System Enable or Disable Secure Boot in Windows 11

  • Thread starter Thread starter Brink
  • Start date Published: Start date Updated Updated:

Secure_Boot_banner.png

This tutorial will show you how to enable or disable Secure Boot on your Windows 10 and Windows 11 PC.

Windows 11 minimum system requirements include your system to be UEFI (Unified Extensible Firmware Interface) and Secure Boot capable. While the requirement to upgrade a Windows 10 device to Windows 11 is only that the PC be Secure Boot capable by having UEFI enabled, you may also consider enabling Secure Boot for better security.

Secure Boot is an important security feature designed to prevent malicious software from loading when your PC starts up (boots). When the PC starts, the firmware checks the signature of each piece of boot software, including UEFI firmware drivers (also known as Option ROMs), EFI applications, and the operating system. If the signatures are valid, the PC boots, and the firmware gives control to the operating system.

Most modern PCs are capable of Secure Boot, but in some instances, there may be settings that cause the PC to appear to not be capable of Secure Boot. These settings can be changed in the PC UEFI/BIOS firmware.

If you're running certain PC graphics cards, hardware, or operating systems such as Linux or previous version of Windows you may need to disable Secure Boot.

Secure Boot helps to make sure that your PC boots using only firmware that is trusted by the manufacturer. You can usually disable Secure Boot through the PC’s firmware (BIOS) menus, but the way you disable it varies by PC manufacturer. If you are having trouble disabling Secure Boot after following the steps below, contact your manufacturer for help.

Starting with Windows 11 build 26100.8457 (24H2) and build 26200.8457 (25H2), Microsoft added a new SecureBoot folder under C:\Windows on eligible devices. The folder contains example scripts intended for organizations with IT professionals who actively manage updates across their device fleet. These scripts can be used to detect Secure Boot certificate update status and automate deployment via a safe rollout mechanism in an Active Directory environment. For more information, see Sample Secure Boot E2E Automation Guide.

References:

If you don't turn off Device Encryption or BitLocker for the Windows OS drive before disabling Secure Boot, you will be prompted to enter the BitLocker Recovery key to unlock your Windows OS drive the next time you restart the computer after disabling Secure Boot.

After disabling Secure Boot and installing other software and hardware, you may need to restore your PC to the factory state to re-activate Secure Boot.

Be careful when changing BIOS settings. The BIOS menu is designed for advanced users, and it's possible to change a setting that could prevent your PC from starting correctly. Be sure to follow the manufacturer's instructions exactly.




Contents





Option One

Enable Secure Boot


1 Boot to UEFI Firmware Settings.

2 Depending on your PC/motherboard manufacturer, open the Security, Boot, or Authentication tab to find the Secure Boot setting. (see screenshot below)

ASUS_secure_boot.png

3 Enable the Secure Boot setting. (see screenshots below)

Depending on your PC/motherboard manufacturer, you may need to Install Default Secure Boot Keys instead to enable Secure Boot.


Secure_Boot_Control.png

4 Open the Exit tab, and click/tap on Save Changes and Exit. (see screenshot below)

Save_Changes_and_Exit.png

5 If prompted, approve changes to UEFI settings.

6 The computer will now reboot.

If the PC isn't able to boot after enabling Secure Boot, then disable Secure Boot in Option Two, and try to boot the PC again.






Option Two

Disable Secure Boot


1 Boot to UEFI Firmware Settings.

2 Depending on your PC/motherboard manufacturer, open the Security, Boot, or Authentication tab to find the Secure Boot setting. (see screenshot below)

ASUS_secure_boot.png

3 Disable the Secure Boot setting. (see screenshots below)

Depending on your PC/motherboard manufacturer, you may need to Clear Secure Boot Keys instead to disable Secure Boot.


Secure_Boot_Control.png
Clear_Secure_Boot_keys.png

4 Open the Exit tab, and click/tap on Save Changes and Exit. (see screenshot below)

Save_Changes_and_Exit.png

5 If prompted, approve changes to UEFI settings.

6 The computer will now reboot.


That's it,
Shawn Brink


 
Last edited:
What is the benefit of doing this?
 

