Fix: Secure Boot is Greyed Out on Windows 11

Outdated BIOS can cause Secure Boot option to be greyed out

Reading time icon 3 min. read


Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

Key notes

  • Some systems require BIOS to have an administrative password in order to use Secure Boot.
  • If you don’t have the default keys installed, you won’t be able to enable this feature properly.

If Secure Boot is grayed out on Windows 11, you won’t be able to enable it, and your PC will be more vulnerable to malicious code such as boot loaders.

In some cases, certain features might not work properly until you resolve this issue, so let’s see how can we address it.

How can I tell if Secure Boot is enabled on my computer?

  1. Press the Windows key + R and enter msinfo32.
  2. Locate Secure Boot State value.
  3. If it’s set to Enabled, it means that Secure Boot is activated.

How do I fix Windows 11’s Secure Boot if it’s greyed out in BIOS?

1. Set administrator password on BIOS

  1. Restart your PC and keep pressing F2 or Del to access BIOS. The key varies depending on the motherboard manufacturer.
  2. Next, navigate to the Security tab.
  3. Select the Administrator password option.
  4. Set the new BIOS password and repeat it again. Press Enter to save it.
  5. Exit BIOS and save changes.
Note icon NOTE
Do not forget your admin password. Without it, you won’t be able to access BIOS anymore.

2. Disable Fastboot in BIOS

  1. Access BIOS to adjust your motherboard firmware settings.
  2. Next, navigate to Advanced Mode and select the Boot in BIOS.
  3. Locate the Fast Boot option and set it to Disabled.
  4. Save changes and restart your PC.

Some users reported that it’s necessary to enable Secure Boot Control in order for this feature to work.

3. Install default keys

  1. Boot into BIOS and navigate to the Secure Boot option.
  2. Choose Install Factory Default Keys or Provision Factory Keys.
  3. Save changes and restart your PC.

A few users suggested that they needed to restore the factory key, update each key, and restore the keys again in order to fix the issue.

4. Adjust CSM settings and boot features

  1. Enter BIOS and enable CSM.
  2. Next, change the Boot Device Control to UEFI and Legacy.
  3. Change Boot from PCIe/PCI Expansion Devices to UEFI First.

Causes of Secure Boot greyed out on Windows 11?

  • The lack of an administrator password can keep the Secure Boot setting disabled.
  • Certain BIOS settings such as Fastboot or CSM can cause issues with Secure Boot.
  • The default keys aren’t installed or you’re using legacy boot mode and not the UEFI Boot Mode.
  • BIOS firmware version is out of date or your drive has the wrong partition style and it’s not using the GPT partition table.

If Secure Boot in BIOS is greyed out on Windows 11 PC, it doesn’t mean that Secure Boot state is unsupported. In most cases, you just need to make a few adjustments in BIOS to fix this issue and protect your PC from malware attacks.

These aren’t the only issues, and many reported that Secure Boot is enabled but not active or that Encrypt contents to secure data is greyed out, but we already tackled those in separate guides.

Did you find a different solution for this issue? If so, don’t hesitate to share it with us!

More about the topics: Windows 11 Fix

User forum

0 messages