Secure Boot Enabled but Not Active: 3 Windows 11 Fixes

Explore these expert-tested methods to fix the issue

Reading time icon 3 min. read


Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

Secure Boot Enabled But Not Active On Windows 11 [Solved]

If you see the Secure Boot option enabled in BIOS, but on the system information page, it shows Not Active, then you are not alone. Many users reported that it stopped them from updating on Windows 11, but don’t worry; it can be fixed with the tested solutions below. 

What can I do if Secure Boot is enabled but inactive on Windows 11?

Before engaging in advanced troubleshooting steps, you need to update BIOS if outdated. Once done, follow these steps in sequence as mentioned below:

1. Disable the Compatibility Support Module (CSM)

  1. Press Windows + I to open Settings.
  2. Go to System, then click Recovery.System - Recovery Window -secure boot enabled but not active windows 11s 11
  3. Now click Restart now beside Advanced startup.Advanced Startup
  4. From Choose an option, select Troubleshoot.Choose an option - Troubleshoot-secure boot enabled but not active windows 11
  5. Now click Advanced Options.Advanced options
  6. Select UEFI firmware settings, then click RestartUEFI
  7. Now select the appropriate option to go into BIOS mode. 
  8. Go to the Boot or Security tab, navigate to CSM and select Disabled for it.secure boot enabled but not active windows 11UEFI with Compatibility Support Module
  9. Once done, click Save Changes & Reset.

2. Change the platform

  1. Go to BIOS mode by following the steps from method 1.
  2. Locate the System Mode, and select User instead of Setup.
  3. Go to Secure Boot Mode. If it stays Standard, switch it to CustomSECURE BOOT MODE -secure boot enabled but not active windows 11
  4. Now change it back to Standard and accept Factory Defaults.

3. Enable Secure Boot 

  1. Go to BIOS mode by following the steps from method 1.
  2. From the Security or Boot menu, locate Secure Boot.Secure boot -secure boot enabled but not active windows 11
  3. Select Enabled. Now select Save changes and exit to confirm the changes.

Why is Secure Boot enabled but not active?

There could be various reasons why the error occurs on your computer, some of them are mentioned here: 

  • Secure Boot feature disabled –  If the Secure Boot option in UEFI firmware settings is set to Disabled, the feature will not work, even if it is technically enabled.
  • CSM enabled – If CSM is enabled in UEFI settings, you might face the error. You need to disable this setting to fix it.
  • BIOS is outdated – If BIOS is not up to date, it may not support the Secure boot feature. You need to update BIOS to get the feature enabled.

So, these are methods that you need to follow to fix secure boot enabled but not active on Windows 11. It is crucial that Secure Boot is enabled at all times otherwise, you’d be exposing your device to errors like the tpm-wmi 1796 or the SECURE_BOOT_VIOLATION error.

We also have a complete guide on how to deal with Secure boot enabled but not active on Windows 10 and what to do if Secure Boot is grayed out on Windows 11.

Try them and let us know what worked for you in the comments below.

More about the topics: Windows 11

User forum

0 messages