-->

How to Enable Secure Boot in Windows 11 (Complete Guide 2026)

    How to Enable Secure Boot in Windows 11 (Complete Guide 2026)

    How to Enable Secure Boot in Windows 11 (Complete Guide 2026)

    Secure Boot is a security feature built into modern UEFI firmware that helps prevent unauthorized software, malware, and rootkits from loading during the startup process. Microsoft recommends enabling Secure Boot to meet Windows 11 system requirements and improve overall device security.

    How to enable Secure Boot in Windows 11 through BIOS or UEFI settings and verify Secure Boot status using System Information
    Enable Secure Boot in Windows 11 by entering your BIOS or UEFI firmware settings, turning on Secure Boot, and verifying the configuration in System Information to improve startup security, prevent boot-level malware, and meet Windows 11 compatibility requirements.

    If Secure Boot is disabled, your PC may fail Windows 11 compatibility checks even if your hardware supports TPM 2.0 and other required features.

    Related: How to Enable TPM 2.0 in Windows 11


    Step 1: Check Secure Boot Status

    1. Press Windows + R.
    2. Type msinfo32.
    3. Press Enter.
    4. Find Secure Boot State.

    You will see one of the following:

    • On – Secure Boot is enabled.
    • Off – Secure Boot is disabled.
    • Unsupported – Your system may be using Legacy BIOS instead of UEFI.

    Step 2: Enter BIOS or UEFI Settings

    1. Open Settings.
    2. Go to System → Recovery.
    3. Click Restart now under Advanced startup.
    4. Select Troubleshoot → Advanced options → UEFI Firmware Settings.
    5. Restart your PC.

    Step 3: Enable Secure Boot

    Within your BIOS or UEFI firmware:

    1. Navigate to the Boot, Security, or Authentication menu.
    2. Locate Secure Boot.
    3. Change the setting to Enabled.
    4. Save the changes and exit.

    Menu names vary depending on the motherboard manufacturer.


    Step 4: Verify Secure Boot

    1. Restart Windows.
    2. Open System Information.
    3. Confirm that Secure Boot State displays On.

    Benefits of Secure Boot

    • Protects against bootkits and rootkits.
    • Verifies trusted boot components.
    • Improves Windows security.
    • Supports Windows 11 compatibility.
    • Works together with TPM 2.0 and BitLocker.

    Common Reasons Secure Boot Is Unavailable

    • Your PC is running in Legacy BIOS mode.
    • UEFI mode is disabled.
    • The system disk uses MBR instead of GPT.
    • Your BIOS firmware requires an update.

    Related Articles


    Frequently Asked Questions

    Can I enable Secure Boot without TPM 2.0?

    Yes. Secure Boot and TPM 2.0 are separate technologies, although both are recommended for Windows 11.

    Will enabling Secure Boot delete my files?

    No. Enabling Secure Boot only changes firmware settings and does not erase personal files.

    Why is Secure Boot grayed out?

    This usually happens when your PC is using Legacy BIOS mode or an MBR partition style. Converting to UEFI and GPT may be required before Secure Boot can be enabled.


    Final Thoughts

    Secure Boot is an essential security feature that helps protect your PC during startup and improves compatibility with Windows 11. By checking its current status, enabling it in your BIOS or UEFI firmware, and verifying the configuration afterward, you can ensure your system meets Microsoft's recommended security requirements.

    LihatTutupKomentar