What they are and why you need them
Secure Boot is a BIOS/UEFI protection mechanism that prevents unverified software from running during PC startup. In practice, it blocks malware and tampered operating systems before Windows even loads.
The TPM (Trusted Platform Module) is a security chip on the motherboard (or integrated into the firmware) that protects encryption keys, credentials, and sensitive data.
Games that require Secure Boot enabled:
- Call of Duty: Warzone / Black Ops 6 (from Season 5 onwards)
- Battlefield 6
- Future titles with kernel-level anti-cheat
Without Secure Boot enabled, these games will not even launch.
Check current status
Secure Boot
Open the Windows search bar, type msinfo32 and press Enter. Look for the "Secure Boot State" line:
- On → you are good to go
- Off → you need to enable it in the BIOS
TPM
Search for tpm.msc in the search bar and press Enter. The window will tell you whether the TPM is active and which version you have (2.0 is required).
On Windows 11 the TPM is almost always already active. If it is not, you need to enable it in the BIOS.
Before touching the BIOS
Back up your important files and make sure your BIOS is updated to the latest version. Issues are rare, but it is always better to be prepared.
How to enable Secure Boot
Step 1: Enter the BIOS
Restart your PC and repeatedly press the DEL key (or F2 on some motherboards) during boot, until the BIOS screen appears.
Step 2: Find and enable Secure Boot
The exact location varies by manufacturer. Here is where to find it:
Gigabyte / AORUS
- Switch to Advanced Mode (F2)
- Go to Boot → confirm that "CSM Support" is Disabled
- Open Secure Boot and set it to Enabled
- Save and exit (F10)
If the game still does not detect it after enabling: re-enter the BIOS → disable Secure Boot → change the mode from Standard to Custom and then back to Standard → accept the default values → re-enable and save.
ASUS
- Press F7 for Advanced Mode
- Go to Boot → CSM and disable "Launch CSM"
- Go back, open Secure Boot and set OS Type to "Windows UEFI Mode"
- In Key Management: if it is greyed out, temporarily change Secure Boot Mode to Custom, then choose "Install Default Secure Boot Keys" and confirm
- Save and exit (F10)
MSI
- Press F7 for Advanced Mode
- Go to Settings → Advanced and verify that CSM/UEFI is set to "UEFI"
- Go back → Security → Secure Boot → enable it
- Save and restart (F10)
On newer BIOS (X870, B850, Z890): Advanced → Security → Secure Boot → Mode = Custom → Maximum Security.
ASRock
- Enter the BIOS → Boot → CSM → disable it
- Go to Security → Secure Boot → set it to Enabled
- Save and exit (F10)
Step 3: Verify
Once Windows has restarted, reopen msinfo32 and check that "Secure Boot State" now shows On.
Common issues after enabling
Boot drive not detected
If Windows was installed in Legacy mode (MBR), disabling CSM can hide the drive. You need to convert the drive from MBR to GPT or reinstall Windows in UEFI mode. In an emergency, re-enable CSM to regain access.
Black screen or no video signal
This usually means the GPU does not support UEFI boot, or the monitor is connected to the wrong port. Try connecting the video cable directly to the motherboard (integrated output), re-enter the BIOS and re-enable CSM. If that does not work, reset CMOS (jumper or battery removal).
Windows does not detect Secure Boot
Outdated, modified, or non-genuine Windows versions may not recognize it. Update Windows or do a clean install with a genuine copy.
How to enable TPM
If tpm.msc shows that TPM is not active, enter the BIOS and look for the option corresponding to your processor:
Intel
Enable PTT
(Platform Trust Technology)
AMD
Enable fTPM
(Firmware TPM)
The option is usually found in the Security or Advanced section of the BIOS, depending on the motherboard brand. After enabling, save (F10), restart, and re-check with tpm.msc.
Note on controller overclocking
Those using controller polling rate overclocking (1000 Hz / 8000 Hz) to reduce input lag may have disabled Secure Boot. There are solutions to keep the overclock active even with Secure Boot enabled — it is one of the things we handle during optimization sessions.
Too complicated? I will do it remotely in 10 minutes.
Book a session
ONLYBOOST