How to Turn Secure Boot Off

How to Turn Secure Boot Off

What turning off Secure Boot changes

Secure Boot is a check built into modern BIOS or UEFI firmware. It helps the computer allow only trusted boot software to start before Windows loads.

Turning it off can help when you need to:

  • Boot from a USB drive
  • Start an older operating system
  • Use a replacement drive
  • Work with hardware or boot media that the computer does not accept with Secure Boot enabled

The trade-off is simple: your computer loses one layer of protection during startup. That doesn't mean the computer will stop working. It does mean the system won't perform the same check on boot software.

Turn Secure Boot off only for the task that needs it. Once the task is done, turn it back on.

The setting lives in BIOS or UEFI, not in the normal Windows Settings app. BIOS and UEFI are the firmware menus that open before Windows starts. Their names, layouts, and keyboard shortcuts vary by computer.

Before you disable Secure Boot

Before you disable Secure Boot

First, save any open work. Changing a firmware setting usually requires a restart, and you won't be working inside Windows while you make the change.

Also, know what task requires Secure Boot to be off. If you're booting from a USB drive, check that the USB drive is ready and connected before you restart. If you're replacing a drive, make sure you have the files or installation media you need.

Keep these points in mind:

  • Write down the original setting. If Secure Boot is currently enabled, note that before changing it.
  • Don't change unrelated BIOS options. BIOS menus contain settings for storage, memory, startup order, and other hardware.
  • Expect different menu names. One computer may show Secure Boot under Security. Another may place it under Boot, Boot Configuration, or Authentication.
  • Check whether CSM is involved. On some systems, enabling CSM is part of booting from certain USB devices. CSM is a compatibility setting for older boot methods. Don't enable it unless your boot task or computer requires it.
  • Be careful with Secure Boot keys. Clearing them is not the same as switching Secure Boot off. It can change the trusted keys stored in firmware and should be treated as a troubleshooting step, not a first choice.

If your computer uses a firmware password, you may need that password before you can change the setting.

How to enter BIOS or UEFI settings

There are two common ways to open the firmware settings. The first is to restart and press a key at the right moment. The second uses Windows to request a restart into firmware settings.

Method 1: Use the startup key

Method 1
  1. Shut down or restart the computer.
  2. Turn it on and watch for the first logo screen.
  3. Press the BIOS or UEFI setup key repeatedly as the computer starts.

The key differs by manufacturer. Common choices include F2, Delete, F10, or Esc, but your computer may use another key. Some systems show the correct key briefly on the startup screen.

If Windows loads normally, restart and try again. Start pressing the key as soon as the computer powers on rather than waiting for the Windows logo.

Some computers open a startup menu first. If that happens, choose the option for BIOS Setup, UEFI Firmware Settings, or a similar name.

Method 2: Start from Windows

Windows can also send the computer to its firmware menu.

  1. Open Settings.
  2. Open the recovery or advanced startup options.
  3. Choose Restart now for advanced startup.
  4. Select the option for troubleshooting or advanced options.
  5. Choose UEFI Firmware Settings, if it appears.
  6. Confirm the restart.

The exact menu wording differs between Windows 10 and Windows 11.

For Windows 11, look in Settings > System > Recovery for the advanced startup option.

For Windows 10, look in Settings > Update & Security > Recovery for advanced startup.

If you don't see a UEFI Firmware Settings option, use the startup-key method instead. Some computers don't expose the firmware option through Windows.

How to turn Secure Boot off

Once you're in BIOS or UEFI, use the arrow keys, mouse, or touchpad, depending on the firmware interface.

Follow this general path:

  1. Open the Security or Boot tab.
  2. Look for Secure Boot.
  3. Select the setting.
  4. Change it from Enabled to Disabled.
  5. Look for a separate setting called Boot Configuration or Authentication if you don't see it in the first two tabs.
  6. Save the change and exit.

The universal method is short: find Secure Boot, set it to Disabled, then save before leaving. The difficult part is usually finding the setting because manufacturers organize their firmware menus differently.

You may see choices such as:

  • Enabled or Disabled
  • Secure Boot Control
  • Secure Boot Configuration
  • Platform Security
  • Authentication

Don't assume a similarly named option is the right one. Read the text shown beside the setting and use the firmware's help panel if one appears.

If you're disabling Secure Boot to start from a USB drive and the USB still isn't accepted, check whether the system uses a CSM option. On some computers, CSM must be enabled for certain USB boot methods. This isn't required on every computer, and enabling it changes how the system handles older boot options.

Where to find Secure Boot on ASUS, Acer, Lenovo, and other computers

Where to find Secure Boot on ASUS, Acer, Lenovo, and other computers

The brand can point you toward the right menu, but it doesn't guarantee the exact path. Firmware versions can differ even between computers from the same manufacturer.

