Enabling Secure Boot
Configure Secure Boot settings in your BIOS
Important Note
Enabling Secure Boot requires UEFI boot mode. If you're currently using Legacy/CSM boot mode, you'll need to convert your system disk to GPT and switch to UEFI first.
What is Secure Boot?
Secure Boot is a security feature that ensures your PC boots using only software trusted by the PC manufacturer. This helps prevent unauthorized programs and malware from loading during the system startup process.
Prerequisites
- - UEFI BIOS (not Legacy/CSM)
- - GPT-formatted system drive
- - Windows installed in UEFI mode
- - TPM 2.0 enabled (recommended)
Check Your Current Status
Before making changes, check if Secure Boot is already enabled on your system:
- Press Win + R to open the Run dialog
- Type msinfo32 and press Enter
- In System Information, look for BIOS Mode — it should say UEFI
- Look for Secure Boot State — it should say On
If both show UEFI and Secure Boot On, you're already good to go — no further action needed.
Step-by-Step Instructions
- 1.Save all your work and close any open applications.
- 2.Restart your PC. During the boot logo, press the BIOS key for your motherboard — commonly DEL, F2, F10, or F12. You may need to press it repeatedly.
- 3.In BIOS, navigate to the Secure Boot setting. Check the common locations listed in the BIOS Settings section below.
- 4.Set Secure Boot to Enabled.
- 5.If prompted about Secure Boot mode, select Standard (not Custom).
- 6.Save changes and exit — usually by pressing F10 and confirming.
- 7.After Windows restarts, open msinfo32 again and verify that Secure Boot State now shows On.
BIOS Settings
Common locations for Secure Boot settings:
- Boot > Secure Boot
- Security > Secure Boot
- Authentication > Secure Boot
- Advanced > Windows OS Configuration
