- Secure Boot requires UEFI, GPT partitions, and valid boot keys.
- msinfo32 allows you to check BIOS mode and Secure Boot status.
- Disabling CSM and choosing Windows UEFI enables signature verification.
- Managing keys (restoring factory defaults) resolves the "Not active" status.
After a BIOS/UEFI update, it's quite common for Secure Boot to be disabled, change status, or appear as "Not Active." Therefore, it's advisable to review the settings to get it working properly again. In this article, I'll explain in detail how to safely re-enable Secure Boot without overlooking critical aspects such as UEFI, GPT, CSM, boot keys, TPM 2.0, and BitLocker.
Before touching anything, it's worth doing a couple of quick checks in Windows and the firmware. This will help you avoid common errors like the infamous "Legacy UEFI" or encryption locks. Have your recovery key handy if you're using BitLocker , and consult your manufacturer's guide if applicable, as each motherboard (ASUS, MSI, Gigabyte, Lenovo, Dell, HP, etc.) may display different menus.
What is Safe Start and why should you want to have it enabled?
Secure Boot is a firmware protection layer that validates the cryptographic signatures of the software loaded at system startup, ensuring that only signed and trusted software is executed. In other words, it blocks the execution of unauthorized bootloaders or drivers and helps contain malware that attempts to infiltrate the boot process.
Beyond security, having it properly configured also impacts stability and compatibility with modern systems. If you need to boot tools or operating systems that don't support this verification, you can temporarily disable it, although manufacturers recommend keeping Secure Boot permanently enabled except for very specific needs.
Initial checks in Windows: BIOS mode and Secure Boot status
The first step is to confirm your computer's current status. Windows offers a quick preview to see if you're in UEFI or Legacy (CSM) mode and whether Secure Boot is enabled. Checking here saves time because if it already shows "Enabled," there's nothing else you need to do.
- Balance Windows + R, writes msinfo32 and confirm with Enter. System Information will open.
- Locate the fields BIOS mode y Secure Boot State.
- If the BIOS Mode indicates UEFI and Secure Boot Status is Enabled, you don't need to make any changes. If it says Disabled, you can enable it. If it says Not compatibleYour motherboard does not support this function.
- If the BIOS Mode shows Inherited/CSMYou will need to switch to UEFI before you can use Secure Boot.
MBR vs GPT: Convert the system disk if necessary
For Secure Boot to work, your Windows installation must be on a disk partitioned in GPT (GUID Partition Table) format. If your system drive is in MBR, you should convert it to GPT using Microsoft's built-in tool. Before doing so, back up your important data.
Check the partition style using Disk Management: Press Windows + X, open Disk Management, right-click on the system disk (not just the C: drive), and open Properties > Volumes. Under Partition style, you'll see if it's GPT or MBR.
If you need to convert, open Command Prompt as Administrator (make sure the window indicates that permission level) and validate with mbr2gpt /validate /disk:0 /allowFullOS (Replace 0 with the correct disk number if it doesn't match). If everything is correct, run mbr2gpt /convert /disk:0 /allowFullOSAfter the conversion, it may be necessary Change the boot mode in the firmware to UEFI.
Pre-validation is key because it checks, among other things, that there is enough space for the GPT tables and that the partition structure is compatible. Although the tool is designed for in-place conversion, any partitioning change carries risk, so it is recommended to perform a backup beforehand.
TPM 2.0 and Windows 11: Quick Verification
Although TPM 2.0 is not required to enable Secure Boot, it is required for Windows 11. If you are using Windows 11, you should confirm that the chip is present and enabled. Run tpm.msc and check the Status: if it says "Ready to use," everything is fine; if not, enable it in BIOS/UEFI (look for TPM, fTPM, or PTT, depending on the manufacturer, usually in Security or Advanced Options).
On many modern devices, TPM is enabled by default, but it may be disabled after a firmware update or a system reset. The typical path is to go to Security > TPM/fTPM/PTT and select Enabled , saving changes with F10 before exiting for the activation to take effect.
