Match the symptom before changing settings
| What you observe | Where to focus |
|---|---|
| Secure Boot State says Unsupported | Check legacy BIOS mode and hardware support |
| Firmware option is greyed out | Check administrator mode and installed platform keys |
| Enabling it stops Windows booting | Restore prior setting and verify UEFI/GPT compatibility |
| Game still says Secure Boot disabled | Confirm Windows Secure Boot State after firmware changes |
Diagnose UEFI Secure Boot readiness with evidence first
Check System Information and firmware setup to record current BIOS mode, Secure Boot state, and whether the PC is using UEFI or legacy/CSM boot. Do this before changing any key or boot option.
Determine whether Secure Boot is merely disabled, unavailable in firmware, blocked by legacy boot, or causing Windows not to start when enabled. Those conditions require different fixes.
Complete these focused checks: open System Information and record BIOS Mode and Secure Boot State; back up BitLocker recovery key before firmware changes; confirm the Windows system disk layout and device support; record current firmware settings before editing. Take screenshots or notes before changing firmware, encryption, recovery, driver or power settings. Those records provide a return path if the first repair does not help.
Use firmware only from the PC or motherboard manufacturer and follow its supported update procedure. Do not import random Secure Boot keys or use unofficial firmware utilities.
Back up important files and save the BitLocker recovery key before changing firmware, TPM, boot mode, or Secure Boot keys. A boot-security change can legitimately trigger BitLocker recovery.
Confirm UEFI and disk prerequisites
Secure Boot requires supported UEFI firmware. A legacy or CSM installation may require an approved MBR-to-GPT migration before switching modes.
Before changing firmware settings, check the current boot mode, partition style, and Secure Boot state in Windows. Secure Boot generally requires UEFI mode and compatible firmware configuration.
1Verification checkpoint
- Return to Windows after the firmware change.
- Check Secure Boot State in System Information.
- If it still reports Off or Unsupported, do not keep toggling unrelated firmware options.
Configure firmware keys and mode
Use the device manual to disable CSM, select standard Windows UEFI mode and install default factory Secure Boot keys when appropriate.
If firmware shows Secure Boot but the option is unavailable, look for platform-key or OS-type settings and confirm Compatibility Support Module or legacy boot is not forcing a legacy path.
2Verification checkpoint
- Restart a second time with the same firmware settings.
- Confirm Windows boots normally and BitLocker does not enter a new loop.
- If boot fails, restore the previous known-good setting.
Verify boot and encryption safety
Restart, check System Information and confirm BitLocker remains healthy. Restore the previous firmware mode immediately if Windows no longer boots.
Do not convert disks or reset firmware keys casually. Back up important data and record BitLocker recovery information before making boot-mode or key-management changes.
3Verification checkpoint
- Verify Windows Hello and normal startup still work.
- Keep the recovery key stored safely after the test.
- Escalate to the device vendor if correct UEFI settings still cannot enable Secure Boot.
Interpret the result before escalating
If Windows is installed in legacy/CSM mode, Secure Boot may remain unavailable until the system is correctly migrated to UEFI. Simply toggling the Secure Boot switch will not solve that mismatch.
If UEFI mode is already active but Secure Boot is disabled or unsupported, firmware keys, manufacturer defaults, or outdated firmware become stronger suspects.
If enabling Secure Boot causes the system to stop booting, restore the previous firmware state and verify boot-mode, storage, and signed boot components before trying again.
Verify the fix and choose the safe escalation
After enabling Secure Boot, boot Windows normally and check System Information or the appropriate Windows security screen to confirm Secure Boot State reports On.
Restart once more and confirm BitLocker, Windows Hello, and normal startup still work. A firmware change is not complete until the machine boots consistently.
If the device cannot enable Secure Boot despite correct UEFI configuration and manufacturer-supported firmware, consult the device vendor before forcing key or firmware changes.
Technical order checked against current Microsoft guidance. Exact controls vary by Windows build, hardware, edition and organization policy.
Frequently asked questions
Does Secure Boot require UEFI?
Yes. It relies on UEFI firmware and a compatible trusted-boot configuration.
Why is Secure Boot greyed out?
Firmware may require administrator mode, disabled CSM or installed platform keys.
Will enabling Secure Boot erase files?
It should not, but incorrect firmware or disk-mode changes can prevent booting, so back up first.