My Computers My Computers

  • At a glance

    Windows11 Pro 26300.9539Intel Core i9 14900F (24 -Core, 68 MB Total C...32GB DDR5RTX 4080 Super w/610.74
    OS
    Windows11 Pro 26300.9539
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Alienware Aurora R16
    CPU
    Intel Core i9 14900F (24 -Core, 68 MB Total Cache)
    Motherboard
    Dell Alienware
    Memory
    32GB DDR5
    Graphics Card(s)
    RTX 4080 Super w/610.74
    Sound Card
    Realtec
    Monitor(s) Displays
    Corsair XENEON 32QHD165
    Screen Resolution
    2560 X 1440
    Hard Drives
    1-2TB Samsung 990 Pro PCIe NVMe M2 SSD
    1-4TB Samsung 990 Pro PCIe NVMe M2 SSD
    PSU
    1000 Watt Platinum Dell
    Case
    Alienware
    Cooling
    Liquid Closed Loop
    Keyboard
    Corsair Strafe RGB
    Mouse
    Logitech MK270 Wireless
    Internet Speed
    100Gb's Down-20 Up
    Browser
    Firefox 155.0.1
    Antivirus
    Defender
    Other Info
    Very Quiet And Fast
    CyberPower UPS CP1500PFCLCD
  • At a glance

    PClinuxOS Mate (2025.7)13th Gen Inter(R) Core(TM) i3-1315U64 GB DDR4 @3200 MHz.Internal
    Operating System
    PClinuxOS Mate (2025.7)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel
    CPU
    13th Gen Inter(R) Core(TM) i3-1315U
    Motherboard
    Intel
    Memory
    64 GB DDR4 @3200 MHz.
    Graphics card(s)
    Internal
    Sound Card
    None
    Monitor(s) Displays
    Dell 2419HGCF
    Screen Resolution
    1920 X 1080
    Hard Drives
    SAMSUNG 980 PRO SSD 2TB, PCIe 4.0 M.2 2280
    PSU
    Chicony 30 Watt
    Case
    Small
    Keyboard
    Dell
    Mouse
    Razor
    Internet Speed
    1GB
    Browser
    Slimjet
What is the benefit of doing this?
Usually, you'd want to leave Secure Boot enabled for better security unless it's causing an issue.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro for WorkstationsIntel i7-8700K 5 GHz64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600...ASUS ROG-STRIX-GTX1080TI-O11G-GAMING (11GB GD...
    OS
    Windows 11 Pro for Workstations
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom self build
    CPU
    Intel i7-8700K 5 GHz
    Motherboard
    ASUS ROG Maximus XI Formula Z390
    Memory
    64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz (F4-3600C18D-32GTZR)
    Graphics Card(s)
    ASUS ROG-STRIX-GTX1080TI-O11G-GAMING (11GB GDDR5X)
    Sound Card
    Integrated Digital Audio (S/PDIF)
    Monitor(s) Displays
    2 x Samsung Odyssey G75 27"
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Samsung 990 PRO M.2,
    4TB Samsung 990 PRO M.2,
    TerraMaster F8 SSD Plus NAS
    PSU
    Seasonic Prime Titanium 850W
    Case
    Thermaltake Core P3 wall mounted
    Cooling
    Corsair Hydro H115i
    Keyboard
    Amazon Basics Wired Full Keyboard MD005
    Mouse
    Logitech MX Master 4
    Internet Speed
    2 Gbps Download and 100 Mbps Upload
    Browser
    Chrome and Edge
    Antivirus
    Microsoft Defender
    Other Info
    Logitech Z625 speaker system,
    Logitech BRIO 4K Pro webcam,
    HP Color LaserJet Pro MFP M477fdn,
    CyberPower CP1500PFCLCD
    Galaxy S23 Plus phone
  • At a glance

