How to Enable Secure Boot on B450 Tomahawk Max

How to Enable Secure Boot on B450 Tomahawk Max

Secure Boot on the MSI B450 Tomahawk Max is enabled in the motherboard BIOS. For a Windows 11 upgrade, you may also need UEFI mode and TPM 2.0 turned on. These settings are related, but they are not the same thing.

Use this order: check the BIOS version, confirm UEFI mode, enable TPM support, then turn on Secure Boot. Don’t change the boot mode blindly. If Windows was installed in legacy mode, switching to UEFI can stop the system from booting until the installation is prepared for it.

What Secure Boot, UEFI mode, and TPM have to do with the Windows 11 upgrade

Each setting handles a different part of the startup process:

  • UEFI mode is the modern firmware mode used instead of legacy BIOS or CSM mode.
  • Secure Boot checks that approved boot software is being used when the PC starts.
  • TPM 2.0 provides hardware-backed security features that Windows can use.

Windows 11 upgrade checks may look for all three. Secure Boot cannot work properly with a legacy boot setup, so UEFI mode needs to be confirmed first. TPM is separate from Secure Boot, which means enabling one does not automatically enable the other.

Your goal on the B450 Tomahawk Max is to have:

  • The system booting in UEFI mode
  • Security Device Support enabled under Trusted Computing
  • Secure Boot enabled
  • TPM available to Windows

The exact wording can vary between BIOS revisions, so don’t worry if a label looks slightly different after an update.

Check the MSI B450 Tomahawk Max BIOS version first

Before changing security settings, check whether the board is running a current BIOS version. The MSI B450 Tomahawk Max has had multiple BIOS revisions, and an older version may hide or handle Secure Boot controls differently.

  1. Restart the PC.
  2. Press Delete repeatedly as soon as the MSI logo appears.
  3. Look at the BIOS screen for the installed BIOS version.
  4. Compare it with the latest BIOS listed for the exact B450 Tomahawk Max model.

Make sure you select the Max model if MSI lists the original B450 Tomahawk separately. The files are not interchangeable just because the board names are similar.

If an update is needed, follow MSI’s instructions for that exact board. Do not shut down the PC during the update. Afterward, enter BIOS again and recheck the settings, since a BIOS update may reset or change some options.

If the BIOS is already current, continue without updating. A BIOS flash is not needed just because you want to enable Secure Boot.

Enter BIOS and confirm the system is using UEFI mode

Enter BIOS with the Delete key, then switch to Advanced mode if the simple EZ Mode screen appears. The F7 key commonly switches between MSI’s EZ Mode and Advanced mode, although the key prompt on the screen should take priority.

Look for the UEFI-related boot setting. On MSI boards, it is commonly found under a path similar to:

Settings → Advanced → Windows OS Configuration

Look for a setting such as:

  • BIOS UEFI/CSM Mode
  • CSM Support
  • A Windows operating system mode that selects UEFI

Choose UEFI or disable legacy CSM, depending on the wording shown by your BIOS revision.

Check before switching

If the current system uses legacy boot mode, changing straight to UEFI may cause Windows not to start. That is why you should first identify the current boot mode in Windows or in the BIOS. If you’re unsure, stop here rather than guessing.

This guide assumes Windows is already set up to boot through UEFI. The Secure Boot setting may remain unavailable until that is true.

After confirming UEFI mode, stay in BIOS and move to the TPM settings.

Enable TPM through Settings → Security → Trusted Computing

Enable TPM through Settings → Security → Trusted Computing

On the MSI B450 Tomahawk Max, the relevant TPM controls are shown through the Trusted Computing section.

From Advanced BIOS mode, use this path:

Settings → Security → Trusted Computing

This is separate from the Secure Boot menu. You’re enabling the board’s security device support here so that Windows can see the TPM security feature.

Open Trusted Computing and look for Security Device Support.

At this point, don’t assume that a TPM setting and Secure Boot are interchangeable. They are separate checks for Windows 11.

Turn on Security Device Support

Inside Trusted Computing:

  1. Select Security Device Support.
  2. Change it to Enabled.
  3. Leave the other Trusted Computing options at their current values unless you know you need to change them.
  4. Return to the main Advanced BIOS screen.

