Skip to main content

How to enable secure boot in Windows 11

Secure Boot setting in an ASUS BIOS.
DigitalTrends

Enabling Secure Boot is an important step in upgrading to Windows 11, as it's part of the system requirements. It ensures that unauthorized software can't run on your PC, and you will have to enable it before you install Windows 11 or it just won't work. Fortunately, enabling Secure Boot is as quick as changing a single BIOS setting.

Here's how to do it.

Recommended Videos

Difficulty

Easy

Duration

5 minutes

What You Need

  • Desktop PC or laptop

Secure Boot setting in an ASUS BIOS.
DigitalTrends

How to enable Secure Boot in Windows 11

The most straightforward way to enable Secure Boot is to use the BIOS setting. To access your BIOS, you'll need to use either your motherboard's BIOS key command (often Del or F2, but it varies by manufacturer), or use the Windows 11 boot options. For more help, follow our guide on how to use the BIOS to access it.

Step 1: Start your PC up and access your UEFI/BIOS using your system's BIOS key during the post process.

Step 2: If your UEFI/BIOS is in a Basic or Simple mode, switch to Advanced or similar to get the full range of options.

Step 3: The actual location of the Secure Boot setting will vary by motherboard manufacturer and model, but look for a Boot or Security tab at the top of the screen and navigate to that. Look through the options to find Secure Boot. You may have to navigate through a few menus to find it.

If you can't find it, check your manufacturer's website to see if it doesn't support it on that motherboard model. Alternatively, you may just need to update your BIOS.

Step 4: Toggle Secure Boot to On or Enabled if it isn't already. If you ever want to disable Secure Boot, you just come right back here and switch it to Off or Disabled as appropriate.

In my case on an ASUS motherboard, I had to set Secure Boot Mode to Standard.

Step 5: Save your settings and reboot your PC. When you boot back up, Secure Boot should be enabled.

How to check if Secure Boot is enabled in Windows 11

It's possible to doublecheck if Secure Boot is enabled in Windows 11. Here's how.

Step 1: Use Windows search to look for "msinfo32" and select the System Information result.

Step 2: Scroll down the list until you find Secure Boot. It will have either an On or Off next to it, letting you know what state it's in. Pictured here, is when I noticed mine was off and I hadn't realized it.

Windows 11 System Information
DigitalTrends

Now that you've enabled Secure Boot, what about Safe Boot? If you've ever gotten stuck with a blue screen of death, or a boot error, booting into safe mode can be a real lifesaver.

Jon Martindale
Jon Martindale is a freelance evergreen writer and occasional section coordinator, covering how to guides, best-of lists, and…
Microsoft is cracking down on unsupported Windows 11 installs
A Dell laptop with Windows 10 sitting on a desk.

A support document showing users how to install Windows 11 on unsupported PCs was deleted sometime in the past two months. Its disappearance, noticed by Neowin, echoes Microsoft's recent "year of the Windows 11 PC refresh" rhetoric, encouraging (or forcing) users to buy new PCs that meet Windows 11 hardware requirements.

When Windows 11 launched in 2021, Microsoft announced that it was adding TPM 2.0 as a hardware requirement -- a move that was met with plenty of resistance. To soften the blow, Microsoft also published a support document detailing how users could edit their registry key values to bypass the TPM 2.0 check.

Read more
Microsoft is making a major change to using your iPhone in Windows
The Dell XPS 13 on a table with the Start Menu open.

In a recent Windows Insider Blog post, Microsoft announced it's adding the option for iPhone users to access their phones from the Start menu. Thanks to a special widget next to the Start menu, when you connect your phone, you can see data such as notifications, battery indicators, recent contacts, connection status, and more.

To enjoy this feature, you must use the recent Windows 11 preview build from the Dev and Beta channels, and you must be a Windows Insider. You must also update the Phone Link app to version 1.24121.30.0 or higher, have a Microsoft account, and have a PC that supports Bluetooth LE. Microsoft said it does not support PCs running Pro Education or Education SKUs. Even if this doesn't affect you, the update is rolling out in phases, so reaching your PC might take some time if you don't already have it.

Read more
Microsoft confirms audio bug hitting multiple versions of Windows
Ifi Go Bar DAC/amp dongle for headphones.

Microsoft has confirmed that a recent bug that has been affecting several Windows OS versions will be addressed with a fix; however, users can tackle the issue with a manual stopgap.

The bug is affecting the audio systems of Windows 11 and Windows 10 versions that have installed the January 2025 security update, rendering sounds on PCs non-functional. The malfunction is especially likely to happen if you have an audio DAC (digital-to-analog converter) connected to your computer via USB.

Read more