Hi ,

I'm glad it worked out, you can always count on the Microsoft community to have a good week.

Hope this helps.

If you find the answer helpful, please mark it as an answer.

Independent Advisor - Community

Thanks

Answer from Ivan B on learn.microsoft.com
🌐
GIGABYTE
gigabyte.com › home › service & support › consumer › seek solutions & frequently asked questions (faq)
How to Enable Secure Boot and TPM 2.0 on GIGABYTE AM4 300/400/500series & sTRX4 TRX40series Motherboards - GIGABYTE Global
2.Go to Advanced Mode > Settings > AMD CPU fTPM, then choose Enabled. ... 6.The 2nd pop-up message shows “Reset Without Saving”, choose Yes, then the restore factory keys will be processed, and the system will be rebooted.
Top answer
1 of 5
4
UPDATED: to provide clarity and to avoid missing steps which some individuals have encountered: Here's what worked for me on a different Gigabyte board with a Ryzen processor - I had to disable CSM under the Boot tab before "Secure Boot" would show up. Here's what I did on this machine to get it working, see if it works for you - 🛑 FIRST, Check This in Windows (IMPORTANT!) Why? If Windows is installed on an older MBR disk, disabling CSM will stop your PC from booting. You must have a GPT disk (it's no problem if you do this, see below, it's just easier to check first and convert the disk to GPT if you need to). How to check: Press Windows Key + R, type diskmgmt.msc, press Enter. Find your main Windows disk (usually Disk 0). Right-click on the disk and select "Properties". Go to the "Volumes" tab. Look at "Partition style". It must say: ✅ "GUID Partition Table (GPT)" If it says ❌ "Master Boot Record (MBR)", you must convert your disk from MBR to GPT before you can proceed with the steps below. If your disk is GPT, then do the following: Restart Computer Press "Del" key while booting to get into BIOS Make sure it's in "Advanced Mode" (If it's in Easy Mode press F2) Go to "Settings" tab at the top... Scroll down, ensure AMD CPU fTPM is ENABLED on AMD machines - or "Intel Platform Trust Technology (PTT)" or "Intel Trusted Technology" (depending on your motherboard) is ENABLED on Intel machines. Go to "Boot" tab at the top Scroll down to "CSM Support"... click and make it DISABLED "Secure Boot" will then appear below it... Click on "Secure Boot" - change Secure boot to enabled Press OK to message Press F10 - click Yes to save and exit Machine will reboot with secure boot now... NOTE: Secure Boot requires a GPT-formatted disk. If you disable CSM with an MBR disk, your PC will not boot. If you've done this, Do Not Worry, this is Easily Fixed - Restart and enter the BIOS again (press Del/F2). Navigate back to the "Boot" tab. Find "CSM Support" (or "Compatibility Support Module") and set it back to ENABLED. Save and exit (F10). Your system will now boot normally again. You CANNOT "brick" your machine with this process. You just need to put it back into a bootable state again, that's all.
2 of 5
1
Is it even possible? Now Awnsers!
Discussions

