If you’re looking for how to disable Secure Boot Windows 11, you’re probably trying to install an operating system, boot from specialized hardware, use older software, or troubleshoot a compatibility problem. Secure Boot is an important security feature, but there are situations where temporarily turning it off can be necessary.
The good news? You usually don’t need to change complicated Windows files or use third-party software. Secure Boot is controlled through your PC’s UEFI firmware settings, commonly referred to as the BIOS menu. Microsoft specifically documents disabling Secure Boot through UEFI firmware and recommends re-enabling it once the compatibility issue has been resolved.
In this beginner-friendly guide, we’ll explain how to disable Secure Boot on Windows 11 safely, how to check whether Secure Boot is currently enabled, how to enter UEFI firmware from Windows, what to do when the option is missing or grayed out, and how to turn Secure Boot back on afterward.
Important: Secure Boot protects the early Windows startup process by allowing trusted, digitally signed boot software to run. Disabling it reduces this protection, so treat it as a temporary troubleshooting or compatibility step whenever possible.
Quick Summary: How to Disable Secure Boot in Windows 11
Here are the basic steps:
- Save your work and close open applications.
- Open Settings → System → Recovery.
- Under Advanced startup, select Restart now.
- Choose Troubleshoot → Advanced options → UEFI Firmware Settings.
- Select Restart.
- Locate Secure Boot in the UEFI/BIOS menu.
- Change Secure Boot from Enabled to Disabled.
- Save the changes and exit UEFI.
- Let Windows restart.
- Confirm the new Secure Boot status in Windows.
The exact UEFI menu and terminology vary by computer manufacturer. Microsoft notes that Secure Boot is commonly found under Security, Boot, or Authentication, but your system may use a different layout.
What Is Secure Boot in Windows 11?
Secure Boot is a security standard built into the UEFI firmware of modern PCs.
Think of it like a security guard standing at the entrance of your computer. Before Windows starts, the firmware checks whether important boot software is trusted and properly signed. If the software passes the check, the computer continues starting.
Microsoft explains that Secure Boot helps prevent malicious software from loading during startup. It forms part of the trusted boot chain that protects Windows before the operating system is fully running.
This is particularly important because some types of malware can attempt to load before Windows and operate at a very low level.
What Does Secure Boot Actually Check?
During startup, UEFI checks signatures associated with boot components.
If the signatures are trusted, the boot process continues.
If something isn’t trusted or has been blocked, the firmware can prevent that component from loading.
This is why certain older operating systems, specialized hardware, or boot configurations can sometimes have compatibility problems with Secure Boot.
Why Would You Need to Disable Secure Boot?
For normal Windows 11 use, there’s generally no reason to turn Secure Boot off.
However, Microsoft identifies several situations where temporarily disabling it may be necessary, including compatibility with certain graphics cards, hardware, Linux installations, or older Windows versions.
Common scenarios include:
- Installing a Linux distribution with a particular boot configuration
- Troubleshooting specialized hardware
- Using an older operating system
- Testing certain bootable tools
- Resolving a compatibility issue
- Working with hardware that doesn’t support Secure Boot correctly
- Following specific manufacturer instructions
The important word here is temporarily.
If you don’t have a specific reason to disable Secure Boot, leaving it enabled provides useful protection.
Is It Safe to Disable Secure Boot on Windows 11?
Disabling Secure Boot isn’t automatically going to damage your computer.
However, it does remove an important layer of startup security.
Microsoft says Secure Boot helps prevent malicious software from loading during startup, including sophisticated threats such as boot-level malware and rootkits.
Therefore, the safest approach is:
Disable Secure Boot only when necessary, complete your compatibility or installation task, and re-enable it afterward.
Also, be careful when changing UEFI settings. Microsoft warns that incorrect firmware changes can prevent a computer from starting correctly.
How to Check If Secure Boot Is Enabled in Windows 11
Before changing anything, it’s smart to check the current status.
Windows provides an easy way to do this.
Step 1: Open System Information
Press:
Windows + R
The Run dialog will appear.
Type:
msinfo32
Press Enter.
Step 2: Find Secure Boot State
The System Information window will open.
Look for:
Secure Boot State
You’ll generally see a status such as:
- On
- Off
- Unsupported
If it says On, Secure Boot is currently enabled.
If it says Off, Secure Boot is already disabled.
If it says Unsupported, your computer may not support Secure Boot or may be configured in a way that prevents it from being used.