The key setting from the MSI AM4 setup path is Security Device Support. If this remains disabled, Windows may not report the TPM as available even after Secure Boot is configured.

You can now move to the Secure Boot controls. On many MSI BIOS versions, these appear under:

Settings → Advanced → Windows OS Configuration → Secure Boot

The menu may be placed slightly differently on your BIOS version. Search the Windows OS Configuration area first.

Turn on Secure Boot, then save and restart

Open the Secure Boot menu.

Before enabling it, confirm that the system is set to boot in UEFI mode. If the BIOS still shows a legacy or CSM boot configuration, Secure Boot may be greyed out or may not appear at all.

When the option is available:

  1. Set Secure Boot to Enabled.
  2. Review any warning shown by the BIOS.
  3. Press F10.
  4. Confirm that you want to save the changes and restart.

The PC should reboot with the new firmware settings. If Windows starts normally, let it load fully before checking the result.

Fix the “System in Setup Mode” Secure Boot warning

Some B450 BIOS screens show this message:

> System in Setup Mode! Secure Boot can be enabled when System is in User Mode.

This does not usually mean that the motherboard is too old for Secure Boot. It means the firmware is still in Setup Mode, so the Secure Boot keys needed for User Mode have not been loaded.

Return to the Secure Boot menu and look for a key-management option. Depending on the BIOS revision, it may be called something like:

  • Key Management
  • Install default Secure Boot keys
  • Restore factory keys
  • Enroll all factory default keys

Choose the option that loads the default Secure Boot keys. Read the confirmation prompt carefully before accepting it. Then return to the Secure Boot screen and check whether the system now shows User Mode.

Once it does:

  1. Set Secure Boot to Enabled.
  2. Press F10.
  3. Confirm the save and restart.

If the BIOS does not show any way to load default keys, check the BIOS version again. An outdated BIOS or a changed firmware layout may be behind the missing control.

What to check when the Secure Boot option is missing

What to check when the Secure Boot option is missing

On the B450 Tomahawk Max, a missing Secure Boot option usually points to one of a few BIOS conditions rather than a dead feature.

Check these items in order:

1. Confirm the exact motherboard model

Make sure the BIOS is for the MSI B450 Tomahawk Max, not the non-Max B450 Tomahawk or another MSI B450 board. The names are close, but the firmware files and menus may differ.

2. Check the BIOS version

Look for the latest BIOS update for the exact board. The available Secure Boot controls can depend on the BIOS revision. If the BIOS is old, update it using MSI’s instructions, then check the Windows OS Configuration menu again.

3. Confirm UEFI mode

Secure Boot depends on UEFI. If the board is still using CSM or another legacy boot setting, the option may be hidden, disabled, or unavailable.

Return to the UEFI-related menu and confirm that the system is configured for UEFI boot. Remember that changing this setting can affect whether Windows starts, so don’t switch it without checking the existing installation mode.

4. Look for Setup Mode

If Secure Boot is visible but cannot be enabled, check the status line. The System in Setup Mode warning means the firmware needs its default Secure Boot keys installed before it can move to User Mode.

5. Check the TPM path separately

Go to:

Settings → Security → Trusted Computing

Then confirm that Security Device Support is enabled. This will not make the Secure Boot menu appear by itself, but it completes the TPM-related part of the Windows 11 setup.

Verify the settings after the PC restarts

After saving with F10 and allowing the computer to restart, verify the settings before continuing with the Windows 11 upgrade.

Check that:

  • Windows is booting through UEFI
  • Secure Boot is shown as enabled
  • TPM 2.0 is available to Windows
  • The PC starts normally after the BIOS changes

If the system fails to boot, return to BIOS and review the UEFI or CSM setting first. If Secure Boot still shows Setup Mode, go back to the Secure Boot key-management options and load the default keys before trying again.

Once Secure Boot, UEFI, and TPM all show the expected status after the restart, you can continue with the Windows 11 upgrade.

DH

Written by Dennis Haymon

Dennis Haymon is a security professional and manager at Safe & Sound Security LLC. With experience in security guard and patrol services, he shares practical information about protecting homes, businesses, and properties. Through Safe & Sound Security LLC, Dennis and the team provide security-focused guidance designed to help individuals and businesses better understand their security needs and available protection options.