kernels and some third-party modules may need signing. Ubuntu’s Machine Owner Key (MOK) process can enroll a key used to sign modules, but enrolling a key changes what the machine trusts. Understand the source and purpose of a key before enrolling it. If a dual-boot system uses an unsigned or otherwise unsupported bootloader, enabling Secure Boot may prevent that system from starting. Check the distribution’s documentation before changing firmware settings.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Secure Boot certificates: a 2026 consideration

Microsoft says certificates issued in 2011 begin expiring from June 2026. Supported systems may receive updated Secure Boot certificates through Windows updates, while some devices may also need an OEM firmware update. Keep Windows and manufacturer firmware updates current, and consult your PC maker’s guidance for your model. ASUS describes its supported-device certificate update process and warns that firmware or certificate changes can trigger a BitLocker recovery prompt. This is separate from the basic task of switching Secure Boot on; do not run vendor-specific key or PowerShell procedures unless the manufacturer says they apply to your device.

Quick decision guide

Your situation Recommended next step
UEFI mode; Secure Boot is Off Enable it in firmware, save, restart, and verify in msinfo32.
Legacy mode Do not switch blindly. Assess a safe conversion or reinstall path for this installation.
Secure Boot setting missing or greyed out Check CSM, OS mode, keys, firmware updates, and device support using the exact-model manual.
Windows will not boot after enabling Temporarily disable Secure Boot in firmware, then investigate the incompatible boot component or boot mode.
Ubuntu or another supported Linux distribution Check that distribution’s Secure Boot and signing guidance; Secure Boot may be usable without disabling it.
Custom kernel, bootloader, or unsigned module Confirm signing and trust-key requirements before enabling Secure Boot.
BitLocker or Device Encryption is active Locate the recovery key before firmware changes and follow the manufacturer’s update guidance.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.