It turns out that "setup" does in fact equate to "disabled".

The steps above are functional, and one can verify this with:

  • In a unix system, either of
    • mokutil --sb-state
    • or dmesg | grep -E 'secure|nvidia'
  • In windows:
    • https://docs.microsoft.com/en-us/mem/intune/user-help/you-need-to-enable-secure-boot-windows
Answer from Seph Reed on Stack Exchange
🌐
ASUS
asus.com › support › faq › 1050047
How to Enable/Disable Secure Boot | Official Support | ASUS Global
3 weeks ago - For those utilizing Notebook, All-in-One PC, or Gaming Handheld devices, the following are the methods to Enable/Disable Secure Boot · First of all, the device needs to enter BIOS configuration. When the device is completely shut down, persistently hold the [F2] key on the keyboard and ...
🌐
Asus
rog-forum.asus.com › t5 › x99 › disable-secure-boot › td-p › 521274
Disable Secure Boot - Republic of Gamers Forum - 521274
March 7, 2024 - Secure boot is only completely active, when you disable CSM under the CSM tab. The CSM (Compatibility Support Module) let you decide, if you want to enable full secure boot with only UEFI startup environment (CSM disabled), or also startup with ...
🌐
Arch Linux Forums
bbs.archlinux.org › viewtopic.php
[SOLVED] disabling secure boot in Asus vivobook 14 arch installation / Installation / Arch Linux Forums
March 15, 2025 - Usually you can re-add the default secure boot keys after deleting, no issue. But ymmv ... After making a backup of the PK and deleting it, it works. So that's the solution. It seems that maybe you will need to set up admin password, but after deleting the pk the secure boot gets disable.
🌐
Reddit
reddit.com › r/asus › can’t disable secure boot again on asus vivobook 15 (stuck in key management lock)
r/ASUS on Reddit: Can’t disable Secure Boot again on Asus Vivobook 15 (stuck in Key Management lock)
August 31, 2025 -

Hi everyone,

I have an Asus Vivobook 15 laptop.

SN: S7N0CV07916628A

EC Version: F00D30C1.308

Running in UEFI mode.

I recently disabled Secure Boot to install Arch Linux. That part worked fine. Later, I needed to enable Secure Boot again (to play Valorant 🙄), so I turned it back on in BIOS.

But now I can’t boot into Windows 11 (or Arch, it’s not set up yet). I get this error:

"SECURE BOOT violation, invalid signature detected. Check Secure Boot policy in Setup."

So I tried disabling Secure Boot again by resetting Key Management to “Setup Mode,” but I get another error:

"Secure variable update is locked down. Try again after system reboot."

I rebooted several times, but it didn’t help.

Right now I’m stuck:

Can’t boot into Windows

Can’t disable Secure Boot

Can’t reset keys

I thought about just deleting the Arch partition and hoping Windows would boot, but that’s not really an option at this point.

Has anyone faced this issue with an Asus Vivobook before? Is there a way to force Secure Boot off or reset the keys without bricking the laptop?

