Secure Boot is a fundamental security standard developed by members of the PC industry to help ensure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM). While this feature provides a robust layer of protection against rootkits and boot-level malware, there are numerous legitimate reasons to turn it off. Whether the goal is to install a Linux distribution, run specialized diagnostic tools like Ventoy, or resolve "Secure Boot Violation" errors caused by hardware upgrades, understanding how to navigate the complex world of UEFI (Unified Extensible Firmware Interface) is essential.

Because each motherboard manufacturer designs its own BIOS/UEFI interface, there is no single "universal button" to disable this feature. The process varies significantly between an ASUS gaming laptop, a Dell office workstation, and a custom-built MSI desktop. This guide provides a comprehensive walkthrough of the general methods and brand-specific instructions required to successfully modify Secure Boot settings.

Essential Warnings and Risks Before Proceeding

Before making any changes to the firmware, it is critical to understand the implications of disabling Secure Boot. This feature acts as a gatekeeper during the boot process, verifying the digital signatures of the bootloader, kernel, and drivers.

  1. Reduced System Security: Disabling Secure Boot removes the shield that prevents unauthorized code from running at system startup. This makes the computer more vulnerable to sophisticated malware that can hide below the operating system level.
  2. BitLocker Recovery Keys: For users with Windows Pro or Enterprise editions, or those with modern laptops that have "Device Encryption" enabled by default, changing Secure Boot settings can trigger a BitLocker recovery prompt. Ensure the 48-digit recovery key is accessible via a Microsoft account or a physical printout before restarting.
  3. Windows 11 Compatibility: While Windows 11 technically requires Secure Boot to be supported, it does not strictly require it to be enabled at all times after installation. However, certain high-security applications, such as Valorant (Vanguard Anti-Cheat), may refuse to launch if Secure Boot is turned off.

Quick Summary of the Disabling Process

For those who need an immediate answer, the general workflow follows these four steps:

  1. Enter the UEFI/BIOS menu: This is done via Windows Settings or by tapping a specific key (like F2 or Del) during startup.
  2. Locate the Security or Boot tab: Secure Boot is almost always housed in one of these two sections.
  3. Toggle the setting: Change "Secure Boot" from "Enabled" to "Disabled."
  4. Save and Exit: Usually performed by pressing F10 and confirming the changes.

Method 1: Entering UEFI Settings via Windows (Recommended)

Modern PCs boot so quickly that hitting a keyboard shortcut during startup can be difficult. The most reliable way to access the firmware on Windows 10 and Windows 11 is through the Advanced Startup menu.

On Windows 11

  1. Press the Start button and select Settings.
  2. Navigate to System > Recovery.
  3. Locate the Advanced startup section and click the Restart now button.
  4. After the computer restarts into the blue "Choose an option" menu, go to Troubleshoot > Advanced options > UEFI Firmware Settings.
  5. Click Restart to boot directly into the BIOS/UEFI interface.

On Windows 10

  1. Open Settings and go to Update & Security.
  2. Select Recovery from the left sidebar.
  3. Under Advanced startup, click Restart now.
  4. Follow the path: Troubleshoot > Advanced options > UEFI Firmware Settings > Restart.

Method 2: Entering BIOS Using Hardware Keys

If the operating system is not accessible or if the PC is currently powered off, the traditional hardware key method is necessary. Immediately after pressing the power button, tap the designated key repeatedly (about twice per second) until the setup screen appears.

Manufacturer Common BIOS Keys
ASUS F2, Delete
Dell F2, F12
HP F10, Esc (then F10)
Lenovo F1, F2, or Fn + F2
MSI Delete
Acer F2, Delete
Gigabyte Delete
Microsoft Surface Volume Up + Power Button
Samsung F2
Toshiba F2

Comprehensive Brand-Specific Instructions

Once inside the UEFI environment, the layout varies by brand. Below are the specific paths for the most popular hardware manufacturers.

How to Disable Secure Boot on ASUS

ASUS motherboards and laptops typically feature two modes: EZ Mode and Advanced Mode.

  1. Enter the BIOS and press F7 to switch to Advanced Mode.
  2. Navigate to the Boot tab at the top.
  3. Scroll down to find Secure Boot. On many ASUS models, this is located inside a sub-menu also titled Secure Boot.
  4. Look for OS Type. Changing this from "Windows UEFI mode" to "Other OS" often effectively disables Secure Boot on older ASUS boards. On newer models, look for Secure Boot Control and set it to Disabled.
  5. If the option is greyed out, navigate to the Security tab, select Set Supervisor Password, create a temporary password, save, and restart. The option should now be available.

How to Disable Secure Boot on Dell (Alienware, Latitude, XPS)

Dell uses a very clean, mouse-driven UEFI interface (often called "Dell BIOS").

  1. On the left-hand sidebar, find the Boot Configuration or Security category.
  2. Locate the Secure Boot section.
  3. Toggle the switch for Secure Boot Enable to OFF.
  4. On some enterprise models, there is a separate section called Secure Boot Mode. Ensure it is set to "Deployed Mode" or "Audit Mode" if you are a developer, but for standard disabling, simply toggling the Enable switch is sufficient.
  5. Click Apply Changes at the bottom and then Exit.

How to Disable Secure Boot on HP (Pavilion, Envy, EliteBook)

HP menus can be tricky as they often hide advanced features behind an "Esc" menu.

  1. After entering the BIOS (F10), use the arrow keys to navigate to the Security tab.
  2. Select Secure Boot Configuration.
  3. You may see a warning about changing these settings. Press F10 to accept.
  4. Change Secure Boot to Disable and, if available, change Legacy Support to Enable (only if you are installing an older OS).
  5. Save changes. HP computers often require a "Change Confirmation." A four-digit code will appear on the screen; type it in and press Enter to confirm the disabling of Secure Boot.

