How to Disable Secure Boot Asus
Secure Boot is a firmware security feature that checks whether your computer is starting approved boot software. It helps protect Windows from some boot-level threats, but it can also block an older operating system, a custom boot tool, or hardware setup that needs a different boot mode.
The steps below focus on the menu differences that often confuse ASUS users. A standard motherboard, ASUS TUF or ROG system, and VivoBook laptop may not show the same screens.
Before disabling Secure Boot: what to check and what may change
Before changing anything, confirm that you really need Secure Boot turned off. If Windows 11 is working normally and you don't need to start another operating system or tool, leaving it enabled is usually the safer choice.
Disabling it may affect:
- Windows 11 security features that rely on Secure Boot
- The ability to start software that expects Secure Boot to be active
- Your system's boot mode
- The way an older operating system or external boot drive starts
You may also see references to CSM. CSM stands for Compatibility Support Module. It lets some systems use older, non-UEFI boot methods. Secure Boot is tied to the newer UEFI boot process, so some ASUS firmware versions ask you to change CSM before Secure Boot can be turned off.
That doesn't mean CSM must be changed on every ASUS computer. Treat it as a troubleshooting branch, not a required first step.
A warning about Secure Boot keys
Some ASUS firmware screens include options for Secure Boot keys. These keys tell the firmware which boot software it trusts.
Don't clear all Secure Boot keys just because you're trying to disable Secure Boot. That is a different action and can create more boot problems. If your firmware asks you to manage or remove keys, first look for an option to save or back them up. If the screen specifically requires a key change, guidance for some ASUS systems recommends deleting only the Platform Key (PK) rather than removing every key.
If you only need Secure Boot disabled, change the Secure Boot setting and leave the keys alone whenever possible.
Enter the ASUS UEFI BIOS and switch to Advanced Mode
You need to change Secure Boot from the ASUS UEFI firmware settings, often called the BIOS.
From a powered-off ASUS computer
- Shut down the computer completely.
- Press the power button.
- As soon as the computer starts, repeatedly press Delete.
- Wait for the ASUS BIOS or UEFI screen to appear.
On some ASUS laptops, another startup key may be used, or Windows may open the firmware screen through its recovery options. If pressing Delete does nothing, use Windows 11:
- Open Settings.
- Go to System, then Recovery.
- Find Advanced startup and choose Restart now.
- Select the options for troubleshooting and UEFI firmware settings.
The exact Windows labels can vary slightly by Windows version. The goal is to restart into firmware settings rather than into the normal desktop.
Once the ASUS screen opens, look for Advanced Mode. Many motherboard BIOS screens start in EZ Mode, which shows a simpler set of controls. Press F7, or select the on-screen Advanced Mode command if it appears.
The ASUS motherboard route commonly starts with powering on the system, pressing Delete, and moving into Advanced Mode. But don't expect every TUF, ROG, or laptop screen to use the same layout.
Disable Secure Boot in the ASUS Security or Boot settings
In Advanced Mode, look for a tab named Boot or Security. ASUS firmware versions place Secure Boot in different areas.
On many ASUS motherboards, try this path:
- Open the Boot tab.
- Select Secure Boot.
- Find OS Type, Secure Boot Control, or a similar setting.
- Change the setting to Other OS or Disabled, depending on what your firmware shows.
Some screens use OS Type instead of a clear on/off switch. Choosing Other OS can turn off the Secure Boot behavior on those models. Other ASUS systems show Secure Boot Control with a direct Enabled or Disabled choice.
Don't change several boot settings at once. First look for the Secure Boot control that your screen actually provides.
If you find Secure Boot under Security, the process is much the same:
- Open the Security tab.
- Select Secure Boot.
- Change the available control to the non-Secure Boot option.
- Leave the key-management section unchanged unless the firmware specifically requires a key action.
The words may differ by firmware version. The important part is to identify the Secure Boot setting, rather than assuming that a guide for one ASUS model matches yours exactly.
When ASUS requires CSM or another boot-mode change
If Secure Boot is missing, locked, or cannot be changed, check whether your BIOS includes CSM.
A common troubleshooting path is:
- Open the Boot tab in Advanced Mode.
- Look for Launch CSM or Compatibility Support Module.
- If the setting is available, review its current state.
- Return to the Secure Boot menu and check whether new options are now visible.
On some ASUS systems, enabling CSM is part of turning Secure Boot off. On others, CSM is hidden, unavailable, or unrelated to the setting you need. Don't force this change simply because you saw it in another guide.
