How to Turn on Secure Boot Asus

How to Turn on Secure Boot Asus

Before changing BIOS settings, save your work and make sure you know your exact ASUS model. Secure Boot changes how your PC checks software during startup. If Windows was installed in Legacy or CSM mode, switching to UEFI settings can stop the system from booting until the settings are corrected.

The path also depends on your device:

  • ASUS motherboard: look in Advanced Mode, usually under Boot.
  • ASUS laptop: the setting may appear under Security in the BIOS utility.
  • ROG, TUF, Prime, and ProArt systems: menu names can vary by model and BIOS version.

Use the decision path below rather than assuming every ASUS BIOS looks the same.

Before enabling Secure Boot: identify your ASUS device and current BIOS mode

Before enabling Secure Boot

First decide which instructions apply to your system.

  • A desktop built with an ASUS ROG, TUF, Prime, or ProArt motherboard uses the motherboard path.
  • An ASUS-branded notebook, such as a gaming or everyday laptop, uses the laptop path.

Next, check the current Windows boot mode.

  1. Press Windows key + R.
  2. Type `msinfo32`.
  3. Press Enter.
  4. Find BIOS Mode in the System Information window.

If it says UEFI, your system is using the boot mode Secure Boot normally needs.

If it says Legacy, stop before changing Secure Boot. Windows may be installed in a way that depends on the older boot method. Changing firmware settings without checking the installation can leave Windows unable to start. Confirm the correct process for your exact ASUS model and Windows setup first.

You can also check the current Secure Boot state in the same window. Look for Secure Boot State. It may show On, Off, or that the feature is unsupported.

For Windows 11 systems, also remember that Secure Boot is separate from firmware TPM settings. ASUS systems may show an fTPM option in the firmware as well. That setting can be part of Windows 11 preparation, but turning on fTPM alone does not turn on Secure Boot.

How to enter ASUS BIOS or UEFI setup

ASUS motherboard

  1. Shut down the computer completely.
  2. Turn it on.
  3. As soon as the ASUS logo appears, press the Delete key repeatedly.
  4. Enter Advanced Mode if the BIOS opens in the simpler EZ Mode view.

Some systems may use another key or show a prompt on screen. If Delete does not work, check the manual or support information for your exact motherboard.

ASUS laptop

  1. Shut down the laptop.
  2. Turn it on.
  3. Press the BIOS setup key repeatedly as soon as the ASUS logo appears.
  4. If the key does not open the BIOS, check the laptop’s model-specific instructions.

Laptop BIOS controls are often more limited than motherboard controls. You may see the Secure Boot setting under Security, while a motherboard may place it under Boot.

Do not change unrelated options while you are looking for Secure Boot. BIOS menus control core startup settings, and a wrong change can affect Windows or your hardware.

How to turn on Secure Boot on an ASUS motherboard

On many ASUS motherboards, Secure Boot is found in Advanced Mode under the Boot tab. Other ASUS BIOS versions place it in a Security screen. Follow the section that exists on your display.

  1. Open the BIOS using the Delete key.
  2. Switch to Advanced Mode.
  3. Open the Boot tab.
  4. Look for Secure Boot.
  5. Select OS Type, Secure Boot Control, or a similarly named option, depending on the BIOS version.
  6. Set the option to Windows UEFI mode or Enabled, if that is how your BIOS labels it.
  7. If you see Secure Boot Mode, leave it at Standard unless you have a specific reason to manage keys yourself.
  8. Save the changes and restart the computer.

If Secure Boot is not under Boot, check the Security tab or screen before assuming the option is missing. ASUS uses more than one menu layout across its motherboard families.

On some systems, Secure Boot controls cannot be changed while CSM is active. CSM is a compatibility setting that supports older, non-UEFI startup methods. If the BIOS shows CSM enabled, review the warning about Legacy installations before disabling it. Do not switch it off blindly if Windows currently uses Legacy mode.

For a Windows 11 PC, the usual target is:

  • BIOS Mode: UEFI
  • Secure Boot: On
  • Secure Boot Mode: Standard

The exact wording can differ, so use the setting that matches your BIOS screen and motherboard manual.

How to enable Secure Boot on an ASUS laptop

How to enable Secure Boot on an ASUS laptop

The laptop path may be different from the motherboard path. ASUS support instructions place Secure Boot inside the Security screen of the BIOS utility, although the exact menu names can vary.

  1. Enter the BIOS during startup.
  2. Open the Security tab or screen.
  3. Find Secure Boot.
  4. Change the setting to Enabled.
  5. If the laptop shows a Secure Boot mode choice, select Standard.
  6. Save the changes and restart.

If you do not find it under Security, check the Boot tab. Some laptop BIOS versions group startup controls there instead.

A laptop may hide or lock the setting when the firmware is using a non-UEFI boot mode. Check BIOS Mode in Windows before changing anything. If Windows reports Legacy mode, changing firmware settings can affect startup.

You may also see fTPM settings in the laptop BIOS. Those settings relate to the system’s firmware-based TPM. They do not replace Secure Boot, so check both settings separately if you are preparing the laptop for Windows 11.

If the laptop is managed by an organization, some BIOS options may also be locked by administrator settings. In that case, use the approved support process rather than trying random BIOS changes.

