October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
Redmond desk4 min

How to Enable Secure Boot on a Windows 11 PC

Use Windows 11 Advanced startup to open UEFI firmware, check boot mode, enable Secure Boot, and verify the result without guessing at vendor-specific menus.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To enable Secure Boot, open your PC’s UEFI firmware settings, make sure it is configured to start in UEFI mode, turn on Secure Boot, and save the change. In Windows 11, go to Settings > System > Recovery > Advanced startup > Restart now, then choose Troubleshoot > Advanced options > UEFI Firmware Settings > Restart. Firmware menus differ by manufacturer and model, so check the computer maker’s instructions before changing boot settings.

Before you change firmware settings

Secure Boot is a UEFI firmware feature. During startup, the firmware checks signatures on boot software, including firmware drivers and the operating system; when the signatures are valid, startup proceeds. Microsoft describes it as a way to help ensure a PC boots using trusted software: Secure Boot overview.

As an Amazon Associate I earn from qualifying purchases.

Firmware changes can prevent a computer from starting if the wrong setting is changed. Identify your PC or motherboard model and consult the manufacturer’s support instructions before changing boot mode or Secure Boot keys. Pay particular attention to whether the current Windows installation supports UEFI startup.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check the current boot mode and Secure Boot state

On many Windows PCs, open System Information by pressing Windows + R, entering msinfo32, and pressing Enter. Check the BIOS Mode and Secure Boot State entries. This is a practical way to see whether the PC is already using UEFI and whether Secure Boot is on; labels or availability can vary by Windows version and system.

Open UEFI firmware settings from Windows 11

  1. Open Settings > System > Recovery.
  2. Under Advanced startup, select Restart now.
  3. At the recovery screen, choose Troubleshoot > Advanced options > UEFI Firmware Settings.
  4. Select Restart to open the firmware setup.

Microsoft documents this route and notes that device-specific firmware instructions come from the PC manufacturer: Windows 11 and Secure Boot. If UEFI Firmware Settings does not appear, use the manufacturer’s instructions to enter firmware setup. Another general route is to hold Shift while selecting Restart, then choose Troubleshoot > Advanced options > UEFI Firmware Settings. Some PCs also use a startup key such as F1, F2, F12, or Esc; the correct key depends on the device. See Microsoft’s firmware settings guidance.

Switch to UEFI mode if the PC uses Legacy or CSM

In the firmware setup, look for a boot mode, Legacy, or CSM setting. Secure Boot requires UEFI; Microsoft says the system may need to be configured to boot in UEFI mode, with UEFI first or as the only boot option. The setting’s name and location vary.

Rank #2
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.

Do not switch from Legacy/CSM to UEFI blindly. A Windows installation configured for Legacy startup may not boot after a mode change. Follow the instructions for your exact PC or motherboard model and confirm the operating system installation supports UEFI before proceeding. Microsoft’s Windows 11 Secure Boot guidance explains the UEFI requirement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Enable Secure Boot and save the change

  1. In firmware setup, look for Secure Boot. It may be under Security, Boot, or Authentication.
  2. Set Secure Boot to Enabled. Some firmware may require selecting Standard mode or loading built-in or factory Secure Boot keys first. Do not manually replace keys unless the manufacturer’s instructions specifically call for it.
  3. Save the firmware changes and exit. The computer should restart into Windows.

Menu labels and key-enrollment requirements depend on the manufacturer and model. Microsoft’s firmware settings guidance recommends consulting the device maker for exact steps.

Rank #3

Confirm Secure Boot is enabled

After Windows starts, reopen System Information with msinfo32 and check Secure Boot State. If it reports On, Secure Boot is enabled. If it reports Off or is unavailable, the firmware setting may not have been saved, the system may still be in Legacy/CSM mode, or the PC may require a model-specific setup step. Check the manufacturer’s instructions rather than changing unrelated firmware options.