    Windows 11 ProSnapdragon X Elite (12 core) 3.42 GHz16 GB LPDDR5x-7467 MHz
    Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Surface Laptop 7 Copilot+ PC
    CPU
    Snapdragon X Elite (12 core) 3.42 GHz
    Memory
    16 GB LPDDR5x-7467 MHz
    Monitor(s) Displays
    15" HDR
    Screen Resolution
    2496 x 1664
    Hard Drives
    1 TB SSD
    Internet Speed
    Wi-Fi 7 and Bluetooth 5.4
    Browser
    Chrome and Edge
    Antivirus
    Microsoft Defender
Usually, you'd want to leave Secure Boot enabled for better security unless it's causing an issue.
Can I install software or do I need to disable it first?
 

My Computer My Computer

At a glance

Win 11 Pro 64 version 23H2Ryzen 5 760032 gig GSkill F5-6000Power Color RX6650XT
OS
Win 11 Pro 64 version 23H2
Computer type
PC/Desktop
Manufacturer/Model
Homebuilt
CPU
Ryzen 5 7600
Motherboard
Aorus ProX X670e
Memory
32 gig GSkill F5-6000
Graphics Card(s)
Power Color RX6650XT
Sound Card
RealTek
Monitor(s) Displays
Asus VX248
Screen Resolution
1080x1280
Hard Drives
Crucial M2 1T
PSU
Corsair RM750x
Case
Corsair RAID
Cooling
Corsair AIO 240
Keyboard
NPET
Mouse
Logitech wired
Internet Speed
Fiber
Browser
Edge
Antivirus
MS

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2 26200.9445Intel® Core™ i7-14700KG.SKILL Ripjaws S5 Series 64GB (2 x 32GB) DDR5ASUS GeForce RTX 4070 Super 12GB
    OS
    Win 11 Pro 25H2 26200.9445
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel® Core™ i7-14700K
    Motherboard
    ASUS TUF Z690-PLUS WIFI (BIOS 4505)
    Memory
    G.SKILL Ripjaws S5 Series 64GB (2 x 32GB) DDR5
    Graphics Card(s)
    ASUS GeForce RTX 4070 Super 12GB
    Sound Card
    Sound Blaster AE-5 Plus
    Monitor(s) Displays
    ASUS TUF Gaming 27" 2K HDR Gaming
    Screen Resolution
    2560 x 1440
    Hard Drives
    Samsung 990 Pro 1TB NVMe (Win 11 25H2)
    SK hynix P41 500GB NVMe
    SK hynix P41 2TB NVMe (x3)
    Crucial P3 Plus 4TB
    PSU
    Corsair RM850x Shift
    Case
    Antec Dark Phantom DP502 FLUX
    Cooling
    Corsair Nautilus 360 RS AIO
    Keyboard
    Logitech MK 320
    Mouse
    Razer Basilisk V3
    Internet Speed
    750Mbs
    Browser
    Firefox
    Antivirus
    Winows Security
    Other Info
    MR 8.1 Home
  • At a glance

    Win 11 Pro 25H2 26200.9445Intel Core i5-1140064 GB DDR4MSI GeForce RTX 3060 Ventus 2X 12GB
    Operating System
    Win 11 Pro 25H2 26200.9445
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel Core i5-11400
    Motherboard
    Asus TUF Gaming Z590 Plus WiFi (BIOS 2803)
    Memory
    64 GB DDR4
    Graphics card(s)
    MSI GeForce RTX 3060 Ventus 2X 12GB
    Sound Card
    SoundBlaster Audigy Fx V2
    Monitor(s) Displays
    Samsung F27T350
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 980 Pro 1TB
    Samsung 970 EVO Plus 2TB
    Samsung 870 EVO 500GB SSD
    PSU
    Corsair HX750
    Case
    Cougar MX330-G Window
    Cooling
    Thermalright Frozen Edge 240 Black AIO
    Internet Speed
    350Mbps
    Browser
    Firefox
    Antivirus
    Windows Security
  • System Three
    Win 11 Pro 25H2 26200.9445
    ASUS PRIME Z370-P II BIOS 3004 7/12/21
    Intel Core i7-8700 CPU @ 3.20GHz
    32GB DDR4 RAM (4x8)
    EVGA RTX 2060 (used)
    iGPU Intel UHD Graphics 630 (backup)
    Cooler Master Hyper 212
    Mid-Tower Desktop
Hi Brink. Thanks for this tut. I have need of some advice. I have a friend who purchased a Windows 11 S and wants to upgrade it to Pro. We have purchased a key through a third party site, but I can't find a way to input it, to upgrade. I turned secure boot off, and it still boots as W11S. The other option you have here is to sign in to MS Store and purchase another one? I've got this thing setup with a local account (no MS account). It's an HP 15-FD0023DX.
Thanks for any assistance!
 

