Disabling Secure Boot

If you're running certain PC graphics cards, hardware, or operating systems such as Linux or previous version of Windows you may need to disable Secure Boot.

Secure Boot helps to make sure that your PC boots using only firmware that is trusted by the manufacturer. You can usually disable Secure Boot through the PC’s firmware (BIOS) menus, but the way you disable it varies by PC manufacturer. If you are having trouble disabling Secure Boot after following the steps below, contact your manufacturer for help.

Warning

  • After disabling Secure Boot and installing other software and hardware, you may need to restore your PC to the factory state to re-activate Secure Boot.
  • Be careful when changing BIOS settings. The BIOS menu is designed for advanced users, and it's possible to change a setting that could prevent your PC from starting correctly. Be sure to follow the manufacturer's instructions exactly.

Disable Secure Boot

  1. Before disabling Secure Boot, consider whether it is necessary. From time to time, your manufacturer may update the list of trusted hardware, drivers, and operating systems for your PC. To check for updates, go to Windows Update, or check your manufacturer's website.

  2. Open the PC BIOS menu:

    • You can often access this menu by pressing a key while your PC is booting, such as F1, F2, F12, or Esc.

      Or

    • From Windows, hold the Shift key while selecting Restart. Go to Troubleshoot > Advanced Options: UEFI Firmware Settings.

  3. Find the Secure Boot setting in your BIOS menu. If possible, set it to Disabled. This option is usually in either the Security tab, the Boot tab, or the Authentication tab.

  4. Save changes and exit. The PC reboots.

  5. Install the graphics card, hardware, or operating system that’s not compatible with Secure Boot.

    In some cases, you may need to change other settings in the firmware, such as enabling a Compatibility Support Module (CSM) to support legacy BIOS operating systems. To use a CSM, you may also need to reformat the hard drive using the Master Boot Record (MBR) format, and then reinstall Windows. For more info, see Windows Setup: Installing using the MBR or GPT partition style.

Re-enable Secure Boot

  1. Uninstall any graphics cards, hardware, or operating systems that aren’t compatible with Secure Boot.

  2. Open the PC BIOS menu:

    • You can often access this menu by pressing a key while your PC is booting, such as F1, F2, F12, or Esc.

      Or

    • From Windows, hold the Shift key while selecting Restart. Go to Troubleshoot > Advanced Options: UEFI Firmware Settings.

  3. Find the Secure Boot setting, and if possible, set it to Enabled. This option is usually in either the Security tab, the Boot tab, or the Authentication tab.

    On some PCs, select Custom, and then load the Secure Boot keys that are built into the PC.

    If the PC doesn't allow you to enable Secure Boot, try resetting the BIOS back to the factory settings.

  4. Save changes and exit. The PC reboots.

  5. If the PC isn't able to boot after enabling Secure Boot, go back into the BIOS menus, disable Secure Boot, and try to boot the PC again.

    Tip

    In some cases, you may need to refresh or Remove everything to its original state before you can turn on Secure Boot. For more info, see How to restore, refresh, or Remove everything.

  6. If the above steps don't work, and you still want to use Secure Boot, contact your manufacturer for help.

Secure Boot Overview