What Is Secure Boot? A Plain-English Explanation

Windows Secure Boot explanation illustration

Secure Boot is a UEFI firmware security feature that checks the software used during startup before Windows loads. It allows trusted, properly signed startup components and blocks untrusted or tampered boot code.

This guide applies to modern PCs with UEFI firmware, typically systems made from about 2012 onward. Older legacy BIOS PCs do not support Secure Boot.

Does This Affect You?

Secure Boot commonly appears in Windows 11 requirement checks, BIOS/UEFI menus, and boot error messages. It protects a narrow but important stage: the startup chain before Windows and antivirus software are running.

What Secure Boot Protects Against

  • Secure Boot is designed to stop bootkits and rootkits that try to load before Windows.
  • It checks digital signatures for firmware and boot components before handing control to the operating system.
  • If a startup component is unsigned or has been changed, Secure Boot can block it.
  • Windows 11 relies on Secure Boot capability along with TPM for newer hardware-backed security features.

Check Secure Boot State in Windows

  1. Press Windows key + R.
  2. Type msinfo32 and press Enter.
  3. On System Summary, find Secure Boot State.
  4. It may show On, Off, or Unsupported. Unsupported usually means legacy BIOS hardware or a configuration that does not expose Secure Boot.

Turn Secure Boot On in UEFI

  1. Restart and enter BIOS/UEFI setup using the key for your PC, often Del, F2, F10, or Esc.
  2. Look under Boot, Security, or Authentication.
  3. Set Secure Boot to Enabled.
  4. If the option is greyed out, check whether Boot Mode is set to UEFI rather than Legacy or CSM.
  5. Save and exit, then confirm the Secure Boot State again in System Information.

Secure Boot Clarifications

It Is Not Antivirus

Secure Boot works before Windows starts. Windows Security or another antivirus still handles ongoing protection after the operating system loads.

Some Tools May Be Blocked

Older Linux bootloaders, specialized recovery tools, or unsigned drivers can be blocked even when they are not malicious. That is the main legitimate reason to disable Secure Boot temporarily.

Turning It Off Is Reversible

Disabling Secure Boot does not delete files, but it removes startup protection and can make a Windows 11 PC report that requirements are not met until it is turned back on.

TPM Is Separate

Secure Boot verifies startup software. TPM stores keys and supports encryption and identity/security features. Windows 11 requires both, but they do different jobs.

Sources

  • Microsoft Learn: Secure Boot overview
  • Microsoft Support: Windows 11 requirements
  • Microsoft Support: Enable TPM 2.0 on your PC
Disclosure: This post may contain affiliate links which means I may receive a commission for purchases made through links. I will only recommend products that I have personally used! Learn more on my Private Policy page.
A thoughtful woman reads a newspaper while enjoying coffee at an indoor workspace.

DEALWEEK

SUBSCRIBE AND GET 20% OFF YOUR NEXT ORDER! OFFER ENDS SOON - DON’T MISS OUT!

We don’t spam! Read our privacy policy for more info.

Shopping Cart