How to Enable Secure Boot on Msi Motherboard
Secure Boot is enabled in your MSI motherboard’s BIOS, but the exact menu can vary by board and BIOS version. The main decision is simple: if Secure Boot is missing or unavailable, check whether the firmware is still using CSM instead of UEFI.
Before changing that setting, make sure you understand how your current Windows installation is configured. Switching firmware modes can affect an existing installation, so don’t change it casually if you’re unsure. If your PC is already set up for UEFI, the change should be more straightforward.
Check these settings first
Secure Boot works with UEFI, the newer firmware mode used by modern Windows systems. It generally won’t be available while the motherboard is using CSM. CSM is a compatibility mode for older boot setups.
You’ll need:
- Access to your MSI motherboard’s BIOS
- The ability to restart the computer
- A few minutes to save and test the change
- Care with any existing Windows installation
If you’re enabling Secure Boot for Windows 11, remember that Secure Boot is only one part of the system’s requirements. MSI also groups Secure Boot, TPM, and UEFI mode together in its setup guidance. Enabling Secure Boot alone doesn’t guarantee that every Windows 11 requirement is met.
The setting may also have a different name or location depending on your MSI board. Don’t worry if the screen in your BIOS doesn’t look exactly like another MSI screenshot.
Open MSI BIOS and switch from CSM to UEFI
You’ll make the first change inside MSI Click BIOS. Save your work in Windows, then restart the PC.
1. Enter the BIOS
As the computer starts, press the Delete key repeatedly. Keep pressing it as soon as the MSI logo appears.
Some systems may respond to another key, but Delete is the usual key for entering MSI BIOS.
If Windows starts normally, restart and try again. You may need to begin pressing the key sooner.
2. Open Advanced mode
MSI Click BIOS can open in a simpler screen. If you see an Advanced button or an EZ Mode screen, press F7 to switch to Advanced mode.
The labels may differ slightly between MSI BIOS versions, so look for the mode switch near the top or bottom of the screen.
3. Find the firmware mode setting
Look for a setting named BIOS CSM/UEFI Mode. It may appear under a BIOS settings menu rather than in the same place on every motherboard.
Set it to:
> UEFI
If it already says UEFI, leave it as it is and move on to the Secure Boot setting.
If it says CSM, changing it to UEFI may make the Secure Boot option appear. However, changing firmware mode can affect how an existing operating system starts. If you’re concerned about your current Windows installation or important files, pause here and check that configuration before continuing.
Enable Secure Boot in MSI Click BIOS
Once the motherboard is using UEFI, look for Secure Boot. MSI BIOS versions commonly use one of these two menu paths.
Path 1: Settings > Security
- Open Settings.
- Select Security.
- Find Secure Boot.
- Change the setting to Enabled.
This path is common in MSI Advanced View. If you don’t see Secure Boot there, don’t assume the feature is unavailable. Try the second path below.
Path 2: Settings > Advanced > Windows OS Configuration
- Open Settings.
- Select Advanced.
- Open Windows OS Configuration.
- Select Secure Boot.
- Change Secure Boot to Enabled.
Some MSI BIOS versions place the option inside Windows OS Configuration, while others show it directly under Security. Both paths lead to the same type of firmware setting.
If Windows 11 is your reason for changing this
The setting you want is Secure Boot: Enabled. Don’t confuse that with the motherboard’s separate TPM or security-device options.
MSI’s setup guidance often discusses Secure Boot, TPM, and UEFI together because all three can matter during a Windows 11 check. Still, this guide focuses on Secure Boot. If Windows 11 continues to report a missing requirement, check the other requirement separately rather than changing random BIOS settings.
Save the setting and restart
After setting Secure Boot to Enabled, press F10.
MSI BIOS should show a confirmation screen listing the changes. Check that the changes include the firmware mode or Secure Boot setting you intended to change.
Choose Yes or confirm the save-and-restart prompt.
The computer will reboot. In some cases, the system may need another restart before Secure Boot keys are enrolled and the setting becomes active. If the first restart doesn’t appear to finish the process, allow the computer to restart again before changing more settings.
