Can't Turn on Secure Boot in Bios

Can't Turn on Secure Boot in Bios

If you can't turn on Secure Boot in BIOS, don't keep flipping settings at random. Secure Boot depends on how Windows was installed, which boot mode your motherboard uses, and whether the right Secure Boot keys are present. Changing the wrong setting can leave the PC unable to start Windows.

Before you change anything, take photos of the current BIOS pages or write down the settings. If the computer stops booting, you'll have a record of what to restore.

Check whether Windows is using Legacy BIOS or UEFI mode

This is the first branch in the troubleshooting path.

Secure Boot works with UEFI, which is the newer firmware mode used to start Windows. It doesn't work with Legacy BIOS mode. Windows installed in Legacy mode also commonly uses an MBR drive. MBR is an older drive partition style that may not boot after you switch the motherboard to UEFI.

Check the current Windows boot mode

In Windows 10 or Windows 11:

  1. Press Windows key + R.
  2. Type `msinfo32`.
  3. Press Enter.
  4. Find BIOS Mode in the System Information window.

You should see either:

  • UEFI — this is the mode Secure Boot needs.
  • Legacy — Secure Boot cannot be used until the Windows installation is changed to support UEFI.

If it says Legacy, stop before disabling CSM or changing other boot settings. Your current Windows installation may rely on Legacy BIOS and an MBR drive. Switching straight to UEFI can send the computer back to the BIOS screen or show a “no boot device” message.

You can also check the drive's partition style in Windows, but don't change it just to make Secure Boot work. Drive conversion needs its own backup and recovery plan. If you can't clearly tell whether Windows is using Legacy or UEFI, leave the BIOS settings alone and get model-specific help first.

If `BIOS Mode` already says UEFI, continue to the CSM check.

Disable CSM and switch the motherboard to pure UEFI mode

Disable CSM and switch the motherboard to pure UEFI mode

CSM, or Compatibility Support Module, is a BIOS setting that allows older Legacy boot methods to work. When CSM is active, the motherboard may not offer Secure Boot or may leave it inactive.

For the troubleshooting steps here, CSM needs to be disabled so the system uses pure UEFI mode.

  1. Restart the PC.
  2. Enter the BIOS or UEFI setup. The key is often Delete, F2, or another key shown briefly during startup.
  3. Look for CSM, Launch CSM, Compatibility Support Module, or a similar option.
  4. Set it to Disabled.
  5. Save the change only if Windows is already confirmed to use UEFI.
  6. Restart and return to the BIOS.

The setting may be under a Boot, Advanced, or Security menu. The name and location depend on the motherboard.

If Windows was installed in Legacy mode, do not disable CSM as a test. That change can make an otherwise working installation stop booting. Return to the earlier step and confirm the boot mode before going further.

After CSM is disabled, check whether the Secure Boot option has become available. On some systems, it was hidden or locked only because CSM was still running.

Find Secure Boot in the BIOS menu

With UEFI active and CSM disabled, look for Secure Boot. It may appear under:

  • Boot
  • Security
  • Authentication
  • Windows OS Configuration
  • Key Management

Some firmware shows Secure Boot Control instead of simply “Secure Boot.” Others show a status such as Enabled, Disabled, Active, or Not Active.

This difference matters. A BIOS can show the setting as enabled while the status remains inactive. That usually means the firmware doesn't have valid Secure Boot keys loaded, or another boot setting is still preventing Secure Boot from becoming active.

Look for related options such as:

  • Secure Boot Mode
  • OS Type
  • Key Management
  • Install Default Keys
  • Restore Factory Keys
  • Delete All Secure Boot Variables

Don't delete keys just to see what happens. If the menu offers Restore Factory Keys or Install Default Keys, that is usually the safer repair path for missing or damaged keys.

Restore the default or factory Secure Boot keys

Secure Boot uses keys, which are small digital records that tell the firmware which boot software it can trust. If those keys are missing or corrupted, Secure Boot may be grayed out, refuse to turn on, or show as enabled but inactive.

Before restoring anything, confirm that:

  • Windows is using UEFI mode.
  • CSM is disabled.
  • You have recorded the original BIOS settings.
  • You know how to return to the previous boot configuration.

Then open the Secure Boot key or key management menu. Depending on the motherboard, choose an option like:

  • Restore Factory Keys
  • Install Default Secure Boot Keys
  • Load Default Keys

The exact wording varies. The goal is to load the motherboard's built-in default keys, not to create a new key set.

After restoring the keys, return to the main Secure Boot screen. Set Secure Boot to Enabled if the option is available, save the changes, and restart. Check Windows again afterward if you need to confirm its Secure Boot status.

If the option is still unavailable, don't keep repeating the same key action. The next likely causes are the Secure Boot mode, old firmware, or a motherboard-specific menu rule.

Try the Standard and Custom Secure Boot modes carefully

Many BIOS menus offer Standard and Custom Secure Boot modes.

