How to Turn On Secure Boot in Windows 11

To turn on Secure Boot for Windows 11, first check that your PC uses UEFI: press Windows key + R, type msinfo32, and look for BIOS Mode: UEFI. Then open your firmware settings from Settings > System > Recovery > Advanced startup > Restart now > Troubleshoot > Advanced options > UEFI Firmware Settings > Restart. Find Secure Boot (usually on the Boot or Security tab), set it to Enabled, save, and exit.

Secure Boot is a firmware setting, so there’s no switch for it inside Windows. Menu names vary by PC maker. Here’s how to check your status, turn it on safely, and fix common problems.

Step 1: Check your current Secure Boot status

  1. Press Windows key + R, type msinfo32, and press Enter.
  2. In System Summary, look at BIOS Mode and Secure Boot State.
Windows System Information showing BIOS Mode UEFI and Secure Boot State highlighted
(1) BIOS Mode must say UEFI, and (2) Secure Boot State shows whether it’s on. (Illustration)
What you see What to do
Secure Boot State: On Nothing. It’s already enabled.
BIOS Mode: UEFI, Secure Boot State: Off Turn it on in firmware (Step 2).
BIOS Mode: Legacy Convert the disk to GPT and switch to UEFI first (see below).
Secure Boot State: Unsupported The PC uses legacy BIOS or doesn’t support Secure Boot.

Step 2: Turn on Secure Boot in UEFI

  1. Save your work and open Settings > System > Recovery.
  2. Next to Advanced startup, click Restart now.
  3. Choose Troubleshoot > Advanced options > UEFI Firmware Settings > Restart.
  4. In the firmware menu, open the Boot, Security, or Authentication tab. On some boards it’s under Advanced mode (often F7).
  5. Set Secure Boot to Enabled. If asked for an OS type, choose Windows UEFI mode.
  6. If the option is grayed out, make sure CSM or Legacy support is Disabled, or choose Restore Factory Keys / Install default Secure Boot keys.
  7. Save and exit, usually with F10.

Windows restarts normally. Run msinfo32 again to confirm Secure Boot State is On.

If your PC uses Legacy BIOS mode

Secure Boot requires UEFI mode and a GPT disk. If Windows is installed in legacy mode on an MBR disk, turning on UEFI alone will stop Windows from starting. Convert the disk first:

  1. Back up your files.
  2. Open Command Prompt as administrator and run mbr2gpt /validate /allowFullOS.
  3. If it passes, run mbr2gpt /convert /allowFullOS.
  4. Restart into firmware settings, switch from Legacy/CSM to UEFI, then enable Secure Boot.

Where to find Secure Boot by PC maker

  • Dell: Press F2 > Boot Configuration or Secure Boot > Secure Boot Enable.
  • HP: Press F10 > Advanced or Security > Secure Boot Configuration.
  • Lenovo: Press F1 or F2 > Security > Secure Boot.
  • ASUS: Press Delete or F2, press F7 for Advanced mode > Boot > Secure Boot.
  • MSI: Press Delete > Settings > Security > Secure Boot.
  • Gigabyte: Press Delete > Boot > Secure Boot.

Troubleshooting

  • Windows won’t start after enabling: Go back into firmware and turn Secure Boot off, then check that BIOS Mode is UEFI and the disk is GPT.
  • Graphics card or Linux boot issues: Older graphics cards and some Linux installs don’t support Secure Boot. Update the graphics card firmware or turn Secure Boot off when needed.
  • BitLocker asks for a recovery key: Changing firmware settings can trigger it. Have your key ready from account.microsoft.com/devices/recoverykey.

Frequently asked questions

Does Windows 11 require Secure Boot?

Windows 11 requires a PC that’s capable of Secure Boot. Some games and anti-cheat tools require it to be turned on.

Is it safe to turn on Secure Boot?

Yes, on a UEFI system with a GPT disk. It helps block malware that loads before Windows.

Will turning on Secure Boot delete my files?

No. Converting a disk with mbr2gpt usually keeps your files too, but back up first.

How do I check Secure Boot with PowerShell?

Run PowerShell as administrator and type Confirm-SecureBootUEFI. It returns True if Secure Boot is on.