My Computer My Computer

At a glance

W10 (Yes, I'm still on W10 lol)i7-9700K 3.6GHz 8 Core32GB DDR4nVidia GeForce GTX 960
OS
W10 (Yes, I'm still on W10 lol)
Computer type
PC/Desktop
Manufacturer/Model
home brew
CPU
i7-9700K 3.6GHz 8 Core
Motherboard
MSi Z390
Memory
32GB DDR4
Graphics Card(s)
nVidia GeForce GTX 960
Monitor(s) Displays
Acer R271 + ASUS
Screen Resolution
1920 x 1080 60Hz
Hard Drives
SSDs + spinners
PSU
EVGA SuperNOVA 750G1 Gold
Case
Corsair Obsidian 750D
Keyboard
Corsair K70 Cherry MX
Mouse
Logitech ergonomic
Internet Speed
200GB
Browser
FF
Hi Brink. Thanks for this tut. I have need of some advice. I have a friend who purchased a Windows 11 S and wants to upgrade it to Pro. We have purchased a key through a third party site, but I can't find a way to input it, to upgrade. I turned secure boot off, and it still boots as W11S. The other option you have here is to sign in to MS Store and purchase another one? I've got this thing setup with a local account (no MS account). It's an HP 15-FD0023DX.
Thanks for any assistance!
switch out of S mode first

then upgrade your Home to Pro via Settings > System > Activation > Change Product Key
 

My Computer My Computer

At a glance

Windows 11 Pro
OS
Windows 11 Pro
switch out of S mode first

then upgrade your Home to Pro via Settings > System > Activation > Change Product

Hi and thanks for your reply.
The problem is, can't recover the MS account to use MS STORE. We finally just made a new MS account.
 

My Computer My Computer

At a glance

W10 (Yes, I'm still on W10 lol)i7-9700K 3.6GHz 8 Core32GB DDR4nVidia GeForce GTX 960
OS
W10 (Yes, I'm still on W10 lol)
Computer type
PC/Desktop
Manufacturer/Model
home brew
CPU
i7-9700K 3.6GHz 8 Core
Motherboard
MSi Z390
Memory
32GB DDR4
Graphics Card(s)
nVidia GeForce GTX 960
Monitor(s) Displays
Acer R271 + ASUS
Screen Resolution
1920 x 1080 60Hz
Hard Drives
SSDs + spinners
PSU
EVGA SuperNOVA 750G1 Gold
Case
Corsair Obsidian 750D
Keyboard
Corsair K70 Cherry MX
Mouse
Logitech ergonomic
Internet Speed
200GB
Browser
FF
Hi and thanks for your reply.
The problem is, can't recover the MS account to use MS STORE. We finally just made a new MS account.
this works. i've done it before (about 2 months ago)

EDIT - @ 8:20 btw

 

My Computer My Computer

At a glance

Windows 11 Pro
OS
Windows 11 Pro
Hi Brink. Thanks for this tut. I have need of some advice. I have a friend who purchased a Windows 11 S and wants to upgrade it to Pro. We have purchased a key through a third party site, but I can't find a way to input it, to upgrade. I turned secure boot off, and it still boots as W11S. The other option you have here is to sign in to MS Store and purchase another one?
Why can't you just input the key?

