Want to protect your PC from malware and unauthorized software during startup? Turning on Secure Boot is one of the smartest things you can do.
In this detailed How to Turn On Secure Boot Windows 10 A Step by Step Guide , we’ll walk you through everything — from checking compatibility to enabling Secure Boot in BIOS/UEFI — in a simple, step-by-step way.
Let’s get started.
What Is Secure Boot?
Secure Boot is a security feature built into modern PCs that ensures your system only boots using trusted software from your manufacturer.
It’s part of the UEFI (Unified Extensible Firmware Interface) firmware and replaces the older BIOS system.
In simple terms:
- It blocks malicious software during startup
- It verifies digital signatures of boot files
- It protects your system before Windows even loads
Why Should You Enable Secure Boot?
Enabling Secure Boot provides:
- 🔒 Protection from boot-level malware
- 🛡️ Defense against rootkits
- ⚡ Safer system startup
- ✔ Required for upgrading to Windows 11
If you’re planning to upgrade or improve system security, Secure Boot is essential.
Does Your PC Support Secure Boot?
Before enabling it, check if your system supports Secure Boot.
How to Check Secure Boot Status in Windows 10
Step 1:
Press Windows + R
Step 2:
Type:
msinfo32
Press Enter.
Step 3:
In the System Information window, look for:
- Secure Boot State
- BIOS Mode
Possible Results:
| Setting | Meaning |
|---|---|
| Secure Boot State: On | Already enabled |
| Secure Boot State: Off | Can be enabled |
| BIOS Mode: Legacy | Needs conversion |
Important Requirements Before Enabling Secure Boot
Before proceeding, make sure:
✔ Your system uses UEFI mode (not Legacy BIOS)
✔ Your disk uses GPT partition style
✔ Your hardware supports Secure Boot
What If BIOS Mode Is Legacy?
You must switch from Legacy to UEFI.
⚠️ Important: This may require converting your disk from MBR to GPT.
How-to-Turn-On-Secure-Boot-Windows-10-a-Step-by-Step-Guide
Now let’s enable Secure Boot.
Step 1: Enter BIOS/UEFI Settings
Method 1 (From Windows):
- Press Windows + I
- Go to Update & Security
- Click Recovery
- Under Advanced Startup, click Restart now
Step 2:
After restart:
- Click Troubleshoot
- Click Advanced Options
- Click UEFI Firmware Settings
- Click Restart
Step 3: Locate Secure Boot Option
Once inside BIOS/UEFI:
- Go to Boot or Security tab
- Look for Secure Boot
Location varies by manufacturer:
- HP → Security tab
- Dell → Boot tab
- ASUS → Boot → Secure Boot
Step 4: Disable Legacy Mode (If Enabled)
Find:
- Legacy Support or CSM (Compatibility Support Module)
Set it to:
Disabled
Step 5: Enable Secure Boot
Now:
- Select Secure Boot
- Change it to:
Enabled
Step 6: Save and Exit
- Press F10 (usually)
- Select Yes
Your system will restart.
Step 7: Verify Secure Boot Is Enabled
Repeat:
msinfo32
Check:
- Secure Boot State → On
Success!
What If Secure Boot Option Is Greyed Out?
This happens when:
- Legacy mode is enabled
- Admin password not set in BIOS
- Incorrect boot mode
Fix:
- Disable CSM
- Set BIOS to UEFI
- Set supervisor/admin password
How to Convert MBR to GPT (If Needed)
If your system uses MBR, you must convert it.
Using Command Prompt:
- Open CMD as admin
- Type:
mbr2gpt /validate /allowFullOS
- Then:
mbr2gpt /convert /allowFullOS
Restart and switch to UEFI.
Is It Safe to Enable Secure Boot?
Yes — for most users.
However, it may block:
- Unsigned drivers
- Older operating systems
- Some Linux distributions
When Should You Disable Secure Boot?
Only if you:
- Install Linux
- Use custom bootloaders
- Run unsigned software
Otherwise, keep it enabled.
Benefits of Secure Boot in Windows 10
✔ Prevents bootkits
✔ Protects firmware integrity
✔ Improves system trust
✔ Required for modern security standards
Common Errors and Fixes
1. PC Won’t Boot After Enabling
✔ Check boot mode
✔ Re-enable CSM temporarily
2. Secure Boot Not Available
✔ Update BIOS
✔ Check motherboard support
3. Windows Not Booting
✔ Ensure disk is GPT
✔ Reinstall bootloader if needed
Secure Boot vs TPM: What’s the Difference?
| Feature | Secure Boot | TPM |
|---|---|---|
| Purpose | Boot security | Encryption |
| Location | Firmware | Hardware chip |
| Required for Windows 11 | Yes | Yes |
Does Secure Boot Improve Performance?
No — it improves security, not speed.
Best Practices
✔ Keep BIOS updated
✔ Use UEFI mode
✔ Enable Secure Boot for protection
✔ Avoid disabling unless necessary
Conclusion
In this complete how-to-turn-on-secure-boot-windows-10-a-step-by-step-guide, we covered:
- What Secure Boot is
- How to check compatibility
- Step-by-step instructions to enable it
- Common issues and fixes
Secure Boot is a powerful feature that protects your system before Windows even starts.
If your system supports it, enabling it is a smart move for better security and peace of mind.
Take a few minutes today and secure your system properly.
FAQs
1. How do I know if Secure Boot is enabled?
Use msinfo32 and check Secure Boot State.
2. Can I enable Secure Boot without UEFI?
No. Secure Boot requires UEFI mode.
3. Will enabling Secure Boot delete my data?
No — but changing disk format might.
4. Why is Secure Boot disabled?
Because Legacy BIOS or CSM is enabled.
5. Can I disable Secure Boot later?
Yes, anytime from BIOS settings.
Summary: Key Takeaways
- Secure Boot protects your PC during startup
- Requires UEFI and GPT disk
- Enable via BIOS/UEFI settings
- Disable Legacy/CSM first
- Verify using
msinfo32
Now you know exactly how to turn on Secure Boot in Windows 10 — step by step, safely, and effectively.