How to Enable Secure Boot on a Gaming Laptop
Short answer: Secure Boot is a firmware security feature that ensures your gaming laptop only boots trusted operating system loaders. To enable it, restart your laptop, enter the BIOS/UEFI setup (usually by pressing a key like F2, Del, or Esc during startup), find the Secure Boot option under Boot or Security settings, set it to Enabled, save changes, and exit. Your laptop must have UEFI firmware and a TPM 2.0 chip, which most modern gaming laptops have. Enabling Secure Boot helps protect against rootkits and other low-level threats, and it is required for Windows 11.
What is Secure Boot and why it matters for gaming laptops
Secure Boot is a security standard that ensures your laptop only starts software that is trusted by the firmware. When you power on your gaming laptop, the UEFI firmware checks the signature of the operating system loader and other critical boot components. If the signatures are valid, the system boots normally. If not, the firmware blocks the boot process, which helps prevent malicious software like rootkits from loading before the operating system. For more on how Secure Boot relates to hardware security, see gaming laptop TPM.
For a gaming laptop, Secure Boot adds a layer of protection that is especially valuable when you download games, mods, or other software from the internet. It does not replace antivirus, but it reduces the risk of low-level infections that are hard to remove. Microsoft lists Secure Boot as a minimum system requirement for Windows 11, so enabling it is also necessary if you want to run the latest version of Windows on your machine. If you are choosing a new laptop, our best gaming laptops list includes models that support Secure Boot.
Check if your gaming laptop supports Secure Boot
Before you change any settings, confirm that your laptop's firmware supports Secure Boot. Most gaming laptops sold in recent years use UEFI firmware, which includes Secure Boot capability. You can check this in Windows by opening System Information. Press Windows + R, type "msinfo32", and press Enter. Look for "Secure Boot State" in the System Summary. If it says "On", Secure Boot is already enabled. If it says "Off", you can enable it in the BIOS.
Also verify that your laptop has a Trusted Platform Module (TPM) version 2.0. Windows 11 requires TPM 2.0, and most gaming laptops include it. In the same System Information window, look for "Device Encryption Support" or use the TPM Management tool (tpm.msc) to check the TPM version. If your laptop does not have TPM 2.0, Secure Boot alone will not meet Windows 11 requirements, but you can still enable it for better security. You can also read our guide to TPM.
How to enter the BIOS or UEFI setup on a gaming laptop
To enable Secure Boot, you need to access the firmware settings, often called BIOS or UEFI setup. The method varies by manufacturer, but the most common way is to restart your laptop and press a specific key during the boot process. Keys like F2, Del, Esc, or F10 are typical. The exact key is usually displayed on the screen during startup or listed in the laptop's manual. If you need help with the initial setup, see gaming laptop first-time setup.
If your laptop boots too quickly to press the key, you can enter the UEFI firmware settings from Windows. Go to Settings > System > Recovery, and under "Advanced startup", click "Restart now". After the laptop restarts, choose Troubleshoot > Advanced options > UEFI Firmware Settings, and click Restart. This will take you directly to the BIOS setup without needing to press a key. For more on BIOS maintenance, see how to update gaming laptop BIOS and drivers.
Step-by-step: Enable Secure Boot in the BIOS
Once you are in the BIOS setup, use the arrow keys to navigate. The exact menu names vary by manufacturer, but you are looking for a tab called "Boot", "Security", or "Authentication". Inside that tab, find an option named "Secure Boot", "Secure Boot Control", or "Secure Boot Mode". Select it and change the value to "Enabled" or "On".
Some laptops have Secure Boot set to "Standard" or "Custom" mode. If you see a mode option, choose "Standard" because it uses the default Microsoft keys. After changing the setting, save your changes and exit. Usually you press F10 to save and exit, but the key is often shown on the screen. The laptop will restart, and Secure Boot will be active. If you are looking for a laptop that makes this process straightforward, consider models from our best esports gaming laptops list.
- Navigate to the Boot or Security tab in BIOS.
- Find the Secure Boot option and set it to Enabled.
- If there is a mode option, choose Standard.
- Save changes and exit (usually F10).
Troubleshooting: What to do if Secure Boot does not enable
If you cannot find the Secure Boot option, your laptop might be in legacy BIOS mode instead of UEFI. Secure Boot only works with UEFI firmware. Check if there is a "Boot Mode" or "UEFI/Legacy" setting and switch it to UEFI. Be aware that changing boot mode can affect how Windows starts, so you may need to reinstall or repair the boot loader. For resetting firmware settings, see how to reset BIOS settings.
Another issue is that some laptops require you to set an administrator password before you can change Secure Boot settings. If the option is grayed out, set a BIOS password first, then try again. Also, if you have installed a different operating system or modified the boot configuration, Secure Boot might fail to validate the boot loader. In that case, you may need to restore the default Secure Boot keys or reinstall Windows.
Secure Boot and Windows 11: What you need to know
Windows 11 lists Secure Boot as a minimum system requirement. Microsoft states that your device must have "UEFI, Secure Boot capable" firmware. This means the firmware must support Secure Boot, but it does not necessarily have to be enabled for the upgrade check. However, for the best security, you should enable it.
If you plan to upgrade to Windows 11, make sure your gaming laptop also has TPM 2.0 and a compatible 64-bit processor. Most modern gaming laptops meet these requirements. After enabling Secure Boot, you can verify that Windows 11 is running with Secure Boot on by checking System Information again. For more on Windows editions, see Windows 11 Home vs Pro.
What to pick for your play
| If you | Pick | Buying guide |
|---|---|---|
| You want a secure gaming laptop that meets Windows 11 requirements | Enable Secure Boot in the BIOS and verify TPM 2.0 | Best Gaming Laptops (2026): Gaming Laptop Reviews |
| You play competitive online games and want extra protection against cheating software | Enable Secure Boot and keep it on | Best Esports Gaming Laptops in 2026: 15 Picks by Specs |
| You download many games and mods from various sources | Enable Secure Boot to reduce the risk of boot-level malware | Best Gaming Laptops for AAA Games: 15 Picks |
| You plan to install Windows 11 and need to meet the system requirements | Enable Secure Boot and ensure TPM 2.0 is active | Best Gaming Laptops Under $1600 in 2026: 3 Picks by Specs |
Questions
Is Secure Boot required for gaming?
Secure Boot is not required for gaming itself, but it is a security feature that helps protect your system. It is required for Windows 11, which many gaming laptops use. You can learn more about gaming laptop TPM.
Will enabling Secure Boot affect game performance?
No, Secure Boot does not affect game performance. It only verifies the boot process and does not impact CPU or GPU performance during gameplay.
Can I enable Secure Boot on any gaming laptop?
Most modern gaming laptops with UEFI firmware support Secure Boot. If your laptop is older and uses legacy BIOS, you may not be able to enable it. Check the manufacturer's documentation or reset BIOS settings.
What if I can't find the Secure Boot option in BIOS?
If you cannot find it, your laptop might be in legacy mode or the option is hidden. Check for a boot mode setting and switch to UEFI, or consult your laptop's manual. You may also need to set an administrator password first.
Recent updates
- : First published.