How to Enable Secure Boot in BIOS: Acer, Dell, ASUS, HP & Lenovo

How to Enable BIOS Secure Boot on Different Motherboards

Secure Boot is disabled or unavailable on your PC? This guide explains how to enable Secure Boot in BIOS on Acer, Dell, ASUS, HP, and Lenovo computers. Before changing any firmware settings, check whether Windows is already running in UEFI mode and back up your BitLocker recovery key if Device Encryption is enabled.

You will find the exact BIOS entry keys and Secure Boot menu paths for each supported brand, followed by solutions for common problems such as Secure Boot being grayed out, showing “Unsupported,” or remaining inactive after it has been enabled. The instructions apply primarily to Windows 11 and most Windows 10 PCs with UEFI firmware.

Table of Contents

Why Enable Secure Boot?

Secure Boot verifies that only digitally signed software, validated by trusted authorities like Microsoft, runs during startup. This prevents malicious code from compromising your system. It’s recommended to keep Secure Boot enabled unless specific requirements, such as running non-supported operating systems, necessitate disabling it. Always be aware of the security risks when disabling Secure Boot.

Note: If your drive is encrypted with BitLocker or Device Encryption, you may need your BitLocker recovery key to access the system after modifying BIOS settings. Magic Recovery Key is helpful in this case.

Supports Windows 7/8/10/11 and Windows Server

Before You Enable Secure Boot

Before entering the BIOS, press Win + R, type msinfo32, and press Enter. Check the following entries in System Information:

  • BIOS Mode: UEFI — You can normally proceed to enable Secure Boot.
  • BIOS Mode: Legacy — Do not switch directly to UEFI without checking whether the Windows system disk and installation support UEFI boot.
  • Secure Boot State: On — Secure Boot is already enabled.
  • Secure Boot State: Off — Enter the BIOS and follow the brand-specific instructions below.
  • Secure Boot State: Unsupported — The PC may be using Legacy BIOS, or its firmware may not support Secure Boot.

If BitLocker or Device Encryption is active, save your recovery key before changing boot settings. A firmware change may cause Windows to request the key during startup.

Enabling Secure Boot on Acer Motherboard

Acer systems typically use a UEFI interface for configuring Secure Boot. Follow these steps to enable Secure Boot on an Acer computer:

1.Enter the BIOS:

    • Shut down your Acer computer completely.
    • Power on the device and immediately press the [F2] key repeatedly until the BIOS setup utility appears.
    • For some Acer models, you may need to press [Del] instead.
How to Enable BIOS Secure Boot on Different Motherboards
2.Navigate to the [Boot] tab and you will see Secure Boot option:
How to Enable BIOS Secure Boot on Different Motherboards

3.If Secure Boot is grayed out, you need to create a password in Security Tab:

    • In the BIOS, use the arrow keys to select the [Security] tab.
    • Locate the [Set Supervisor Password] option, press Enter and set a password.
How to Enable BIOS Secure Boot on Different Motherboards

 4.Enable Secure Boot:

    • Select [Boot] tab and set Secure Boot to Enabled.
    • Note: The Secure Boot state (Active/Not Active) updates automatically based on your settings and cannot be changed manually.
How to Enable BIOS Secure Boot on Different Motherboards

5.Save and Exit:

    • Press [F10] to save changes and exit, or navigate to the Save & Exit tab and select Save Changes and Exit.
    • Confirm by selecting Yes, and the system will restart with Secure Boot enabled.

Enabling Secure Boot on Dell Motherboard

Dell provides a straightforward process to enable Secure Boot through its UEFI interface. Follow these steps:

1.Enter the BIOS:

    • Shut down your Dell computer completely.
    • Power on and press [F2] repeatedly to enter the BIOS setup utility.

2.Access Secure Boot Configuration and enable Secure Boot:

How to Enable BIOS Secure Boot on Different Motherboards
3.Click APPLY CHANGES to Save and Exit:
How to Enable BIOS Secure Boot on Different Motherboards

Enabling Secure Boot on ASUS Motherboard

ASUS systems, such as the ROG MAXIMUS Z790 HERO, use a UEFI interface with options to configure Secure Boot. Here’s how to enable it:

1.Enter the BIOS:

    • Shut down the ASUS computer completely.
    • Power on and press [Del] or [F2] repeatedly to enter the BIOS setup utility.

2.Navigate to Secure Boot Settings:

    • In the BIOS, click or navigate to the [Boot] tab.
    • Select [Secure Boot] to access its settings.
How to Enable BIOS Secure Boot on Different Motherboards
3.set Secure Boot Control = Enabled (or set OS Type to Windows UEFI Mode)
How to Enable BIOS Secure Boot on Different Motherboards

4.Save and Exit:

    • Press [F10] or go to the Exit tab and select Save Changes and Exit.
    • Confirm by selecting Ok, and the system will restart.

Enabling Secure Boot on HP Motherboard

HP computers use a UEFI interface to manage Secure Boot settings. Follow these steps to enable Secure Boot:

1.Enter the BIOS:

    • Shut down your HP computer completely.
    • Power on and presse ESC key repeatedly until the Startup Menu opens.
How to Enable BIOS Secure Boot on Different Motherboards

2.Press F10 and open BIOS Setup

3.Access Secure Boot Settings:

    • Navigate to the [Security] or [System Configuration] tab, depending on the model.
    • Select [Boot Options].
How to Enable BIOS Secure Boot on Different Motherboards
4.Find Secure Boot and enable it.
How to Enable BIOS Secure Boot on Different Motherboards
5.press F10 and select Save Changes and Exit.