How to input Key - Change Product Key in Windows 11 (Option One)

That said, not sure if there are also "other" requirements to switch out of "S", but still try the above and see if that changes the OS to Pro.

I've got this thing setup with a local account (no MS account).
Just saw this ^^^, the above assumes you're using a Microsoft Account to log in. Sorry.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 24H2 (Build 26100.4770)Intel Core 9 Ultra 285K64G (4x16) DDR5 Corsair RGB Dominator Platinu...Radeon (XFX Mercury) RX 9070XT OC (with Magne...
    OS
    Windows 11 Pro 24H2 (Build 26100.4770)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom built
    CPU
    Intel Core 9 Ultra 285K
    Motherboard
    Gigabyte Aorus Z890 Xtreme AI Top
    Memory
    64G (4x16) DDR5 Corsair RGB Dominator Platinum (6400Mhz)
    Graphics Card(s)
    Radeon (XFX Mercury) RX 9070XT OC (with Magnetic Fans)
    Sound Card
    Onboard (DTS:X® Ultra Audio: ESS ES9280A DAC)
    Monitor(s) Displays
    27-inch Eizo Color Edge - CG2700X
    Screen Resolution
    3840 x 2160
    Hard Drives
    4 Samsung NVM 990 Pro drives: 1TB (OS), 2TB, 2 X 4TB.
    PSU
    Seasonic TX-1300 (1300 Watts)
    Case
    Cooler Master H500M
    Cooling
    Corsair Link Titan 280 RX RGB
    Keyboard
    Logitech Craft
    Mouse
    Logitech MX Master 3S
    Internet Speed
    1TB Download. 512mb Upload
    Browser
    Microsoft Edge Chromium
    Antivirus
    Windows Security
    Other Info
    System used for gaming, photography, music, school.
  • At a glance

    Windows 11 Pro 24H2 (Build 26100.4061)Intel Core i9-9900K32gig (4 x 8) Corsair Dominator Platinum DDR4...Radeon XFX Merc 7900XT (20gig)
    Operating System
    Windows 11 Pro 24H2 (Build 26100.4061)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom built
    CPU
    Intel Core i9-9900K
    Motherboard
    Gigabyte Z390 Aorus Xtreme
    Memory
    32gig (4 x 8) Corsair Dominator Platinum DDR4 3600Mhz (B-Die)
    Graphics card(s)
    Radeon XFX Merc 7900XT (20gig)
    Sound Card
    Onboard
    Monitor(s) Displays
    24-Inch NEC PA242W
    Screen Resolution
    2880 x 1800
    Hard Drives
    2 X NVME, 1 X SATA SSD
    PSU
    EVGA Super Nova 1000 P2 (1000 Watt)
    Case
    Phantek Enthoo Luxe
    Cooling
    Corsair H115i Elite AIO Cooler
    Keyboard
    Logitech Keys
    Mouse
    Logitech MX Master 3
    Internet Speed
    1TB Download. 512mb Upload
    Browser
    Microsoft Edge Chromium
    Antivirus
    Windows Security
    Other Info
    Backup System
Here.. summed up the video. @Brink, not sure if you have a tutorial for this method.

1) Reboot into Advanced Startup
2) Troubleshoot > Advanced Options > Command Prompt
3) type Regedit
4) Regedit > Highlight HKEY_LOCAL_MACHINE Hive > File > Load Hive > C:\Windows\System32\config\SYSTEM > Open
5) Name it: OFFLINE SYSTEM
6) Regedit > HKEY_LOCAL_MACHINE > OFFLINE SYSTEM > ControlSet001 > Control > CI > Policy
7) SkuPolicyRequired
0 = S Mode Disabled
1 = S Mode Enabled
8) Highlight OFFLINE SYSTEM key > File > Unload Hive
9) Close Command Prompt
10) Reboot PC
 

My Computer My Computer

At a glance

Windows 11 Pro
OS
Windows 11 Pro

Latest Support Threads

Back
Top Bottom