How to enter BIOS/UEFI: keys and path from Windows
To access Secure Boot, you need to access the firmware. The most common way is to restart the computer and repeatedly press a key during POST. The most common keys are Delete, F2, F10, F12, or Esc , although this depends on the manufacturer.
If you prefer to do it from within the system itself, use Advanced Startup. In Windows 10, navigate to Settings > Update & Security > Recovery and click Restart now under Advanced Startup. In Windows 11, go to Settings > Windows Update > Advanced options > Recovery and, under Advanced Startup, choose Restart now. After restarting, go to Troubleshoot > Advanced options > UEFI Firmware Settings and confirm.
On some laptops (especially gaming laptops), it's common to hold down F2 while turning them on after they're off . On certain gaming laptops, the method might involve holding down the volume down button and pressing the power button simultaneously. Consult your model's manual if you can't get it to boot the first time.
Secure Boot's location in the firmware and what you need to disable.
Once inside the BIOS/UEFI, look for the Secure Boot option. It may be located in tabs such as Security, Boot, Advanced, or Authentication , depending on whether the interface is classic UEFI, "MyASUS in UEFI," or another manufacturer's layer.
Before enabling Secure Boot, disable the Compatibility Support Module (CSM) or Legacy mode. Secure Boot only works in pure UEFI, so if CSM is enabled, disable it. Next, check for an OS Type option; many firmwares will show "Windows UEFI mode" versus "Other OS." To enable Secure Boot, select Windows UEFI.
With CSM disabled and the correct OS type selected, locate the Secure Boot switch (it may appear as Secure Boot Control). Switch it from Disabled to Enabled. If the firmware prompts you to manage keys, install the factory defaults or restore the default keys; this database is what allows Microsoft-signed bootloaders to be validated.
Save changes, exit, and verify in Windows
When you're finished, save and exit. This is usually done by pressing F10 and confirming (OK/Accept/Confirm), or by going to the Save and Exit tab and choosing "Save changes and exit." The computer will restart with the new settings applied.
Back in Windows, repeat the msinfo32 query to confirm that Secure Boot status now appears as Enabled. If it still shows "Not active" or "Disabled," keys may be missing or CSM may still be enabled somewhere in the firmware.
What to do if "Not active" appears: reset keys and force the appropriate mode
There are scenarios where, despite having UEFI and Secure Boot enabled, the status shows "Not active ." On modern motherboards, the typical solution is to enable Secure Boot and restore the factory default keys, saving the changes afterward.
On laptops, all-in-one PCs, or game consoles with classic UEFI: Go to Security > Secure Boot and enable Secure Boot Control . Then go to Key Management. First, use "Reset to Setup Mode" to clear the databases, confirm with Yes, and then select Restore Factory Keys . Save the changes (F10) and restart.
On devices with "MyASUS in UEFI," the process is similar: enable Secure Boot, enter Key Management, reset to Setup Mode , and then restore the keys with "Restore Factory Keys." Finally, save the changes and restart for the status to update.
On desktop computers, some firmwares require changing Secure Boot Mode to Custom to manage keys: open Key Management, run "Clear Secure Boot Keys," confirm, and then choose "Install Default Secure Boot Keys." Don't forget to close with F10 or "Save Changes and Exit" so that the status changes to User/Active when appropriate.
Many UEFI BIOSes have a basic mode and an advanced mode. If you don't see the options above, press F7 to enter Advanced Mode and then check the Security and Boot tabs again. You can navigate using the arrow keys and Enter, or with a mouse or touchpad, depending on your system.
The interface may vary slightly between models and firmware versions. Don't be surprised to find the path listed as Security > Secure Boot > Secure Boot Control or Boot > Secure Boot > OS Type . The goal is the same: disable CSM, select Windows UEFI, and ensure the Secure Boot keys are loaded.
BitLocker and device encryption: avoid surprises when restarting
If you use BitLocker or Device Encryption, modifying critical boot parameters (CSM, Secure Boot, TPM) may cause Windows to request your recovery key on the next startup. Have it ready before touching the BIOS/UEFI to avoid being locked out.
