How to Turn on Secure Boot Msi

How to Turn on Secure Boot Msi

Secure Boot on an MSI motherboard or laptop usually becomes available only after the system is set to UEFI mode. If your BIOS is still using CSM, the Secure Boot option may be hidden or locked.

The usual order is:

  1. Enter the MSI BIOS.
  2. Change BIOS CSM/UEFI Mode to UEFI.
  3. Open the Secure Boot menu.
  4. Enable Secure Boot.
  5. Save with F10 and restart.

The menu names can vary a little between MSI motherboards, laptops, and BIOS versions. The decision points are the same: check the boot mode first, then deal with a missing or greyed-out setting if needed.

What to check before changing Secure Boot settings

What to check before changing Secure Boot settings

Before changing anything, make sure you know which MSI BIOS screen your system uses. MSI Click BIOS versions can look different, and a laptop may show fewer settings than a desktop motherboard.

A few things to check:

  • Your system is an MSI motherboard or MSI laptop.
  • You can restart the computer and enter BIOS.
  • You know where the CSM/UEFI Mode setting is located.
  • You have saved any open work in Windows.

Secure Boot is commonly needed for Windows 11, but it depends on the full setup of your computer. MSI groups Secure Boot with UEFI and TPM settings in its setup guidance. If you are following a Windows 11 requirement, check those related settings too.

The key warning is simple: do not try to enable Secure Boot before changing CSM to UEFI. On many MSI systems, Secure Boot will not appear or cannot be selected while CSM is active.

How to enter the MSI BIOS

Start with the computer fully shut down or restart it from Windows.

As soon as the MSI logo appears, press the Delete key repeatedly. This normally opens the BIOS on an MSI desktop motherboard. Some MSI laptops may use a different key, such as F2, so watch for the startup message on your screen if Delete does not work.

Once BIOS opens, you may see either the simplified EZ Mode screen or the more detailed Advanced Mode screen.

If you are in EZ Mode, press F7 to switch to Advanced Mode. The exact shortcut can vary by BIOS version, so use the key shown at the bottom or side of the screen if it differs.

Do not change other BIOS settings while looking for Secure Boot. First locate the UEFI setting, then make the required change.

Switch MSI BIOS CSM/UEFI Mode to UEFI

This is the step that fixes many cases where MSI Secure Boot is not showing.

In MSI Click BIOS, open the setting for the system boot mode. Depending on your BIOS version, the path may look like this:

  1. Open the Settings tab.
  2. Select Advanced.
  3. Find BIOS CSM/UEFI Mode.
  4. Change the value from CSM to UEFI.

Some MSI BIOS versions show this setting directly in an Advanced menu. Others place it under a Windows operating system configuration area. Look for wording that includes CSM, UEFI, or Windows OS Configuration.

Choose UEFI, sometimes described as pure UEFI mode. Do not leave the system in CSM mode if you want Secure Boot to become available.

At this stage, you may see the Secure Boot menu appear after the BIOS refreshes its options. If it does not, continue to the next step and look for it manually.

Enable Secure Boot in MSI Click BIOS

After changing the boot mode to UEFI, use the Secure Boot path shown in MSI’s BIOS layout:

Settings > Advanced > Windows OS Configuration > Secure Boot

Inside the Secure Boot screen:

  1. Open Secure Boot.
  2. Change the setting to Enabled.
  3. Check that the new value remains selected.
  4. Press F10 to save the BIOS changes.

Some systems may show the setting under a nearby Windows OS or security menu instead. If you do not see it in the exact location above, stay in Advanced Mode and check Windows OS Configuration.

The important part is that the system must be using UEFI first. If the Secure Boot setting is present but cannot be changed, return to the CSM/UEFI setting and confirm that it is set to UEFI rather than CSM.

Save the changes and restart

Press F10 after enabling Secure Boot. MSI BIOS should show a confirmation screen listing the changes you are about to save.

Review the list. You should see changes related to:

  • BIOS CSM/UEFI Mode, now set to UEFI
  • Secure Boot, now enabled

Confirm the save and let the computer restart.

