Getting your Windows 11 PC fully up to speed often means making sure Secure Boot is enabled. This feature is a crucial security layer that helps prevent malicious software from loading before your operating system even starts. To turn it on, you will typically restart your computer into the Advanced Startup options, navigate to your UEFI firmware settings, locate the Secure Boot setting, enable it, and then save your changes. It sounds a bit technical, but really, it’s just a few clicks and restarts, and we’ll walk through it together.
Tutorial – How To Turn Secure Boot On Windows 11
Alright, let’s get down to business. These steps guide you through enabling Secure Boot on your Windows 11 machine. It is a vital step for several reasons, including meeting Windows 11 system requirements and boosting your PC’s overall security. Think of it as putting a bouncer at the door of your computer, making sure only trusted software gets in.
Step 1: Access the Recovery Options in Windows 11
First things first, you need to tell your computer you want to do something a little different than just booting into Windows. Go to your Windows Search bar, type “Recovery options,” and hit enter. This will open a settings page with several options to fix or reset your PC.
This path is often the easiest way to reach the advanced startup settings we need. You could also get there by holding the Shift key while clicking “Restart” from the Start Menu, but using the Recovery options gives you a clear, guided approach. It is all about choosing the method that feels most comfortable for you.
Step 2: Restart to Advanced Startup
On the Recovery options page, look for the “Advanced startup” section. You will see a button that says “Restart now.” Go ahead and click that button. Your computer will warn you that it is about to restart, so make sure you have saved any open work before proceeding.
Clicking “Restart now” will take you out of the regular Windows environment and into a special menu. This menu offers various troubleshooting tools, including access to your computer’s firmware settings. It is like unlocking a secret service menu for your PC, where you can change fundamental settings.
Step 3: Navigate to UEFI Firmware Settings
Once your PC restarts, you will see a blue screen with several options. Select “Troubleshoot,” then “Advanced options,” and finally, “UEFI Firmware Settings.” This is the golden ticket, the gateway to where Secure Boot lives.
UEFI, or Unified Extensible Firmware Interface, is essentially the modern version of the old BIOS. It is the software that starts up before Windows does, telling your computer how to wake up and what hardware it has. Getting into these settings lets us tweak the very fundamental startup instructions.
Step 4: Locate the Secure Boot Option
Your computer will restart again, and this time you will enter the UEFI settings, which often look a bit different depending on your computer’s manufacturer. It might be a dark blue screen, a grey screen, or something else entirely. Look for tabs like “Boot,” “Security,” or “Authentication.” Within one of these tabs, you should find “Secure Boot.”
Sometimes, Secure Boot might be hidden under another option, like “Boot Mode” or “OS Type,” where you might need to select “UEFI” instead of “Legacy” or “CSM” first. Take your time to explore the menus; they are usually organized logically. If you have trouble finding it, check your computer or motherboard manual.
Step 5: Enable Secure Boot
Once you have found “Secure Boot,” select it and change its status from “Disabled” to “Enabled.” You might have to confirm your choice, or it might just toggle with a single click. Some systems might require you to set a “Supervisor Password” before you can change security settings, such as Secure Boot.
If your system was previously set to “Legacy” or “CSM” (Compatibility Support Module) boot mode, you will often need to switch that to “UEFI” mode before Secure Boot becomes visible or enabled. Secure Boot only works with UEFI, so these two settings go hand in hand.
Step 6: Save Changes and Exit
After enabling Secure Boot, it is crucial to save your changes before exiting the UEFI settings. Look for an option like “Save and Exit,” “Exit Saving Changes,” or simply “F10” (a common shortcut for saving and exiting). Confirm your choice when prompted.
Saving your changes writes your new settings to the computer’s non-volatile memory, making them permanent. Your computer will then restart, and this time, it should boot into Windows 11 with Secure Boot actively protecting your system. If you do not save, all your hard work will be undone.
After you complete these steps, your computer will restart, and Windows 11 should boot normally, with Secure Boot enabled. This means your system has an extra layer of protection from boot-time malware. If everything goes smoothly, you will notice no difference, other than the added security.
Tips For Turning Secure Boot On Windows 11
- Check Your Current Status First: Before you even begin, open System Information (type msinfo32 in the Run dialog or search) and check “Secure Boot State.” If it is already “On,” you are all set.
- Backup Important Data: While enabling Secure Boot rarely causes issues, it is always a good idea to back up your critical files before changing your computer’s core settings. Just in case.
- Know Your Motherboard/PC Manufacturer: UEFI interfaces vary widely. Knowing whether you have a Dell, HP, ASUS, or custom PC helps you find specific instructions or visuals if you get stuck.
- Disable CSM (Compatibility Support Module): If Secure Boot is grayed out, it is often because CSM is enabled. You need to disable CSM and set the boot mode to “UEFI Native” or “UEFI only” for Secure Boot to become available.
- Update Your BIOS/UEFI: Sometimes, older firmware versions might not fully support Secure Boot for Windows 11. Checking for and applying a firmware update from your manufacturer can resolve this.
