On this page 7 sections
Secure Boot used to be a setting most players never touched. Then kernel-level anti-cheats started requiring it, and “Secure Boot is not enabled” became one of the most searched game errors on PC.
What Secure Boot is
Secure Boot is part of UEFI, the firmware that starts your PC before Windows loads. With it on, the firmware checks every piece of software involved in starting the computer, from the boot loader to the early drivers, against a list of trusted signatures. Anything not signed by a trusted key is refused.
The point is to stop bootkits and rootkits: malware that loads before Windows, hides beneath it and is very hard to remove once it is there. Secure Boot has been part of the UEFI standard for over a decade, and PCs built for Windows 8 or later almost always support it.
Why games require Secure Boot
Cheats learned the same trick as malware. A cheat that loads before Windows, or before the anti-cheat, can hide from it. Secure Boot closes that door, because nothing unsigned can load during startup.
For a kernel-level anti-cheat, that matters enormously. It can trust that nothing ran before it, and with a TPM it can even ask for proof of how the PC started.
| Game or platform | Requirement |
|---|---|
| Battlefield 6 | Secure Boot must be on for Javelin, or the game will not start |
| Valorant and League of Legends on Windows 11 | TPM 2.0 and Secure Boot, checked by Riot Vanguard |
| FACEIT | Secure Boot and TPM 2.0 for every player since November 2025 |
How to check Secure Boot
- Press Windows and R, type
msinfo32and press Enter. - In System Summary, find BIOS Mode and Secure Boot State.
| What you see | What it means |
|---|---|
| BIOS Mode: UEFI, Secure Boot State: On | Secure Boot is working |
| BIOS Mode: UEFI, Secure Boot State: Off | Supported, just switched off. Enable it in the firmware |
| BIOS Mode: Legacy | The PC boots the old way. The disk and firmware mode need changing first |
| Secure Boot State: Unsupported | Usually Legacy mode on a capable PC, or genuinely old hardware |
How to enable Secure Boot
Every motherboard maker lays its firmware out differently, but the steps are the same.
1. Make sure the disk is GPT
Secure Boot needs UEFI mode, and UEFI needs your system disk to use the GPT partition layout. In Disk Management, right-click the disk, choose Properties and check Partition style on the Volumes tab. If it says MBR, Windows’ own mbr2gpt tool can convert it in place. Back up first.
2. Switch the firmware to UEFI mode
Restart and press the firmware key during startup, usually Delete or F2. Look for CSM (Compatibility Support Module) or a Boot Mode setting and set it to UEFI only, with CSM disabled.
3. Turn Secure Boot on
Find Secure Boot, usually under Boot or Security, and enable it. On some boards you also set the OS type to Windows UEFI mode, or choose to install or restore the default Secure Boot keys if none are loaded. Save and restart.
4. Check again
Run msinfo32 once more. Secure Boot State should now read On.
Things to watch out for
- BitLocker. If your drive is encrypted, changing firmware security settings can make Windows ask for the BitLocker recovery key on the next start. Have it ready from your Microsoft account before you begin.
- Very old graphics cards. Disabling CSM on a PC with a graphics card that lacks UEFI support can leave you with a black screen. Most cards from the last decade are fine.
- Dual booting. Some Linux setups and unsigned drivers will not load with Secure Boot on until they are set up for it.
Secure Boot and your games
Where a game requires Secure Boot, it stays on: Battlefield 6 will not start without it, and the same goes for Valorant on Windows 11. Our Battlefield 6 Secure Boot guide walks through that game’s error message and fix. For other games, leave Secure Boot as it is unless the game asks you to change it, and if you are unsure what a game or build needs, ask support before you change any firmware setting.
Frequently asked questions
How do I check if Secure Boot is on?
Press Windows and R, type msinfo32 and press Enter. In System Summary, Secure Boot State shows On, Off or Unsupported, and BIOS Mode shows UEFI or Legacy. Secure Boot needs UEFI mode.
Does Secure Boot affect gaming performance?
No. Secure Boot only checks software while the PC starts. Once Windows is running it costs nothing, so there is no frame rate to gain by turning it off.
Does Windows 11 need Secure Boot turned on?
Windows 11 needs a PC that is capable of Secure Boot, but it can run with it switched off. Individual games are what require it to be on: Battlefield 6, and Valorant and League of Legends on Windows 11.
Will enabling Secure Boot delete my files?
Switching Secure Boot on does not touch your files. If your system disk uses the older MBR layout, it must be converted to GPT first, which Windows can do in place, but back up anything important before you start.
First published 6 October 2026. Last updated 6 October 2026. We update Wiki pages when the game, the anti-cheat or the build changes, not on a schedule.
Related articles
What Is TPM 2.0? Why Windows 11 and Games Need It
TPM 2.0 is a security chip that stores keys and proves how your PC started. What it does, why Windows 11 and anti-cheats need it and how to enable it.
Updated 6 October 2026 Anti-cheatWhat Is Kernel-Level Anti-Cheat? How It Works and Why
Kernel-level anti-cheat runs as a Windows driver with deep system access. What kernel level means, which games use it, what it can see and the trade-offs.
Updated 6 October 2026 PC and WindowsWhat Is Virtualization-Based Security (VBS) in Windows?
VBS walls off part of memory so even the Windows kernel cannot touch it. What VBS and Memory Integrity do, what they cost in games and who requires them.
Updated 6 October 2026 RequirementsBattlefield 6 Secure Boot: How to Fix the Error and Enable It
Battlefield 6 will not start without Secure Boot because its Javelin anti-cheat requires it. How to check Secure Boot, enable it safely and fix the error.
Battlefield 6 Updated 6 October 2026 Anti-cheatVAC vs FACEIT: How Counter-Strike 2's Anti-Cheats Differ
Counter-Strike 2 has two anti-cheats: Valve's VAC in matchmaking and FACEIT's kernel-level client. How they differ, what each requires and how bans work.
Counter-Strike 2 Updated 6 October 2026Still stuck?
Ask Barry first: he answers in Discord around the clock and fixes most things on the spot. For billing or account questions, open a ticket and a person follows up.