UEFI Secure Boot readiness

Cannot Enable Secure Boot in Windows 11

Fix Secure Boot unavailable or disabled in Windows 11 by checking UEFI mode, GPT system disk, firmware keys and compatibility without risking an unbootable PC.

Updated August 4, 2026 · Safety-first troubleshooting · About 15–35 minutes

Match the symptom before changing settings

What you observeWhere to focus
Secure Boot State says UnsupportedCheck legacy BIOS mode and hardware support
Firmware option is greyed outCheck administrator mode and installed platform keys
Enabling it stops Windows bootingRestore prior setting and verify UEFI/GPT compatibility
Game still says Secure Boot disabledConfirm Windows Secure Boot State after firmware changes

Diagnose UEFI Secure Boot readiness with evidence first

Check System Information and firmware setup to record current BIOS mode, Secure Boot state, and whether the PC is using UEFI or legacy/CSM boot. Do this before changing any key or boot option.

Determine whether Secure Boot is merely disabled, unavailable in firmware, blocked by legacy boot, or causing Windows not to start when enabled. Those conditions require different fixes.

Complete these focused checks: open System Information and record BIOS Mode and Secure Boot State; back up BitLocker recovery key before firmware changes; confirm the Windows system disk layout and device support; record current firmware settings before editing. Take screenshots or notes before changing firmware, encryption, recovery, driver or power settings. Those records provide a return path if the first repair does not help.

Use firmware only from the PC or motherboard manufacturer and follow its supported update procedure. Do not import random Secure Boot keys or use unofficial firmware utilities.

Back up important files and save the BitLocker recovery key before changing firmware, TPM, boot mode, or Secure Boot keys. A boot-security change can legitimately trigger BitLocker recovery.

Confirm UEFI and disk prerequisites

Secure Boot requires supported UEFI firmware. A legacy or CSM installation may require an approved MBR-to-GPT migration before switching modes.

Before changing firmware settings, check the current boot mode, partition style, and Secure Boot state in Windows. Secure Boot generally requires UEFI mode and compatible firmware configuration.

1Verification checkpoint

  1. Return to Windows after the firmware change.
  2. Check Secure Boot State in System Information.
  3. If it still reports Off or Unsupported, do not keep toggling unrelated firmware options.

Configure firmware keys and mode

Use the device manual to disable CSM, select standard Windows UEFI mode and install default factory Secure Boot keys when appropriate.

If firmware shows Secure Boot but the option is unavailable, look for platform-key or OS-type settings and confirm Compatibility Support Module or legacy boot is not forcing a legacy path.

2Verification checkpoint

  1. Restart a second time with the same firmware settings.
  2. Confirm Windows boots normally and BitLocker does not enter a new loop.
  3. If boot fails, restore the previous known-good setting.

Verify boot and encryption safety

Restart, check System Information and confirm BitLocker remains healthy. Restore the previous firmware mode immediately if Windows no longer boots.

Do not convert disks or reset firmware keys casually. Back up important data and record BitLocker recovery information before making boot-mode or key-management changes.

3Verification checkpoint

  1. Verify Windows Hello and normal startup still work.
  2. Keep the recovery key stored safely after the test.
  3. Escalate to the device vendor if correct UEFI settings still cannot enable Secure Boot.

Interpret the result before escalating

If Windows is installed in legacy/CSM mode, Secure Boot may remain unavailable until the system is correctly migrated to UEFI. Simply toggling the Secure Boot switch will not solve that mismatch.

If UEFI mode is already active but Secure Boot is disabled or unsupported, firmware keys, manufacturer defaults, or outdated firmware become stronger suspects.

If enabling Secure Boot causes the system to stop booting, restore the previous firmware state and verify boot-mode, storage, and signed boot components before trying again.

Important: Do not switch Legacy/CSM to UEFI blindly. An incompatible disk layout can make Windows unbootable.

Verify the fix and choose the safe escalation

After enabling Secure Boot, boot Windows normally and check System Information or the appropriate Windows security screen to confirm Secure Boot State reports On.

Restart once more and confirm BitLocker, Windows Hello, and normal startup still work. A firmware change is not complete until the machine boots consistently.

If the device cannot enable Secure Boot despite correct UEFI configuration and manufacturer-supported firmware, consult the device vendor before forcing key or firmware changes.

Technical order checked against current Microsoft guidance. Exact controls vary by Windows build, hardware, edition and organization policy.

Frequently asked questions

Does Secure Boot require UEFI?

Yes. It relies on UEFI firmware and a compatible trusted-boot configuration.

Why is Secure Boot greyed out?

Firmware may require administrator mode, disabled CSM or installed platform keys.

Will enabling Secure Boot erase files?

It should not, but incorrect firmware or disk-mode changes can prevent booting, so back up first.

Related Windows 11 security and recovery fixes