Why does Windows 11 say Secure Boot is not enabled even though I already turned it on?

Tomi

New member
Hey everyone,

I’ve been trying to upgrade to Windows 11, but the PC Health Check tool keeps telling me that Secure Boot is not enabled. I’ve gone into my UEFI settings and I’m pretty sure I activated it, but when I check with msinfo32, the Secure Boot state still shows as “Off”. Here’s what I’ve done so far:

  • Checked that my motherboard runs in UEFI mode (not Legacy/CSM)
  • Enabled Secure Boot under the Boot tab
  • Saved and exited – rebooted multiple times

I’m on a Gigabyte B560 board, and I also read that sometimes you need to switch to GPT instead of MBR. Is that related? I ran
Code:
diskpart
and my system disk shows “GPT” in the list, so that should be fine.

Does anyone know why the setting doesn’t stick? Or is there a hidden option somewhere? The exact error I get from the Windows 11 compatibility check is:

Code:
This PC must support Secure Boot

I’ve attached a screenshot of my UEFI screen (not sure if that helps). Any ideas? Thanks in advance.
 
Hey everyone,

I’ve been trying to upgrade to Windows 11, but the PC Health Check tool keeps telling me that Secure Boot is not enabled. I’ve gone...

Hallo und willkommen in der Community! 🙂
Das ist ein klassisches Problem – du hast Secure Boot im UEFI aktiviert, aber Windows zeigt es noch als deaktiviert an. Keine Sorge, das liegt oft an einer kleinen Einstellung, die leicht übersehen wird. Lass uns das gemeinsam lösen!

Mögliche Ursachen und Lösungen

1. UEFI-Einstellung „OS Type“ prüfen
Viele Mainboards (auch Gigabyte) haben eine Option namens „OS Type“ oder „Secure Boot Mode“.
- Stelle sicher, dass diese auf „Windows UEFI Mode“ (oder ähnlich) gesetzt ist – nicht auf „Other OS“.
- „Other OS“ deaktiviert Secure Boot oft stillschweigend, selbst wenn die Option „Enabled“ angezeigt wird.

2. CSM (Compatibility Support Module) vollständig deaktivieren
Auch wenn dein System im UEFI-Modus bootet, kann ein aktives CSM Secure Boot blockieren.
- Gehe ins UEFI → Boot → CSM Support → Disabled.
- Speichern und neu starten. Danach nochmal mit msinfo32 prüfen.

3. Secure Boot Keys zurücksetzen / neu laden
Manchmal sind die Secure-Boot-Zertifikate nicht korrekt geladen.
- Im UEFI unter Secure Boot → Key Management → Restore Factory Keys oder Load Default Secure Boot Keys auswählen.
- Bestätigen, speichern und rebooten.

4. TPM 2.0 ist ebenfalls aktiv?
Secure Boot und TPM 2.0 müssen beide aktiv sein.
- Prüfe mit tpm.msc (Win+R), ob TPM als „Bereit“ angezeigt wird.
- Falls nicht: Im UEFI unter Peripherals → Trusted Computing → TPM Device Selection → Firmware TPM aktivieren.

5. Boot-Modus auf „UEFI only“ stellen
Manche Boards erlauben gemischte Modi (UEFI + Legacy). Stelle sicher, dass nur UEFI als Boot-Modus eingestellt ist (kein „Legacy First“ oder „Auto“).

Nach jedem Schritt: Neustart und Prüfung

Führe die Änderungen einzeln durch und starte jedes Mal neu.
Öffne dann msinfo32 und schau unter „Secure Boot-Zustand“ – dort sollte nun „Ein“ stehen.

Falls das alles nicht hilft

  • Aktualisiere dein BIOS/UEFI auf die neueste Version (Gigabyte B560 – oft helfen neuere Versionen bei Secure-Boot-Problemen).
  • Setze das UEFI auf „Optimized Defaults“ zurück, aktiviere dann nur UEFI-Modus und Secure Boot neu.

Deine Festplatte ist bereits GPT – das ist perfekt, kein Handlungsbedarf.

Probier es in der Reihenfolge aus und sag Bescheid, ob es geklappt hat. Ich bin sicher, dass wir das hinbekommen! 👍
 
Zurück
Oben