Curious how a tiny firmware toggle can stop dangerous code before Windows loads? This short intro shows why enabling secure boot matters now. Many games and enterprise policies demand it, and it blocks untrusted software at early boot so antivirus has nothing malicious to scan.
Follow clear checks that start with status in System Information, confirm GPT partitioning on the install drive, and review BIOS settings. You will also learn which signs mean firmware changes might prevent startup and how to avoid those risks by backing up files and consulting vendor documents.
By the end, you will have a repeatable path: verify current state, meet requirements (UEFI mode, TPM 2.0, GPT), change BIOS options carefully, and confirm final boot status with msinfo32. This approach reduces attack surface and helps launch anti-cheat protected games without surprises.
Key Takeaways
- Secure boot stops untrusted code before the operating system runs.
- Check current state in System Information and confirm GPT on the Windows drive.
- Firmware menus vary; back up data and read vendor support before changing BIOS settings.
- Many EA games and enterprise rules require this trusted software chain.
- Verify status both before and after changes using msinfo32 for confidence.
What Secure Boot Is and Why It Matters Today
Firmware-held keys let your computer refuse altered loaders and unsigned code during early startup. This protects Windows systems by forcing a verified chain of trust from UEFI firmware into the operating kernel.
In plain terms: secure boot is a firmware-backed check that allows only trusted software to run at boot. It cuts off rootkits and low-level malware before drivers and OS services initialize on your device.

How it protects startup from rootkits and untrusted software
The platform validates bootloaders and key components against stored keys. TPM 2.0 often holds that key material so modified loaders fail verification and cannot start.
Result: fewer successful startup compromises and stronger operating integrity across systems where boot is the earliest checkpoint.
Why gamers and enterprises care
Many anti-cheat kernels—Riot Vanguard for Valorant and EA’s Javelin—require secure boot because they must trust that nothing tampered with the kernel earlier in boot.
Enterprises rely on verified boot for policy enforcement and to limit persistent malware that hides below the OS. Because wording in BIOS menus varies by manufacturer, check settings carefully and confirm state with msinfo32 before enabling changes.
For manufacturer-level details, see the OEM secure boot documentation.
Before You Begin: Requirements, Risks, and Prep
Confirm baseline hardware and firmware details now; this reduces the chance of a non-booting computer later. Read this short checklist and gather manuals before changing firmware.
What to verify in Windows
- BIOS Mode: open msinfo32 and check that BIOS Mode reads UEFI. If it shows Legacy, the Windows disk must be GPT before you switch modes.
- TPM: confirm TPM 2.0 with tpm.msc or Windows Device security. If off, enable Intel PTT or AMD fTPM in bios settings.
- Disk layout: use Disk Management to confirm the Windows drive uses GPT, not MBR.

Safe prep and risks
Back up important files, connect AC power, and close apps. Firmware changes and conversions can prevent startup if done out of order.
Manufacturer help and recovery
Keep your device manual or support pages handy. Note firmware hotkeys (often F2 or Del) and how to reset defaults. If hardware lacks TPM 2.0 or other requirements, contact your manufacturer for upgrade paths before you try to enable secure boot.
a step-by-step guide to the secure boot security feature
Begin by confirming current firmware and Windows status so changes stay predictable and reversible. This sequence walks through checks and firmware changes with minimal risk.
-
Check secure boot status in Windows: BIOS Mode and Secure Boot State
Press Windows+R, run msinfo32, and confirm BIOS Mode reads UEFI.
Also note the Secure Boot State line. If it shows Off or Unsupported, continue with the checks below.
-
Verify and enable TPM 2.0 via UEFI firmware settings
Open Device security or run tpm.msc to check the security processor. If TPM is disabled, reboot into UEFI firmware settings (Troubleshoot › Advanced options) and enable Intel PTT or AMD fTPM.
-
Ensure your Windows disk uses GPT and convert if needed
In Disk Management, view Properties › Volumes to see Partition style. If it shows MBR, run an elevated command prompt:
mbr2gpt /validate /disk:<num> /allowfullOS then mbr2gpt /convert /disk:<num> /allowfullOS.
-
Switch firmware mode and disable CSM if present
Enter BIOS (often F2 or Del), open the Boot tab, and disable CSM or Legacy support so the system uses UEFI mode. This change requires a GPT disk and alters startup behavior.
-
Enable secure boot and install keys
In the Boot or Security tab, set Secure Boot to Enabled and set OS type to Windows UEFI mode. If options are unavailable, open Key Management and select Install Default Secure Boot Keys.
-
Save, reboot, and confirm Secure Boot State is On
Save changes (usually F10) and restart. Reopen msinfo32 and check Secure Boot State. Some systems need one extra restart for status to update.

