What Secure Boot and TPM 2.0 do, and why you might want them on
Secure Boot checks that the software loading when your computer starts is genuine and hasn't been tampered with. TPM 2.0 (Trusted Platform Module) is a chip that stores encryption keys and verifies your operating system hasn't changed. Together, they form a security layer that stops some malware from running at startup, before your antivirus software even loads.
Windows 11 requires both to be on. Older Windows versions and Linux don't require them, but turning them on adds protection. The tradeoff is minor: startup takes a few seconds longer, and some older hardware or software may not work. Most people with newer computers should have both on.
Both settings live in your BIOS or UEFI firmware — the low-level software that runs before Windows loads. You reach it by restarting your computer and pressing a specific key during startup. The key varies by manufacturer: Dell uses F2, HP uses Esc, Lenovo uses F1, Asus uses Del, and others differ. Your computer usually shows which key to press during the boot screen, or you can check your manual or manufacturer's website.
Key Takeaways
- Secure Boot and TPM 2.0 are settings in your BIOS or UEFI firmware, not in Windows itself, so you must restart and enter firmware setup to change them.
- The key to enter firmware setup varies by computer maker — Dell, HP, Lenovo, and Asus each use different keys — and usually appears on screen during startup.
- Secure Boot must be on for Windows 11; older Windows versions and Linux do not require it but benefit from it.
- TPM 2.0 requires compatible hardware; computers made before 2016 may not have it, and you cannot add it later.
- If you dual-boot Linux and Windows, Secure Boot may prevent Linux from starting unless you configure it to allow unsigned bootloaders.
How to enable Secure Boot on Windows
Restart your computer. As it boots, watch for a message telling you which key to press to enter Setup, BIOS, or UEFI — this usually appears for only a few seconds. Press that key immediately. If you miss it, restart and try again.
Once in the firmware menu, look for a section called Security, Boot, or Startup. The menu layout differs by manufacturer, but the option is usually labeled "Secure Boot" and will show a dropdown or toggle set to "Disabled" or "Off". Change it to "Enabled" or "On". Some firmware menus also ask you to choose between "Setup Mode" and "User Mode" — User Mode is the standard choice for most people.
Save and exit. The firmware menu will prompt you to save changes; select Yes or press the key it indicates. Your computer will restart. Windows may take longer to start the first time as it verifies the boot files.
How to enable TPM 2.0 on Windows
Restart your computer and enter the firmware setup using the same method as Secure Boot. Look for a section called Security, Trusted Computing, or PTM (Platform Trust Module). The option is usually labeled "TPM", "TPM 2.0", "Security Chip", or "PTT" (Intel Platform Trust Technology on some laptops).
The setting will show "Disabled" or "Off". Change it to "Enabled" or "On". Some firmware menus offer additional options like "Clear TPM" — do not select this unless you are troubleshooting a specific problem, as it erases stored keys. Save and exit the same way as Secure Boot.
After restart, Windows will recognize TPM 2.0 and may prompt you to restart again. This is normal. You can verify TPM is working by opening the Run dialog (Windows key + R), typing tpm.msc, and pressing Enter. A window will open showing TPM status and version.
What to do if Secure Boot or TPM 2.0 won't turn on
If the option is grayed out or missing, your hardware may not support it. Computers made before 2016 often lack TPM 2.0 — they may have TPM 1.2 instead, which is older and less secure. You cannot add TPM 2.0 to a computer that doesn't have the chip. Check your computer's specifications on the manufacturer's website to confirm what you have.
If the option exists but won't stay on after you save, restart, and check again, your firmware may need an update. Visit your computer maker's support page, download the latest BIOS or UEFI update for your model, and follow their instructions to install it. This usually requires creating a bootable USB drive and restarting into the update tool.
If you see an error message about a "Setup Password" or "Administrator Password", your firmware is locked. You set this password yourself at some point, or it was set during initial setup. You will need to enter the correct password to change security settings. If you don't remember it, contact your computer maker's support line — they can help you reset it, though the process varies by brand.
Secure Boot and TPM 2.0 with Linux and dual-boot systems
If you run Linux alongside Windows on the same computer, enabling Secure Boot may prevent Linux from starting. This happens because Linux bootloaders are often unsigned, and Secure Boot rejects unsigned code by default.
You have three options: disable Secure Boot (reduces security for both systems), configure Secure Boot to allow your Linux bootloader (requires additional setup), or use a Linux distribution that ships with signed bootloaders, such as Ubuntu or Fedora. Ubuntu handles this automatically on most systems. Check your Linux distribution's documentation for Secure Boot support before enabling it.
TPM 2.0 does not conflict with Linux. Most modern Linux distributions recognize and use TPM 2.0 without additional configuration.
Troubleshooting after enabling Secure Boot or TPM 2.0
If Windows won't start after you enable these settings, restart and enter firmware setup again. Disable Secure Boot and TPM 2.0, save, and restart. Windows should boot normally. Then enable them one at a time and restart after each change to identify which one is causing the problem. This is rare on modern systems but can happen if your Windows installation is very old or corrupted.
If you see a message about "Secure Boot Violation" or "Unauthorized Changes Detected", a program or driver is trying to load code that Secure Boot doesn't recognize. This usually means a driver needs an update. Check your computer maker's support page for driver updates, particularly for chipset, storage, or network drivers. Install them and restart.
If your computer is slow to start after enabling these settings, this is normal — Secure Boot and TPM verification add a few seconds. If startup takes much longer than before (more than 30 seconds), restart into firmware setup and check that both settings are actually on. Sometimes they revert to off if the firmware loses power during a shutdown.
Checking that Secure Boot and TPM 2.0 are actually on
In Windows, open the Run dialog (Windows key + R), type msinfo32, and press Enter. Look for "Secure Boot State" — it should say "On". For TPM, open Run again, type tpm.msc, and press Enter. The window will show "TPM 2.0" under the status section if it is working.
You can also check in Settings. Open Settings, go to System, then About, and scroll down to "Device Specifications". Look for "Secure Boot" — it should say "On". TPM does not appear here, so use tpm.msc to verify it.
If either shows as off after you enabled it in firmware, restart your computer. Sometimes the change takes a full restart cycle to register in Windows. If they still show as off after a restart, go back into firmware setup and confirm the settings are actually saved.
Frequently Asked Questions
Do I need Secure Boot and TPM 2.0 for Windows 10?
Windows 10 does not require either one, though Microsoft recommends both for security. Windows 11 requires both. If you plan to upgrade to Windows 11, turning them on now will make the upgrade smoother.
Will enabling Secure Boot or TPM 2.0 slow down my computer?
Startup will take a few seconds longer because the firmware must verify boot files. Day-to-day performance is not affected. If you notice significant slowdown after enabling them, restart and check that they are actually on — sometimes they revert to off.
Can I turn off Secure Boot or TPM 2.0 after I enable them?
Yes. Restart, enter firmware setup, find the setting, change it back to Disabled or Off, save, and restart. Windows will continue to work. You may see warnings that security features are off, but the system will function normally.
What if my computer maker's firmware menu looks completely different from the steps you described?
Firmware menus vary widely. Search your computer maker's name plus "enable Secure Boot" or "enable TPM 2.0" — most manufacturers publish step-by-step guides with screenshots for their specific models. Your computer's manual or support page is the most reliable source for your exact hardware.
Is it safe to enable both at the same time, or should I do them one at a time?
It is safe to enable both in one session. However, if Windows fails to start afterward, enabling them one at a time makes it easier to identify which one caused the problem. Most modern computers handle both without issues.