- Be Patient and Careful: The UEFI environment can look intimidating. Take your time, read the options, and do not change anything you are unsure about. Stick to the Secure Boot and Boot Mode settings.
- Take Photos with Your Phone: If you are nervous, snap pictures of the settings screens before you make changes. This way, you can always revert to the original settings if something goes wrong.
What exactly is Secure Boot?
Secure Boot is a security feature built into your computer’s UEFI firmware. Think of it as a digital gatekeeper. When your PC starts, Secure Boot checks the digital signature of the bootloaders, drivers, and operating system components. If any of these lack a trusted signature or have been tampered with, Secure Boot prevents them from loading. This prevents malicious software, such as rootkits, from inserting themselves into the boot process and taking control of your system before Windows even starts.
Why is Secure Boot important for Windows 11?
Secure Boot is a fundamental security requirement for Windows 11. Microsoft made it mandatory because it significantly enhances the operating system’s security posture. By ensuring that only trusted software loads during startup, it protects against sophisticated malware that can bypass traditional antivirus programs. Beyond security, having Secure Boot enabled is often a prerequisite for receiving certain Windows 11 updates and features, as well as for some software that relies on these security measures.
What if I cannot find Secure Boot in my BIOS or UEFI settings?
If you are struggling to find the Secure Boot option, there are a few common reasons. First, ensure your system is actually running in UEFI mode, not the older Legacy BIOS mode. Secure Boot is a UEFI-only feature. You might need to disable the Compatibility Support Module (CSM) or set your boot mode to “UEFI Native” or “UEFI only” for Secure Boot to appear or become editable. Sometimes the option is just in an unexpected place, perhaps under a “Security” or “Authentication” tab rather than “Boot.” If all else fails, consult your motherboard or PC manufacturer’s manual or support website.
Can enabling Secure Boot cause problems with my computer?
While enabling Secure Boot is generally a smooth process, there are rare instances where it might cause issues. If you have very old or specialized hardware, such as certain graphics cards or specialized PCIe cards, they might not have UEFI-compatible drivers. Also, if you are running other operating systems alongside Windows 11 or use specific bootloaders, enabling Secure Boot might prevent them from loading because their signatures are not recognized. In such cases, your PC might fail to boot or revert the setting automatically. If this happens, you would need to go back into the UEFI settings and disable Secure Boot.
How do I check if Secure Boot is enabled after I have done all this?
It is super easy to verify if Secure Boot is enabled. Just type “msinfo32” into the Windows search bar and press Enter. This will open the System Information utility. In the main window, look for “Secure Boot State.” It should say “On.” If it says “Off” or “Unsupported,” then it is either not enabled or your hardware does not support it (which is rare for a Windows 11 compatible PC). If it is “Off” and you followed the steps, you might need to revisit your UEFI settings.
Summary
- Access Recovery options.
- Restart to Advanced startup.
- Choose UEFI Firmware Settings.
- Locate Secure Boot.
- Enable Secure Boot.
- Save changes and exit.
Conclusion
So, there you have it: a comprehensive guide on how to turn on Secure Boot in Windows 11. You have walked through the steps, understood the why, and even picked up some helpful tips along the way. It might have seemed like a daunting task at first to dive into the deeper settings of your computer, but I hope you now feel more confident and empowered. Enabling Secure Boot is more than just ticking a box for a Windows 11 requirement; it is a proactive step towards a safer, more resilient computing experience.
Think of Secure Boot as your computer’s personal bodyguard, standing guard right from the moment you press the power button. It ensures that no unwelcome guests, like malicious software, can sneak in during those critical first moments of startup. This protection is invaluable in today’s digital landscape, where threats are constantly evolving. By taking this simple action, you are significantly reducing your exposure to rootkits and other sophisticated malware that aim to compromise your system at its most vulnerable point.
Beyond the immediate security benefits, enabling Secure Boot ensures your system is fully compliant with Microsoft’s latest security standards. This can be important for receiving future Windows updates, accessing certain applications, or even just enjoying the peace of mind that comes with a hardened operating system. If you encountered any bumps along the road, remember that most issues can be resolved by carefully reviewing your UEFI settings or consulting your PC manufacturer’s support. Do not hesitate to retrace your steps or seek further information if something does not feel right.
Ultimately, understanding how to turn Secure Boot on Windows 11 is a valuable skill for any modern PC user. It is a testament to your commitment to keeping your digital life secure. Now that you have mastered this, why not explore the other security features Windows 11 offers? Your journey towards a more secure and robust computing experience is always ongoing, and this is a fantastic step forward. Keep learning, keep exploring, and keep your digital fortress strong.

Matthew Burleigh has been writing tech tutorials since 2008. His writing has appeared on dozens of different websites and been read over 50 million times.
After receiving his Bachelor’s and Master’s degrees in Computer Science he spent several years working in IT management for small businesses. However, he now works full time writing content online and creating websites.
His main writing topics include iPhones, Microsoft Office, Google Apps, Android, and Photoshop, but he has also written about many other tech topics as well.
Read his full bio here.