What Secure Boot does and why you might disable it
Secure Boot is a firmware security feature that checks whether your operating system and drivers are signed by trusted publishers before your computer starts up. It prevents unsigned or malicious code from running during the boot process. On most computers, Secure Boot is turned on by default.
You might need to disable Secure Boot if you're installing an older operating system that doesn't support it, using certain Linux distributions, installing unsigned drivers, or troubleshooting hardware compatibility problems. Some specialized software or custom configurations also require Secure Boot to be off. However, disabling it removes a layer of security, so only turn it off if you have a specific reason.
Key Takeaways
- Secure Boot lives in your computer's BIOS or UEFI firmware settings, not in Windows or your operating system.
- You access these settings by restarting your computer and pressing a specific key during startup — usually Delete, F2, F10, or F12, depending on your manufacturer.
- The exact steps and menu names vary widely between Dell, HP, Lenovo, ASUS, and other manufacturers, so you may need to look up your specific model.
- Some computers require you to set an administrator password or disable other security features before Secure Boot can be turned off.
How to enter your BIOS or UEFI settings
Secure Boot is controlled in your computer's firmware — the low-level software that runs before Windows or your operating system loads. This is called BIOS on older computers and UEFI on newer ones. You cannot change Secure Boot from within Windows itself.
To enter these settings, restart your computer and watch the screen carefully as it boots. You'll see a message telling you which key to press — commonly Delete, F2, F10, F12, or Escape. The key appears only briefly, usually for a few seconds. Press it before Windows starts loading. If you miss it, restart and try again.
On some newer computers, especially those running Windows 11, you can also reach firmware settings through Windows itself. Go to Settings > System > Recovery, then under "Advanced startup" click "Restart now". When your computer restarts, select "Troubleshoot" > "Advanced options" > "UEFI Firmware Settings" > "Restart". This method is slower but gives you more time to find the right button.
Finding and disabling Secure Boot in your firmware menu
Once you're in the BIOS or UEFI menu, you need to locate the Secure Boot setting. The menu layout differs significantly between manufacturers. Look for a section called "Security", "Boot", "Authentication", or sometimes "Startup". Secure Boot might be listed as "Secure Boot", "Secure Boot Control", or "Secure Boot Mode".
Use your keyboard arrow keys to navigate — the mouse usually doesn't work in firmware menus. When you find Secure Boot, select it and change the value from "Enabled" to "Disabled". Some computers show it as "On" or "Off" instead. After making the change, look for a button or menu option to save and exit, usually labeled "Save and Exit", "Exit and Save Changes", or "Save Changes and Reset".
Your computer will restart after you save. It may take longer than usual to boot the first time, and you might see a message saying Secure Boot is off — this is normal.
Manufacturer-specific steps
While the general process is the same, the exact menu names and locations vary. Dell computers typically label it "Secure Boot" under the Security tab and use F2 to enter setup. HP and Lenovo often use F10 or F2 and may call the section "Security" or "System Security". ASUS computers frequently use Delete or F2 and list it under "Boot" or "Security". Acer and MSI systems vary widely depending on the model year.
If you're unsure about your computer's specific steps, search for your exact model number plus "disable Secure Boot" — for example, "Dell XPS 13 disable Secure Boot" or "HP Pavilion 15 disable Secure Boot". Manufacturer support pages and user manuals usually have screenshots showing the exact menu location.
What to do if Secure Boot won't turn off
Some computers require you to set an administrator password in BIOS before you can change Secure Boot. If you see a message saying the setting is locked or grayed out, look for a "Set Administrator Password" or "Set Supervisor Password" option in the Security menu. Set a password, save, restart, and then try disabling Secure Boot again.
A few computers also require you to disable other security features first, such as "TPM" (Trusted Platform Module) or "Intel PTT" (Platform Trust Technology). If Secure Boot still won't disable after setting a password, check your computer's manual or support page for any prerequisites specific to your model.
If you've forgotten an administrator password set in BIOS, you may need to contact the manufacturer's support team or visit a repair shop — there's no standard way to reset it without specialized tools.
Re-enabling Secure Boot later
If you disabled Secure Boot to install software or troubleshoot a problem, you can turn it back on using the same process. Enter your BIOS or UEFI settings, find Secure Boot, change it back to "Enabled", and save. Your computer will restart and Secure Boot will be active again.
Turning Secure Boot back on is recommended once you've finished whatever required it to be off. It provides protection against certain types of malware and unauthorized changes to your system during startup.
Frequently Asked Questions
Will disabling Secure Boot make my computer less secure?
Yes, it removes one layer of protection against malware that tries to run before your operating system loads. However, if you need it off for a specific reason — like installing an older operating system or certain Linux distributions — that reason outweighs the security loss. Turn it back on once you're done.
Can I disable Secure Boot from Windows without restarting?
No. Secure Boot is controlled by your computer's firmware, which runs before Windows loads. You must restart and enter BIOS or UEFI settings to change it. Windows has no way to modify firmware settings directly.
What if my computer won't start after I disabled Secure Boot?
Go back into BIOS or UEFI and turn Secure Boot back on. If your operating system doesn't support Secure Boot being off, it may refuse to start. You may also need to change other boot settings or reinstall your operating system with Secure Boot disabled from the beginning.
Does disabling Secure Boot affect Windows updates?
Windows will still update normally with Secure Boot off. However, some security updates or driver updates may require Secure Boot to be on. If you encounter update problems, try turning Secure Boot back on before installing updates.
Can I disable Secure Boot on a work or school computer?
Probably not. Most managed computers have administrator passwords set in BIOS that prevent changes to security settings. Contact your IT department or help desk if you need Secure Boot disabled for work purposes.