How to Turn Off Secure Boot on Windows 11

Secure Boot is a firmware (UEFI) feature that only lets trusted, signed software start your PC, which blocks boot-level malware. Windows 11 is designed to use it. You might need to turn it off to boot certain Linux distributions or recovery tools, install unsigned drivers, or use older graphics cards and hardware. This guide shows how to disable Secure Boot on Windows 11, what to check first, and how to turn it back on.

Quick Answer

Go to Settings > System > Recovery, click Restart now next to Advanced startup, then choose Troubleshoot > Advanced options > UEFI Firmware Settings > Restart. In the firmware, find Secure Boot (usually under the Security, Boot, or Authentication tab), set it to Disabled, and press F10 to save and exit.

UEFI firmware setup Security tab with the Secure Boot option highlighted and set to Disabled
Secure Boot is set in your PC’s firmware. The menu location varies by manufacturer.

Before You Turn It Off

  • Get your BitLocker recovery key. Changing Secure Boot can trigger BitLocker recovery at the next startup. Find the key at aka.ms/myrecoverykey or in Control Panel > BitLocker Drive Encryption > Back up your recovery key. Or suspend BitLocker first (Suspend protection).
  • Games may stop working. Several popular online games’ anti-cheat systems require Secure Boot to be on.
  • Security features: some features that rely on it, such as certain device security and Windows Hello protections, may be reduced.
  • Windows 11 keeps running. Windows 11 requires a PC that’s Secure Boot capable; it continues to start with Secure Boot off.

Step 1: Check Whether Secure Boot Is On

  1. Press Windows + R, type msinfo32, and press Enter.
  2. In System Summary, look at Secure Boot State: On, Off, or Unsupported.

Also check BIOS Mode. Secure Boot only works in UEFI mode.

Step 2: Open the UEFI Firmware Settings

  1. Save your work and open Settings > System > Recovery.
  2. Next to Advanced startup, click Restart now.
  3. Choose Troubleshoot > Advanced options > UEFI Firmware Settings, then Restart.

Alternatively, press the firmware key during startup (commonly F2, Del, F10, F1, or Esc).

Step 3: Disable Secure Boot

  1. Use the arrow keys or mouse to find Secure Boot. Common locations:
    • Security tab (many laptops)
    • Boot tab, sometimes inside Secure Boot Configuration
    • Advanced > Windows OS Configuration or Boot > OS Type on some desktop motherboards, where you choose Other OS instead of Windows UEFI mode
  2. Set Secure Boot to Disabled.
  3. Press F10 (or go to Exit > Save Changes and Reset) and confirm.

Secure Boot option grayed out?

  • Some firmware only allows changes after you set a Supervisor/Administrator password. Set one, change Secure Boot, and remove the password afterward if you like.
  • On some boards you must choose Custom mode or clear the keys (Delete all Secure Boot variables / Reset to Setup Mode). Only do this if you understand it; restoring factory keys puts it back.

Step 4: Confirm It’s Off

After Windows starts, open msinfo32 again. Secure Boot State should say Off. If you’re asked for a BitLocker recovery key at startup, enter it.

How to Turn Secure Boot Back On

  1. Return to the UEFI settings the same way.
  2. Set Secure Boot to Enabled (and choose Restore Factory Keys if you cleared them).
  3. Make sure boot mode is UEFI, not Legacy/CSM.
  4. Save and exit.

If Windows won’t enable Secure Boot because the disk uses MBR, it must be converted to GPT first (Windows’ mbr2gpt tool can do this; back up first).

A Note on Secure Boot Certificate Updates

Microsoft’s original Secure Boot certificates from 2011 began expiring in 2026, and Windows Update and PC makers have been rolling out replacement certificates and firmware updates. Keeping Windows and your BIOS updated ensures Secure Boot keeps working normally when you turn it back on.

Frequently Asked Questions

Is it safe to disable Secure Boot?

It lowers protection against boot-level malware but won’t harm your PC. Turn it back on when you’re done if you only needed it off temporarily.

Do I need to disable Secure Boot to dual-boot Linux?

Usually not. Major distributions such as Ubuntu and Fedora support Secure Boot. You may need to disable it for some smaller distributions or custom kernels.

Will disabling Secure Boot fix a game that won’t launch?

No. Games more often require it on.

Summary

  1. Save your BitLocker recovery key.
  2. Restart into UEFI Firmware Settings from Settings > System > Recovery.
  3. Set Secure Boot to Disabled and press F10.
  4. Check msinfo32 to confirm, and re-enable it the same way.