Why Check This First?
It prevents unnecessary BIOS changes.
Imagine checking the door before searching for your keys. If the door is already unlocked, there’s no reason to start changing locks.
The same idea applies here.
How to Enter UEFI Firmware Settings From Windows 11
The easiest method is usually through Windows’ Advanced startup options.
Microsoft documents the following route:
Settings → System → Recovery → Advanced startup → Restart now
From there, choose:
Troubleshoot → Advanced options → UEFI Firmware Settings → Restart
Let’s go through it carefully.
Step 1: Open Windows 11 Settings
Press:
Windows + I
You can also open Start and select Settings.
Step 2: Open System
Select:
System
Then scroll down and choose:
Recovery
Step 3: Find Advanced Startup
Under Recovery options, locate:
Advanced startup
Click:
Restart now
Windows will restart and open the recovery environment.
Save Your Work First
Before selecting Restart now, save any documents or projects you have open.
Your computer will restart immediately after you confirm the action.
Step-by-Step: How to Disable Secure Boot Windows 11
Now we’re ready for the main process.
Step 1: Open Advanced Startup
Go to:
Settings → System → Recovery → Advanced startup → Restart now
Windows will restart.
Step 2: Select Troubleshoot
When the recovery menu appears, choose:
Troubleshoot
Step 3: Select Advanced Options
Choose:
Advanced options
You’ll see several recovery and startup tools.
Step 4: Select UEFI Firmware Settings
Choose:
UEFI Firmware Settings
If this option is available, select it.
Step 5: Click Restart
Windows will restart again.
Instead of loading directly into Windows, your PC should enter its UEFI firmware interface.
This is the modern equivalent of what many people still call the BIOS screen.
Where Is Secure Boot Located in BIOS or UEFI?
This is where things become slightly different from one computer to another.
There is no universal BIOS layout.
Your Secure Boot setting might be under:
- Security
- Boot
- Authentication
- Advanced
- System Configuration
Microsoft specifically notes that Secure Boot is commonly located under Security, Boot, or Authentication.
Don’t worry if your screen looks completely different from a tutorial you found online.
The manufacturer determines the firmware interface.
What Might the Setting Be Called?
Look for wording such as:
- Secure Boot
- Secure Boot Control
- Secure Boot Configuration
- Secure Boot Option
- OS Type
- Windows UEFI Mode
The exact terminology depends on the manufacturer and firmware version.
Step-by-Step: Disable Secure Boot in UEFI
Once you’ve located Secure Boot:
Step 1: Open the Secure Boot Setting
Select the relevant Secure Boot option.
It may currently say:
Enabled
Step 2: Change It to Disabled
Change the setting to:
Disabled
Some systems may ask you to confirm the change.
Step 3: Save the Changes
Look for an option such as:
- Save & Exit
- Save Changes
- Apply Changes and Exit
- Exit Saving Changes
Your computer should restart.
Microsoft’s official instructions similarly say to locate Secure Boot, set it to Disabled, then save the changes and exit.
How to Disable Secure Boot on a Laptop
The overall process is similar on laptops.
The biggest difference is how you access UEFI.
Some laptops allow you to enter firmware settings by pressing a key during startup.
Common keys include:
- F1
- F2
- F12
- Esc
- Delete
However, the correct key depends on the manufacturer.
Microsoft recommends checking your PC manufacturer’s instructions if you’re unsure.
Using Windows Advanced startup is often easier because you don’t need to guess the correct startup key.
How to Disable Secure Boot on a Desktop PC
Desktop computers follow essentially the same process.
You can use:
Settings → System → Recovery → Advanced startup → Restart now
Then:
Troubleshoot → Advanced options → UEFI Firmware Settings → Restart
After entering UEFI, locate the Secure Boot setting and change it to Disabled.
The motherboard manufacturer determines the exact menu structure.
What If UEFI Firmware Settings Isn’t Available?
This is a common question.
You may not see UEFI Firmware Settings under Advanced options.
Several things can cause this.
Your PC May Already Be Using a Different Boot Configuration
Older systems may use Legacy BIOS rather than UEFI.
Secure Boot requires UEFI. Microsoft’s Windows 11 requirements specify UEFI firmware and Secure Boot capability.
Your Firmware May Not Support Secure Boot
Very old computers may not provide the feature.
The Manufacturer Uses a Different Recovery Configuration
Some systems expose firmware settings differently.