Troubleshoot Secure Boot problems

Secure Boot is greyed out or unavailable

Check whether the PC is in UEFI mode and whether Legacy/CSM boot is enabled. The firmware may also require a particular Secure Boot mode or built-in keys. Exact remedies differ by model; consult its official support instructions before changing settings.

Rank #4
15.6 Inch Laptop Computer, N4020, 4GB DDR4 RAM, 128GB eMMC,with Windows 11
  • EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
  • 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
  • RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
  • ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
  • LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.

The UEFI Firmware Settings option is missing

Use the computer maker’s instructions to enter firmware setup. Startup keys vary, and Microsoft’s examples include F1, F2, F12, and Esc. There is no universal key or firmware menu path.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The PC will not start after the change

Return to firmware setup and disable Secure Boot to test whether the previous boot configuration starts again. Microsoft also identifies restoring firmware defaults as a possible remedy if Secure Boot cannot be enabled; that reset can affect other firmware settings, so follow the manufacturer’s recovery instructions. Contact the manufacturer if the computer still will not boot.

Best Value
Windows 11 Laptop with i3 Processor 15.6" Work Laptop for College Students
  • 【Efficient Performance】 Powered by Intel Core i3 processor (2 cores, 4 threads, up to 3.4GHz) with 12GB RAM and 256GB SSD. Handles multitasking, office software, online classes, and HD video streaming smoothly. Integrated Intel UHD Graphics 620
  • Backlit Keyboard & Complete Package】Comes with a cool backlit keyboard. Comes with awebcam, dual stereo speakers (8Ω/1.0W each), DC charger, and user manual – ready for late-night studying, online classes, video conferencing, and daily productivity
  • 【Vibrant Display】 15.6-inch Full HD (1920x1080) anti-glare screen with 16:9 aspect ratio delivers crisp images and vivid colors – perfect for studying, watching lectures, or entertainment. Thin-bezel design maximizes viewing area
  • 【Fast Connectivity & Expansion】 Equipped with WiFi 6 (802.11ax) and Bluetooth 5.2 for stable, high-speed wireless. Features 3 x USB 3.0, HDMI 2.1, Type-C (supports PD3.0 fast charging), and a TF card slot expandable up to 2TB – easily connect external monitors, mice, drives, or expand storage for all your files
  • 【Long Battery Life & Portable】 Built-in 11.55V 5000mAh/57.75Wh high-capacity battery delivers approximately 7 hours of mixed-use battery life – enough for a full day of classes and assignments. Lightweight at just 1.63kg (3.6 lbs) and 19.5mm thin, plus a compact packing size – easily slips into a backpack for campus, library, or coffee shop

A device or operating system stops working

Some graphics cards, hardware, or operating-system configurations may require Secure Boot to be disabled. Check compatibility and the device maker’s instructions before deciding whether to turn it off; do not change other boot settings as a workaround without understanding their effect.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Secure Boot capability is not the same as being enabled

Microsoft distinguishes a PC that supports Secure Boot from one with the feature turned on. Its Windows 11 upgrade eligibility guidance calls for Secure Boot capability with UEFI/BIOS enabled; turning Secure Boot on is a separate security improvement. See Microsoft’s Windows 11 and Secure Boot information.

There is also a current certificate update separate from the steps above. Microsoft says certificates issued in 2011 begin expiring in June 2026 and that it is updating certificates so Windows devices can continue to verify trusted boot software. Supported Windows devices receive the update automatically, according to Microsoft’s Windows 11 support page. This does not mean ordinary users should manually replace Secure Boot keys as part of enabling the feature. Read Microsoft’s Secure Boot overview and Windows 11 Secure Boot guidance for details.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

Bestseller No. 1
Bestseller No. 2
Dell Latitude 5420 14' FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
256 GB SSD of storage.; Multitasking is easy with 16GB of RAM; Equipped with a blazing fast Core i5 2.00 GHz processor.
$285.00
Bestseller No. 3
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
$245.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.