How to Enable Secure Boot on Windows and Mac

How to Enable Secure Boot on Windows and Mac


Secure Boot helps protect your computer by allowing only trusted software to run during startup. Enabling this feature helps reduce the risk of boot-level malware and unauthorized operating systems. Follow the steps below to enable Secure Boot on supported Windows PCs and Intel-based Mac computers, then verify that it is enabled correctly.

Enable Secure Boot on Windows PCs

  1. Check Whether Your Computer Supports Secure Boot

    Before making changes to your firmware settings, confirm that your computer supports Secure Boot.

    1. Press Windows + R.
    2. Type msinfo32, then press Enter.
    3. In System Information, locate Secure Boot State.
    4. Review the current status.
    • On – Secure Boot is already enabled.
    • Off – Secure Boot is supported but currently disabled.
    • Unsupported – Your computer may not support Secure Boot or is using Legacy BIOS mode.
  2. Back Up Important Files

    Although enabling Secure Boot normally does not affect your files, back up important data before changing BIOS or UEFI settings.

  3. Access the BIOS or UEFI Settings

    Method 1 (Recommended)

    1. Open Settings.
    2. Select System > Recovery.
    3. Under Advanced startup, click Restart now.
    4. Select Troubleshoot > Advanced options > UEFI Firmware Settings.
    5. Click Restart.

    Method 2

    Restart your computer and repeatedly press the key used to open your computer's BIOS or UEFI settings during startup. Common keys include:

    • F2
    • Delete
    • Esc
    • F10

    If you're unsure which key to use, refer to your computer manufacturer's documentation.

  4. Find the Secure Boot Setting
    1. Open the Boot, Security, or Authentication tab.
    2. Locate the Secure Boot setting.

    Note: The location and name of the Secure Boot setting vary by computer manufacturer.

  5. Enable Secure Boot
    1. Set Secure Boot to Enabled.
    2. If prompted:
    • Enable UEFI Boot Mode.
    • Disable Legacy Boot or CSM.
  6. Save the Changes
    1. Save the settings (commonly by pressing F10).
    2. Exit the BIOS or UEFI settings.
    3. Allow Windows to restart normally.
  7. Verify Secure Boot Is Enabled
    1. Open msinfo32 again.
    2. Verify that Secure Boot State displays On.

    If Secure Boot State still displays Off, return to the BIOS or UEFI settings to confirm that Secure Boot is enabled and that your changes were saved before proceeding to the troubleshooting section.

Enable Secure Boot on Intel-based Mac Computers

Note: These instructions apply only to Intel-based Macs with the Apple T2 Security Chip. Macs with Apple silicon (M1, M2, M3, and newer) already use a secure boot process automatically and do not provide a manual Secure Boot setting.

  1. Shut Down Your Mac

    Completely power off your Mac before entering macOS Recovery.

  2. Start macOS Recovery
    1. Turn on your Mac.
    2. Immediately press and hold Command (⌘) + R until the Apple logo appears.
  3. Open Startup Security Utility
    1. From the menu bar, select Utilities.
    2. Select Startup Security Utility.
  4. Authenticate

    Select your startup disk, then enter an administrator password when prompted.

  5. Select Full Security

    Under Secure Boot, select Full Security to allow only trusted operating systems to start.

  6. Restart Your Mac

    Close Startup Security Utility and restart your Mac normally.

  7. Verify Secure Boot Is Enabled

    Reopen Startup Security Utility if needed and verify that Full Security is still selected for your startup disk.

Optional verification for Experienced Users

The following methods are intended for experienced users who prefer to verify Secure Boot using command-line tools.

Windows (PowerShell)

  1. Open PowerShell as an administrator.
  2. Run the following command:
Confirm-SecureBootUEFI

If the command returns True, Secure Boot is enabled.

Linux

  1. Open a terminal.
  2. Run the following command:
mokutil --sb-state

If the command returns SecureBoot enabled, Secure Boot is active on your system.