In that situation, consult the computer or motherboard manufacturer’s documentation.
What If Secure Boot Is Grayed Out?
Sometimes you’ll enter UEFI and discover that Secure Boot is visible but cannot be changed.
Don’t immediately start changing unrelated firmware settings.
The setting may be restricted because of the current firmware configuration.
Potential causes include:
- Legacy/CSM mode
- Firmware security settings
- Administrator or supervisor passwords
- Platform key configuration
- Manufacturer-specific restrictions
- A customized OEM firmware interface
Should You Disable CSM or Legacy Mode?
Not automatically.
CSM stands for Compatibility Support Module and can affect how firmware handles older boot methods.
Microsoft notes that some situations involving older operating systems may require additional firmware changes, such as enabling CSM. It also warns that changing boot modes can have consequences for disk partitioning and Windows installation.
Don’t change UEFI/Legacy settings simply because a random guide recommends it.
If Windows is already installed in UEFI mode, changing boot configuration without understanding the consequences can cause boot problems.
How to Check Whether Windows Uses UEFI or Legacy BIOS
You can use System Information again.
Press:
Windows + R
Type:
msinfo32
Press Enter.
Look for:
BIOS Mode
If it says:
UEFI
your system is using UEFI.
If it says:
Legacy
the machine is using a legacy BIOS compatibility mode.
This distinction matters because Secure Boot is a UEFI feature.
Does Disabling Secure Boot Delete Windows?
No.
Simply changing Secure Boot from Enabled to Disabled does not normally erase your Windows installation.
You’re changing a firmware security setting.
However, changing additional boot settings, storage settings, partition modes, or other firmware options can potentially affect whether Windows starts.
That’s why you should change only the setting you actually need.
Will Disabling Secure Boot Affect Windows 11?
Windows 11 is designed with Secure Boot as part of its security architecture and requires systems to be Secure Boot capable, along with UEFI firmware, for its minimum system requirements.
Temporarily disabling Secure Boot does not automatically mean Windows will be removed.
However, while Secure Boot is disabled, your PC no longer has that particular startup protection.
Microsoft recommends re-enabling Secure Boot after the issue requiring it to be disabled has been resolved.
What Happens After You Disable Secure Boot?
Usually, the computer simply restarts.
Windows should load normally if the rest of your firmware configuration remains compatible with your existing installation.
The major difference is that Secure Boot will now report as disabled.
You can confirm this from Windows using System Information.
Verify the Setting
Press:
Windows + R
Enter:
msinfo32
Then find:
Secure Boot State
It should now display:
Off
If it still says On, the firmware change may not have been saved or the system may use a different configuration.
How to Re-Enable Secure Boot in Windows 11
Once you’ve finished whatever task required Secure Boot to be disabled, turning it back on is recommended.
The process is essentially the reverse.
Step 1: Enter UEFI
From Windows, open:
Settings → System → Recovery → Advanced startup → Restart now
Then select:
Troubleshoot → Advanced options → UEFI Firmware Settings → Restart
Step 2: Find Secure Boot
Look under the appropriate UEFI menu.
Step 3: Set Secure Boot to Enabled
Change:
Disabled → Enabled
Step 4: Save and Exit
Save the firmware changes and restart the computer.
Microsoft provides these same basic steps for re-enabling Secure Boot and notes that some systems may require loading the Secure Boot keys built into the PC.
What If Windows Won’t Boot After Re-Enabling Secure Boot?
Don’t panic.
Microsoft notes that if the PC cannot boot after Secure Boot is enabled, you can return to the UEFI firmware settings and disable Secure Boot again while troubleshooting the configuration.
Possible causes include:
- An incompatible bootloader
- Unsupported hardware
- Legacy boot configuration
- Custom Secure Boot keys
- A boot configuration that isn’t compatible with Secure Boot
If the problem persists, consult your PC or motherboard manufacturer’s support documentation.
Does Secure Boot Need to Be Disabled to Boot From USB?
Not necessarily.
This is an important misconception.
Many modern bootable USB drives work with Secure Boot enabled.
If you’re having trouble booting from a USB device, first check:
- Whether the USB was created correctly
- Whether the USB supports UEFI boot
- Whether the firmware boot order is correct
- Whether the USB is recognized
- Whether the boot media is compatible with Secure Boot
Only disable Secure Boot if the specific software or operating system actually requires it.
Does Secure Boot Need to Be Disabled to Install Linux?