Enabling Secure Boot on Lenovo Motherboard

Lenovo systems provide a clear process to enable Secure Boot via the UEFI interface. Follow these steps:

1.Enter the BIOS:

    • Shut down your Lenovo computer completely.
    • Power on and press [F1] to enter the BIOS Setup utility.
How to Enable BIOS Secure Boot on Different Motherboards
2.Navigate to Security — Secure Boot Settings:
How to Enable BIOS Secure Boot on Different Motherboards

3.Enable Secure Boot:

    • Set [Secure Boot] to Enabled.
    • Ensure CSM (Compatibility Support Module) is disabled, as it may conflict with Secure Boot.
How to Enable BIOS Secure Boot on Different Motherboards
4.Press [F10] to save and exit BIOS Setup.
How to Enable BIOS Secure Boot on Different Motherboards

Checking Secure Boot Status

To verify whether Secure Boot is enabled on your system:

1.Press [Win + R] to open the Run dialog, and type msinfo32 and press Enter to open the System Information window.

How to Enable BIOS Secure Boot on Different Motherboards

2.Locate the [Secure Boot State] entry:

    • On: Secure Boot is enabled.
    • Off: Secure Boot is disabled.
How to Enable BIOS Secure Boot on Different Motherboards

Important Notes

  • BitLocker and Device Encryption: Modifying Secure Boot settings on a system with BitLocker or Device Encryption may trigger a recovery key prompt. Ensure you make a backup for the key before making changes.
  • Legacy Boot Conflicts: Secure Boot requires UEFI mode. Disable Legacy Boot or CSM in the BIOS to avoid conflicts.
  • Security Risks: Disabling Secure Boot may expose your system to unauthorized software. Only disable it when necessary and re-enable it afterward.

What to Do If Secure Boot Cannot Be Enabled

ProblemRecommended check
Secure Boot is grayed outConfirm UEFI mode, disable CSM/Legacy Boot, and check whether factory Secure Boot keys are installed. Acer may require a Supervisor Password.
Secure Boot shows Enabled but Windows says OffSave the BIOS changes, restart Windows, select Windows UEFI Mode if available, and restore the default Secure Boot keys.
Secure Boot State says UnsupportedCheck whether BIOS Mode shows Legacy. Also verify that the motherboard supports UEFI Secure Boot.
PC does not boot after changing to UEFIReturn to the previous boot mode and verify the system disk configuration before trying again.
BitLocker recovery screen appearsEnter the BitLocker recovery key saved before changing the BIOS settings.

For additional support, visit the official support pages:

Conclusion

By following these step-by-step instructions, you can easily enable Secure Boot on Acer, Dell, ASUS, HP, or Lenovo mainboards. Doing so not only strengthens your system’s security and stability by ensuring only trusted software loads at startup, but also helps you meet compatibility requirements for certain applications and games — including Battlefield 6, which requires Secure Boot to prevent cheating.

FAQ

Why is Secure Boot important?

Secure Boot ensures that only trusted, digitally signed software runs during startup, preventing malware, unauthorized software, and even some game cheats. Many modern games and applications, including Battlefield 6, require it to be enabled for enhanced security.

What if Secure Boot is grayed out in BIOS?

If the Secure Boot option is unavailable, check if Legacy Boot or CSM (Compatibility Support Module) is enabled, as these conflict with Secure Boot. Switching the boot mode to UEFI and restoring factory Secure Boot keys often resolves the issue.

How to check if Secure Boot is enabled in Windows?

Press Win + R, type msinfo32, and press Enter. In the System Information window, find "Secure Boot State". If it says On, Secure Boot is enabled; if Off, it's disabled.

Why does Secure Boot show Enabled but not Active?

Secure Boot may be enabled in the BIOS but remain inactive when CSM or Legacy Boot is still enabled, the platform keys have not been installed, or the operating system type is set incorrectly. Disable CSM, select Windows UEFI Mode when available, restore the default Secure Boot keys, save the changes, and restart the computer.

Can I enable Secure Boot without converting MBR to GPT?

Secure Boot requires the computer to start in UEFI mode. A Windows system installed in Legacy BIOS mode commonly uses an MBR system disk and may not boot after switching directly to UEFI. Check BIOS Mode and the system disk’s partition style before making changes, and back up important data first.

Does enabling Secure Boot delete files?

Enabling Secure Boot itself does not normally delete personal files. However, changing from Legacy BIOS to UEFI incorrectly can prevent Windows from starting, and encrypted computers may request a BitLocker recovery key. Back up important files and encryption keys before changing firmware or boot-mode settings.

Vasilii is a data recovery specialist with around 10 years of hands-on experience in the field. Throughout his career, he has successfully solved thousands of complex cases involving deleted files, formatted drives, lost partitions, and RAW file systems. His expertise covers both manual recovery methods using professional tools like hex editors and advanced automated solutions with recovery software. Vasilii's mission is to make reliable data recovery knowledge accessible to both IT professionals and everyday users, helping them safeguard their valuable digital assets.