Troubleshoot Secure Boot Issues

  1. Secure Boot Option Is Missing

    If you cannot find the Secure Boot option in your BIOS or UEFI settings:

    • Confirm that your computer supports UEFI firmware.
    • Update the BIOS or UEFI firmware to the latest version available from your computer manufacturer.
    • Check different firmware menus, such as Boot, Security, or Authentication.
  2. Windows Was Installed Using Legacy BIOS Mode

    Secure Boot requires UEFI mode. If Windows was installed using Legacy BIOS mode:

    • Convert the system disk from MBR to GPT.
    • Switch the firmware from Legacy BIOS to UEFI mode.
    • Enable Secure Boot after the conversion is complete.
  3. Windows Does Not Start After Enabling Secure Boot
    • Return to the BIOS or UEFI settings.
    • Verify that the correct startup drive is selected.
    • If necessary, temporarily disable Secure Boot while you troubleshoot the issue.
  4. Secure Boot Reports Missing or Invalid Keys
    • Open the BIOS or UEFI settings.
    • Restore or install the default Secure Boot keys.
    • Save the changes and restart your computer.
  5. BitLocker Requests the Recovery Key

    Firmware changes can trigger BitLocker recovery.

    • Enter your BitLocker recovery key to unlock the drive.
    • Verify that Secure Boot and other firmware settings are configured correctly.
  6. Startup Security Utility Is Not Available on Mac

    If you cannot access Startup Security Utility:

    • Confirm that your Mac is an Intel-based model with the Apple T2 Security Chip.
    • Macs with Apple silicon (M1, M2, M3, and newer) automatically use a secure boot process and do not include Startup Security Utility.

Important Notes

  • Create a backup of your important files before changing BIOS, UEFI, or startup security settings.
  • Secure Boot requires UEFI firmware. Systems using Legacy BIOS (CSM) must be converted before Secure Boot can be enabled.
  • If BitLocker is enabled, save your BitLocker recovery key before making firmware changes.
  • Only Intel-based Macs with the Apple T2 Security Chip support manual Secure Boot settings.
  • Macs with Apple silicon (M1, M2, M3, and newer) already use a secure boot process automatically and do not require manual configuration.
  • Depending on your computer manufacturer, the Secure Boot option may appear under the Boot, Security, or Authentication menu.
  • Disable Secure Boot only if required for a trusted operating system or compatible hardware, as doing so reduces startup protection.

Frequently Asked Questions (FAQs)

What is Secure Boot?

Secure Boot is a UEFI security feature that verifies the software loaded during startup, helping prevent unauthorized software and boot-level malware from running before the operating system starts.

How can I tell if Secure Boot is enabled?

Open System Information (msinfo32) and locate Secure Boot State. If it displays On, Secure Boot is enabled.

Why can't I find the Secure Boot setting?

Your computer may be using Legacy BIOS mode, require a BIOS or UEFI firmware update, or place the Secure Boot option under a different menu depending on the manufacturer.

Will enabling Secure Boot delete my files?

No. Enabling Secure Boot does not remove your personal files or installed applications. However, incorrect firmware settings can prevent your computer from starting properly, so backing up your data beforehand is recommended.

Can Apple silicon Macs enable Secure Boot manually?

No. Macs with Apple silicon (M1, M2, M3, and newer) automatically use a secure boot process and do not provide a manual Secure Boot setting.

Conclusion

Enabling Secure Boot helps protect your computer by allowing only trusted software to run during startup. After verifying that Secure Boot is enabled, your system is better protected against boot-level malware and other unauthorized software.

If you need additional assistance or continue to experience problems after enabling Secure Boot, contact Swazzy Support. Our team can help verify your device's compatibility, troubleshoot BIOS or UEFI settings, and guide you through the process safely.

    • Related Articles

    • Enable Device Encryption on Windows

      Protect Your Data with Device Encryption Protecting the data stored on your device is an important part of maintaining security. Windows provides built-in encryption tools, including Device Encryption and BitLocker, to help keep your files and ...
    • How to Record a Microsoft Teams Meeting Using Xbox Game Bar on Windows

      The Xbox Game Bar is a pre-installed feature on Windows PCs designed to enhance the gaming experience, offering screen recording capabilities. While primarily intended for gaming, it can also be used to record any on-screen activity, including ...
    • How to Enable Mobile Hotspot Tethering

      Mobile hotspot tethering lets you share your smartphone's internet connection with laptops, tablets, and other devices when a Wi-Fi network isn't available. The steps below will help you enable hotspot tethering, secure the connection, optimize ...
    • How to Fix Windows High Uptime After Shutting Down

      If your Windows computer continues to show a high uptime even though you shut it down every day, it may not be completing a full shutdown. Features like Fast Startup can preserve part of the system state to speed up startup, causing the uptime ...
    • Enable Two-Factor Authentication (2FA) to Secure Your Cloud Account

      A password alone may not be enough to protect your cloud account from unauthorized access. Enabling two-factor authentication (2FA) adds an extra verification step, helping protect your account from phishing attempts, password theft, and other common ...