How to Disable Secure Boot on Windows 11
Before changing anything, check whether Secure Boot is actually enabled. Then use Windows 11 to open your computer’s UEFI settings—the firmware menu often called BIOS—and change the setting there. The exact label and location can differ by manufacturer.
Check whether Secure Boot is currently enabled
Secure Boot is a firmware setting, so you won’t find its on/off switch in the normal Windows Settings app. You can, however, check its current status from Windows.
- Press Windows + R to open the Run box.
- Type `msinfo32`.
- Press Enter.
- In the System Information window, find Secure Boot State.
The value should show whether Secure Boot is On or Off.
This check is worth doing before you restart. If it already says Off, you don’t need to change the firmware setting. If it says On, you can continue to the UEFI menu.
If `msinfo32` doesn’t open, search for System Information from the Start menu and open that result. The same Secure Boot status appears there.
A quick note about Windows and firmware
Windows can take you to the firmware settings, but it doesn’t directly control Secure Boot from the desktop. That means searching for a Windows setting, using a normal Command Prompt command, or changing a Windows security option generally won’t replace the firmware step.
So if you’re looking for a way to disable Secure Boot on Windows 11 without BIOS, the practical answer is that you still need to reach the UEFI/BIOS menu. Windows provides a route into it; the change itself is made outside Windows.
Open UEFI firmware settings from Windows 11
Windows 11 includes a built-in Advanced startup route. It avoids guessing which key to press during startup, since those keys vary between computers.
- Open Settings.
- Select System.
- Select Recovery.
- Next to Advanced startup, select Restart now.
- Windows will restart and show a recovery menu.
- Choose Troubleshoot.
- Select Advanced options.
- Choose UEFI Firmware Settings.
- Select Restart.
Your computer should now open its firmware setup screen.
You can reach the same place another way:
- Open the Start menu.
- Select the Power button.
- Hold Shift while selecting Restart.
- Choose Troubleshoot.
- Open Advanced options.
- Select UEFI Firmware Settings.
- Choose Restart.
If you don’t see UEFI Firmware Settings, the computer may use a different firmware mode or may not expose the option through this Windows menu. In that case, check the computer maker’s instructions for entering its firmware setup.
Before restarting, save any open work. The computer will leave Windows and may take you through several menus before the firmware screen appears.
Disable Secure Boot in the BIOS/UEFI menu
Once the firmware setup screen opens, look for a menu named Security, Boot, Authentication, or something similar. Menu names vary, and some firmware screens use a simple text layout while others use a mouse-friendly interface.
Look for an item such as:
- Secure Boot
- Secure Boot Control
- Secure Boot State
- Secure Boot Configuration
Select the setting and change it to Disabled. One manufacturer support path, for example, places the control on a Security screen and calls it Secure Boot Control.
After making the change, look for a command such as Save Changes and Exit. The wording may differ. Confirm the change if the firmware asks you to do so.
Your computer should restart. Once Windows loads, use the `msinfo32` check again:
- Press Windows + R.
- Enter `msinfo32`.
- Check Secure Boot State.
It should now show Off if the change was accepted.
What if a Command Prompt is easier?
You may see advice about disable Secure Boot Windows 11 Command Prompt. Command Prompt can help you check some Windows information, but the supplied steps for this change lead to the UEFI firmware menu. Secure Boot is controlled there, not through a regular Windows command.
The Windows Advanced startup menu is the safer model-neutral route because it takes you to the firmware screen without asking you to guess a startup key.
What to do when the Secure Boot option is missing or locked
A missing or unavailable setting doesn’t always mean something is broken. The item may be in a different firmware section, or the computer may require another setup step before it can be changed.
Work through these checks:
Look in more than one firmware menu
Check Security, Boot, and any menu named Authentication or Secure Boot. Don’t assume the setting must appear under Boot. On some systems, it appears under Security instead.
Also look for a submenu with words such as Key Management, OS Type, or Secure Boot Configuration. Don’t change other items at random, though. If the menu is unclear, use the instructions for your exact computer model.
Check for a firmware password
Some computers require a BIOS or administrator password before Secure Boot can be changed. The available results point to this requirement on some systems, especially certain Acer models.
If the setting is greyed out, the firmware may be waiting for that password. The password is separate from your normal Windows sign-in password. If you don’t know it, don’t keep guessing. Check the computer’s support instructions or ask the person who set up the machine.
