How to Enable Secure Boot Gigabyte Bios

How to Enable Secure Boot Gigabyte Bios

Secure Boot is usually a BIOS setting, but the switch alone may not be enough. On some Gigabyte and AORUS boards, Secure Boot can show as enabled in BIOS while Windows still reports it as inactive. The right fix depends on what status you see, so follow the normal setup first and then use the matching recovery path if needed.

Before changing Secure Boot: confirm the PC is using UEFI mode

Secure Boot works with UEFI, the newer firmware mode used to start Windows. It does not work the same way with Legacy or Compatibility Support Module (CSM) boot settings.

Before changing anything, check whether Windows is already using UEFI mode. You can do this from Windows system information by looking for the BIOS Mode entry. It should show UEFI.

If it shows Legacy, do not immediately turn on Secure Boot. Changing boot mode without preparing Windows can leave the computer unable to start. The exact steps for moving from Legacy to UEFI depend on your Windows installation and motherboard settings.

Also check your motherboard manual before changing boot options. Gigabyte uses different BIOS layouts across its boards, including B550, H410, Intel boards, and AORUS models. The labels may move or use slightly different names.

If your PC already uses UEFI, continue with the steps below.

Enter the Gigabyte BIOS and switch to Advanced Mode

You need to make the change before Windows starts.

  1. Save any open work and restart the computer.
  2. As the computer begins to start, press the Delete key repeatedly.
  3. Wait for the Gigabyte BIOS screen to appear.
  4. If the BIOS opens in Easy Mode, press F2 to switch to Advanced Mode.

The exact screen may look different depending on the motherboard. Some AORUS boards use a similar layout but place settings under different tabs.

If pressing Delete does not open the BIOS, restart and try again as soon as the Gigabyte or AORUS logo appears. A wireless keyboard may also respond too late during startup, so a wired keyboard can help.

Once Advanced Mode is open, avoid changing unrelated settings. Secure Boot is tied to boot mode and key settings. Random changes in the same area can affect how the PC starts.

Enable the related TPM or AMD CPU fTPM setting

Enable the related TPM or AMD CPU fTPM setting

Windows 11 and some games may also check for a TPM setting. TPM is a security feature that helps Windows store and use system security information. On AMD systems, the option is often called AMD CPU fTPM.

The setting may appear in a security, trusted computing, or advanced CPU section. Menu names vary by Gigabyte model, so look for wording such as:

  • AMD CPU fTPM
  • Firmware TPM
  • TPM
  • Trusted Computing

If you have an AMD processor and see AMD CPU fTPM, enable it. One common setup path turns this on before saving the BIOS changes.

This setting is separate from Secure Boot. Enabling fTPM does not automatically turn on Secure Boot, and Secure Boot does not replace the TPM requirement. If you are preparing a Gigabyte B550 system for Windows 11, you may need both settings.

Do not change a TPM option simply because it has a similar name. If the setting is unclear on your board, check the manual for the exact model first.

Enable UEFI and open the Secure Boot menu

Now find the boot settings in Advanced Mode.

Look for a Boot, BIOS, or Secure Boot section. Some Gigabyte BIOS versions show the Secure Boot option directly. Others first require you to change a boot setting related to UEFI or disable a compatibility mode.

You may see an option connected to:

  • UEFI boot
  • Legacy boot
  • CSM Support
  • Compatibility Support Module
  • Windows 8/10 Features
  • Windows UEFI mode

The wording is not the same on every board. For the how to enable UEFI in Gigabyte BIOS question, the important point is to find the UEFI-related boot control for your exact motherboard rather than copy a menu path from a different model.

If the board is still using a Legacy or compatibility boot mode, Secure Boot may be unavailable, greyed out, or unable to become active. Set the boot configuration to the UEFI option shown by your BIOS. On some boards, this may mean disabling a compatibility setting first.

Be careful here. If Windows was installed in Legacy mode, changing this setting can stop it from booting. Confirm the Windows boot mode before making the change.

Once the system is configured for UEFI, open the Secure Boot menu.

Turn on Secure Boot and save the BIOS changes

Turn on Secure Boot and save the BIOS changes

Inside the Secure Boot menu, find the main Secure Boot control.

  1. Set Secure Boot to Enabled.
  2. Review the screen for any warning about keys or custom mode.
  3. If you also changed AMD CPU fTPM, leave that enabled.
  4. Save the BIOS changes.
  5. Exit and allow the computer to restart.

Gigabyte boards commonly use an option such as Save & Exit, though the exact label may differ.

After Windows loads, check its Secure Boot status. If it reports that Secure Boot is on, the basic setup is complete.

If BIOS says Secure Boot is enabled but Windows or another checker says it is off, do not keep toggling the main switch. That status usually means the setting was selected, but the required Secure Boot keys were not loaded correctly. Move to the troubleshooting path below.

