This thread helped me. Set admin and user password, disabled fast boot. This set my secure boot to enabled. However, I got secure boot violation. So I had to go to secure boot keys and update each of them(5 in total) to system default. This fixed it. Answer from SaurabhSSidhu on reddit.com
🌐
ASUS
asus.com › support › faq › 1050047
How to Enable/Disable Secure Boot | Official Support | ASUS Global
3 weeks ago - Solution for Secure Boot Displaying as "Not Active" First, enable Secure Boot Control, then restore the Secure Boot keys to their default values.
🌐
JustAnswer
justanswer.com › computer › r8uar-asus-590-tuff-gaming-m-i-m-trying-disable.html
Fix Greyed Out Secure Boot on Asus 590 Tuff - Q&A
My cpu is a asus, mother board is tuff gaming, and I haven’t yet but I’m ... Thank you for providing the additional information and the screenshot. Seeing the BIOS screen is very helpful! You are correct; even with the latest BIOS version, Secure Boot can still be quite persistent. The important point here is that the "Secure Boot state" is set to "User." This indicates that Secure Boot is active and managed by pre-enrolled keys.
🌐
Gentoo Forums
forums.gentoo.org › board index › assistance › kernel & hardware
[solved] Secure Boot disabled: Asus Tuf Gaming motherboard - Gentoo Forums
May 5, 2025 - I found an FAQ from Asus that describes the firmware UI in more detail. The table at the bottom shows the SecureBoot state in each combination of OS Type and Secure Boot mode. Unintuitively, Secure Boot is only enabled when OS Type is set to Windows UEFI Mode.
🌐
Asus
rog-forum.asus.com › t5 › asus-software › windows-11-can-t-activate-secure-boot › td-p › 835536
Windows 11 - Can't activate secure boot - Republic of Gamers Forum - 835536
March 5, 2024 - Do you have the latest BIOS update Maybe you need to disable CSM in the BIOS What I need to see in the device security window? and yes, I just updated the bios yesterday, for some reason i dont have even the csm option in my bios. ... If TPM and UEFI were not enabled you wouldnt be able to install win 11.
Find elsewhere
🌐
Microsoft Learn
learn.microsoft.com › en-us › answers › questions › 4026426 › secure-boot-enabled-in-bios-but-not-seen-by-window
Secure Boot Enabled in BIOS, but not seen by Windows 11 - Microsoft Q&A
May 10, 2024 - If Windows does not see Secure Boot active, try resetting TMP keys in your BIOS to factory keys to see if that works, if not, check the support page for your PC or motherboard to see if there is any BIOS update available that may need to be ...
🌐
YouTube
youtube.com › watch
Enable Secure Boot Settings in ASUS Bios Utility - YouTube
Updating to Windows 11 required me to have TPM 2 and Secure Boot enabled to play VALORANT, here’s what i did.Note: Some settings probably look different on e...
Published   November 4, 2021
🌐
NZXT
support.nzxt.com › hc › en-us › articles › 39968244053787-How-to-enable-Secure-Boot-on-your-Gaming-PC-Asus
How to enable Secure Boot on your Gaming PC (Asus) – NZXT Support Center
1 week ago - To confirm that the setting is active, select Trusted Computing in the Advanced tab and ensure that it states TPM 2.0 Device Found and shows Security Device Support as Enabled. With the Trusted Platform Module enabled, we are ready to enable ...
🌐
EaseUS
easeus.com › computer instruction › (solved!) secure boot enabled but not active🔥
Secure Boot Enabled But Not Active - How to Fix?🔥
August 11, 2025 - UEFI Boot Mode Enabled: Your BIOS/UEFI firmware must be set to UEFI mode, not Legacy/CSM. This is essential for Secure Boot to function. TPM 2.0 Enabled: Trusted Platform Module (TPM) version 2.0 must be active on your device.
🌐
ASUS
asus.com › me-en › support › faq › 1050047
How to Enable/Disable Secure Boot | Official Support | ASUS
Solution for Secure Boot Displaying as "Not Active" First, enable Secure Boot Control, then restore the Secure Boot keys to their default values.
🌐
Reddit
reddit.com › r/asus › secure boot asus tuf gaming a15
r/ASUS on Reddit: Secure Boot Asus Tuf Gaming A15
October 27, 2021 -

I am trying to enable secure boot but in BIOS it seems to already be enabled but in system information, it shows it as 'Off'. Any ideas of things that may be causing this issue and/or how to fix it?

🌐
TroubleChute Hub
hub.tcno.co › security › boot › tuf
Enable Secure Boot, TPM and UEFI on ASUS TUF | TroubleChute Hub
October 2, 2025 - Choose Save Changes & Reset (Reset ... Head back to the Boot tab at the top of your screen ... Make sure OS Type is set to Windows UEFI Mode instead of Other OS. This will enable Secure Boot....
Top answer
1 of 2
1

Hi,

Do the following: download PC Check Health, take a screenshot, and post a picture of your PC here:

https://support.microsoft.com/en-us/windows/como-usar-o-aplicativo-verifica%C3%A7%C3%A3o-de-integridade-do-pc-9c8abd9b-03ba-4e67-81ef-36f37caa7844

Thanks

2 of 2
0

Windows 11 requires that the device be UEFI- and Secure Boot–capable, have TPM 2.0, and meet the other minimum hardware requirements (CPU, RAM, storage, graphics, display, and Windows version) before Windows Update or the Installation Assistant will allow the upgrade.

