What Secure Boot does and why you might need it
Secure Boot is a BIOS security feature that checks whether your operating system and boot files have been tampered with before Windows or Linux starts up. When it is on, your motherboard will refuse to load anything it does not recognize as legitimate. This stops some types of malware from running at the earliest possible moment — before your operating system even loads.
You may need to turn Secure Boot on if your computer manufacturer requires it, if you are installing Windows 11 (which strongly prefers it), or if you want an extra layer of protection against rootkits and bootkits. Some people turn it off when they are installing a fresh operating system or using older hardware, because Secure Boot can sometimes block legitimate boot files it does not recognize.
The steps below work on most Gigabyte motherboards made in the last ten years. The exact menu names and locations vary slightly between models, but the principle is the same across all of them.
Key Takeaways
- Secure Boot lives in your BIOS settings under Security or Boot, not in Windows itself.
- You must restart your computer and enter BIOS setup before Windows loads — usually by pressing Delete or F2 during startup.
- On Gigabyte boards, Secure Boot is typically under Security > Secure Boot, and you change it from Disabled to Enabled.
- After you enable Secure Boot, your motherboard will ask you to enter a password or confirm the change — this is normal and expected.
- If your computer will not boot after enabling Secure Boot, you can turn it back off the same way, or reset your BIOS to factory defaults.
Restart your computer and enter BIOS setup
Close all open programs and restart your computer. As soon as the screen goes black and you see the motherboard logo (usually the Gigabyte logo), begin pressing Delete repeatedly — about once per second. On some older Gigabyte boards, the key is F2 instead. If you are not sure which one, try Delete first; if that does not work, restart again and try F2.
You are aiming to see the BIOS setup screen before Windows starts loading. If Windows loads all the way, you waited too long. Restart and try again, pressing the key faster. The window to enter BIOS is usually only two to three seconds long.
Once you are in BIOS, you will see a menu with white text on a dark background. The exact layout depends on your motherboard model, but you should see tabs or menu items across the top or left side. Do not be alarmed by the unfamiliar appearance — you are in the right place.
Navigate to the Security menu
Look for a tab or menu item labeled Security. On most Gigabyte boards, this is one of the main tabs at the top of the BIOS screen, alongside tabs like Main, Boot, and Chipset. Use your arrow keys to move between tabs, and press Enter when Security is highlighted.
If you do not see a Security tab, look for Boot instead — on some models, Secure Boot settings live under Boot rather than Security. Once you are in the right menu, you should see a list of options. Scroll down through the list until you find an entry that says Secure Boot or Secure Boot Control.
Change Secure Boot from Disabled to Enabled
Highlight the Secure Boot line and press Enter. A small menu will appear showing two or three options: usually Disabled and Enabled, and sometimes a third option like Audit Mode. Select Enabled and press Enter.
After you select Enabled, your motherboard may ask you to set a Secure Boot password or confirm the change by pressing a key. Follow the on-screen instructions. This confirmation step exists to prevent accidental changes, so take your time and read what the screen is asking you to do.
Save your changes and exit BIOS
Once Secure Boot is set to Enabled, you need to save your changes before you leave BIOS. Look for a menu item labeled Save & Exit or Exit — this is usually at the bottom of the menu list or in a separate tab. Press Enter on it.
The BIOS will ask you to confirm that you want to save changes and exit. Select Yes or OK. Your computer will restart, and Windows (or your operating system) will load normally. Secure Boot is now on.
What to do if your computer will not boot
In rare cases, Secure Boot can prevent your computer from starting if your operating system or boot files are not recognized as legitimate. If your computer gets stuck on a black screen, shows an error message about secure boot, or will not load Windows, you can turn Secure Boot back off the same way you turned it on.
Restart your computer, enter BIOS (Delete or F2), navigate to Security > Secure Boot, change it back to Disabled, save, and exit. Your computer should boot normally. This does not mean Secure Boot is broken — it usually means your system needs a firmware update, or your operating system installation needs to be repaired. Contact your computer manufacturer or operating system support for next steps.
If you want to reset your entire BIOS to factory defaults instead, look for an option called Load Optimized Defaults or Reset to Default in the BIOS menu. This will turn off Secure Boot along with any other custom settings you have made.
Verify that Secure Boot is actually on
Once Windows has loaded, you can confirm that Secure Boot is running. Press the Windows key and type msinfo32, then press Enter. A window called System Information will open. Look for a line that says Secure Boot State. If it says On, Secure Boot is working. If it says Off, something went wrong — go back into BIOS and check that you saved your changes.
On Linux systems, you can check Secure Boot status by opening a terminal and typing mokutil --sb-state. The output will tell you whether Secure Boot is enabled or disabled.
Frequently Asked Questions
Will Secure Boot slow down my computer?
No. Secure Boot only runs during the boot process, before Windows loads. It adds a fraction of a second to startup time — usually less than one second — and has no effect on performance once your operating system is running.
Can I turn Secure Boot on and off whenever I want?
Yes. You can enter BIOS at any time and change Secure Boot from Enabled to Disabled or back again. The change takes effect the next time you restart. There is no limit to how many times you can toggle it.
What is the difference between Secure Boot and TPM?
Secure Boot checks your boot files before Windows loads. TPM (Trusted Platform Module) is a separate chip that encrypts sensitive data like Windows passwords. They work together but do different jobs. You can have one without the other, though Windows 11 prefers both to be on.
Do I need Secure Boot if I am not using Windows 11?
No, but it does not hurt. Windows 10 and earlier versions work fine with Secure Boot off. If you are running Linux, Secure Boot is optional — some distributions support it, others do not. Check your operating system documentation if you are unsure.
What does "Audit Mode" mean in the Secure Boot menu?
Audit Mode logs which files fail Secure Boot checks without actually blocking them. This is useful if you are troubleshooting boot problems and want to see what is being rejected. Most people should use Enabled or Disabled instead.