How to Disable Secure Boot on Lenovo (ThinkPad, IdeaPad, Legion)

Lenovo devices often have a "Novo" button (a small pinhole on the side) that can be used to enter the BIOS if the keyboard shortcuts fail.

  1. Navigate to the Security tab.
  2. Select Secure Boot.
  3. Toggle Secure Boot to Disabled.
  4. On ThinkPads, if the option is locked, you must go back to the Security tab and ensure Set Supervisor Password is configured.
  5. If you are installing Linux, check the Startup tab. Ensure UEFI/Legacy Boot is set to "Both" or "UEFI Only" depending on your requirements, but Secure Boot must be "Off."

How to Disable Secure Boot on MSI

MSI interfaces are usually very graphical (Click BIOS 5).

  1. Enter Advanced Mode by pressing F7.
  2. Go to Settings > Advanced > Windows OS Configuration.
  3. Select Secure Boot.
  4. Change Secure Boot to Disabled.
  5. Note: Some MSI boards require you to change the "Secure Boot Mode" from "Standard" to "Custom" before the "Disable" option appears or before you can clear the Secure Boot keys.

How to Disable Secure Boot on Acer (Aspire, Nitro, Predator)

Acer is known for locking Secure Boot settings behind a password requirement.

  1. Go to the Security tab.
  2. Select Set Supervisor Password and enter a password you will remember.
  3. Now, navigate to the Boot tab.
  4. The Secure Boot option, which was previously greyed out, should now be selectable. Change it to Disabled.
  5. Navigate to the Exit tab and select Exit Saving Changes. You can return later to remove the supervisor password if desired.

Troubleshooting: Why is Secure Boot Greyed Out?

The most common frustration users encounter is the inability to select the Secure Boot toggle. This "greyed out" state occurs for three primary reasons:

1. Missing Supervisor Password

As noted in the Acer and Lenovo sections, many manufacturers require an administrative-level password to be set before allowing changes to security-sensitive firmware settings. This prevents unauthorized users from bypassing boot security. Once the password is set, the menu item becomes active.

2. Fast Boot Conflict

In some rare BIOS versions, "Fast Boot" must be disabled before Secure Boot can be modified. Look for Fast Boot under the Boot or Advanced tabs.

3. CSM (Compatibility Support Module)

Secure Boot and CSM are fundamentally incompatible. Secure Boot requires a pure UEFI environment. If CSM is enabled (to support older, non-UEFI operating systems), Secure Boot is automatically disabled or locked. Conversely, you cannot enable CSM while Secure Boot is on. If you are trying to switch to a Legacy boot mode, you must disable Secure Boot first.

How to Verify Secure Boot Status in Windows

Once the PC has rebooted, it is important to verify that the change was successful without entering the BIOS again.

  1. Press Windows Key + R to open the Run dialog.
  2. Type msinfo32 and press Enter.
  3. In the System Summary (the first screen that appears), look for the item labeled Secure Boot State.
  4. If the operation was successful, it will display Off. If it says On, the settings were not saved correctly in the UEFI menu.

Handling the "Secure Boot Violation" Error

If you are disabling Secure Boot because you saw a red box at startup saying "Secure Boot Violation: Invalid signature detected," this usually means an update (like a Windows KB update or a driver update) has invalidated the signature stored in your firmware's database (db/dbx).

In this scenario, simply disabling Secure Boot allows the PC to boot. However, for a more permanent and secure fix:

  1. Go to UEFI settings.
  2. Look for "Key Management."
  3. Select Reset to Factory Keys or Install Default Secure Boot Keys.
  4. This refreshes the database of "trusted" signatures, often allowing you to re-enable Secure Boot while still fixing the boot error.

Summary

Disabling UEFI Secure Boot is a powerful tool for power users, developers, and those looking to explore alternative operating systems. While it involves navigating various hardware-specific menus and occasionally setting administrative passwords, the logic remains consistent across most platforms: enter the firmware, find the security/boot settings, and toggle the gatekeeper off. Always remember to back up your BitLocker keys and understand that you are trading a layer of automated security for increased system flexibility.

Frequently Asked Questions (FAQ)

Will disabling Secure Boot delete my data?

No. Disabling Secure Boot does not affect the files stored on your hard drive or SSD. However, if your drive is encrypted with BitLocker, you will need your recovery key to access your data after the change.

Can I re-enable Secure Boot later?

Yes. You can return to the BIOS/UEFI settings at any time and toggle the feature back to "Enabled." Note that if you installed an OS that doesn't support Secure Boot (like some older Linux distros), that OS will fail to boot once the feature is turned back on.

Does Windows 11 require Secure Boot to be enabled?

Windows 11 requires that your PC is capable of Secure Boot and that it is supported by the hardware. During the initial installation, the installer checks for this. However, once installed, most versions of Windows 11 will run with Secure Boot disabled, though some specific features and games may not function.

What is the difference between UEFI and BIOS?

UEFI is the modern successor to the traditional BIOS (Basic Input/Output System). UEFI supports larger hard drives, faster boot times, and more advanced security features like Secure Boot. Most people still use the term "BIOS" to refer to the UEFI settings menu.

Why does Linux often require disabling Secure Boot?

While major distributions like Ubuntu and Fedora have signed bootloaders that work with Secure Boot, many smaller distributions or custom kernels do not. Additionally, third-party drivers (like proprietary Nvidia drivers) can sometimes fail to load if Secure Boot is enforcing strict signature verification.