From the described configuration:

  • Firmware TPM 2.0 is enabled and visible in tpm.msc.
  • Secure Boot is enabled in UEFI and reported as active in Windows.

In this situation, the remaining checks to focus on are:

  1. Confirm UEFI (no Legacy/CSM) and Secure Boot mode
    • In UEFI firmware, ensure the system is not booting in Legacy/CSM mode. The firmware must be set to UEFI mode, with Secure Boot capability enabled. Some systems allow both Legacy and UEFI; in that case, UEFI must be the first or only option.
    • If needed, use the Windows path to UEFI settings:
      1. Open Settings > System > Recovery.
      2. Under Advanced startup, select Restart now.
      3. On the blue screen, select Troubleshoot > Advanced options > UEFI Firmware Settings and then Restart.
    • In the firmware menus, verify that Secure Boot is enabled and that the system is booting in UEFI mode, not Legacy/CSM.
  2. Verify all Windows 11 minimum requirements
    • Storage: At least a 64 GB or larger storage device must be present.
    • System firmware: UEFI and Secure Boot capable (already configured, but must be recognized as such by Windows).
    • TPM: TPM 2.0 (already confirmed via tpm.msc).
    • Graphics: DirectX 12–compatible with WDDM 2.0 driver.
    • Display: 720p or higher, >9" diagonal, 8 bits per color channel.
    • Windows version: The current OS must be Windows 10, version 2004 or later, to upgrade via Windows Update.
  3. Use firmware menus to confirm boot mode
    • If there is still doubt about the boot mode, use the firmware boot menu to see how the OS drive is listed. For example, entries like UEFI: indicate UEFI mode. If only BIOS/Legacy entries appear, the system may still be in Legacy mode, which will block Windows 11.

If any of these checks fail (for example, the system is actually booting in Legacy/CSM mode or the current Windows 10 version is older than 2004), Windows Update and the Installation Assistant will continue to report that the device does not meet requirements even if TPM 2.0 and Secure Boot appear active.


References:

  • Windows 11 System Requirements
  • Windows 11 and Secure Boot
  • Boot to UEFI Mode or legacy BIOS mode
Top answer
1 of 5
23

You cannot install Windows 11 with Legacy BIOS. Installing in Legacy or CSM mode on a modern UEFI BIOS is like buying a new car and disabling all of the safety and performance features.

So you'd either need to reinstall Windows 10 exactly as I wrote out with illustrated tutorials, install Windows 11 in UEFI mode which I again gave you illustrated tutorials showing how to do this, or if you want to try to convert your present install to UEFI you can try this method:
https://www.windowscentral.com/how-convert-mbr-...

Once you convert the install and enable UEFI mode in BIOS, hopefully Secure boot will be apparent in the BIOS settings.

If not, then again I told you every single step you should make, even provided your BIOS Manual, the latest BIOS Update, how to contact Asus Support or a dozen different Asus forums that can help you with the specific settings in your Asus BIOS, since they are all different.

There is no one else on the web who would have taken the time and effort to do all of this research for you, posted back step by step instructions, each step illustrated by a tutorial explaining how to do it.

2 of 5
2

Hi Alireza. I'm Greg, 10 years awarded Windows MVP, specializing in Installation, Performance, Troubleshooting and Activation, here to help you.

There's a November 2021 BIOS Update here if yours is not updated:

https://www.asus.com/Motherboards-Components/Mo...

Then you can read the Manual here to find out how to enable Secure Boot:

https://www.asus.com/Motherboards-Components/Mo...

If it's still not clear then contact Asus Support to find out how to enable Secure Boot on your BIOS:

https://www.asus.com/support/

You can also ask in Asus forums:

https://blog.feedspot.com/asus_forums/

Is Windows presently installed in UEFI mode, as this can make a big difference in Secure Boot showing up? If you're unsure type System Information in Search, open and look for BIOS mode.

If not installed to UEFI I'd consider reinstalling to UEFI either with WIndows 10 doing this gold standard Clean Install which includes everything that works best in Windows 10: http://answers.microsoft.com/en-us/windows/wiki...

or do a Windows 11 Clean Install:

https://www.groovypost.com/howto/clean-install-...

https://pureinfotech.com/clean-install-windows-11/

Make sure to create the bootable media using Media Creation Tool only, boot the media as a UEFI device, delete all partitions down to Unallocated Space to clear formatting, then select the Unallocated Space and click Next to let the installer create and format the needed partitions - which makes it foolproof.

Feel free to ask back any questions. If you'll report back results for each step it can help determine what else needs to be tried. I will stick with you until it is fixed.

______________________________________________

Standard Disclaimer: There are links to non-Microsoft websites. The pages appear to be providing accurate, safe information. Watch out for ads on the sites that may advertise products frequently classified as a PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the sites before you decide to download and install it.

🌐
Reddit
reddit.com › r/asustuf › secure boot disablement in asus tuf a15 2023 model?
r/Asustuf on Reddit: Secure boot disablement in ASUS TUF A15 2023 Model?
September 19, 2025 -

Hey all.

As a guy who works in IT and knows most of the BIOS fairly well, I'm surprised we are locked down from disabling secure boot without tampering with Key Management. Pretty sure messing with Key Management bricks the laptop from what I heard.

Is there a way to disable secure boot as it does not play well with Ventoy and keep getting s Secure Boot Violation error no matter the distro, or bootloader I use?

I buy a laptop, and if I want to go on BIOS to change a setting I should have the facility to do that, especially if an ASUS product has an "Advanced Mode" setting.

Many thanks,