If Windows starts normally, allow it to finish loading before checking the setting. If the system returns to BIOS instead, look at the boot settings again and confirm that UEFI is still selected. Do not keep changing unrelated options.

What to do if Secure Boot is missing

What to do if Secure Boot is missing

If you cannot find Secure Boot anywhere, check the boot mode before assuming the feature is unavailable.

Check CSM first

Return to:

Settings > Advanced > BIOS CSM/UEFI Mode

If the value is CSM, change it to UEFI. Save or apply the change if your BIOS asks you to, then return to:

Settings > Advanced > Windows OS Configuration > Secure Boot

The menu may appear only after the system is set to pure UEFI mode.

Check the Advanced Mode screen

Check the Advanced Mode screen

Secure Boot may not be visible in MSI EZ Mode. Press F7 to open Advanced Mode, then check the full settings list.

Look under:

  • Settings
  • Advanced
  • Windows OS Configuration

The labels can differ between MSI BIOS versions, so look for the words Secure Boot and Windows OS Configuration rather than expecting every screen to match.

Check for an AM4 BIOS update

Check for an AM4 BIOS update

For some MSI AM4 motherboards, the BIOS may need an update before Secure Boot can be enabled. If your AM4 board is already set to UEFI and the Secure Boot menu is still absent, check the BIOS version and the update information for your exact MSI model.

Use the update instructions for that specific motherboard. Do not install a BIOS file meant for another model.

What to do if Secure Boot is greyed out

A greyed-out Secure Boot option usually points back to the boot mode.

Open:

Settings > Advanced > BIOS CSM/UEFI Mode

If it is set to CSM, change it to UEFI. Then return to:

Settings > Advanced > Windows OS Configuration > Secure Boot

The Secure Boot control should be available after the BIOS is using pure UEFI mode.

If the setting is still greyed out:

  1. Confirm that the CSM/UEFI setting actually stayed on UEFI.
  2. Return to the Secure Boot page after changing the mode.
  3. Save the change with F10 if the BIOS requires a restart before showing the new option.
  4. Re-enter BIOS and check Secure Boot again.
  5. If the board is an AM4 model, consider whether a BIOS update is needed.

Avoid changing other security or boot options at random. The CSM-to-UEFI change is the main fix for this specific MSI Secure Boot problem.

AM4 motherboards and possible BIOS updates

AM4 users can run into a separate issue: the board may support the feature, but its current BIOS version may not expose the Secure Boot controls correctly.

If you have an MSI AM4 motherboard and Secure Boot is still missing after switching to UEFI, check these points:

  • The exact motherboard model
  • The installed BIOS version
  • The BIOS update notes for that model
  • MSI’s instructions for updating that board

Update only when the BIOS information for your exact board indicates that it is needed. Keep the model name and BIOS version in front of you while checking. AM4 boards do not all use the same BIOS files.

After the update, enter BIOS again and repeat the normal path:

Settings > Advanced > BIOS CSM/UEFI Mode > UEFI

Then open:

Settings > Advanced > Windows OS Configuration > Secure Boot

If Secure Boot is now listed, enable it and press F10 to save.

How to confirm the setting is enabled in Windows

After Windows restarts, you can check the result from inside the operating system.

Press Windows key + R, type `msinfo32`, and press Enter. In System Information, look for Secure Boot State. It should show On when the BIOS change worked.

You can also restart the computer and re-enter BIOS to check the Secure Boot setting directly. It should still show Enabled, and the boot mode should remain UEFI.

If Windows reports that Secure Boot is off, return to BIOS and check both settings together. Secure Boot should be enabled, and BIOS CSM/UEFI Mode should be set to UEFI. If the menu is missing or unavailable, use the matching troubleshooting section above instead of changing unrelated BIOS options.

Follow the MSI BIOS path that matches your screen, then use the missing-option or greyed-out troubleshooting steps if Secure Boot is not available.

DH

Written by Dennis Haymon

Dennis Haymon is a security professional and manager at Safe & Sound Security LLC. With experience in security guard and patrol services, he shares practical information about protecting homes, businesses, and properties. Through Safe & Sound Security LLC, Dennis and the team provide security-focused guidance designed to help individuals and businesses better understand their security needs and available protection options.