Secure Boot helps protect your computer by allowing only trusted software to run during startup. Enabling this feature helps reduce the risk of boot-level malware and unauthorized operating systems. Follow the steps below to enable Secure Boot on supported Windows PCs and Intel-based Mac computers, then verify that it is enabled correctly.
Before making changes to your firmware settings, confirm that your computer supports Secure Boot.
msinfo32, then press Enter.Although enabling Secure Boot normally does not affect your files, back up important data before changing BIOS or UEFI settings.
Method 1 (Recommended)
Method 2
Restart your computer and repeatedly press the key used to open your computer's BIOS or UEFI settings during startup. Common keys include:
If you're unsure which key to use, refer to your computer manufacturer's documentation.
Note: The location and name of the Secure Boot setting vary by computer manufacturer.
msinfo32 again.If Secure Boot State still displays Off, return to the BIOS or UEFI settings to confirm that Secure Boot is enabled and that your changes were saved before proceeding to the troubleshooting section.
Note: These instructions apply only to Intel-based Macs with the Apple T2 Security Chip. Macs with Apple silicon (M1, M2, M3, and newer) already use a secure boot process automatically and do not provide a manual Secure Boot setting.
Completely power off your Mac before entering macOS Recovery.
Select your startup disk, then enter an administrator password when prompted.
Under Secure Boot, select Full Security to allow only trusted operating systems to start.
Close Startup Security Utility and restart your Mac normally.
Reopen Startup Security Utility if needed and verify that Full Security is still selected for your startup disk.
The following methods are intended for experienced users who prefer to verify Secure Boot using command-line tools.
Windows (PowerShell)
Confirm-SecureBootUEFIIf the command returns True, Secure Boot is enabled.
Linux
mokutil --sb-stateIf the command returns SecureBoot enabled, Secure Boot is active on your system.
If you cannot find the Secure Boot option in your BIOS or UEFI settings:
Secure Boot requires UEFI mode. If Windows was installed using Legacy BIOS mode:
Firmware changes can trigger BitLocker recovery.
If you cannot access Startup Security Utility:
Enabling Secure Boot helps protect your computer by allowing only trusted software to run during startup. After verifying that Secure Boot is enabled, your system is better protected against boot-level malware and other unauthorized software.
If you need additional assistance or continue to experience problems after enabling Secure Boot, contact Swazzy Support. Our team can help verify your device's compatibility, troubleshoot BIOS or UEFI settings, and guide you through the process safely.