Thanks in advance 🙏

Find elsewhere
🌐
Qualityology
qualityology.com › tech › disable-asus-motherboards-uefi-secure-boot
Disable ASUS Motherboard's UEFI secure boot | Tech | Qualityology
August 7, 2023 - Most new ASUS motherboards do not have the option to let users to turn off the UEFI secure boot. The “Secure Boot Enabled” is always greyed out and unable to change that option.
🌐
TechNorms
technorms.com › home › how-to
How to Disable or Enable Secure Boot for ASUS Motherboard
Secure Boot is often enabled by default on ASUS motherboards with UEFI BIOS. I wanted to have a dual-boot setup on my new PC, and that is not possible when secure boot is enabled. That meant having to identify the Asus BIOS key for the motherboard, enter the Asus BIOS utility and disable secure boot on my Windows 10 running PC.
Published   September 7, 2021
🌐
Visioncomputers
visioncomputers.com › asus-secure-boot-guide
ASUS Secure Boot: Enable, Disable & Fix Greyed Out | Vision Computers | Vision Computers
March 22, 2026 - You cannot click it, toggle it, or change it. There are three reasons this happens. ASUS firmware requires a BIOS administrator password before it allows Secure Boot changes. This is a security measure that prevents someone from walking up to an unattended machine and disabling Secure Boot.
🌐
ASUS
zentalk.asus.com › t5 › faq › motherboard-how-to-enable-or-disable-secure-boot › ta-p › 408885
[Motherboard] How to enable or disable Secure Boot... - ASUS - ZenTalk - 408885
October 7, 2025 - [Motherboard] How to enable or disable Secure Boot ? Content Set Secure Boot state Check Secure Boot state (For example: ROG MAXIMUS Z790 - 408885
🌐
Asus
rog-forum.asus.com › t5 › other-motherboards › can-t-disable-secure-boot-on-asus-maximus-vii-hero › td-p › 604486
Can't disable Secure Boot on Asus Maximus VII Hero - Republic of Gamers Forum - 604486
March 6, 2024 - MeanMachine wrote: Hi rakavolver and Welcome to ROG Here is a link that explains your problem and how to disable secure boot in Windows 8.1 if that is your OS. http://itsfoss.com/disable-uefi-secure-boot-in-windows-8/ Hope this helps. MM Hello MeanMachine, i already checked that link, unfortunately, as explained shortly in my first post, under "Advanced Options" i have no "UEFI Firmware Settings".
🌐
Asus
asus.com › us › support › faq › 1052728
[NUC] Guide to Disable Secure Boot on NUCs | Official Support | ASUS USA
January 12, 2024 - If you need to disable Secure Boot, use the following steps: Yes No · What we can do to improve the article? Submit Skip · Close · North America Contact Support · If you need more help, see our solutions to get support. See support · Above information might be partly or entirely quoted from exterior websites or sources.
🌐
Tech Junkie
techjunkie.com › pc › windows
How To Disable Secure Boot on an ASUS Motherboard - Tech Junkie
May 30, 2022 - Don’t worry, you can always reverse this process and enable Secure Boot without any problems. You also won’t void the warranty by disabling or enabling Secure Boot. Before you disable Secure Boot mode on your computer with an ASUS motherboard, you should enable GPT partitions.
🌐
JustAnswer
justanswer.com › computer › r8uar-asus-590-tuff-gaming-m-i-m-trying-disable.html
Fix Greyed Out Secure Boot on Asus 590 Tuff - Q&A
Here's a breakdown of how to disable Secure Boot when it's greyed out, specifically for ASUS TUF motherboards (though the process is similar across many models): ... Restart your computer.
🌐
YouTube
youtube.com › watch
How to Enable or Disable Secure Boot on Asus Laptop - YouTube
A quick tutorial on, how to enable or disable secure boot on your Asus Laptop. Turn on / Turn off secure boot Asus bios.
Published   June 21, 2023
🌐
Quora
quora.com › How-do-I-turn-off-the-secure-boot-Asus
How to turn off the secure boot Asus - Quora
Answer (1 of 2): You turn off secure boot on any PC through the BIOS. The exact page varies between one BIOS and PC brand and the next.
🌐
Tom's Hardware Forum
forums.tomshardware.com › home › motherboards
Unable to disable secure boot. | Tom's Hardware Forum
March 14, 2015 - Here are some screenshots of the ... posting from the options did not work correctly.) ... As I recall, you have to enter a UEFI password before it will allow you to disable secure boot on Asus systems....
🌐
Ten Forums
tenforums.com › antivirus-firewalls-system-security › 133241-disabling-secure-boot.html
disabling secure boot - Windows 10 Help Forums
May 24, 2019 - In order to disable boot on z 390 ASUS motherboard on my TUF Gaming Plus Wi-Fi set one has to go to firmware> Advanced. From advanced to secure boot and change secure boot mode from UEFI to other, exit and save changes. This disables secure boot. To enable it, the reverse is done.