What to do when Secure Boot says enabled but not active

The Gigabyte Secure Boot enabled not active problem is confusing because the BIOS appears to accept the setting. The main switch may say Enabled, yet Windows reports Secure Boot as inactive or off.

Treat this as a separate state from normal setup:

  • Disabled: Secure Boot is not turned on.
  • Enabled but not active: the BIOS setting is on, but the system is not using the required Secure Boot key setup.
  • Active: Secure Boot is enabled and working during startup.

Start by returning to the BIOS:

  1. Restart the computer.
  2. Press Delete during startup.
  3. Press F2 if the BIOS opens in Easy Mode.
  4. Return to the Secure Boot menu.
  5. Check whether the system is using UEFI.
  6. Look for a factory-key or key-management option.

The most common fix described for this status is to enable or restore the built-in factory keys. These keys let the firmware verify approved boot software. Without them, the Secure Boot toggle may appear enabled without becoming active.

Do not assume that switching Secure Boot off and on will load the keys. Use the key option shown in your BIOS instead.

How to enable Secure Boot on Gigabyte for Windows 11

For a Windows 11 setup, the order matters:

  1. Confirm Windows is using UEFI mode.
  2. Open Gigabyte BIOS with Delete.
  3. Switch to Advanced Mode with F2.
  4. Enable the required TPM setting, such as AMD CPU fTPM on an AMD system.
  5. Open the UEFI and Secure Boot settings.
  6. Enable Secure Boot.
  7. Restore the factory keys if the status remains inactive.
  8. Save the changes and restart.

That sequence covers the settings most often connected with a Windows 11 requirement. If Windows still reports a problem, check the status again after the restart rather than assuming the BIOS screen tells the whole story.

Restore factory keys when Secure Boot remains inactive

If Secure Boot still shows as inactive, use the key-management option in the Secure Boot menu. The labels vary, but one known path is:

Secure Boot > Custom > Restore Factory Keys

On some Gigabyte BIOS versions, you may first need to change the Secure Boot mode from Standard to Custom. Then choose Restore Factory Keys. Another version may show a direct factory-key option without requiring the same sequence.

Take your time and read each prompt. Restoring factory keys changes the firmware's Secure Boot key database. That is why you should use the exact instructions for your Gigabyte or AORUS model if the screen differs.

A cautious sequence is:

  1. Open Secure Boot in Advanced Mode.
  2. Select Custom, if your BIOS requires it.
  3. Choose Restore Factory Keys.
  4. Accept the confirmation prompt only if you intend to restore the default keys.
  5. Check that Secure Boot is enabled.
  6. Save the BIOS changes and restart.

After Windows starts, check the Secure Boot status again.

This is also the likely fix if the BIOS says Secure Boot is enabled but not active. The toggle controls the feature, while the factory keys provide the trusted key setup needed for it to operate.

What to do if the computer does not boot after the change

A boot problem after enabling Secure Boot does not always mean the motherboard is damaged. It can happen when the Windows installation uses a different boot mode, when the firmware keys do not match the setup, or when a UEFI option was changed without checking the existing installation.

If the PC will not boot normally:

  1. Restart the computer and press Delete to return to BIOS.
  2. Look for the boot settings you changed.
  3. Check whether the system is still set to the correct UEFI mode.
  4. If you can reach the BIOS but cannot restore a working setup, load or reset the UEFI defaults.
  5. Save the defaults before exiting.
  6. Restart and check whether Windows starts again.

The name may be Load Optimized Defaults, Load UEFI Defaults, or something similar. Gigabyte menu labels vary, so use the wording shown on your board.

Loading defaults can change other BIOS settings too. If you previously set a custom boot order, memory profile, fan curve, or storage setting, you may need to configure those again. If you are not sure which default option to use, check the motherboard manual before accepting it.

You may also see a Gigabyte Secure Boot violation message. Do not keep forcing the computer to boot by changing random settings. Return to the BIOS, review the UEFI and Secure Boot configuration, and use the factory-key option only when it matches your intended setup.

If the computer still will not start, reset the UEFI settings as directed by the motherboard manual, then save and exit. The recovery step is worth taking before attempting more Secure Boot changes.

If Secure Boot remains inactive after restoring the factory keys, check the related Gigabyte BIOS troubleshooting guide or the manual for your exact motherboard model. That model-specific information is the safest next step because the menu names, key options, and UEFI defaults can differ between Gigabyte and AORUS boards.

DH

Written by Dennis Haymon

Dennis Haymon is a security professional and manager at Safe & Sound Security LLC. With experience in security guard and patrol services, he shares practical information about protecting homes, businesses, and properties. Through Safe & Sound Security LLC, Dennis and the team provide security-focused guidance designed to help individuals and businesses better understand their security needs and available protection options.