How to Enable Secure Boot and Tpm 2.0
Secure Boot and TPM 2.0 are separate security settings. A game, tournament tool, Windows feature, or other app may require both before it will run. The good news is that you can check TPM 2.0 in Windows first, then change only the firmware settings you actually need.
The menu names vary by motherboard and PC maker. Treat the paths below as examples, not fixed rules.
What Secure Boot and TPM 2.0 do—and why both may be required
TPM 2.0 is a security feature built into many newer PCs. It can appear as a physical TPM setting or as firmware-based TPM support. On AMD systems, that firmware option is often called AMD CPU fTPM.
Secure Boot is a separate setting in BIOS or UEFI firmware. It controls whether the PC starts with approved boot software.
They are not the same feature. A PC can have TPM 2.0 enabled while Secure Boot is off, or the other way around. That is why a game or system check may still reject the computer after you turn on only one of them.
Before changing anything, use this simple diagnosis:
- If TPM 2.0 is already ready in Windows, you may only need Secure Boot.
- If TPM 2.0 is missing or unavailable, check the BIOS/UEFI setting.
- If both settings appear enabled but Steam or a game still complains, verify them again after a full restart and check the manufacturer-specific menu names.
A warning before changing BIOS settings
BIOS and UEFI control important startup settings. The exact screens differ between ASUS, MSI, Gigabyte, Dell, HP, Lenovo, and other manufacturers.
Before you change anything:
- Write down the settings you plan to change.
- Change only TPM and Secure Boot-related options.
- Do not alter boot drives, storage mode, processor settings, or other options unless you know why.
- If a setting is missing, don't guess. It may be under another menu or controlled by a different firmware mode.
Check whether TPM 2.0 is already enabled in Windows
Start here. You may not need to change TPM 2.0 at all.
- Press Windows key + R.
- Type `tpm.msc`.
- Press Enter.
The TPM management window will open. Look at the Status area.
If TPM 2.0 is active, the window can show:
> The TPM is ready for use
That message tells you Windows can use the TPM. Look for the TPM version details in the same window as well. If the TPM is ready and the version is 2.0, leave that setting alone for now and move on to Secure Boot.
If Windows reports that a compatible TPM cannot be found, or says the TPM is not ready, the firmware setting may be disabled. It may also be hidden under a manufacturer-specific name.
This check is useful because it separates two common cases:
- TPM works in Windows: focus on Secure Boot.
- TPM does not appear in Windows: open BIOS/UEFI and look for the TPM option.
Do not assume a game’s warning is accurate about which setting is missing. Check TPM directly in Windows before changing firmware options.
Open the BIOS/UEFI settings
You need to enter the motherboard’s firmware setup. This is the screen that appears before Windows loads.
The common method is:
- Restart the computer.
- As it starts, repeatedly press Delete.
- Wait for the BIOS or UEFI setup screen.
Some PCs use another key. The correct key depends on the manufacturer and model. If Delete does nothing, look for the startup key shown on the screen or use the Windows recovery route below.
Use Windows advanced startup instead
Windows can also take you to a recovery menu where you can choose the firmware settings.
One listed route is:
- Open Settings.
- Go to Update & Security.
- Select Recovery.
- Under advanced startup, choose Restart now.
- After the PC restarts, select Troubleshoot.
- Choose Advanced options.
- Select the option for UEFI Firmware Settings, if it appears.
- Choose Restart.
The wording can vary by Windows version. If you do not see a UEFI firmware option, the PC may use a different startup setup, or the manufacturer may provide its own recovery path.
Once BIOS or UEFI opens, look for an Advanced Mode option if the first screen is a simplified view. MSI systems, for example, may place the useful controls under Advanced Mode, then Settings or Boot. That is an example of one manufacturer’s layout, not a universal path.
Enable TPM 2.0, including AMD fTPM options
TPM settings can be placed under several different menus. Check areas named:
- Security
- Advanced
- Trusted Computing
- CPU Configuration
- Firmware TPM
- Security Device Support
The label may simply say TPM, TPM Device, or Security Device. On AMD systems, look for AMD CPU fTPM. The “f” refers to firmware-based TPM support, so you may not see a separate physical TPM chip listed.
Common manufacturer differences
There is no single BIOS path that works on every motherboard.
- On an AMD system, search for AMD CPU fTPM and enable it.
- On an MSI system, you may first need to switch to Advanced Mode, then check Settings for TPM-related controls.
- On another motherboard, the same control may be under Security or an advanced processor menu.
If you find an option that disables or enables a security device, set it to Enabled. If there is a choice between a firmware TPM and a separate hardware TPM, don't change that choice unless you understand which device your PC uses.
After enabling the setting, check the page for a version or device-status entry. You want the system to expose TPM 2.0, not an older version.
If TPM is not visible
First, use the BIOS search feature if your firmware has one. Search for `TPM`, `fTPM`, or `security`.
Then check the system type:
- AMD systems often use the AMD CPU fTPM label.
- Intel systems may use a firmware TPM label that is different from AMD’s wording.
- Branded PCs may place the control under a simple Security menu rather than an overclocking or processor menu.
