Secure Boot is an important security feature built into modern PCs that helps protect Windows 11 from unauthorized software loading before the operating system starts. If Secure Boot is turned off, you may see warnings in Windows Security, encounter compatibility requirements for certain features, or discover that your PC does not meet specific Windows 11 security checks.
If you want to know how to turn on Secure Boot in Windows 11, the process usually involves checking your current firmware mode, entering your computer’s UEFI settings, and enabling Secure Boot. The exact menu names can vary between manufacturers, but the overall process is similar.
The good news is that you usually do not need to reinstall Windows just to enable Secure Boot. However, you should check whether your system is already using UEFI mode before changing firmware settings.
This guide explains everything step by step, including how to check Secure Boot status, enter UEFI firmware settings, enable Secure Boot, troubleshoot common problems, and verify that it is working correctly.
What Is Secure Boot in Windows 11?
Secure Boot is a security feature provided by modern UEFI firmware. It checks whether important boot components have trusted digital signatures before allowing them to run during the startup process.
Think of Secure Boot as a security checkpoint at the beginning of your PC’s startup. Before Windows loads, the firmware checks the software responsible for starting the operating system. If the software does not meet the firmware’s trusted requirements, the system can prevent it from loading.
Secure Boot is particularly important because some threats attempt to interfere with a computer before Windows and traditional security software have fully started.
Why Should You Turn On Secure Boot?
There are several reasons to enable Secure Boot on a Windows 11 PC.
1. It Improves Startup Security
Secure Boot helps prevent unauthorized boot software from loading before Windows.
2. It Supports Windows 11 Security Requirements
Secure Boot is one of the security technologies associated with Windows 11. Windows 11 systems commonly use UEFI firmware and Secure Boot capabilities.
3. It Helps Protect Against Boot-Level Threats
Some sophisticated malware attempts to operate at a very early stage of the startup process. Secure Boot adds another layer of protection against unauthorized boot components.
4. It Can Resolve Compatibility Checks
Some Windows features, applications, games, and security requirements may check whether Secure Boot is enabled.
Before You Turn On Secure Boot
Before changing your firmware settings, take a few minutes to check your current configuration.
This is especially important if your computer was upgraded from an older version of Windows or has unusual boot settings.
Check these items:
- Windows should preferably be installed using UEFI mode.
- Your system disk should normally use the GPT partition style.
- You should know how to enter your PC’s UEFI firmware settings.
- If BitLocker or device encryption is enabled, make sure you have access to your recovery key.
- Avoid changing unrelated firmware settings.
Do not randomly change options in the BIOS or UEFI interface. A small configuration change can affect how Windows starts.
How to Check Whether Secure Boot Is Already Enabled
Before changing anything, check whether Secure Boot is already active.
Windows provides a simple tool for this.
Step 1: Open System Information
Press Windows + R on your keyboard.
Type:
msinfo32
Then press Enter.
The System Information window will appear.
Step 2: Find Secure Boot State
Look for:
Secure Boot State
You should see one of these values:
- On — Secure Boot is enabled.
- Off — Secure Boot is supported but currently disabled.
- Unsupported — your current configuration does not support Secure Boot in its present state.
Also find:
BIOS Mode
Ideally, it should say:
UEFI
If BIOS Mode says Legacy, do not immediately change firmware settings. Your Windows installation may have been configured for Legacy BIOS mode.
How to Check Your BIOS Mode
You can use the same System Information window.
Press:
Windows + R → type msinfo32 → Enter
Then locate BIOS Mode.
If it says UEFI, your PC is already using the modern firmware mode required for Secure Boot.
If it says Legacy, additional preparation may be necessary before Secure Boot can be enabled.
How to Check Whether Your Disk Uses GPT
Secure Boot is generally associated with UEFI systems, and UEFI Windows installations commonly use GPT rather than the older MBR partitioning system.
You can check your disk type without changing anything.
Step 1: Open Disk Management
Right-click the Start button.
Select Disk Management.
Step 2: Open Disk Properties
Find the disk containing your Windows installation.
Right-click the disk label on the left side, such as Disk 0.
Select Properties.
Step 3: Open Volumes
Select the Volumes tab.
Look for:
Partition style
It may show:
- GUID Partition Table (GPT)
- Master Boot Record (MBR)
If your Windows installation is already using UEFI and GPT, enabling Secure Boot is generally more straightforward.
How to Enter UEFI Firmware Settings in Windows 11
You do not always need to press a function key during startup. Windows 11 provides a way to restart directly into firmware settings.
Step 1: Open Windows Settings
Press:
Windows + I
Step 2: Open Recovery Options
Select:
System → Recovery
Step 3: Find Advanced Startup
Locate Advanced startup.
Click:
Restart now
Windows will restart and display a recovery menu.
Step 4: Open UEFI Firmware Settings
Choose:
Troubleshoot → Advanced options → UEFI Firmware Settings
Then select:
Restart
Your computer should restart and open the UEFI firmware interface.