If you prefer to temporarily disable encryption, first consult Microsoft's official guidelines to avoid data loss. On corporate computers, it's advisable to coordinate these changes with the IT team to comply with policies and maintain security.
Alternative route to enable UEFI and convert partitions without reinstalling
If you were coming from Legacy/CSM mode and your disk was formatted as MBR, the cleanest way is to convert to GPT using the utility mbr2gpt and then switch to UEFI in the BIOS. Remember to validate first with mbr2gpt /validate and then run it mbr2gpt /convert with the correct disk identifier.
One detail that's often overlooked: the command prompt window must display "Administrator" . If you don't run the console with elevated privileges, the commands may fail without a clear message, forcing you to repeat the steps.
When to temporarily disable Secure Boot
Some diagnostic tools, maintenance images, and operating systems don't work with signature verification enabled. In those cases, you can temporarily disable Secure Boot, use what you need, and then re- enable it when you're finished.
If you install Linux and had "Other OS" selected in your BIOS, it's common to see messages or errors related to legacy UEFI. The solution usually involves configuring UEFI mode, keeping CSM disabled, and, if you're keeping Windows, verifying that your system disk is formatted as GPT and that the Secure Boot keys are loaded. Some Linux scenarios require signed bootloaders; otherwise, your temporary solution is to boot with Secure Boot disabled.
Laptops and all-in-one PCs: With the computer powered off, hold down F2 while powering on to enter the system setup. Once inside, switch to advanced mode with F7 , go to Security > Secure Boot, and adjust Secure Boot Control. If it doesn't appear, also check the Boot tab, especially the OS Type (Windows UEFI vs. Other OS).
MyASUS in UEFI: Navigation is very similar, only the appearance changes. Go to Advanced Settings, then to Security > Secure Boot, and enable the control and manage keys from Key Management if the status remains as Not Active. Remember to save with F10.
Desktop computers: On some models, the key to enter is Delete (Del) . Look for Boot > Secure Boot and, if key management is enabled, set the mode to Custom to clear and install the default keys (Install Default Secure Boot Keys). Also, check that CSM is set to Disabled so that it becomes active.
Final check and troubleshooting
After each BIOS change, save and restart. In Windows, reopen msinfo32 to confirm: BIOS Mode is set to UEFI and Secure Boot Status is set to Enabled. If something goes wrong and the computer fails to boot, revert to the firmware and temporarily disable Secure Boot or revert the last setting to restore functionality.
Typical errors that reveal the problem: if "Not active" persists, keys are missing; if you don't see the Secure Boot switch, you're in basic view and need to switch to advanced mode; if Windows doesn't start after converting to GPT, the firmware might still be in CSM/Legacy mode instead of UEFI. Adjusting these three points almost always resolves the issue.
Always consult your manufacturer's documentation. Although the goal is the same across all brands, the terminology and exact path vary. It's not uncommon for an option called "OS Type" to be the one that enables or disables Secure Boot behind the scenes (Windows UEFI = active, Other OS = inactive).
• Verify in msinfo32 that you are in UEFI mode and check the Secure Boot status. If you are in Legacy mode, convert to GPT and change to UEFI in the firmware.
• Disable CSM in the BIOS. Set OS Type to Windows UEFI and enable Secure Boot. If prompted, install default keys or restore them from Key Management.
• If the status shows "Not active", reset to Setup Mode and reinstall the factory keys. On desktop computers, you may need to switch to Custom mode to manage keys. Remember to save with F10.
• Use TPM 2.0 if you're on Windows 11 and keep BitLocker in mind: write down the recovery key before touching the firmware. If something goes wrong, revert the last change and try again.
With UEFI, GPT, and CSM disabled, and the factory keys loaded, Secure Boot will be operational, and your computer will only boot trusted software. This setting is worth checking, especially after a BIOS update, because sometimes these changes reset boot parameters or delete the key database. Once you understand the process (msinfo32 for diagnostics, mbr2gpt if necessary, settings in Security/Boot, and key management), re-enabling Secure Boot takes only minutes and provides added security without sacrificing performance.