If the setting still does not appear, do not enable random security options. Leave the menu, restart Windows, and run `tpm.msc` again. A missing firmware option may be a manufacturer limitation, a different menu location, or a sign that the PC does not expose the feature in the expected way.
Enable Secure Boot and confirm UEFI mode
Secure Boot is usually found under a Boot, Security, or Authentication menu.
Look for a setting named Secure Boot and set it to Enabled. On an MSI board, for example, the path may involve Advanced Mode, then Settings, then Boot. Other systems may put it directly under Security.
Before turning it on, confirm that the firmware is using UEFI mode. Secure Boot is tied to the UEFI startup method, so the option may be unavailable or inactive when the system is using a different legacy startup mode.
The labels may include:
- UEFI/Legacy Boot
- Boot Mode
- CSM
- Legacy Support
- Secure Boot
These names differ by manufacturer. If you see a choice between UEFI and a legacy mode, don't change it casually. Boot-mode changes can affect whether Windows starts. If Secure Boot is greyed out, first look for a UEFI or legacy-mode setting in the same Boot menu.
If Secure Boot is already enabled
Leave it enabled. You don't need to turn it off and on again.
Instead, confirm that TPM 2.0 is also ready in Windows. Remember, Secure Boot and TPM 2.0 are checked separately. Seeing one enabled does not prove that the other is working.
Save changes and restart safely
When both settings are ready, save the firmware changes.
Most BIOS and UEFI screens have a Save & Exit option. Some also show a key shortcut for saving. Read the confirmation screen before accepting it. Make sure it lists only the changes you intended to make.
The PC will restart. Let it boot into Windows normally.
If Windows starts as usual, continue with the checks below. If the PC returns to firmware setup or does not start Windows, go back into BIOS/UEFI and review the last boot-mode change. Do not keep changing unrelated settings. Restore the previous value if you recorded it.
A safe process looks like this:
- Enable TPM 2.0 or AMD CPU fTPM.
- Confirm Secure Boot and UEFI settings.
- Save once.
- Restart.
- Check both settings in Windows or firmware.
Saving after each random change makes troubleshooting harder because you won't know which setting caused a problem.
Check Secure Boot and TPM 2.0 after restarting
Now verify the result instead of relying on the BIOS screen alone.
Check TPM 2.0 in Windows
Press Windows key + R, type `tpm.msc`, and press Enter.
Look for the status message:
> The TPM is ready for use
Then check that the TPM version shown is 2.0. If the message still says that no compatible TPM can be found, return to BIOS/UEFI and review the TPM setting. On an AMD PC, look specifically for AMD CPU fTPM.
Check Secure Boot separately
Restart the PC and enter BIOS/UEFI again using the same method you used earlier, commonly the Delete key during startup.
Open the Boot or Security menu and confirm that Secure Boot still shows Enabled. Also check that the startup mode remains UEFI, where that option is shown.
This second check matters because a saved TPM setting does not confirm Secure Boot. They are independent controls.
If your game or software offers its own system check, run it only after these two checks pass. A restart is often required before another program sees a firmware change.
What to do if Steam or a game still does not detect them
This is the third diagnosis: both settings seem enabled, but Steam or another game still reports a problem.
Work through the checks in order rather than changing more BIOS options at random.
1. Restart again
A full restart gives Windows and the game another chance to read the firmware state. Don't judge the result immediately after leaving BIOS. Start Windows, wait for the desktop, and then run the game or its security check again.
2. Check TPM with `tpm.msc`
Press Windows key + R, enter `tpm.msc`, and look for The TPM is ready for use.
If that message is missing, the game may be reacting to a real TPM problem even if the BIOS menu showed an enabled option. Return to the firmware and confirm the correct TPM label for your hardware.
3. Check Secure Boot in BIOS/UEFI
Go back into firmware setup and confirm Secure Boot is still enabled. Also verify UEFI mode. Some menus show the option in a different place after you switch to Advanced Mode.
For an MSI example, check Advanced Mode, then review Settings and Boot. On another board, those same controls may be under Security or a firmware authentication menu.
4. Check for a mismatch between settings
A game may require both features. These combinations can cause confusion:
- TPM 2.0 is ready, but Secure Boot is disabled.
- Secure Boot is enabled, but TPM 2.0 is not ready.
- Both settings were changed, but the PC was not restarted afterward.
- Secure Boot appears enabled in one menu, while the system is not using UEFI mode.
- You enabled a general security option, but not the actual TPM or fTPM setting.
Treat the game’s warning as a prompt to verify both settings, not as proof that one specific menu is wrong.
5. Use the manufacturer’s wording
If an instruction says “enable TPM,” your motherboard may use a different label. AMD systems may show AMD CPU fTPM. MSI systems may require Advanced Mode before the relevant settings appear.
Avoid following a path copied from another motherboard as if it were universal. The same feature can sit in Security on one PC, Advanced on another, and Settings or Boot on a third.
If Steam or the game still does not detect the features after the Windows check and the firmware check, compare the exact requirement shown by that game or software with your current settings. Then restart once more and verify TPM 2.0 and Secure Boot independently before trying the software again.