WikiMotherboard

When you buy through our links, we may earn a commission. Why we link ›

Secure Boot on Motherboards: What It Does and How to Enable It

Short answer: Secure Boot is a UEFI security feature that verifies the digital signature of the operating system loader before allowing it to run. Windows 11 requires it alongside a TPM 2.0 module. You can enable it in your motherboard's BIOS/UEFI settings. Most modern motherboards support it, and our guides can help you choose one.

What Secure Boot does

Secure Boot is a key part of the UEFI firmware that controls how your PC starts. Its job is to check the digital signature of the operating system loader and any critical boot drivers before they execute. If the signature is valid and comes from a trusted source, the system proceeds; if not, the boot process stops. This helps prevent malware like rootkits from injecting themselves into the startup sequence.

Secure Boot is not a separate piece of hardware. It is built into the motherboard's UEFI firmware and works with the operating system. Both Microsoft and Linux distributions support Secure Boot, though the process differs slightly. For most home users, Secure Boot is simply a setting that should stay enabled to keep the system protected.

To understand how Secure Boot fits into the firmware environment, see our guide to BIOS and UEFI.

  • UEFI firmware contains a database of trusted certificate authorities and signatures.
  • At boot, the firmware checks the signature of the bootloader against that database.
  • If the signature is missing or invalid, the system refuses to load the operating system.
  • Secure Boot can be disabled, but doing so weakens the security boundary.

Why Windows 11 makes Secure Boot mandatory

Microsoft lists Secure Boot as a minimum system requirement for Windows 11. According to the official specifications, your device must have "UEFI, Secure Boot capable" firmware. The same document also requires a Trusted Platform Module (TPM) version 2.0. These two features work together: Secure Boot verifies the bootloader, while the TPM checks the integrity of the operating system and stores encryption keys.

If you are building a new PC with Windows 11 in mind, you need a motherboard that ships with UEFI and Secure Boot enabled. Many boards leave Secure Boot switched on by default, but some older models or those with legacy BIOS mode may require a change in the firmware settings.

For a deeper look at the TPM portion, read our motherboard TPM guide.

How to enable Secure Boot in your motherboard firmware

Enabling Secure Boot usually takes a few minutes. You will need to enter the UEFI/BIOS setup during startup, find the Secure Boot option, and turn it on. The exact path varies by motherboard manufacturer, but the steps are similar.

Before you start, make sure your operating system is installed in UEFI mode, not legacy BIOS compatibility mode. If the drive uses an MBR partition table, you may need to convert it to GPT first. Some motherboards also require you to disable the Compatibility Support Module (CSM) to expose the Secure Boot options.

  • Restart your PC and press the key indicated on screen (often Del, F2, or F12) to enter the firmware setup.
  • Look for a menu named "Boot", "Security", or "Authentication".
  • Find the "Secure Boot" option and set it to "Enabled".
  • If the option is grayed out, enable "Windows 10/11 mode" or switch the OS type to "Windows UEFI mode" first.
  • Save changes and exit. The system will reboot with Secure Boot active.

Other security features on modern motherboards

Secure Boot is only one layer of protection. Windows 11 also requires a TPM 2.0 chip, which is often integrated into the CPU or motherboard chipset. The TPM provides hardware-level storage for encryption keys and can verify that the operating system has not been tampered with. Many business-oriented platforms go further: Intel's vPro technology, for example, adds remote management and security features for enterprise PCs, as noted in Intel's processor documentation.

When you shop for a motherboard, pay attention to firmware options beyond Secure Boot. A board with a dedicated TPM header (for discrete TPM modules) or an integrated TPM 2.0 is a solid choice. You might also want a board with dual BIOS or a flashback feature to recover from corrupted firmware.

Choosing a motherboard that supports Secure Boot

Every modern motherboard with UEFI firmware can enable Secure Boot, but not all are easy to configure. The best approach is to pick a board from a reputable maker that ships with a recent UEFI update and a clear user interface. Intel's current desktop chipsets, such as the B860 and Z890, are marketed for consumers and enthusiasts and pair with processors like the Intel Core Ultra family. These platforms include standard UEFI support and TPM 2.0 integration.

If you are building a new system, also consider the connectivity you need. The USB4 specification allows up to 80 Gbps operation over certified cables, and Wi-Fi 7 delivers multi-gigabit wireless speeds using 320 MHz channels in the 6 GHz band. Features like these add convenience but do not affect Secure Boot.

For specific recommendations, browse our buying guides. If you are on a modern AMD platform, the best AM5 motherboards list covers current options. For Intel's latest socket, see best LGA1851 motherboards. If you want a compact build, the best ITX motherboards guide has smaller boards that still offer full Secure Boot support.

What to pick for your use

If youPickBuying guide
You are building a Windows 11 gaming PC on Intel's latest socketLGA1851 motherboardBest LGA1851 Motherboards in 2026: 7 Picks Compared on Specs
You prefer AMD's current platform for a balanced buildAM5 motherboardBest AM5 Motherboards in 2026: 12 Picks Compared on Specs
You want the smallest case that still supports Secure BootITX motherboardBest ITX Motherboards in 2026: 12 Picks Compared on Specs
You need maximum expansion and robust firmware featuresATX motherboardBest ATX Motherboards 2026: 15 Picks by Socket and Features
You are on a tight budget but still need Windows 11 compatibilityBudget motherboardBest Budget Motherboards in 2026: 12 Picks
You are building a high-end workstation with vPro or advanced securityWorkstation motherboardBest Workstation Motherboards 2026: 12 Picks Compared on Specs

Questions

What is Secure Boot on a motherboard?

Secure Boot is a UEFI firmware feature that checks the digital signature of your operating system loader before it runs. It stops unauthorized code from taking control of the boot process.

How do I check if Secure Boot is enabled on my PC?

Enter the UEFI/BIOS setup during startup and look for a Secure Boot option under Boot or Security menus. The exact location depends on the motherboard maker. You can also run the Windows System Information tool under the BIOS Mode field.

Will enabling Secure Boot break my older operating system?

Older systems that do not have a signed bootloader may fail to boot. If you dual-boot with Linux, most major distributions support Secure Boot, but you may need to install additional keys. Windows 11 requires Secure Boot, so it must be enabled for that OS.

Can I disable Secure Boot after installing Windows 11?

Yes, you can disable it in the UEFI settings, but Windows 11 may become unstable or fail to start if you change the firmware security after installation. Some newer Windows updates require Secure Boot to be active.

Is Secure Boot the same as TPM?

No. Secure Boot verifies the bootloader, while TPM (Trusted Platform Module) is a separate hardware chip that stores encryption keys and checks system integrity. Windows 11 requires both Secure Boot and TPM 2.0.

Do all motherboards support Secure Boot?

Any motherboard with UEFI firmware can support Secure Boot, but very old boards with only legacy BIOS cannot. If you have a board from the last decade, check the firmware settings for the option. Most modern Intel and AMD boards include it.

Revision notes

  • : First published.

Sources

Related buying guides