How to check that Secure Boot is active

After saving the BIOS changes and letting Windows start, check the result from Windows.

  1. Press Windows key + R.
  2. Enter `msinfo32`.
  3. Press Enter.
  4. Check BIOS Mode.
  5. Check Secure Boot State.

You want to see:

  • BIOS Mode: UEFI
  • Secure Boot State: On

If Secure Boot still says Off, return to BIOS and check whether the setting was saved. Also look for a second control such as OS Type, Secure Boot Control, or Secure Boot Mode.

If Windows does not start after the change, return to BIOS and restore the previous boot setting. Then confirm whether Windows was installed in Legacy mode before trying again. Your exact ASUS model documentation should guide the next step.

What to do when ASUS Secure Boot is greyed out

A greyed-out Secure Boot setting usually means another firmware setting or the current boot configuration is preventing changes. Use this order:

  1. Check BIOS Mode in Windows.

If it says Legacy, do not force Secure Boot on. Resolve the boot-mode issue first.

  1. Look for CSM or Legacy Boot.

Secure Boot may be unavailable while compatibility support is active. Read the warning shown by your BIOS before changing CSM.

  1. Check for a separate operating system setting.

ASUS BIOS versions may use an option such as Windows UEFI mode or OS Type. Changing this can reveal the Secure Boot controls.

  1. Check Secure Boot Mode.

If the BIOS offers Standard and Custom, use Standard for a normal Windows installation.

  1. Save, restart, and check again.

Some settings only become available after another BIOS option is changed and the system is restarted.

  1. Check your model documentation.

A laptop BIOS may intentionally expose fewer controls than a desktop motherboard BIOS.

Do not clear or replace Secure Boot keys just because the control is greyed out. Key management belongs to Custom mode and can create another problem if you do not know which keys the system needs.

What to do when there is no Secure Boot option in ASUS BIOS

What to do when there is no Secure Boot option in ASUS BIOS

If there is no Secure Boot option in BIOS on an ASUS system, work through this decision tree:

Is it an ASUS laptop?

Check Security first, then Boot. Laptop menu layouts can differ, and the feature may be shown in only one of those areas.

Is it an ASUS motherboard?

Enter Advanced Mode and check Boot. If it is not there, check Security. The motherboard family—ROG, TUF, Prime, or ProArt—does not guarantee one fixed menu path.

Is the system using Legacy mode?

Check `msinfo32` in Windows. A Legacy installation can explain why Secure Boot is hidden or unavailable. Do not switch firmware settings until you understand how Windows is installed.

Is CSM enabled?

CSM can prevent the Secure Boot controls from appearing. Review the BIOS warning and your model instructions before disabling it.

Is the BIOS version or model information unclear?

Write down the full ASUS model name and current BIOS version. Then consult the documentation for that exact model. Two ASUS systems with similar names may use different firmware layouts.

Avoid treating a missing setting as proof that the feature is broken. It may be hidden by the current boot mode, placed under another menu, or unavailable on that particular firmware version.

ASUS Secure Boot Mode: Standard or Custom

ASUS Secure Boot Mode

Choose Standard for a normal Windows installation.

Standard mode uses the firmware’s built-in Secure Boot setup. It is the sensible choice if your goal is to enable Secure Boot for Windows 10 or Windows 11 and you do not manage boot keys yourself.

Custom mode is for advanced key management. It can expose controls for changing or enrolling Secure Boot keys. Those keys decide which startup software the firmware trusts. Changing them without a clear plan can stop trusted boot software from loading.

Use this simple rule:

  • You only need Secure Boot enabled: choose Standard.
  • You are managing your own Secure Boot certificates or keys: choose Custom, and follow the exact ASUS documentation for your model.

If Standard mode is selected but Secure Boot is still off, check the UEFI and CSM settings first. Do not move to Custom mode as a general fix for a greyed-out or missing option.

Common ASUS BIOS menu differences across ROG, TUF, Prime, and ProArt systems

ASUS uses the same broad ideas across its motherboard families, but the screens may not match.

  • ROG systems may place many controls in Advanced Mode and may include extra gaming-related firmware settings.
  • TUF systems may show the same Secure Boot controls with different labels or grouping.
  • Prime systems can use a simpler layout, but Boot and Security locations still depend on the BIOS version.
  • ProArt systems may also place Secure Boot in a different screen from another ASUS motherboard.

The useful distinction is not the product family alone. It is the path your BIOS presents:

  1. Check whether the device is a laptop or motherboard.
  2. Enter BIOS or UEFI setup.
  3. Use Advanced Mode on a motherboard when needed.
  4. Check Boot, then Security.
  5. If the control is greyed out, check UEFI, Legacy, and CSM settings.
  6. If the control is missing, confirm the exact model and BIOS version.
  7. Keep Secure Boot Mode on Standard unless you are managing keys manually.

Before making another BIOS change, confirm your full ASUS model and consult its official support documentation if the Secure Boot menu or setup path differs from these instructions.

DH

Written by Dennis Haymon

Dennis Haymon is a security professional and manager at Safe & Sound Security LLC. With experience in security guard and patrol services, he shares practical information about protecting homes, businesses, and properties. Through Safe & Sound Security LLC, Dennis and the team provide security-focused guidance designed to help individuals and businesses better understand their security needs and available protection options.