Changing CSM can change how the computer looks for boot devices. If Windows was installed for UEFI, switching to an older boot mode may leave you at a boot error or make the Windows drive harder to start. Record the original CSM and boot settings before changing them.
If your goal is to start Windows 11 normally after disabling Secure Boot, keep the change as small as possible. Change only the setting needed for your hardware or boot tool.
ASUS TUF and ROG menu variations
TUF and ROG systems often use a more detailed BIOS layout. Their menus may include extra firmware sections that don't appear on a basic ASUS motherboard screen.
On some ASUS TUF systems, users find Secure Boot through a route that includes:
Firmware → Advanced → Secure Boot
That wording may appear in a firmware or security area rather than directly under the first Boot menu. If you don't see Secure Boot on the first screen, move into Advanced Mode and check the deeper firmware menus.
For an ASUS TUF or ROG motherboard, try this order:
- Enter the BIOS with Delete.
- Press F7 for Advanced Mode.
- Check Boot for Secure Boot.
- If it isn't there, check Security, Firmware, or an Advanced section.
- Look for OS Type, Secure Boot Control, or the Secure Boot key menu.
ROG screens may show more labels and options than a basic board. That does not mean you need to change all of them. Avoid changing boot priority, storage settings, or key databases unless your specific problem calls for it.
The same approach applies to an ASUS TUF laptop. Its firmware may look different from a TUF desktop motherboard even though both carry the TUF name.
Why ASUS laptops such as VivoBook may not show a simple Disable option
If you're searching for how to disable Secure Boot ASUS laptop, don't be surprised if a VivoBook doesn't show a plain Disable button.
Some ASUS VivoBook firmware screens don't provide one direct switch. Instead, they may show a Secure Boot state, an operating system type, or key-management controls. The wording can also depend on the exact VivoBook model and firmware version.
Check these areas:
- Security
- Boot
- Advanced
- Secure Boot
- OS Type
- Key Management
If you find OS Type, the non-Windows or Other OS option may be the setting that changes Secure Boot behavior. If you only see key controls, don't immediately clear the keys. That is more destructive than simply turning off Secure Boot.
A laptop may also hide certain firmware options until you set a firmware administrator password or change another boot setting. Because that behavior differs by model, check the instructions shown on your own screen before making another change. Don't guess at a key-management action.
This is why a motherboard guide may not solve a VivoBook problem. The feature has the same name, but the control can be placed somewhere else—or may not appear as a single disable switch at all.
What to do when Secure Boot cannot be disabled
If you can't disable Secure Boot on an ASUS system, work through these checks in order.
1. Confirm you're in Advanced Mode
EZ Mode may hide the menu you need. Press F7 and check again.
2. Search more than one tab
Look under Boot, Security, Firmware, and Advanced. ASUS does not use one universal menu path.
3. Check for an OS Type setting
A screen that lacks a direct switch may use Windows UEFI Mode and Other OS choices instead. If Other OS is available, it may be the intended alternative to Secure Boot.
4. Check the CSM branch
If the Secure Boot control is locked or absent, look for Launch CSM. Changing it may reveal additional Secure Boot choices, but write down the original value first.
5. Don't clear every Secure Boot key
Key Management is not the same as the Secure Boot on/off setting. Save keys if your firmware offers that option. If the firmware requires a key change, avoid deleting all keys when removing only the PK is the supported choice.
6. Check for a firmware password or lock
Some laptop firmware screens restrict security settings until an administrator password or similar firmware control is set. If your screen explains that a setting is locked, follow that exact instruction rather than changing unrelated options.
If none of these checks helps, note your ASUS model, the BIOS version, and the exact labels on screen. A VivoBook, TUF board, ROG board, and standard ASUS motherboard may need different instructions.
Save the changes and verify the new boot configuration
After changing Secure Boot, press F10 or choose Save & Exit. Read the confirmation screen before accepting it. Make sure you are saving the intended change and not resetting every BIOS setting.
The computer should restart. Check whether it now starts the operating system or boot device you were trying to use.
If Windows 11 no longer starts, return to the UEFI settings and review:
- Secure Boot
- CSM
- Boot priority
- The Windows boot drive
Restore the original setting if the change caused the problem. If you later need to enable Secure Boot on ASUS Windows 11, return to the same firmware area and restore the Windows UEFI or Secure Boot-enabled option, then save and restart.
Your ASUS model's firmware screen is the deciding guide here. Compare the labels on your motherboard, TUF, ROG, or VivoBook with the branches above, and check the site's other practical troubleshooting articles before changing additional BIOS settings.