How to Enable Secure Boot Asrock
Secure Boot on an ASRock motherboard is not always a single on/off switch. You usually need to move the system from compatibility mode to UEFI, choose the right Secure Boot mode, and load the factory keys. The menu names can vary between boards such as the B450 and B650, so use the path below as a guide rather than assuming every screen will look identical.
Check these points first
Before changing BIOS settings, make sure you can return to the BIOS if Windows does not start. Secure Boot changes how the motherboard checks the files used to start the operating system.
You should also know which Windows version you use. The steps apply to Windows 10 and Windows 11, but Windows 11 commonly checks for Secure Boot during setup or compatibility checks.
A few things to keep in mind:
- Save any work and shut down open programs.
- Do not turn off the computer while saving BIOS changes.
- Take note of your current BIOS settings if you have changed settings for storage, boot order, or hardware.
- Use the exact ASRock instructions for your motherboard if a menu is missing.
- Expect the BIOS screen on an older B450 board to look different from a newer B650 board.
The main path is:
- Enter BIOS with F2.
- Disable CSM under Boot.
- Open Secure Boot under Security.
- Set Secure Boot Mode as required, usually Custom for the factory-key setup.
- Install the factory default keys.
- Save and check the Secure Boot status.
The order matters. Secure Boot settings may stay unavailable or inactive while CSM is still enabled.
Enter the ASRock BIOS setup
Start or restart the computer. As soon as the ASRock logo or the first startup screen appears, press F2 repeatedly.
This opens the ASRock BIOS setup. On some keyboards, pressing the key once at exactly the right moment can be difficult, so repeated presses during POST—the early startup check—are usually more practical.
If Windows starts normally, restart and try again. You may need to begin pressing F2 immediately after the computer powers on.
Once the BIOS opens, look for the main tabs across the top or along the side. ASRock boards commonly group startup settings under Boot and security settings under Security, but the exact layout depends on the board and BIOS version.
Do not change unrelated options while looking for the settings. BIOS changes take effect before Windows loads, so an incorrect setting can stop the system from reaching Windows.
Disable CSM to enable UEFI mode
CSM is the compatibility setting that allows older, non-UEFI startup methods. Secure Boot works through UEFI, so CSM needs to be disabled first.
In the ASRock BIOS:
- Open the Boot tab.
- Select CSM, or Boot\CSM if the BIOS shows the path in that form.
- Set CSM to Disabled.
This is the key step for enabling the UEFI path on the ASRock systems covered here.
After setting CSM to Disabled, check whether new boot or security options appear. Some BIOS versions hide Secure Boot controls until compatibility support is turned off.
A warning about the next restart
Do not assume that disabling CSM is harmless for every existing Windows installation. A system installed using one startup method may not boot if the motherboard is switched to another. If Windows stops loading after this change, return to the BIOS and review the CSM setting before making more changes.
For now, stay in the BIOS if the Secure Boot menu is available. You can save the complete set of changes later.
Open Secure Boot and choose the required mode
With CSM disabled, open:
Security → Secure Boot
On some ASRock BIOS screens, this appears as Security\Secure Boot.
Look for Secure Boot Mode. Set it to Custom when the BIOS instructions or the factory-key option require that mode.
The label may differ by model. You might see a mode selector, a key-management page, or a separate option for restoring default keys. Do not worry if your B450 or B650 board places those controls in a slightly different order. The goal is still the same:
- CSM is disabled.
- Secure Boot settings are visible.
- Secure Boot Mode is set to the mode needed for key installation.
- The factory default keys are available to install.
Do not confuse Secure Boot Mode with the final Secure Boot status. A mode such as Custom controls how the BIOS handles the Secure Boot key settings. It does not always mean Secure Boot is already active.
That distinction explains why a system can show User Mode or an inactive status while you are still finishing the setup.
Install the factory default Secure Boot keys
In the Secure Boot area, look for an option such as:
- Install factory default keys
- Install default Secure Boot keys
- Load factory keys
The wording can change with the ASRock model and BIOS version.
Choose the factory-key option and confirm the prompt if one appears. These keys give the firmware the information it needs to check approved startup files.
If the option is greyed out, check the earlier steps:
- Return to Boot\CSM.
- Confirm that CSM is set to Disabled.
- Return to Security\Secure Boot.
- Check Secure Boot Mode again.
- Look for the factory-key option once more.
Some boards show key-management entries only after the mode has been changed. Others may show them immediately but require a separate confirmation before anything is loaded.
