How to Turn on Secure Boot with Gigabyte
If you’re preparing a Windows 11 PC or a game that requires Secure Boot, the setting lives in your Gigabyte motherboard’s BIOS/UEFI. The basic switch is easy to change. The confusing part comes when Secure Boot is missing, shows as enabled but not active, or refuses to turn on because the system is still in the wrong mode.
Use the normal steps first. If your screen doesn’t match, stop at that point and follow the model-specific notes later rather than changing random boot options.
What you need to check before enabling Secure Boot
Secure Boot works with UEFI, the newer firmware mode used to start Windows. A PC using an older Legacy boot setup may not show the Secure Boot option at all.
Before opening BIOS, check these things:
- You’re using a Gigabyte motherboard.
- You know the exact motherboard model, such as B550, B650, B760, Z390, or H410.
- Windows is already starting normally.
- You’re ready to reverse the change if Windows stops booting.
- You know that the menu names can differ between Gigabyte boards and BIOS versions.
The last point matters. A Gigabyte B550 board may place the setting in a different area from a B650 board. Even two boards from the same series can use slightly different labels.
It’s also wise to check your current Windows boot mode before making changes:
- Press Win + R.
- Type `msinfo32`.
- Press Enter.
- Look for BIOS Mode in the System Information window.
If it says UEFI, you’re in the right mode for Secure Boot. If it says Legacy, don’t simply force Secure Boot on. Changing boot settings without preparing the Windows installation can stop the PC from starting. In that case, check the motherboard and Windows setup details first, or ask a technician for help.
You can also use this window later to confirm whether the change worked.
How to enter Gigabyte BIOS/UEFI
Start with the PC fully shut down, or restart it from Windows.
As soon as the computer begins starting, press the Delete key repeatedly. Keep tapping it before Windows appears. If the timing is right, the Gigabyte BIOS/UEFI screen will open.
If Windows loads instead, restart and try again. The key needs to be pressed early in the startup process.
A few things can make this step harder:
- Some wireless keyboards may not respond early enough.
- Fast startup can shorten the time available to press the key.
- The screen may briefly show a Gigabyte logo before Windows loads.
Use a wired keyboard if the Delete key doesn’t work. If your board uses a different key or the BIOS screen never appears, check the manual for your exact model. Gigabyte’s instructions commonly use Delete, but no single key or screen layout applies to every motherboard.
Switch from Easy Mode to Advanced Mode
Gigabyte BIOS often opens in Easy Mode. This screen shows basic information and a smaller set of controls. Secure Boot may not be visible there.
Look along the bottom or top edge of the BIOS screen for an option named Advanced Mode. On some Gigabyte boards, pressing F2 switches between Easy Mode and Advanced Mode.
Once you switch, you should see more tabs and settings. Depending on the board, the main tabs may include:
- Tweaker
- Settings
- System Information
- BIOS
- Peripherals
- Chipset
- Boot
- Save & Exit
Don’t worry if your board doesn’t show every tab listed above. Gigabyte changes the layout between models and BIOS versions.
Your goal is to find the boot settings, then locate Secure Boot. The setting may be directly under the Boot tab, or it may appear inside a page named Secure Boot.
How to enable UEFI and find Secure Boot
First, check that the system is set up to use UEFI rather than Legacy boot mode.
Open the Boot tab, or check the boot-related settings under Settings. Look for wording such as:
- UEFI
- Legacy
- CSM Support
- Boot Mode
- Windows 8/10 Features
- Secure Boot
The exact label depends on the board. Some Gigabyte BIOS versions expose UEFI through a boot mode setting. Others use a Windows operating system feature setting or a Compatibility Support Module setting.
If you see a choice between Legacy and UEFI, select UEFI. If the board uses a CSM setting, the board may need CSM disabled before Secure Boot appears. Read the wording on your screen before changing it.
A warning about changing boot mode
If Windows was installed in Legacy mode, switching to UEFI can make the system fail to boot. Don’t keep changing settings if you’re unsure which mode Windows uses.
Use the BIOS Mode result in `msinfo32` as your guide. When it already says UEFI, you’re in a much better position to continue. When it says Legacy, pause and confirm that the Windows installation is ready for UEFI before changing the BIOS.
Once UEFI is available, look for Secure Boot. Common locations include:
- Boot > Secure Boot
- Settings > Secure Boot
- A Secure Boot area inside the main BIOS settings
Open the page, but don’t save anything yet. First check what the current status says. It may show Disabled, Enabled, Not Active, Standard, Custom, or a key-management option.
How to enable Secure Boot and save the BIOS changes
If the Secure Boot page has a simple switch, set Secure Boot to Enabled.
On some boards, that’s all you need to do. On others, the setting won’t become active until the board has Secure Boot keys loaded and the system is placed in User mode. We’ll cover those cases in the troubleshooting sections.
After changing the setting:
- Open Save & Exit.
- Choose the option to save changes and restart.
- Confirm the changes if the BIOS asks.
- Let Windows start normally.
Some Gigabyte BIOS versions also use a keyboard shortcut for saving, but the menu option is safer if you’re not sure. Read the confirmation box carefully. It should show that Secure Boot or the related UEFI setting is being changed.
If Windows starts normally, don’t assume the job is finished. Check the status from inside Windows.
How to confirm Secure Boot is active in Windows
Windows has a built-in way to check Secure Boot.
- Press Win + R.
- Enter `msinfo32`.
- Press Enter.
- In System Information, find Secure Boot State.
