Does Windows 11 Require Secure Boot
Windows 11 needs your PC to support Secure Boot through UEFI firmware. That does not always mean Secure Boot must stay enabled every time Windows starts.
That difference explains most of the conflicting answers online. Some installation checks look for Secure Boot support. Other guidance says Secure Boot must be turned on during an upgrade or installation. Windows 11 may also run after Secure Boot is turned off.
So the practical answer is:
- Supported installation: Your PC should be Secure Boot capable, and the official installer may require Secure Boot to be enabled.
- Unsupported installation: It may be possible to install Windows 11 without Secure Boot, but Microsoft does not officially support that setup.
- After installation: Some guidance says Windows 11 does not need Secure Boot enabled to boot.
Before changing firmware settings, check what your PC supports. “Capable of Secure Boot” and “Secure Boot is currently on” are two different things.
What Secure Boot requirement appears during a Windows 11 upgrade or installation
Windows 11 installation checks can focus on the PC’s firmware, not only on the current Secure Boot switch.
UEFI is the newer firmware system that starts your computer before Windows loads. Older PCs may use a legacy BIOS mode instead. Secure Boot is a feature provided through UEFI.
That means a PC can be in one of these situations:
- It supports UEFI and Secure Boot, but Secure Boot is turned off.
- It uses UEFI, but Secure Boot is unavailable or cannot be used.
- It is running in legacy BIOS mode and does not expose Secure Boot.
- It can technically support Secure Boot, but a firmware setting is blocking it.
The Windows 11 installer may report that the PC must support Secure Boot when it detects the second or third situation. It can also show the message when the computer is capable of Secure Boot but the firmware is not set up correctly.
This is why simply seeing Secure Boot: Off does not always mean the PC fails the requirement. “Off” can mean the feature exists but has not been enabled. “Unsupported” usually points to a deeper firmware or hardware limitation.
The search results also differ on whether Secure Boot must be enabled for the installation itself. Treat that as a distinction between the official installation path and other installation methods. If the normal installer asks for Secure Boot, the safest response is to enable it rather than trying to work around the check.
Can you install Windows 11 without Secure Boot?
In some cases, yes. The search results describe ways to install Windows 11 without Secure Boot, and some also mention installing without other required checks.
That does not make the setup officially supported by Microsoft.
An unsupported installation can leave you outside the normal requirements for Windows 11. You may also run into problems later when the system checks hardware or firmware settings again. The available guidance is not fully consistent about which checks apply during setup and which settings Windows needs after it is installed.
There are two separate questions here:
- Can the installation be made to run?
- Is the resulting Windows installation supported?
A bypass may answer the first question while leaving the second unanswered. If you are upgrading a computer you rely on, use the supported path whenever possible:
- Confirm that the PC uses UEFI firmware.
- Confirm that Secure Boot is available.
- Turn Secure Boot on if the installer requires it.
- Run the Windows 11 upgrade or installation again.
If Secure Boot is genuinely unavailable, you can research an unsupported installation method. But do not treat that as a normal fix for the error. It is a workaround with no promise that the PC meets Microsoft’s requirements.
Why Windows 11 may say the PC must support Secure Boot
The message usually means Windows Setup cannot confirm the required firmware capability. It does not always mean that the computer has no Secure Boot feature at all.
Common reasons include:
- The PC is starting in legacy BIOS mode instead of UEFI mode.
- Secure Boot is turned off in the firmware settings.
- The firmware has a setting that hides or disables Secure Boot.
- The computer is old enough that Secure Boot is not available.
- The installer cannot read the firmware state correctly.
The wording matters. “Secure Boot state unsupported” is different from “Secure Boot state off.”
- Off generally means Secure Boot is available but disabled.
- On means the feature is active.
- Unsupported means Windows cannot use Secure Boot in the current firmware setup, or the hardware and firmware do not provide it.
Do not change random firmware options just because the error appears. Firmware settings control how the computer starts, and a wrong change can prevent Windows from loading until the setting is corrected.
How to check Secure Boot and UEFI/BIOS support
You can check the current state from Windows before entering firmware setup.
Check in System Information
- Press Windows key + R.
- Type `msinfo32`.
- Press Enter.
- Look for BIOS Mode.
- Look for Secure Boot State.
The results tell you whether Windows is currently using UEFI or legacy firmware and whether Secure Boot is on, off, or unsupported.
Read the two lines together:
- UEFI + Secure Boot On: The PC is already using the feature.
- UEFI + Secure Boot Off: The PC may support it, but you need to enable it in firmware.
