How to Enable Secure Boot State

How to Enable Secure Boot State

Before changing anything in BIOS, check the two Windows status lines that matter: BIOS Mode and Secure Boot State. This tells you whether Secure Boot is simply turned off or whether the PC is using a mode that may not support it.

Secure Boot is a firmware setting that helps the computer check startup software before Windows loads. Many people look for it when moving from Windows 10 to Windows 11. The setting is controlled by your PC’s BIOS or UEFI firmware, not by a normal Windows switch.

Check Secure Boot State and BIOS Mode in Windows

Start in Windows. You don’t need to restart the PC just to see the current settings.

  1. Press Windows key + R.
  2. Type `msinfo32`.
  3. Press Enter.

The System Information window will open. Find these two entries in the main section:

You may see results such as:

  • BIOS Mode: UEFI
  • Secure Boot State: On
  • Secure Boot State: Off
  • Secure Boot State: Unsupported

The result tells you which path to follow:

  • If Secure Boot State says On, it’s already enabled.
  • If it says Off, the PC may be ready for you to turn it on in BIOS or UEFI.
  • If it says Unsupported, check BIOS Mode before changing anything.
  • If BIOS Mode does not say UEFI, enabling Secure Boot may not be a simple toggle.

This status-first check can save you from changing a setting that your current startup setup isn’t ready to use.

Confirm whether the PC is using UEFI mode

In System Information, look at BIOS Mode.

For the guidance in this article, it should say:

> UEFI

UEFI is the newer firmware mode used by modern PCs. Older systems may use a mode often shown as Legacy instead. The exact wording can vary, but the key point is that Secure Boot is tied to the UEFI setup.

If BIOS Mode already says UEFI, you can usually continue by checking the Secure Boot option in BIOS or UEFI.

If it shows something other than UEFI, stop before switching settings. Changing firmware options without checking how Windows starts can leave the computer returning to BIOS instead of loading Windows. That does not mean the PC is broken, but it does mean you should first follow the instructions for your exact motherboard or computer model.

Also, don’t assume that a PC with Windows installed is automatically using UEFI. Windows can be installed and working while Secure Boot State still says Off.

Enter BIOS or UEFI settings

BIOS and UEFI settings open before Windows starts. You normally enter them by restarting the PC and pressing a key when the computer first begins to boot.

The key depends on the manufacturer. Some systems show the key briefly on screen. If yours doesn’t, use the support instructions for your exact PC or motherboard model.

Before entering firmware settings:

  • Save any open files.
  • Keep the PC connected to power if it’s a laptop.
  • Note the current settings if you plan to change more than Secure Boot.
  • Change only the setting you understand.

The menus are different from one computer to another. A Dell screen won’t necessarily use the same labels as an HP, Lenovo, ASUS, or custom-built PC. You may see BIOS Setup, UEFI Firmware Settings, or simply Setup.

Manufacturer menu differences

The Secure Boot option may be placed in different areas:

  • ASUS: On at least one ASUS interface, press Delete to enter setup, switch to Advanced Mode, open Boot, then select Secure Boot. Other ASUS models may use slightly different labels.
  • Lenovo: Look through the Security, Boot, or a similar firmware section. The exact screen depends on the model.
  • Dell: Check the Boot or Security area. Some Dell systems place related startup controls in a broader boot configuration section.
  • HP: Look under Security or Boot Options. HP firmware screens can differ between desktops and laptops.
  • Other manufacturers: Start with Boot, Security, or Authentication. If you can’t find the setting, search the on-screen help or the manufacturer’s instructions using the full model name.

These are starting points, not guaranteed menu paths. Don’t enable random options just because their names sound related.

Find Secure Boot under the Boot or Security menu

Once BIOS or UEFI is open, look for a tab or menu named Boot or Security. On some systems, the setting may be under Authentication, Advanced, or a similar heading.

Look for one of these labels:

  • Secure Boot
  • Secure Boot Control
  • Secure Boot State
  • OS Type, with Secure Boot included nearby

You may first need to open an advanced view. Some firmware interfaces show only a simple screen at first. Look for an option such as Advanced Mode if the basic screen doesn’t show the setting.

If the Secure Boot option is greyed out, don’t force a change. A disabled control can mean that another firmware setting must be changed first, or that the system is not currently configured for UEFI startup.

Read the surrounding text carefully. Firmware menus often include warnings that are easy to miss, and the names may not match the wording used in Windows.

