Secure Boot is a firmware setting that checks whether your operating system has been tampered with before your computer starts
Secure Boot is a security feature built into your computer's firmware — the low-level software that runs before Windows or Linux loads. It verifies that the files your operating system needs to start have not been altered or replaced by malware. You turn it on in your BIOS or UEFI settings, which you reach by restarting your computer and pressing a specific key during startup.
Most new computers ship with Secure Boot already enabled. If you have disabled it to install older software or a different operating system, you can turn it back on through the same settings menu. The exact steps depend on your computer's manufacturer — Dell, HP, Lenovo, ASUS, and others use slightly different menu layouts — but the process is the same: restart, enter firmware settings, find the Secure Boot option, and enable it.
Key Takeaways
- Secure Boot is turned on and off in your BIOS or UEFI settings, not in Windows or your operating system itself.
- You reach these settings by restarting your computer and pressing a key during startup — usually Delete, F2, F10, or F12, depending on your manufacturer.
- If Secure Boot is enabled and you install an unsigned operating system or driver, your computer will not start until you disable it again.
- Disabling Secure Boot for troubleshooting is temporary; you should re-enable it once the problem is resolved.
How to enter your BIOS or UEFI settings
Restart your computer completely. As it powers back on, watch the screen for a message that says "Press [key] to enter Setup" or "Press [key] for BIOS Settings." The key varies by manufacturer: Dell and Lenovo often use F2, HP and Compaq use F10, ASUS uses Delete, and some older systems use F1 or F12. If you do not see a message, try pressing the most common key for your brand as soon as the logo appears.
You have only a few seconds to press the key before Windows loads. If you miss it, restart and try again. Once you press the correct key, your computer will load a blue or gray menu screen with white text. This is your firmware settings interface. You are no longer in Windows — you are in the layer of software that runs before Windows starts.
Finding Secure Boot in the settings menu
The menu layout differs by manufacturer, but Secure Boot is usually under a section called "Security," "Boot," or "System Configuration." Look for a tab or menu item with one of those names. If you see "Boot Order" or "Boot Priority," that is not the right section — keep looking for "Security" or a similar heading.
Once you find the Security section, scroll down until you see an option labeled "Secure Boot," "Secure Boot Control," or "Secure Boot Mode." It will show a status of either "Enabled" or "Disabled." If it is already enabled, you can exit the settings and restart. If it is disabled and you want to turn it on, highlight the option and press Enter or the spacebar to change it.
Enabling Secure Boot and saving your changes
When you select the Secure Boot option, a small menu will appear with choices like "Enabled" and "Disabled." Use the arrow keys to highlight "Enabled" and press Enter. The setting will change immediately in the menu.
After you enable Secure Boot, you must save your changes before exiting. Look for a button or menu option that says "Save and Exit," "Exit and Save," or "Save Changes and Reset." Press Enter on that option. Your computer will restart automatically. Do not turn off your computer during this restart — let it complete the process on its own.
What happens after you enable Secure Boot
Your computer will restart and load Windows or your operating system normally. You should not notice any difference in how your computer runs. Secure Boot works silently in the background, checking your system files each time you start up.
If you have recently installed a new operating system, a bootloader, or a driver that is not signed by Microsoft or your hardware manufacturer, your computer may fail to start after you enable Secure Boot. If this happens, you will see an error message or a black screen. You will need to go back into BIOS settings, disable Secure Boot again, and then investigate which software is causing the conflict.
When you might need to disable Secure Boot temporarily
Some older software, custom Linux distributions, or unsigned drivers will not work with Secure Boot enabled. If you are installing one of these and your computer will not start, you can disable Secure Boot using the same process: restart, enter BIOS settings, find the Secure Boot option, change it to "Disabled," save, and exit.
Once you have finished installing or troubleshooting the software, return to BIOS settings and re-enable Secure Boot. Leaving it disabled permanently weakens your computer's security against malware that targets the startup process. Think of Secure Boot as a lock on your startup files — you can unlock it when you need to, but you should lock it again when you are done.
Secure Boot on different manufacturers' computers
Dell computers usually label the setting "Secure Boot" under the Security tab and use F2 to enter settings. HP computers use F10 and often place Secure Boot under "System Configuration" or "Security." Lenovo ThinkPad models use F1 or F2 and list it in the Security section. ASUS computers use Delete to enter BIOS and may label it "Secure Boot Control" under the Boot tab.
If you are unsure which key to press or where to find the setting on your specific model, search your manufacturer's name plus "enable Secure Boot" or check your computer's manual. Most manufacturers publish step-by-step guides for their own systems. Your computer's support website will have the exact key and menu path for your model.
Frequently Asked Questions
Will enabling Secure Boot slow down my computer?
No. Secure Boot adds a small delay — usually less than a second — to your startup time, but it does not affect how fast your computer runs once Windows has loaded. The check happens only during startup, not while you are using your computer.
Can I enable Secure Boot if I have Windows 7 or an older operating system?
Windows 7 and earlier do not support Secure Boot. If you enable it on a computer running those versions, the system will not start. You would need to disable Secure Boot again or upgrade to Windows 10 or later. Windows 11 requires Secure Boot to be enabled.
What if I forgot my BIOS password and cannot access the settings?
If your computer has a BIOS password, you will need to enter it to change any settings. If you have forgotten it, you may be able to reset it by removing the CMOS battery from the motherboard for a few minutes, but this varies by model. Contact your manufacturer's support or consult your computer's manual for the correct procedure.
Is Secure Boot the same as Windows Defender or antivirus software?
No. Secure Boot is a firmware-level check that runs before Windows starts. Antivirus software runs inside Windows after it has loaded. They protect against different threats at different stages — Secure Boot stops tampering with your startup files, while antivirus stops malware running in Windows itself.
Do I need to enable Secure Boot if I use Linux?
Many modern Linux distributions support Secure Boot, but some do not. If you are installing Linux and your computer will not start with Secure Boot enabled, you will need to disable it. Check your Linux distribution's documentation to see whether it supports Secure Boot before you install.