Secure boot enabled but not active on gigabyte motherboard
I have a gigabyte B760m motherboard, secure boot is enabled but not active in bios, shows "off" in msinfo32. I've read certain threads that lead me to believe that secure boot mode - custom and then back to standard and "yes" when it… More on learn.microsoft.com
🌐 learn.microsoft.com
3
0
March 12, 2025
How do I enable Secure Boot on a Gigabyte motherboard?
I've been having an issue with trying to enable secure boot in my gigabyte bios. I've disabled CSM support as seen below, and I've made sure that I don't have secure boot already enabled my settings. Even though I've done these things, when I go on the… More on learn.microsoft.com
🌐 learn.microsoft.com
10
17
Secure Boot/Platform keys
Set Secure Boot Mode to "Custom" then click "Expert Key Management". At the top on this screen, you should see "Vendor Keys" and "Valid". If you don't see this, downgrade/update your BIOS to the nearest non-Beta as Gigabyte released a few BIOS updates without importing the Secure Boot variables. If you do see "Vendor Keys" and "Valid", then return to the previous screen and click "Restore Factory Keys". When it tells you to reboot, chose "No". At this point, your Secure Boot status should change to "User", "Enabled", and "Active" in real time. It's now safe to Save and Exit the BIOS. Upon reboot, reenter the BIOS to confirm Secure Boot is Active and enabled ... More on reddit.com
🌐 r/gigabyte
21
15
November 13, 2024
I cannot get secure boot to activate. I have tried every single fix I can find online for gigabyte motherboards and it doesn't fix mine. Sos please help.
try this: Step 1: Access the BIOS and disable CSM Restart your computer and press the Delete key repeatedly to enter the BIOS/UEFI. Navigate to the "Boot" tab. Set CSM Support to Disabled. If you cannot find this setting, ensure you are in "Advanced Mode" by pressing F2 or F7. Step 2: Enable Secure Boot and enroll keys In the "Boot" tab, find Secure Boot and set it to Enabled. If Secure Boot is enabled but shows as "Not Active," change Secure Boot Mode to Custom. Go to Key Management (or Expert Key Management). Select Restore Factory Keys and confirm by choosing Yes when prompted. Some versions may prompt you to "Reset Without Saving," select that option to continue the process. Step 3: Finalize the changes Re-enter the BIOS/UEFI and navigate back to the Secure Boot settings. Confirm that Secure Boot is still Enabled and shows as Active. If you previously set the mode to "Custom," change Secure Boot Mode back to Standard. Go to the "Save & Exit" tab and select Save Changes and Exit Setup. More on reddit.com
🌐 r/gigabyte
32
13
October 13, 2025
🌐
NZXT
support.nzxt.com › hc › en-us › articles › 39908453484827-How-to-enable-Secure-Boot-on-your-Gaming-PC-Gigabyte
How to enable Secure Boot on your Gaming PC (Gigabyte) – NZXT Support Center
February 28, 2026 - Select Restore Factory Keys, then when prompted to Install factory defaults click Yes. If prompted to Reset without saving, select Yes to continue. To confirm Secure Boot is properly enabled, re-open the UEFI and check the Secure Boot settings to make sure that it is Enabled and Active.
🌐
Microsoft Learn
learn.microsoft.com › en-us › answers › questions › 3887665 › secure-boot-enabled-but-not-active-on-gigabyte-mot
Secure boot enabled but not active on gigabyte motherboard - Microsoft Q&A
March 12, 2025 - Enter your BIOS. Navigate to the Secure Boot settings. ... If there is an option to enable secure boot, enable it. If you have doubts about the key state, and you have the option to "Restore Factory Keys" or similar, do so.
🌐
GIGABYTE
gigabyte.com › Support › Security › 2020
Enable Secure Boot to protect systems from UEFI rootkit ‘CosmicStrand’ | Security & Technical Advisory - GIGABYTE Global
August 26, 2022 - GIGABYTE acknowledges security vulnerabilities affecting modern consumer and enterprise products that use UEFI, which has Secure Boot feature that traditional BIOS lacks.
🌐
CCBoot
ccboot.com › wiki home › installation › gigabyte with uefi secure boot
GIGABYTE with UEFI SECURE BOOT | CCBoot Cloud Wiki
November 9, 2025 - The following provides detailed ... Enter the BIOS by pressing one of the following keys during startup typically Del, F2, F1, F10, F12, or Esc....
Find elsewhere
🌐
Tech News Today
technewstoday.com › home › computer tips › how to enable secure boot on gigabyte
How To Enable Secure Boot on Gigabyte - Tech News Today
January 13, 2023 - Restart the computer and press the Del Key continuously during the initial boot-up. The system will then boot into the BIOS. Go to the BIOS tab. Go to Secure Boot and Select Enabled.
🌐
Livingwithtech
livingwithtech.net › blog › enable-secure-boot-gigabyte
How to Enable Secure Boot on Gigabyte Motherboards
September 12, 2025 - If it's using MBR (Master Boot Record), you'll need to convert it to GPT before enabling Secure Boot, or you might encounter boot issues. Make sure that CSM Support (Compatibility Support Module) is disabled in the BIOS. Restart your PC and press the F12 key during boot to enter the BIOS/UEFI ...
🌐
Linus Tech Tips
linustechtips.com › the workbench › troubleshooting
Unable to enable secure boot in Gigabyte bios - Troubleshooting - Linus Tech Tips
September 5, 2024 - Select "Restore Factory Keys". This should allow you to enable Secure Boot. The issue was with the bios version, i downgraded to the one from jun 2023 and everything went smoothly, when swapping between custom and standard, keys were actually ...
🌐
FACEIT
support.faceit.com › hc › en-us › articles › 4406281700370-Enabling-Secure-Boot
Enabling Secure Boot – FACEIT
Gigabyte: set CSM to "Disabled", then you can open the "Secure Boot" menu. After opening it, set "Secure Boot Mode" to "Standard" and "Secure Boot" to "Enabled". If that all of the above is correct and it still does not work, you might need to use the "Reset/Restore factory keys" option
🌐
TroubleChute Hub
hub.tcno.co › home › security › boot › enable secure boot, tpm and uefi on gigabyte aorus
Enable Secure Boot, TPM and UEFI on Gigabyte AORUS | TroubleChute Hub
October 2, 2025 - Re-enter (if you exited) your Advanaced Mode bios using F2. Head back to the Boot tab, and use the arrow keys to go down past the last option on the screen (to scroll) down to Secure Boot
🌐
Reddit
reddit.com › r/gigabyte › what does this mean? trying to enable secure boot
r/gigabyte on Reddit: What does this mean? Trying to enable secure boot
August 8, 2025 - Change Secure Boot from "Standard" To "Custom" - this will allow the other settings to not be grayed out. Click "Expert Key Management". Verify that the top of the screen says that the "Vendor Keys" are "Valid". If they are not "Valid", do NOT proceed any further. Update or downgrade your BIOS one revision at a time until they are "Valid" as Gigabyte released BIOS updates last August/September that had NO Secure Boot credentials imported.
🌐
YouTube
youtube.com › watch
How to Enable Secure Boot in Windows 11 with GIGABYTE B450m Motherboard - YouTube
Enabling Secure Boot on a GIGABYTE B450M motherboard for Windows 11 requires careful steps in the BIOS to avoid boot issues. Here’s a concise guide:Enter BIO...
Published   June 6, 2025
🌐
MS.Codes
ms.codes › blogs › windows › how-to-enable-secure-boot-windows-11-gigabyte
How To Enable Secure Boot Windows 11 Gigabyte
March 1, 2024 - First, access the BIOS settings by restarting your computer and pressing the appropriate key (usually Del or F2) to enter the BIOS setup. Once in the BIOS, navigate to the Boot menu and locate the Secure Boot option.
🌐
GearUP Booster
gearupbooster.com › blog › secure-boot-tutorial-giga-01.html
GIGABYTE Motherboard Secure Boot Guide - 01
October 9, 2025 - Then click Secure Boot in the list and select Enabled. After completing the settings, press F10 to save and restart the computer. After completing the above settings, please open GearUP and recheck whether Secure Boot has been enabled.