Secure Boot helps a Windows 11 PC start using trusted boot software. Before enabling it, confirm that Windows is already using UEFI mode and that the computer’s disk and firmware configuration support the change. Randomly switching from Legacy/CSM to UEFI can make an existing installation fail to boot.
Check Secure Boot status first
- Press Windows+R, type
msinfo32, and press Enter. - Find BIOS Mode and Secure Boot State.
- If Secure Boot already says On, no firmware change is needed.
- If BIOS Mode says UEFI and Secure Boot is Off, identify the exact computer or motherboard and open its firmware setup using the manufacturer’s instructions.
- Locate Secure Boot and enable it without changing unrelated storage, TPM, or boot settings.
- Save the firmware configuration, restart Windows, and check System Information again.
Keep the BitLocker recovery key available
Firmware and boot-security changes can trigger BitLocker recovery on encrypted systems. Save the recovery key somewhere separate from the PC before changing UEFI settings. Organization-managed computers should be changed according to administrator policy.
Legacy mode may require preparation
If System Information reports Legacy BIOS mode, do not simply disable CSM and enable Secure Boot. The Windows installation may need a supported MBR-to-GPT conversion and validation first. Back up the system and follow Microsoft and hardware-vendor guidance for the exact configuration.
Secure Boot is one part of Windows 11 security
TPM 2.0, supported hardware, current firmware, updates, device encryption, and account security also matter. Enabling Secure Boot does not compensate for malware, an unsupported device, or missing security updates.
If Secure Boot shows Unsupported even though the computer is relatively modern, consult the manufacturer’s documentation before assuming the hardware lacks the feature. Firmware mode, key state, or configuration can affect what Windows reports.
Take a photo or note of the original firmware settings before saving changes. If the machine stops booting normally, having the previous values makes recovery much easier.
UEFI mode and disk layout may need preparation
Secure Boot depends on UEFI firmware. A PC still booting through Legacy/CSM mode may need its system disk and boot configuration prepared before you switch firmware modes. Do not simply toggle Legacy off if you have not confirmed that Windows can boot in UEFI mode.
Do not clear Secure Boot keys casually
Enabling Secure Boot normally does not require deleting platform keys. Save the BitLocker recovery key before firmware changes, record the original settings, and use the PC or motherboard manufacturer’s instructions. After restarting, verify Secure Boot State in System Information.

Kermit Matthews is a freelance writer based in Philadelphia, Pennsylvania with more than a decade of experience writing technology guides. He has a Bachelor’s and Master’s degree in Computer Science and has spent much of his professional career in IT management.
He specializes in writing content about iPhones, Android devices, Microsoft Office, and many other popular applications and devices.