- Check whether it says On.
You can also confirm the BIOS Mode entry in the same window. It should show UEFI.
The result you want is:
- BIOS Mode: UEFI
- Secure Boot State: On
This check is more useful than relying only on the BIOS toggle. A BIOS page can show that Secure Boot is enabled while Windows still reports that it isn’t active.
If Windows says Off, Disabled, or Not Supported, return to BIOS and use the decision path below.
What to do when Secure Boot is enabled but not active
This is one of the most common points of confusion. The BIOS setting may read Enabled, but Windows still reports Secure Boot as inactive.
Work through these checks in order.
1. Confirm that Windows is using UEFI
Open `msinfo32` again and check BIOS Mode.
If it says Legacy, Secure Boot won’t become active just because you enabled the switch. The Windows installation and the motherboard’s boot mode need to match the UEFI setup.
Return to BIOS and review the UEFI, Legacy, CSM, or Boot Mode settings. Don’t make several changes at once. If you’re unsure what the current setup means, stop and check your exact motherboard manual.
2. Check for factory keys
Some Gigabyte troubleshooting instructions require the motherboard’s Secure Boot factory keys to be loaded.
In BIOS, open the Secure Boot page. If you see a setting such as Custom, open it and look for an option to enable or install the factory keys. The wording may be different on your board.
After loading the keys:
- Return to the main Secure Boot page.
- Check whether the status changes.
- Save the BIOS settings.
- Boot into Windows.
- Check `msinfo32` again.
Don’t delete or clear keys unless you know why you’re doing it. The goal here is to load the board’s standard factory keys, not remove the existing key data.
3. Check the system mode
A Gigabyte BIOS may show a system mode such as Setup mode or User mode. One common reason Secure Boot won’t activate is that the system still needs to be in User mode.
If the BIOS tells you that Secure Boot can be enabled only when the system is in User mode, look for the related key-management or factory-key option. Loading the factory keys may move the system into the required mode.
The labels vary, so don’t assume that every Gigabyte board uses the same sequence. If you can see the message but not the setting it refers to, check the manual for your model and current BIOS version.
4. Return to Standard mode if needed
Some BIOS versions show Standard and Custom Secure Boot modes. Custom mode may expose key-management controls. Standard mode is usually the simpler choice for a normal Windows installation after the required keys are present.
If the board has a Standard option, select it only after reviewing what the screen says it will change. Save, restart, and check Windows again.
Factory keys, User mode, and common Gigabyte BIOS issues
Here’s how to read the most common messages without guessing.
“Secure Boot can be enabled when System in User mode”
The board is telling you that the current Secure Boot key state or system mode isn’t ready. Look for factory-key or key-management controls under the Secure Boot settings. Loading the standard keys may move the board into User mode.
Secure Boot is missing
Check that you’re in Advanced Mode. Then review UEFI, Legacy, and CSM settings. Secure Boot may stay hidden while the board is configured for Legacy boot.
Secure Boot is enabled in BIOS but Windows says it’s off
Check both BIOS Mode and Secure Boot State in `msinfo32`. If BIOS Mode is Legacy, fix the boot-mode issue before trying more Secure Boot changes. If BIOS Mode is UEFI, check factory keys and User mode.
Windows no longer starts after the change
Return to BIOS and undo the last boot-mode change. This is especially important if you changed from Legacy to UEFI without checking how Windows was installed.
The menu names don’t match this guide
That’s normal across Gigabyte models. Look for the same ideas under different labels: UEFI, Boot Mode, CSM, Secure Boot, factory keys, Standard mode, Custom mode, and User mode.
Model-specific notes for Gigabyte B550, B650, B760, Z390, and H410 boards
The model matters because Gigabyte doesn’t use one universal BIOS layout.
Gigabyte B550
B550 boards commonly offer the needed settings through the Boot or Secure Boot area after switching to Advanced Mode. If Secure Boot is unavailable, check the UEFI and CSM-related settings first.
Do not assume every B550 BIOS version places the option in the same tab. Use `msinfo32` to confirm that Windows is already using UEFI before changing boot behavior.
Gigabyte B650
B650 boards may use newer-looking BIOS screens and different wording from older AMD boards. Look through the Advanced Mode boot and Secure Boot pages.
If Windows reports that Secure Boot is enabled but not active, check for factory-key controls and the User mode message. The solution may be in the Secure Boot key settings rather than the main on/off switch.
Gigabyte B760
B760 boards can also place Secure Boot inside the Boot tab or a related BIOS settings page. If the option is hidden, check whether the board is configured for UEFI and whether a compatibility setting is preventing Secure Boot from appearing.
Save the change, boot into Windows, and verify the result with `msinfo32` instead of stopping at the BIOS screen.
Gigabyte Z390
Z390 boards may use older menu wording than newer Gigabyte boards. You may need to look through the Boot or Windows-related settings to find UEFI, CSM, and Secure Boot controls.
Pay close attention to the current BIOS Mode shown in Windows. A Z390 board that has been running an older Legacy installation may need more care before switching to UEFI.
Gigabyte H410
H410 boards, including model-specific versions such as H410M boards, may show a simpler or slightly different path. Start with Advanced Mode, then check the Boot and Secure Boot pages.
If the option is not visible, review the UEFI and compatibility settings. Don’t force a setting just because a walkthrough for another H410 model uses a different menu path.
Your exact motherboard model is the best guide here. Check its BIOS menu labels before making further boot-setting changes, especially if your screen differs from the steps above.