SOLUTION: How to enable Secure Boot on Gigabyte Motherboard
Enabling Secure Boot on Gigabyte Z590 Motherboard: Complete Guide
Secure Boot is an important security feature that ensures your system only boots with trusted software. For Gigabyte Z590 motherboard users, enabling Secure Boot requires several preparatory steps and careful configuration in the BIOS. This comprehensive guide will walk you through the entire process.
Prerequisites for Enabling Secure Boot
Before enabling Secure Boot on your Gigabyte Z590 motherboard, you need to ensure several system requirements are met:
- UEFI Mode: Your system must be running in UEFI mode, not Legacy BIOS mode 7
- GPT Partition Style: Your boot drive must use GPT (GUID Partition Table) rather than MBR (Master Boot Record) 7 14
- Updated BIOS: Ensure you have the latest BIOS version installed for your motherboard 12
- TPM 2.0 Enabled: Windows 11 requires TPM 2.0 (though Secure Boot itself doesn't require it) 16
Step 1: Check Current Secure Boot Status
Before making any changes, verify your current Secure Boot status:
- Press Win + R, type msinfo32, and press Enter
- In System Information, look for:
- Secure Boot State (should show "Off" initially)
- BIOS Mode (must say "UEFI") 7
Step 2: Verify Disk Partition Style
Secure Boot requires GPT partition style:
- Press Win + X and select Disk Management
- Right-click your boot disk > Properties > Volumes tab
- Check "Partition style" - must be "GUID Partition Table (GPT)" 7
If your disk is MBR, you'll need to convert it to GPT before proceeding. Backup your data first as this process may erase your disk.
Step 3: Enter BIOS Setup
- Restart your computer
- During startup, repeatedly press the Delete key to enter BIOS 16
- Press F2 to switch to Advanced Mode if needed 16
Step 4: Disable Compatibility Support Module (CSM)
Secure Boot cannot be enabled while CSM is active:
- Navigate to the BIOS tab
- Find CSM Support (may be under Boot options)
- Set CSM Support to Disabled 7 12
- Save changes and exit (F10)
- Re-enter BIOS to continue configuration 12
Step 5: Enable TPM 2.0 (Optional for Windows 11)
For Intel processors on Z590:
- Navigate to Settings > Miscellaneous or Peripherals
- Find Intel Platform Trust Technology (PTT)
- Set to Enabled 16
- Save changes (F10)
Step 6: Enable Secure Boot
Now you can enable Secure Boot:
- Navigate to the BIOS tab
- Find Secure Boot option (may be under Security tab)
- Set Secure Boot to Enabled 7
- If prompted about Platform Keys (PK), select Install Default Secure Boot Keys 12
- Save changes and exit (F10)
Note: Some systems may require you to first set Secure Boot Mode to "Custom", restore factory keys, then switch back to "Standard" mode 14
Step 7: Verify Secure Boot is Active
After rebooting:
Troubleshooting Tips
If you encounter issues:
- Black screen on boot: Likely indicates your disk is still MBR - convert to GPT 14
- Secure Boot option greyed out: Ensure CSM is completely disabled 12
- Error about Platform Keys: Install default Secure Boot keys 12
- Windows won't boot: You may need to disable Secure Boot temporarily to access recovery options
Important Notes
- Enabling Secure Boot is not strictly required for Windows 11 installation (the system just needs to support it) 14
- Some older operating systems or hardware may not work with Secure Boot enabled
- Certain games (like Valorant) require Secure Boot for their anti-cheat systems 14
By following these steps carefully, you should successfully enable Secure Boot on your Gigabyte Z590 motherboard, adding an important layer of security to your system.