Don’t turn off the PC while the BIOS is saving or while the system is restarting.
Why Secure Boot may be missing from the BIOS
A missing Secure Boot option usually points to the current firmware mode or a different BIOS menu layout.
Work through these checks:
- Return to MSI BIOS by restarting and pressing Delete.
- Press F7 if needed to open Advanced mode.
- Find BIOS CSM/UEFI Mode.
- Set it to UEFI if it is still set to CSM.
- Save the change and restart if MSI asks you to.
- Open BIOS again.
- Check both Secure Boot locations:
- Settings > Security
- Settings > Advanced > Windows OS Configuration > Secure Boot
The option may only become visible after the system is set to UEFI. This is the first thing to check before looking for a special key or trying unrelated settings.
If you still can’t find it, your board may use a different MSI BIOS layout. Read the menu labels carefully and look for Security, Windows OS Configuration, or Secure Boot rather than relying on one exact screenshot.
What to do when Secure Boot is greyed out
A greyed-out setting can’t be changed from its current screen. On MSI motherboards, start by checking the firmware mode:
- Is BIOS CSM/UEFI Mode set to UEFI?
- Are you in Advanced mode rather than the simplified EZ Mode?
- Have you checked both possible menu paths?
- Have you saved the UEFI change and restarted before returning to Secure Boot?
If the system is still using CSM, switch to UEFI first. Secure Boot needs UEFI, so the option may remain unavailable until that change is made.
If the setting remains greyed out after the restart, avoid changing several firmware options at once. Write down the current values, return to the UEFI and Secure Boot screens, and check the displayed state before making another change. MSI BIOS versions don’t all expose the same controls in the same order.
How User Mode, Setup Mode, and key enrollment affect Secure Boot
You may see a Secure Boot status labeled User Mode or Setup Mode. These labels describe the Secure Boot state, so they can make the process look more confusing than it is.
User Mode
If the BIOS says User Mode, the system is in a Secure Boot key state that may affect what actions are available. If you see a message such as “Secure Boot can be enabled when system in User Mode,” don’t keep toggling the same setting without saving.
First check that:
- BIOS CSM/UEFI Mode is set to UEFI.
- Secure Boot is set to Enabled, if the option is available.
- You save with F10.
- You let the system restart.
A reboot may be needed for the motherboard to enroll the Secure Boot keys. After the restart, return to BIOS and check the Secure Boot status again.
Setup Mode
Setup Mode means the BIOS is showing a different Secure Boot key state. The exact controls available from there can vary by MSI BIOS version.
Don’t guess at key-management options or change them randomly. Start with the basic path: confirm UEFI mode, check Secure Boot, save, and restart. If the board still shows Setup Mode or won’t allow Secure Boot to turn on, record the exact message shown on screen and use the BIOS instructions for your specific MSI board.
Why the keys matter
Secure Boot relies on firmware keys to check trusted boot software. The supplied MSI guidance indicates that a restart may be required before those keys are enrolled.
That’s why saving the setting and rebooting is part of the process, rather than an optional last step. If the status doesn’t change immediately, restart once more and check the screen again before assuming the motherboard failed to save the setting.
How to confirm Secure Boot is enabled for Windows 11
After Windows starts, check whether Windows can see the firmware setting.
- Press Windows + R.
- Type `msinfo32`.
- Press Enter.
- In System Information, find Secure Boot State.
- Check that it says On.
You can also restart and check the setting directly in MSI BIOS. The expected state is:
- Firmware mode: UEFI
- Secure Boot: Enabled
If Windows still says Secure Boot isn’t enabled, compare both places. If BIOS says Secure Boot is enabled but Windows reports otherwise, restart again and check whether the system returned to UEFI mode. If the BIOS still shows CSM, Secure Boot won’t work as expected.
If your PC is still failing a Windows 11 check, review the UEFI and Secure Boot settings against the steps above before changing anything else. Then explore the site’s other practical guides for the remaining parts of your PC setup.