How to Know If Secure Boot Is Enabled
The quickest way to check Secure Boot is from inside Windows. You don't need to restart your PC or change any BIOS settings first. Windows 10 and Windows 11 both give you built-in tools that show whether Secure Boot is On, Off, or unavailable.
Use Windows Security for a quick check
Windows Security gives you the simplest answer.
- Open the Start menu.
- Type Windows Security.
- Open the app.
- Select Device security.
- Look for Secure Boot.
The status should say On if Secure Boot is enabled.
This is the fastest answer if you only need to know whether Secure Boot is active before installing software, changing firmware settings, or checking a Windows 11 upgrade.
If you don't see a clear Secure Boot status, use the System Information tool next. It shows two fields that give you more detail.
Check the exact status with msinfo32
The `msinfo32` tool, also called System Information, shows both your boot mode and Secure Boot state.
- Press Windows key + R.
- Type `msinfo32`.
- Press Enter.
- In the System Information window, make sure System Summary is selected.
- Find these two entries:
- BIOS Mode
- Secure Boot State
For the expected Secure Boot setup, the fields should read:
- BIOS Mode: `UEFI`
- Secure Boot State: `On`
You can use the search box at the bottom of the window if you have trouble finding either field. Click the window first, then type part of the field name, such as `Secure Boot`.
This check works well when you're asking how to know if Secure Boot is enabled in Windows 11 or how to know if Secure Boot is enabled in Windows 10. The labels are the same in both versions.
What each field tells you
BIOS Mode tells you how Windows started. For Secure Boot to work in the expected way, it should show UEFI.
Secure Boot State tells you the current Secure Boot status. The value you want is On.
The two fields answer different questions. Seeing `UEFI` does not, by itself, prove that Secure Boot is enabled. You should also check that Secure Boot State says `On`.
How to read Secure Boot State and BIOS Mode
Use this quick guide to make sense of what you see:
| BIOS Mode | Secure Boot State | What it means |
|---|---|---|
| UEFI | On | Secure Boot is enabled and active in the expected setup |
| UEFI | Off | The PC is using UEFI, but Secure Boot is disabled |
| Not UEFI | Off or unavailable | Windows did not start in the UEFI mode needed for the expected Secure Boot setup |
| UEFI | Unsupported | Windows or the firmware does not report Secure Boot as available |
The exact display can vary slightly between computers. The key result is still the same: BIOS Mode should say UEFI, and Secure Boot State should say On.
If Secure Boot State says Off, Secure Boot isn't currently enabled. If it says Unsupported, don't assume the setting is simply turned off. Your firmware or current boot setup may not support it in its present state.
Also, don't assume Secure Boot is enabled just because you're running Windows 10 or Windows 11. Check the actual status instead.
Check Secure Boot in your PC’s BIOS or UEFI settings
Windows is usually the best first check. If the result is unclear, you can look directly in the computer's firmware settings.
People often call this screen the BIOS, even though newer PCs commonly use UEFI firmware. It opens before Windows starts and contains settings for how the computer boots.
To check it:
- Save your work and restart the PC.
- Watch the first screen for a message that tells you which key opens BIOS, UEFI, or Firmware Settings.
- Press that key during startup.
- Look for a setting named Secure Boot.
The setting may be under a menu such as Boot, Security, or Authentication. The exact menu depends on your computer or motherboard.
You don't need to change anything just to check the setting. Look for whether Secure Boot is shown as Enabled, Disabled, or something similar.
Be careful here. Firmware menus can include settings that affect whether Windows starts. If your goal is only to verify Secure Boot, write down the current setting and exit without saving changes.
After you leave the firmware screen, return to Windows and check `msinfo32` again. The result you want is still:
- BIOS Mode: `UEFI`
- Secure Boot State: `On`
That Windows check confirms what the operating system actually sees after the firmware starts the PC.
What it means if Secure Boot is Off or unsupported
A status of Off means Secure Boot is available but not enabled at the moment. You may need to review the Secure Boot setting in BIOS or UEFI before changing it.
A status of Unsupported means Windows isn't reporting Secure Boot as available in the current setup. In that case, changing a random firmware option may not fix the issue. First check:
- What BIOS Mode says in `msinfo32`
- Whether the firmware has a Secure Boot setting
- Whether the current boot mode is UEFI
If BIOS Mode doesn't say `UEFI`, the PC isn't using the boot mode expected for an active Secure Boot setup. Make changes carefully. A boot-mode change can affect whether the existing Windows installation starts.
If you are checking before a game installation or another software requirement, use the exact requirement shown by that software. Don't change firmware settings just because one status looks unfamiliar.
Why Windows 11 users may need to verify Secure Boot
Secure Boot often comes up during Windows 11 upgrade checks. It can also appear in setup instructions or troubleshooting steps.
That doesn't mean Windows 11 automatically turned Secure Boot on. The current state can differ from one PC to another, so verify it rather than guessing.
Before an upgrade, run both Windows checks if you want a clear record:
- Open Windows Security > Device security and check the Secure Boot status.
- Run `msinfo32`.
- Confirm BIOS Mode says `UEFI`.
- Confirm Secure Boot State says `On`.
If Windows Security shows On and `msinfo32` shows `UEFI` plus `On`, you have the expected result. If the values don't match, use `msinfo32` and the BIOS or UEFI screen to investigate before changing anything.
Check Secure Boot on Linux with mokutil
Linux users can check the firmware status with `mokutil`. The command needs administrator access.
Open a terminal and run:
```bash
sudo mokutil --sb-state
```
Enter your password if Linux asks for it. The command reports whether Secure Boot is enabled or disabled.
This is useful when Windows isn't installed, when you're working from a Linux system, or when you want to confirm the firmware status from another operating system. As with the Windows check, read the result carefully. An enabled result means Secure Boot is enabled according to the system's current firmware state.
What to do if Secure Boot is enabled but not active
Sometimes the settings you see don't line up. For example, the firmware screen may appear to show Secure Boot enabled, while Windows Security doesn't show On. Treat that as a status mismatch rather than assuming everything is ready.
Go through these checks:
- Restart Windows and check Windows Security > Device security.
- Run `msinfo32`.
- Confirm BIOS Mode is `UEFI`.
- Confirm Secure Boot State is `On`.
- If it still isn't active, restart and review the Secure Boot setting in BIOS or UEFI.
- Exit without saving if you aren't sure which setting to change.
If Secure Boot is Off, check the BIOS or UEFI settings next. If you're preparing for a Windows 11 upgrade, use the Windows 11 setup requirements guide after you confirm the current state.