How to Turn On Secure Boot in Windows 11
Once you are inside your computer’s UEFI firmware settings, you can enable Secure Boot.
The exact menus depend on your motherboard or computer manufacturer.
Step 1: Locate the Secure Boot Menu
Look through menus such as:
- Security
- Boot
- Authentication
- Advanced
- Windows OS Configuration
Search for an option called:
Secure Boot
Step 2: Enable Secure Boot
Change the Secure Boot setting from:
Disabled
to:
Enabled
Step 3: Save Your Changes
Look for an option such as:
Save & Exit
You may also see a keyboard shortcut such as F10.
Confirm that you want to save the changes.
Your computer will restart.
Step 4: Allow Windows to Start
If everything is configured correctly, Windows should start normally.
If Windows does not boot, do not repeatedly change random firmware options. Return to the UEFI settings and review the configuration.
How to Enable Secure Boot on Different PC Brands
The exact location of Secure Boot can vary considerably.
ASUS
On many ASUS systems, Secure Boot can be found under the Boot or Security area of UEFI settings.
You may need to look for an operating-system type or Secure Boot configuration option.
Dell
On many Dell computers, Secure Boot is available under the Boot Configuration or Secure Boot section.
HP
HP systems commonly provide Secure Boot under the Security or Boot Options area.
Lenovo
On Lenovo computers, Secure Boot is often located under a Security or Boot menu.
Acer
Acer systems may place Secure Boot under the Security or Boot sections.
Because firmware interfaces change between models, use the menu names shown on your own computer rather than following a specific menu path blindly.
What to Do If Secure Boot Is Grayed Out
Sometimes the Secure Boot option appears but cannot be changed.
Several things can cause this.
Check Whether UEFI Mode Is Enabled
Return to Windows and open:
System Information
Check BIOS Mode.
If it says Legacy, Secure Boot may not be available until the system is configured for UEFI booting.
Check for Legacy or CSM Mode
Some UEFI firmware includes a compatibility setting called:
CSM
or
Compatibility Support Module
If legacy compatibility mode is enabled, Secure Boot may be unavailable.
However, do not simply disable CSM without checking your Windows installation first.
A Windows installation configured for Legacy BIOS mode may fail to boot after switching to UEFI-only settings.
What If BIOS Mode Says Legacy?
If BIOS Mode says Legacy, your PC may need to transition from an MBR-based Windows installation to a GPT-based configuration before Secure Boot can be enabled.
Windows includes a tool called MBR2GPT that can convert a compatible system disk from MBR to GPT without the traditional requirement to reinstall Windows.
However, disk conversion is a significant system configuration change.
Before attempting it:
- Back up important files.
- Make sure you understand the recovery process.
- Confirm that your PC firmware supports UEFI.
- Check whether drive encryption is enabled.
- Have your Windows recovery information available.
Do not treat an MBR-to-GPT conversion as a casual BIOS setting change.
How to Verify Secure Boot Is Enabled
After Windows starts again, verify the setting.
Step 1: Open System Information
Press:
Windows + R
Type:
msinfo32
Press Enter.
Step 2: Check Secure Boot State
Find:
Secure Boot State
It should now display:
On
Also confirm that:
BIOS Mode
shows:
UEFI
If both values are correct, Secure Boot is active.
How to Check Secure Boot Through Windows Security
You can also check related security information through Windows Security.
Open the Start menu.
Search for:
Windows Security
Open the application.
Select:
Device security
Depending on your hardware and Windows configuration, you may see information related to security features and hardware-backed protection.
For the clearest Secure Boot status, however, System Information is usually the easiest place to check.
What Happens When You Enable Secure Boot?
For most properly configured Windows 11 computers, enabling Secure Boot should not noticeably change everyday Windows usage.
You may notice:
- Windows starts normally.
- Secure Boot reports as enabled.
- Some security checks recognize the feature.
- Certain applications that require Secure Boot can pass their system checks.
Secure Boot primarily works behind the scenes.
It is not an application that you open manually each time you start Windows.
Can You Enable Secure Boot Without Reinstalling Windows?
Yes, in many cases.
If Windows is already installed using UEFI mode and the system is configured appropriately, you can often enable Secure Boot without reinstalling Windows.
The important distinction is between:
UEFI + compatible disk configuration
and:
Legacy BIOS + older disk configuration
If your PC is already using UEFI, the process is usually much easier.
Common Problems After Enabling Secure Boot
Although Secure Boot is designed to work with modern Windows installations, problems can occur when firmware settings are changed incorrectly.
Windows Does Not Start
If Windows suddenly fails to boot after enabling Secure Boot, return to UEFI settings and check the boot configuration.
If necessary, restore the previous setting temporarily while you determine what is incompatible.
Secure Boot Still Says Off
If Windows reports that Secure Boot is still off, restart the PC and enter UEFI settings again.
Check that:
- Secure Boot is actually enabled.
- Changes were saved.