ASUS

On many ASUS computers and motherboards, start by checking the Boot tab. If Secure Boot isn't there, check Security or a boot-configuration submenu.

The setting may appear as Secure Boot Control or simply Secure Boot. Select it, change it to Disabled, and then save the change. If the option is unavailable, look for any instructions shown in the firmware window before trying another setting.

Acer

On Acer systems, check the Security tab first, then the Boot tab. Some models place the option within a boot or authentication area.

If Secure Boot is greyed out, don't immediately change several settings at once. Note what is locked, check whether the firmware asks for a password, and use the troubleshooting steps below.

Lenovo

Lenovo systems commonly place related settings under Security or Boot. Some firmware versions use a Startup section instead of calling the tab Boot.

Look for Secure Boot under those areas, set it to Disabled, and save. Lenovo computers can also use different startup keys, so the key that opens the firmware menu may not match the key used by another Lenovo model.

Other computers and custom motherboards

For a desktop motherboard or another brand, check these locations in this order:

  1. Security
  2. Boot
  3. Boot Configuration
  4. Authentication

You may need to switch from a simple view to an advanced view before all settings appear. If the option still isn't visible, move through each main tab rather than changing settings at random.

The goal is the same on every system. Find the Secure Boot control, disable it, save it, and restart.

How to save the setting and check that it worked

How to save the setting and check that it worked

Changing the value isn't enough. You must save it before exiting BIOS or UEFI.

Look for one of these choices:

  • Save and Exit
  • Save Changes and Exit
  • Exit Saving Changes

Many systems also show a shortcut key for saving, often near the bottom of the screen. The key is not the same on every computer, so read the on-screen prompt.

When asked to confirm, choose the option that saves the changes. The computer should restart.

After Windows starts, check whether the setting changed:

  1. Press Windows key + R.
  2. Type `msinfo32`.
  3. Press Enter.
  4. In System Information, find Secure Boot State.

It should show that Secure Boot is off or disabled. If Windows doesn't start, return to BIOS or UEFI and check the setting again. Also check the boot order and any CSM setting you changed for the USB or drive task.

If the computer boots normally but the USB still doesn't start, the problem may be with the USB's boot method rather than Secure Boot itself. Compare the requirements of the USB or replacement drive with the firmware settings before making more changes.

What to do when Secure Boot is locked or will not disable

A locked setting doesn't always mean the computer cannot use Secure Boot. It may mean the firmware requires another step first, or that a setting is controlled elsewhere in the menu.

Work through these checks one at a time:

  1. Look through all likely locations. Check Security, Boot, Boot Configuration, and Authentication.
  2. Open the advanced firmware view. Some systems hide extra controls in a basic view.
  3. Check for a firmware password. A password may be required before security settings can be changed.
  4. Look for CSM. If your goal is USB booting, the system may use CSM as part of that process.
  5. Read the message beside the locked option. Firmware often explains what it expects, though the wording varies.
  6. Avoid clearing keys unless necessary.

Some systems may allow Secure Boot to be disabled only after the stored Secure Boot keys are cleared. This is a more serious change than switching the feature off. The keys help firmware identify trusted boot software, so clearing them can affect how the computer validates boot files.

Only use Clear Secure Boot Keys when the firmware or the instructions for your specific boot task point you there. Record the current settings first, and understand that restoring Secure Boot later may require the correct keys or a firmware option to restore them.

If the option remains locked, stop before changing unrelated settings. Check the computer's manual or the exact instructions for its firmware version. Menu names and rules can differ even across models from the same brand.

How to turn Secure Boot back on

Once the USB, drive, or installation task is finished, restore the protection.

  1. Restart the computer.
  2. Enter BIOS or UEFI with the setup key or Windows advanced startup.
  3. Open Security, Boot, Boot Configuration, or Authentication.
  4. Find Secure Boot.
  5. Change it to Enabled.
  6. Save the change and exit.
  7. Let Windows start, then check the setting again if needed.

If you enabled CSM for the temporary task, check whether it also needs to be turned off before Secure Boot can be enabled. Make changes carefully and save only after the settings match the boot setup you plan to keep.

Before you switch anything back, compare the device requirements and safety features of the hardware or boot setup you plan to use next. That small check can tell you whether you need compatibility settings—or whether it is safer to leave Secure Boot on.

DH

Written by Dennis Haymon

Dennis Haymon is a security professional and manager at Safe & Sound Security LLC. With experience in security guard and patrol services, he shares practical information about protecting homes, businesses, and properties. Through Safe & Sound Security LLC, Dennis and the team provide security-focused guidance designed to help individuals and businesses better understand their security needs and available protection options.