What UEFI Secure Boot does and why it matters

UEFI Secure Boot is a firmware security feature that checks whether the software loading when your computer starts up has been digitally signed by a trusted source. If unsigned or tampered-with code tries to run during startup, Secure Boot stops it before Windows even loads. This blocks a specific class of malware — rootkits and bootkits — that infect the lowest level of your system before your antivirus software has a chance to run.

Windows 11 can run without Secure Boot enabled, but Microsoft recommends it as part of the security baseline for the system. If your computer came with Windows 11 pre-installed, Secure Boot is almost certainly already on. If you built your own machine, upgraded from Windows 10, or need to re-enable it after troubleshooting, you will need to turn it on in your firmware settings — the low-level software that runs before Windows starts.

The process involves restarting your computer, entering the UEFI firmware menu (sometimes called BIOS, though technically UEFI is the newer standard), and flipping a toggle. The exact steps depend on your computer manufacturer, but the general path is the same across most machines made in the last five years.

Key Takeaways

  • Secure Boot is a firmware setting, not a Windows setting, so you access it by restarting and entering your computer's UEFI menu during startup.
  • The key combination to enter UEFI varies by manufacturer — common ones are F2, F10, Del, or Esc pressed immediately after power-on — and your computer usually displays the correct key on the startup screen.
  • Once in UEFI, look for a setting called "Secure Boot" or "Secure Boot Control" under a section labeled "Security" or "Boot", then change it from Disabled to Enabled.
  • After enabling Secure Boot, save your changes and restart; Windows will boot normally and you can verify the setting is active in Windows Settings under System > System Information.
  • If your computer will not start after enabling Secure Boot, restart into UEFI again and disable it temporarily while you troubleshoot — this usually means a driver or piece of software needs updating.

How to restart and enter your UEFI firmware menu

The first step is to shut down your computer completely, then power it back on and watch for the startup screen. Most computers display a message during the first few seconds that says something like "Press F2 to enter Setup" or "Press Del for BIOS Settings." The key you need varies by manufacturer: Dell and Lenovo often use F2, HP and Asus use F10 or Del, and some Acer machines use F1. If you miss the message, restart and watch more carefully — it usually appears for only a few seconds.

If you cannot see the message or your computer boots straight into Windows, you can force the restart from Windows itself. Open Settings, go to System > Recovery, and under "Advanced startup" click "Restart now." Your computer will restart into a blue menu. From there, select "Troubleshoot," then "Advanced options," then "UEFI Firmware Settings." Click "Restart" and your computer will reboot directly into the UEFI menu.

Once you are in the UEFI menu, you will see a screen with text options and sometimes a mouse cursor. The layout and colors vary widely — some are dark blue, some are graphical, some look like old DOS screens. This is normal. Take a moment to look for a section labeled "Security," "Boot," "Authentication," or sometimes just "Advanced." That is where Secure Boot lives.

Finding and enabling the Secure Boot setting

Navigate to the Security section using your arrow keys or mouse, depending on what your UEFI menu supports. Look for an option called "Secure Boot," "Secure Boot Control," or "Secure Boot Mode." You will see it is currently set to "Disabled." Highlight that option and press Enter, or click on it if your menu supports a mouse. A small menu will pop up with two choices: "Enabled" and "Disabled." Select "Enabled."

Some UEFI menus also show a "Secure Boot Mode" setting below the main toggle. This is usually set to "Standard" or "Custom," and Standard is the correct choice for Windows 11. You do not need to change this unless you have a specific reason to do so.

After you change Secure Boot to Enabled, look for a button or option that says "Save and Exit" or "Save Changes and Reset." This is usually at the bottom of the menu or accessible by pressing F10. Select it, and your computer will restart. Windows will boot normally — you should not see any error messages or unusual behavior.

Verifying Secure Boot is actually on

Once Windows has restarted, you can confirm that Secure Boot is enabled by checking Windows Settings. Open Settings, go to System, then scroll down and click "System Information." Look for a field labeled "Secure Boot" — it should say "On." If it says "Off," Secure Boot did not enable properly, and you will need to go back into UEFI and check your settings.

Alternatively, you can open the Run dialog by pressing Windows key + R, type msinfo32, and press Enter. The System Information window will open. Look for "Secure Boot State" in the list — it should show "On."

What to do if your computer will not start after enabling Secure Boot

In rare cases, enabling Secure Boot causes your computer to fail to start or to get stuck on a black screen. This usually means a driver or piece of firmware on your system is not signed with a certificate that Secure Boot recognizes. This is most common on older computers, computers with custom hardware, or machines that have had significant driver updates.

If this happens, restart your computer and go back into UEFI the same way you did before. Disable Secure Boot again, save, and restart. Your computer should boot normally. Then, visit your computer manufacturer's support website and download the latest BIOS or firmware update for your specific model. Install it according to the manufacturer's instructions, then try enabling Secure Boot again. The firmware update usually includes updated drivers and certificates that Secure Boot will recognize.

If you still cannot enable Secure Boot after updating firmware, check whether you have any external USB devices connected — printers, external drives, USB hubs — and disconnect them. Sometimes Secure Boot rejects unsigned firmware on external devices. Try enabling Secure Boot again with only your keyboard and mouse connected.

Secure Boot and third-party software

Some specialized software — particularly older antivirus programs, disk encryption tools, or system utilities — may conflict with Secure Boot. If you installed new software and then Secure Boot stopped working, that software is the likely culprit. Disable Secure Boot temporarily, uninstall the software, then re-enable Secure Boot. If that fixes the problem, check whether the software has an updated version that supports Secure Boot, or consider whether you still need it.

Windows Defender, Windows Firewall, and built-in Windows security features all work fine with Secure Boot enabled and do not require you to disable it.

Frequently Asked Questions

Will enabling Secure Boot slow down my computer?

No. Secure Boot runs only during startup and adds a fraction of a second to your boot time — usually less than one second and often unnoticeable. Once Windows is running, Secure Boot has no effect on performance.

Can I disable Secure Boot if I need to?

Yes. You can disable it anytime by restarting into UEFI and changing the setting back to Disabled. Some older software or specialized hardware may require this, though it is uncommon. If you disable it, you lose the protection against bootkits, so re-enable it as soon as the software or hardware issue is resolved.

Is Secure Boot the same as Windows Defender?

No. Secure Boot is a firmware-level check that runs before Windows loads. Windows Defender is antivirus software that runs after Windows starts. They work together but are separate systems. You can have one without the other, though having both is more secure.

Do I need to do anything after enabling Secure Boot?

No. Once it is enabled and verified in Windows Settings, it runs automatically in the background. You do not need to configure it, update it, or check on it. It will remain enabled until you manually disable it or reset your UEFI settings to factory defaults.

What if I forgot my UEFI password?

If your UEFI menu is password-protected and you cannot remember the password, you will need to reset it. Most manufacturers allow you to do this by removing the CMOS battery from the motherboard for a few minutes, but this requires opening your computer case. Contact your computer manufacturer's support line with proof of ownership — they can walk you through the reset process for your specific model.