- The computer is using UEFI mode.
- Legacy/CSM settings are not preventing Secure Boot from functioning.
Secure Boot Is Unsupported
If System Information says Secure Boot is unsupported, the computer may have older firmware or a configuration that does not currently support it.
Check your motherboard or computer documentation to determine whether UEFI and Secure Boot are supported.
A Bootable USB No Longer Starts
Secure Boot can affect how certain external boot media starts.
Modern operating systems generally provide signed boot components, but older or specially created boot media may not work with Secure Boot enabled.
If you regularly use specialized boot tools, check that they support Secure Boot before changing firmware settings.
Should You Turn Off Secure Boot After Enabling It?
In most normal Windows 11 installations, there is no reason to turn Secure Boot off.
Leaving it enabled provides an additional layer of startup protection.
You might temporarily need to change firmware settings for certain troubleshooting, operating-system installation, or specialized boot scenarios. If you do so, understand why the change is necessary and restore secure settings afterward when appropriate.
Secure Boot vs TPM 2.0
Secure Boot and TPM 2.0 are often mentioned together, but they are not the same technology.
Secure Boot helps verify trusted boot software before Windows starts.
TPM 2.0 is a hardware-based security component that can store and protect cryptographic information.
Windows 11 uses several security technologies together rather than relying on one feature.
You can think of Secure Boot as checking the software involved in startup, while TPM provides protected hardware-based security functions.
Secure Boot vs UEFI: What’s the Difference?
These terms are related but different.
UEFI is the modern firmware interface that replaces traditional BIOS.
Secure Boot is a security feature provided through UEFI firmware.
In simple terms:
- UEFI = modern firmware environment
- Secure Boot = security feature within that environment
- GPT = modern partitioning format commonly used with UEFI systems
Understanding these differences makes troubleshooting much easier.
Tips Before Changing BIOS or UEFI Settings
Firmware configuration deserves extra caution.
Follow these recommendations:
Back Up Important Files
Always maintain a current backup of important documents and personal files before making major system configuration changes.
Photograph Existing Settings
If you are unfamiliar with your firmware interface, you can take pictures of important configuration pages before making changes.
This can help you restore settings if necessary.
Change One Setting at a Time
Avoid changing Secure Boot, boot order, virtualization, storage settings, and other options simultaneously.
If something goes wrong, changing only one setting makes troubleshooting easier.
Don’t Disable Random Security Features
Your firmware may contain many options that look technical or unfamiliar.
If you do not know what a setting does, leave it alone.
Frequently Asked Questions
Is Secure Boot required for Windows 11?
Secure Boot is an important part of the Windows 11 security design and is commonly expected on supported systems. However, the exact requirements and enforcement can depend on how Windows was installed and how the PC is configured.
How do I know if Secure Boot is enabled?
Press Windows + R, enter msinfo32, and press Enter. In System Information, look for Secure Boot State. If it says On, Secure Boot is enabled.
Can I enable Secure Boot without reinstalling Windows?
Often, yes. If your Windows installation already uses UEFI mode and a compatible disk configuration, you can generally enable Secure Boot through your UEFI firmware settings without reinstalling Windows.
Why can’t I enable Secure Boot?
Common reasons include Legacy BIOS mode, an MBR-based Windows installation, compatibility settings such as CSM, or unsupported firmware. Check your BIOS Mode in System Information before changing firmware settings.
Does enabling Secure Boot delete files?
Simply enabling Secure Boot does not normally delete your files. However, changing firmware configuration can affect whether Windows boots, so backing up important data before making changes is a smart precaution.
Conclusion
Learning how to turn on Secure Boot in Windows 11 is relatively straightforward when your computer is already configured for UEFI. Start by checking System Information and confirming that your BIOS Mode is set to UEFI. Then enter your UEFI firmware settings, locate Secure Boot, enable it, save your changes, and restart Windows.
The most important thing is not to rush through the firmware configuration. If your PC uses Legacy BIOS mode or an older MBR-based installation, you may need additional preparation before Secure Boot can be enabled safely.
Once enabled, verify the result by opening msinfo32 and checking that Secure Boot State says On. Keeping Secure Boot enabled can provide an additional layer of protection during the earliest stages of the Windows startup process.
Key Takeaways
- Secure Boot helps protect the Windows startup process.
- Check BIOS Mode before changing firmware settings.
- UEFI mode is normally required for Secure Boot.
- Use
msinfo32to check Secure Boot status. - Secure Boot settings are found inside UEFI firmware.
- Legacy BIOS and MBR configurations may require additional preparation.
- Do not randomly change BIOS or UEFI settings.
- Back up important files before making major system configuration changes.
- After enabling Secure Boot, verify that Secure Boot State says On.
- If Windows fails to boot after a firmware change, review the previous configuration rather than changing multiple settings at once.
This draft is structured for search and answer-engine readability, with the primary keyword, related terms, troubleshooting guidance, and FAQ content naturally distributed throughout.