  • Standard normally uses the factory key set.
  • Custom exposes more key-management controls and may let you restore those keys manually.

A common troubleshooting sequence is:

  1. Open the Secure Boot menu.
  2. Change Standard to Custom.
  3. Open key management.
  4. Restore or install the factory keys.
  5. Change the mode back to Standard.
  6. Save and restart.

On some Gigabyte systems, switching from Standard to Custom and then back to Standard has helped the Secure Boot status change to On. This isn't a universal fix, and it shouldn't be your first step if you haven't checked Windows' boot mode.

Be careful with options that say Clear, Delete, or Reset all keys. Clearing keys is different from restoring the factory set. If you aren't sure what a menu item does, stop and check the manual for the exact motherboard model.

Check for outdated BIOS firmware or corrupted keys

If Windows is already using UEFI, CSM is off, and the default keys are loaded, outdated firmware may be the reason Secure Boot still won't work.

BIOS firmware is the motherboard software that controls startup and hardware settings. Older firmware can have different Secure Boot menus, missing options, or problems handling the key database.

Check the BIOS version shown on the main firmware screen. Then compare it with the instructions for your exact motherboard model. Do not install firmware meant for a similar-looking board. The model name and revision must match.

Before updating BIOS firmware:

  • Keep the PC connected to reliable power.
  • Record your current settings.
  • Read the motherboard's update instructions.
  • Avoid interrupting the update.
  • Have a recovery plan if the update resets settings.

A firmware update may reset boot options, so Windows could return to the wrong boot mode afterward. If that happens, check the boot mode and Windows Boot Manager entry before changing Secure Boot again.

If the motherboard supports loading factory Secure Boot keys but the keys won't save, or if Secure Boot remains grayed out after a firmware update, the problem may be damaged firmware settings. Resetting BIOS settings can sometimes help, but it also returns other choices to their defaults. Only do that if you know how to restore the required boot configuration.

What to do if enabling Secure Boot sends the PC back to BIOS

This is the most important failure scenario.

If turning on Secure Boot makes the computer open BIOS every time, the system may no longer see a bootable Windows setup. The usual reason is a mismatch between the new UEFI setting and the existing Legacy/MBR installation.

Try this:

  1. Enter BIOS.
  2. Reverse the last Secure Boot or boot-mode change.
  3. Re-enable the previous CSM setting if it was changed.
  4. Restore the previous boot order.
  5. Save and restart.

If Windows starts again, don't immediately try Secure Boot a second time. Open `msinfo32` and confirm BIOS Mode. If it says Legacy, the installation needs to be prepared for UEFI before you switch modes. A direct change from Legacy with an MBR drive to pure UEFI can prevent Windows from starting.

If you can't get Windows back after restoring the old settings, use the motherboard's recovery or boot-selection instructions for your model. Avoid deleting partitions or Secure Boot keys while trying to recover. Those actions can make the original setup harder to restore.

The same warning applies if you can enter BIOS but don't see Windows Boot Manager as a boot choice. First restore the previous boot setup and identify how Windows was installed.

Troubleshooting differences on ASUS and Gigabyte motherboards

Troubleshooting differences on ASUS and Gigabyte motherboards

The same idea can appear under different names, so motherboard menus can make a simple fix look impossible.

ASUS menu differences

On ASUS firmware, CSM and Secure Boot may be in different sections depending on the motherboard and firmware version. Check the Boot and Security areas, as well as any Windows-specific configuration page.

Look for options similar to:

  • Launch CSM
  • Secure Boot Control
  • OS Type
  • Key Management
  • Install Default Secure Boot Keys

If Secure Boot is unavailable, check CSM first. If it is already disabled, inspect the key management page and look for an option to install or restore the default keys. Don't assume that an option being visible means Secure Boot is active; check the status shown by the firmware.

Gigabyte menu differences

Gigabyte menu differences

Gigabyte boards may place CSM under the BIOS or Boot settings and may use Secure Boot Mode with Standard and Custom choices.

If the status remains off after loading the default keys, the Standard-to-Custom-to-Standard sequence may help:

  1. Set Secure Boot Mode to Custom.
  2. Restore the factory keys.
  3. Set the mode back to Standard.
  4. Check the Secure Boot status.
  5. Save only after confirming the settings.

Menu names can change between board generations. A setting that works on one Gigabyte model may not exist on another.

The same rule applies to ASUS, Gigabyte, and every other brand: compare the instructions for your exact motherboard model before changing a setting you can't confidently restore. If you can't identify whether Windows is using Legacy or UEFI mode, stop there and get model-specific support rather than risking a boot loop.

DH

Written by Dennis Haymon

Dennis Haymon is a security professional and manager at Safe & Sound Security LLC. With experience in security guard and patrol services, he shares practical information about protecting homes, businesses, and properties. Through Safe & Sound Security LLC, Dennis and the team provide security-focused guidance designed to help individuals and businesses better understand their security needs and available protection options.