Confirm that you’re in the right setup screen
Windows and the firmware menu are separate. Changing a Windows boot option won’t necessarily change Secure Boot. Make sure you reached UEFI Firmware Settings, rather than only opening Windows recovery tools.
Check the exact model instructions
Manufacturer menus can differ between models from the same company. A laptop made several years ago may use different names and locations from a newer desktop made by the same brand.
The most useful details to have ready are:
- The manufacturer
- The exact model name or number
- Whether the device is a laptop or desktop
- The firmware menu where you found the setting
This is also the right step if you’re asking, why can’t I disable Secure Boot? The reason may be a required firmware password, a different menu location, or a model-specific restriction. The available results don’t establish one universal cause.
Firmware menu differences by maker
The setting can move around between manufacturers. These are useful places to check, but your exact model may use different wording.
ASUS systems
On an ASUS computer, look through the Boot and Security areas for Secure Boot or a related control. Some ASUS firmware screens may use a submenu rather than showing the switch on the first page.
If you don’t see it, check whether the firmware has a separate advanced view. Avoid changing unrelated boot settings just to find the option. Use the exact ASUS model instructions if the menu doesn’t match these names.
HP systems
On HP computers, check the firmware’s Security and Boot sections. The Secure Boot control may appear alongside other startup or security settings.
HP systems can also ask for confirmation when you change firmware options. Read the prompt before accepting it. If the item is unavailable, look for a firmware password requirement or consult the instructions for the exact HP model.
MSI systems
On MSI desktops and laptops, check the Boot section first, then look through the advanced security-related settings if the switch isn’t visible.
MSI firmware screens can offer different views. If you’re using a simplified screen, open the advanced settings only if you’re comfortable doing so, and change only the Secure Boot control you need.
Acer systems
On Acer systems, Secure Boot may appear under a Security or Boot menu. Some Acer computers may require you to set a BIOS password before the Secure Boot option can be changed.
That password requirement is a firmware setup step. It isn’t the same as changing your Windows account password. If the option stays locked, check the instructions for your specific Acer model before making any further changes.
Do you need to disable Secure Boot for Windows 11?
The available results do not establish that you must disable Secure Boot to install Windows 11. A standard Windows 11 installation question is different from a Linux or dual-boot problem.
If you’re installing Windows 11 on a computer that already supports the required setup, don’t turn Secure Boot off just because you’re preparing installation media. The supplied information does not show that disabling it is a required Windows 11 installation step.
A better approach is to identify the exact problem first:
- Is Windows refusing to start from the installation media?
- Are you trying to install another operating system?
- Are you setting up a dual-boot arrangement?
- Is a firmware option unavailable?
Those situations can lead to different instructions. Changing Secure Boot without knowing which problem you’re solving may leave you with a setting that doesn’t address the real issue.
The supplied results also don’t provide enough detail to make broad claims about specific risks from turning Secure Boot off. The clear fact here is narrower: you’re changing a setting in the computer’s UEFI/BIOS firmware. Treat it as a firmware change, record what you changed, and be ready to restore it later.
What the available results say about Linux and dual-boot setups
Linux and dual-boot setups are the main situations connected with questions about disabling Secure Boot in the available results. That doesn’t mean every Linux installation needs Secure Boot disabled. It means the setting can come up when you’re trying to start a different operating system or arrange more than one system on the same computer.
Before changing it, check the instructions for the Linux distribution and the exact computer model. The right choice can depend on the boot setup you’re trying to create. If the instructions only tell you to change Secure Boot, don’t also alter unrelated firmware options unless they specifically call for it.
For troubleshooting, keep a simple record:
- The original Secure Boot status
- The firmware menu where you found the setting
- The option you changed
- Any password or confirmation prompt shown by the firmware
That record makes it easier to reverse the change if the test or installation doesn’t solve the problem.
Restore Secure Boot after testing
To turn the setting back on, use the same Windows route:
- Open Settings > System > Recovery.
- Select Restart now beside Advanced startup.
- Choose Troubleshoot.
- Select Advanced options.
- Open UEFI Firmware Settings.
- Select Restart.
- Find the Secure Boot control in the firmware menu.
- Change it to Enabled.
- Save the change and exit.
Then return to Windows and confirm the result in System Information. Press Windows + R, enter `msinfo32`, and check Secure Boot State.
Before changing firmware settings, verify the instructions for your exact computer model. That final check matters because ASUS, HP, MSI, Acer, and other systems can place the same control in different menus or require different access steps.