Enable Secure Boot and save the BIOS changes

When you find the setting, select Secure Boot and change it from Disabled or Off to Enabled or On.

The wording varies. Some systems use a drop-down menu. Others use the Enter key, arrow keys, or a small selection window.

After changing it:

  1. Open Save & Exit, or use the save command shown on screen.
  2. Confirm that you want to save the change.
  3. Let the PC restart.
  4. Wait for Windows to load.

Don’t turn off the computer while the firmware is saving or restarting. Also, don’t change several unrelated settings at the same time. If something goes wrong, it’s much easier to identify the cause when Secure Boot was the only change.

Once Windows starts, press Windows key + R, enter `msinfo32`, and press Enter again. Check Secure Boot State.

If the change worked, it should now show On. If it still says Off, return to the firmware settings and check whether the change was actually saved.

What to check when Secure Boot is disabled

A Disabled or Off status does not necessarily mean there is a serious problem. It usually means the feature is available but not currently active.

Start with the two Windows checks:

  • BIOS Mode should say UEFI.
  • Secure Boot State should say Off if the feature is available but not enabled.

If BIOS Mode says UEFI, restart and look for Secure Boot under Boot or Security. It may be listed under a different name, especially on a laptop or a custom motherboard.

If you can see Secure Boot but can’t select it, look for a related setting or a required firmware mode. Don’t guess at changes. Write down the exact labels you see and compare them with the instructions for your model.

If the setting turns on but Windows no longer starts, return to BIOS and undo the change. A system that stops loading Windows needs configuration troubleshooting, not repeated attempts to restart it.

For someone preparing for Windows 11, the useful check is the result in `msinfo32` after the firmware change. Don’t rely only on what the BIOS screen appeared to show.

What Secure Boot State unsupported means

What Secure Boot State unsupported means

When System Information says Secure Boot State: Unsupported, Windows is telling you that Secure Boot isn’t available in the current setup. This is different from simply being turned off.

First, check BIOS Mode.

If BIOS Mode is not UEFI, that is the first issue to investigate. The computer may be using a different startup mode, so the Secure Boot control may be missing, unavailable, or unable to work in its current state.

If BIOS Mode already says UEFI but Secure Boot still shows Unsupported, check the firmware menus. Look under Boot, Security, and any advanced settings. Some systems use different names or hide the option until another firmware choice is set correctly.

There are several possible reasons the option may not appear:

  • The firmware interface places it under an unexpected menu.
  • The PC is in a startup mode that doesn’t match the Secure Boot setup.
  • The firmware uses different wording.
  • The model has limited firmware options.

Avoid treating “unsupported” as a sign that repeatedly switching settings will fix it. Check the exact PC or motherboard model and use its support instructions if the option remains unavailable.

Troubleshoot being sent back to BIOS after enabling Secure Boot

Troubleshoot being sent back to BIOS after enabling Secure Boot

If enabling Secure Boot sends you back to BIOS instead of Windows, don’t keep restarting over and over. A BIOS loop means the firmware is not proceeding to Windows as expected.

Start by checking the setting you just changed:

  1. Open the firmware menu again.
  2. Confirm whether Secure Boot is still enabled.
  3. Check the boot settings and the available Windows startup entry.
  4. Make sure the PC is still configured to use the startup mode it used before the change.
  5. Save only the needed correction and restart.

The exact boot labels differ between manufacturers. You may see a boot list, a Windows entry, or a general boot order screen. Don’t move entries around unless you know what they control.

If you can’t get Windows to load, return Secure Boot to its previous setting and save the change. This is a recovery step, not proof that Secure Boot can never be used. The problem may be a mismatch between the firmware mode and the way Windows was installed.

Once Windows loads again, open `msinfo32` and check BIOS Mode and Secure Boot State. Those two lines give you a clearer picture than the BIOS screen alone.

If Secure Boot remains unavailable, or the computer keeps returning to BIOS, stop making repeated changes. Verify the two Windows statuses, then consult the support instructions for your motherboard or PC manufacturer.

DH

Written by Dennis Haymon

Dennis Haymon is a security professional and manager at Safe & Sound Security LLC. With experience in security guard and patrol services, he shares practical information about protecting homes, businesses, and properties. Through Safe & Sound Security LLC, Dennis and the team provide security-focused guidance designed to help individuals and businesses better understand their security needs and available protection options.