Not always.
Many modern Linux distributions support Secure Boot.
However, specific distributions, custom bootloaders, unsigned drivers, or specialized configurations may require Secure Boot to be disabled.
If you’re installing Linux, check the documentation for the specific distribution and version you’re using before changing firmware settings.
Secure Boot and Windows 11: Important Security Considerations
Secure Boot is more than an annoying BIOS checkbox.
It helps establish a trusted startup chain.
Microsoft describes Secure Boot as a security mechanism that helps prevent malicious or corrupted boot components from loading.
This matters because some malware attempts to operate below or before the normal operating-system security layer.
For everyday Windows 11 use, keeping Secure Boot enabled is therefore generally preferable from a security perspective.
Disabling it should be treated like temporarily removing a lock from a door: sometimes necessary, but not something you want to leave undone without a reason.
Common Mistakes When Disabling Secure Boot
Changing Multiple BIOS Settings at Once
This is one of the biggest mistakes.
If you change Secure Boot, CSM, boot mode, storage mode, and other settings simultaneously, troubleshooting becomes much harder.
Change one thing at a time.
Forgetting to Record the Original Setting
Before changing a firmware option, make a note of its original value.
That makes it easier to restore your previous configuration.
Changing Boot Mode Without Understanding It
Switching between UEFI and Legacy/CSM can affect how an operating system boots.
Don’t change this setting just because Secure Boot isn’t immediately available.
Disabling Security Features Permanently
If Secure Boot was disabled for a temporary task, turn it back on when you’re finished.
Downloading Third-Party BIOS Tools
You generally don’t need random software to disable Secure Boot.
The setting is controlled directly through your PC’s UEFI firmware.
What Should You Do Before Changing Secure Boot?
Use this checklist:
-
Save all open work.
-
Know why you’re disabling Secure Boot.
-
Check your current Secure Boot status.
-
Confirm your PC uses UEFI.
-
Record important firmware settings before changing them.
-
Check the manufacturer’s instructions if necessary.
-
Avoid changing unrelated BIOS settings.
-
Know how to return to UEFI if needed.
-
Plan to re-enable Secure Boot after completing the task.
This takes only a few minutes and can save you a lot of troubleshooting later.
Frequently Asked Questions
1. How do I disable Secure Boot in Windows 11?
Open Settings → System → Recovery → Advanced startup → Restart now. Then select Troubleshoot → Advanced options → UEFI Firmware Settings → Restart. In UEFI, find Secure Boot, change it to Disabled, save your changes, and exit.
2. Can I disable Secure Boot without entering BIOS?
The actual Secure Boot setting is controlled by your PC’s UEFI firmware, so you need to enter the firmware interface to change it. Windows can take you there through UEFI Firmware Settings, which avoids having to guess a startup key.
3. Is it safe to turn off Secure Boot?
It can be appropriate temporarily for compatibility or troubleshooting, but Secure Boot provides an important layer of protection against untrusted boot software. Microsoft recommends re-enabling it after the issue has been resolved.
4. Why is Secure Boot grayed out in Windows 11 BIOS?
The option may be restricted by your firmware configuration, Legacy/CSM mode, firmware security settings, or manufacturer-specific requirements. Check your PC manufacturer’s documentation before changing additional firmware settings.
5. How do I know if Secure Boot is disabled?
Press Windows + R, enter msinfo32, and press Enter. In System Information, find Secure Boot State. It should report Off when Secure Boot is disabled.
Final Thoughts: Should You Disable Secure Boot?
Learning how to disable Secure Boot Windows 11 is relatively straightforward once you understand where the setting lives.
The key point is that Secure Boot isn’t controlled by an ordinary Windows Settings switch. It’s a UEFI firmware security feature, so you’ll need to enter your computer’s firmware settings.
For most PCs, the simplest route is:
Settings → System → Recovery → Advanced startup → Restart now → Troubleshoot → Advanced options → UEFI Firmware Settings → Restart
From there, locate Secure Boot, set it to Disabled, save your changes, and restart.
Remember that firmware menus vary between manufacturers. If your screen doesn’t match this guide exactly, don’t start changing random options. Check the documentation for your specific PC or motherboard.
Most importantly, don’t disable Secure Boot unless you have a reason to do so. It helps protect the Windows startup process from untrusted boot software and other low-level threats. Once your installation, hardware, or troubleshooting task is complete, re-enable Secure Boot to restore that protection.