- Legacy + Secure Boot Unsupported: The PC is not currently using the firmware mode needed for Secure Boot.
- UEFI + Secure Boot Unsupported: Check the firmware settings and the PC’s documentation. The feature may be disabled, hidden, or unavailable.
You can also check the firmware setup screen. Restart the PC and use the key shown during startup to enter UEFI or BIOS settings. The key varies by computer maker. Look for menus named Boot, Security, Authentication, or something similar.
The exact wording differs between PCs. That is normal. You are looking for a Secure Boot option and for a setting that identifies the startup mode as UEFI rather than legacy or compatibility mode.
How to enable Secure Boot on a Windows 11 PC
Before changing anything, save important files and make sure you know how to return to the current settings. If the firmware screen offers a way to save or take a photo of the existing configuration, use it.
The general process looks like this:
- Open Settings in Windows.
- Go to the recovery options and choose the option to restart into advanced startup.
- Select the option for UEFI firmware settings, if it appears.
- Restart into the firmware setup screen.
- Find Secure Boot.
- Change it to Enabled.
- Save the changes and restart.
You can also enter firmware setup during startup, using the key shown on screen by the computer maker.
Some systems will not let you turn Secure Boot on while a legacy compatibility mode is active. That mode may be called Legacy Boot, CSM, or something close to it. If you see such an option, check the PC maker’s instructions before changing it. The goal is to use UEFI, but changing startup modes without checking the existing setup can affect whether Windows starts.
If Secure Boot is greyed out, the firmware may require another setting first. It might also require default Secure Boot keys or a change from a custom security mode to a standard mode. The names and order vary by manufacturer, so do not assume every PC uses the same menu.
After Windows starts again, open `msinfo32` and check Secure Boot State. It should show On. Then run the Windows 11 installer again.
What to do when Secure Boot cannot be enabled or shows as unsupported
Start by separating a configuration problem from a hardware limit.
If the PC shows Secure Boot State: Off, enter UEFI firmware and look for the Secure Boot setting. Check whether legacy or compatibility startup mode is blocking it. If the option is still unavailable, look for firmware updates or instructions from the computer maker.
If the PC shows Secure Boot State: Unsupported, check BIOS Mode in System Information. A legacy mode can explain why Secure Boot is unavailable to Windows. The computer itself may still have UEFI support, but switching modes can affect the existing Windows installation, so do not make that change casually.
If the firmware has no Secure Boot option at all, the PC may not support the feature. At that point, check the model’s firmware documentation. Avoid guessing based only on the age or brand of the computer.
When the installer still says the PC must support Secure Boot, work through this order:
- Check BIOS Mode and Secure Boot State in `msinfo32`.
- Confirm that the firmware screen actually offers Secure Boot.
- Check whether legacy or compatibility mode is preventing access to it.
- Look for a firmware update from the PC maker.
- Save the current settings before making further changes.
- Try the supported Windows 11 installation again.
If the PC truly cannot support Secure Boot, an unsupported bypass may still be possible according to some installation guides. That does not change the requirement or make the computer officially supported. Keep that option separate from troubleshooting a PC that simply has Secure Boot turned off.
Does Windows 10 require Secure Boot?
Windows 10 is not the same case as Windows 11. The Windows 11 checks are the reason this issue appears so often during an upgrade. A Windows 10 PC may run with Secure Boot off, but that does not prove the computer meets the Windows 11 installation requirements.
Use the Windows 11 checks for the Windows 11 decision. Check UEFI mode and Secure Boot capability instead of assuming that a working Windows 10 installation will automatically qualify.
Is Secure Boot better on or off after Windows 11 is installed?
For a supported Windows 11 setup, leaving Secure Boot enabled is the safer choice when your PC supports it and Windows starts normally afterward.
The supplied guidance is not fully consistent about whether Secure Boot must remain enabled for Windows 11 to boot. Some results say it only needs to be enabled before installation or upgrade. Others describe it as a required Windows 11 feature. That is why it helps to separate the installation check from the system’s current boot behavior.
If you turn Secure Boot off after installation, Windows may still start. But disabling it can put the PC outside the setup path expected by some Windows 11 checks. There is little reason to switch it off unless you have a specific firmware or boot problem and understand the trade-off.
If you are seeing unsupported, do not begin with a bypass. First check your PC’s UEFI/BIOS mode and Secure Boot state. Those two details will tell you whether Secure Boot is already active, available but disabled, blocked by a firmware setting, or not supported by the computer at all.