How to Enable Secure Boot in Gigabyte BIOS for Windows 11

On this page

If a game throws a “Secure Boot is not enabled” or anti-cheat error on your Gigabyte rig, you just need to enable Secure Boot in BIOS. Modern anti-cheats — Valorant (Vanguard), Fortnite, Call of Duty / Warzone (Ricochet), and Faceit — require Secure Boot on Windows 11. This guide covers Gigabyte and AORUS boards step by step.

How to Enable Secure Boot in Gigabyte BIOS for Windows 11

Written for Gigabyte / AORUS motherboards on modern UEFI BIOS. For other brands, use those guides instead. Secure Boot works alongside TPM 2.0 — see How to Enable TPM in Gigabyte BIOS for Windows 11 if you haven’t enabled that yet.

Quick checklist before you touch BIOS

  • Back up important data before changing firmware settings.
  • Confirm your drive is GPT, not MBR. Secure Boot needs UEFI + GPT.
  • Connect keyboard and monitor directly (no remote access).
  • Update Windows so anti-cheat services detect the change.

Step 1 – Check whether Secure Boot is already on

  1. Press Win + R, type msinfo32, press Enter.
  2. Check BIOS Mode (should be UEFI) and Secure Boot State (should be On).

If BIOS Mode shows Legacy, convert to UEFI/GPT first. If it’s UEFI but Secure Boot is Off, you only need the BIOS toggle below.

Step 2 – Enter the Gigabyte BIOS

  1. Fully shut down your PC.
  2. Power on and repeatedly tap Del (sometimes F2) at the Gigabyte/AORUS logo.
  3. Press F2 to switch between Easy Mode and Advanced Mode if needed.

Step 3 – Disable CSM

Secure Boot will not enable while CSM is on.

  1. Go to the BIOS tab (or Boot on some models).
  2. Set CSM Support to Disabled.
  3. The board may warn it needs to apply Windows UEFI settings — accept it.

If Windows won’t boot after disabling CSM, your drive is MBR. Boot into Windows and run mbr2gpt /validate then mbr2gpt /convert from an elevated command prompt, then retry.

Step 4 – Enable Secure Boot on Gigabyte

  1. Still on the BIOS tab, open Secure Boot.
  2. Set Secure Boot Enable to Enabled.
  3. If it’s greyed out, set Secure Boot Mode to Standard, or open Restore Factory Keys / Install default keys and confirm.

On some AORUS boards the order is Secure Boot → Secure Boot Enable → Enabled, with key options just below.

Step 5 – Save and reboot correctly

  1. Press F10 to Save & Exit.
  2. Confirm Secure Boot Enable = Enabled and CSM Support = Disabled.
  3. Select Yes and boot into Windows.

Step 6 – Verify Secure Boot in Windows 11

  1. Press Win + R, type msinfo32, press Enter.
  2. Confirm Secure Boot State: On and BIOS Mode: UEFI.

Restart your game — Vanguard, Ricochet, and EAC checks should now pass.

Troubleshooting on specific Gigabyte lineups

AORUS Master / AORUS Elite / AORUS Pro

All security options are exposed. Disable CSM Support under the BIOS tab, then enable Secure Boot. Use Restore Factory Keys if the toggle is locked.

Gigabyte Gaming / UD / DS3H

These budget boards sometimes ship with CSM on. Disable it, convert the drive to GPT if needed, then enable Secure Boot.

Greyed-out Secure Boot toggle

This almost always means CSM is still enabled or keys are missing. Disable CSM, set Secure Boot Mode to Standard, and install default keys.

Does Secure Boot affect gaming performance?

No. Secure Boot validates the boot chain at startup only — no FPS or latency cost in Fortnite, Apex Legends, or Warzone. It simply lets modern anti-cheats run.

Pair this with:

Summary – Gigabyte Secure Boot for Windows 11

  • Disable CSM Support under the BIOS tab.
  • Set Secure Boot Enable to Enabled (Mode: Standard).
  • Install / restore default keys if greyed out.
  • Verify with msinfo32Secure Boot State: On.

Once enabled, your Gigabyte PC passes the Secure Boot checks Valorant, Fortnite, and Call of Duty require — with no performance loss.