Avoid deleting keys or changing individual key databases unless your exact ASRock manual tells you to do so. For a normal Windows 10 or Windows 11 setup, the factory-key option is the safer path to check first.
Save the BIOS changes and confirm Secure Boot status
Once CSM is disabled, Secure Boot Mode is set correctly, and the factory keys are installed, save the changes.
Use the BIOS option for Save Changes and Exit, or the save-and-exit key shown on your screen. Confirm the prompt, then allow the computer to restart.
After the restart, check whether Windows loads. If it does, you can confirm the result from the BIOS by pressing F2 again and returning to:
Security → Secure Boot
Look for a status that shows Secure Boot as active or enabled. The exact words can differ between ASRock boards.
You may see User Mode during this process. That label alone does not tell you whether Secure Boot is currently active. Check the separate Secure Boot status field as well as the mode field.
If the status is active, the ASRock Secure Boot setup is complete. If it still says inactive, use the checks below before changing more settings.
What to do if ASRock Secure Boot is not active
An inactive status usually means one part of the chain has not been completed. Work through the settings in order instead of repeatedly switching the main Secure Boot toggle.
Check CSM again
Return to:
Boot → CSM
Make sure CSM still says Disabled. If it has returned to Enabled, Secure Boot may not become active because the system is still allowing the older compatibility startup path.
Save the setting again if needed, then return to the Secure Boot page.
Check the mode and keys
Open:
Security → Secure Boot
Review Secure Boot Mode. If the ASRock instructions for your screen use Custom to manage the keys, select Custom and check for the factory-key option.
Then verify that the factory default keys were actually installed. Seeing the option on the screen is not the same as completing the installation. If the BIOS displayed a confirmation prompt, the change may not be complete until you accepted it and saved the BIOS afterward.
Treat “User Mode” as a clue, not the final answer
If the BIOS shows User Mode, do not immediately assume something is broken. User Mode refers to the state of the Secure Boot key setup. The important question is whether the separate Secure Boot status says active.
If Secure Boot remains inactive, review these three items together:
- CSM: Disabled
- Secure Boot Mode: The required mode, including Custom where shown
- Factory keys: Installed
Save after making the changes. Then check the status again rather than changing several other BIOS options at the same time.
B450 and B650 screens may not match
An ASRock B450 BIOS can use older-looking tabs and different wording from a B650 BIOS. The path may still be based on Boot\CSM and Security\Secure Boot, but the key options may be placed on another part of the Secure Boot page.
If you cannot find the setting, do not substitute a similarly named option at random. Check the manual for the exact motherboard model and BIOS version.
How to handle an ASRock BIOS loop after enabling Secure Boot
An ASRock BIOS loop happens when the computer keeps returning to setup instead of starting Windows. This can occur after changing CSM or Secure Boot, but the exact cause depends on the board and the existing Windows boot setup.
First, stay calm and avoid changing multiple settings at once. Use the loop to review the settings that were just changed.
Recheck the CSM setting
Press F2 if needed and open:
Boot → CSM
Look at the current value. If CSM is Disabled and the computer began returning to BIOS immediately after that change, note the setting before trying anything else.
You can temporarily review or restore the previous CSM setting to see whether Windows starts again. Make only one change, save it, and test the next restart. This helps show whether the loop is tied to the UEFI and compatibility setting.
Recheck Secure Boot Mode and keys
If the loop began after installing keys, return to:
Security → Secure Boot
Review Secure Boot Mode and the factory-key setting. Make sure the BIOS did not leave the system in an unexpected combination of mode and key settings.
Do not delete keys as a first response. The safer first step is to inspect the current mode, confirm the CSM state, and compare the screen with the instructions for your exact ASRock board.
Check the boot choice
A BIOS loop can also mean the firmware is not selecting the Windows boot entry after the startup settings change. Look at the available boot entries and the current boot order, but do not remove entries you do not recognize.
If Windows does not appear as a usable boot option, return to the last setting that allowed the system to start and check the motherboard-specific guide. The right fix depends on how that Windows installation was set up.
If the system keeps returning to BIOS
Use this careful sequence:
- Enter BIOS with F2.
- Record the current CSM, Secure Boot Mode, and Secure Boot status.
- Change only the setting most recently changed.
- Save and restart.
- If the loop continues, return to BIOS and compare the settings again.
A B450 board and a B650 board may react differently, so do not assume a setting that works on one model will behave the same way on another.
If the menu names or Secure Boot status still differ from these steps, check the manual for your exact ASRock motherboard and its model-specific BIOS guide before making further changes.