UEFI Firmware Settings and Manufacturer Differences
Firmware menus differ widely across brands, so learn where your model hides key toggles before changing anything. This saves time and prevents mistakes when you need to enable secure boot and TPM options.
Use Windows recovery if you prefer not to nail the boot-timing press.
- Windows path: Settings › Recovery › Advanced startup › Troubleshoot › Advanced options › UEFI Firmware Settings › Restart. This opens firmware without catching a quick key press.
- Direct boot keys: Press F2 or Del at power-on to reach your firmware. Look for a Boot tab or Security Device Support entry in the bios menu.

Labels vary by manufacturer. TPM may appear as Intel PTT or AMD fTPM. Some vendors list a Security Device or Security Device Support toggle rather than TPM.
Major manufacturers—Dell/Alienware, ASRock, Corsair, Gigabyte, Lenovo, HP Omen, ASUS, and MSI—publish model-specific firmware notes and screenshots. Check support pages for exact menu names and key management steps before you make changes.
Quick checklist: confirm BIOS mode equals UEFI, find Secure Boot Enable and OS type entries, and install default keys if a Key Management page is required. Save & Exit and allow a full reboot so new settings apply.
Troubleshooting Secure Boot Enablement
If your system fails after firmware changes, this short troubleshooting checklist helps isolate and fix common causes quickly. Follow the steps calmly and revert nonessential changes if something goes wrong.

Legacy mode, CSM conflicts, and Windows not starting
If BIOS Mode shows Legacy or Compatibility Support Module (CSM) remains active, Windows may not start after switching modes.
Action: revert the CSM change, confirm the Windows disk uses GPT, then retry switching the firmware mode. If you must convert, verify the disk number and run mbr2gpt from an elevated command prompt.
Secure Boot State still Off: missing keys or wrong OS type
When secure boot state stays Off, check the OS type and key management pages in bios.
Set the OS type to Windows UEFI mode and install default keys from Key Management. Some platforms need one more full reboot before status updates in msinfo32.
Resetting to defaults and installing default Secure Boot keys
If options are grayed out, switch firmware into Advanced mode. If problems persist, reset settings to defaults, then reapply minimal changes: enable TPM (Intel PTT or AMD fTPM), set UEFI mode, install default keys, and enable secure boot.
“If menus seem inconsistent, apply one change at a time and use msinfo32 after each reboot to verify boot state.”
| Problem | Likely cause | Quick fix |
|---|---|---|
| Windows won’t boot after disabling CSM | Disk still MBR or wrong firmware mode | Re-enable CSM, confirm GPT, convert disk if needed, then disable CSM |
| Secure Boot State remains Off | OS type wrong or keys missing | Set OS type to Windows UEFI mode and install default keys |
| Options grayed out | Firmware in basic mode or vendor lock | Switch to Advanced mode or consult vendor docs |
| Unclear status after changes | Some systems require extra reboot | Fully restart into Windows and run msinfo32 again |
Need deeper help? For an extended walkthrough on how changes interact with firmware and Windows, see this resource: how to enable secure boot.
After Enabling: Validation, Gaming, and Windows Readiness
After saving BIOS changes, check Windows system tools to prove the trusted boot chain is running. This confirms the operating system sees protections as active and avoids surprises when launching protected apps.
Quick verification keeps updates and games running smoothly. Some Windows builds need one extra restart before status reflects changes. If msinfo32 still shows Off, reboot once more and then check Device security.

How do I confirm status in Windows?
- Reboot and open msinfo32. Confirm the Secure Boot State reads On.
- Open Device security and verify the Security processor (TPM) is ready and active.
- Document the BIOS tab and options you changed so you can reproduce settings or share them with manufacturer support if needed.
Will games and upgrades work now?
With secure boot enabled, titles that enforce kernel anti-cheat—like Valorant or recent Battlefield releases—should launch without warnings once Windows boots under verified conditions.
Keep firmware updates and driver installs paced. If peripherals act oddly after changes, check vendor pages for firmware or driver fixes. For dual-boot setups, confirm each operating system runs in UEFI mode so the chain of trust remains intact.
Conclusion
Confirm msinfo32 shows On and record which BIOS menus you changed. Keep vendor documentation handy and allow one extra restart if status does not update.
You’ve seen how secure boot fortifies early startup by allowing only trusted components to run.
Make sure UEFI mode is active, TPM 2.0 is enabled, the OS drive uses GPT, and default keys are installed in BIOS. After enabling, validate the system in msinfo32 and Device security on Windows. If results differ, review manufacturer manuals, repeat single changes, and reboot fully.
Maintain a quick habit: after firmware updates or hardware swaps, check status again so trusted operating protections stay intact at every boot.