If you have recently attempted to upgrade to Windows 11 or are trying to run specific anti-cheat software for competitive gaming, you may have realized that you need to know how to enable secure boot on ASRock motherboard hardware. While the process might seem intimidating for those who are not comfortable poking around in the BIOS, it is actually a straightforward procedure once you understand the underlying settings that govern your system’s security features.
Secure Boot is a fundamental security standard designed to ensure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM). By preventing malicious software, such as rootkits or bootkits, from loading during the startup process, Secure Boot acts as a critical line of defense for your operating system. ASRock, being a leading motherboard manufacturer, provides a robust UEFI interface that makes toggling this feature relatively simple, provided you follow the correct sequence of operations.
Understanding Why Secure Boot is Necessary
Before diving into the technical steps, it is helpful to understand why this feature exists. In the past, computers would load whatever bootloader was present on the storage drive without verification. This created a massive security vulnerability. Secure Boot changes this by requiring a digital signature for every piece of boot software. If the signature does not match the database stored in your motherboard’s firmware, the system refuses to boot that specific component.
The primary driver for many users today is the Windows 11 requirement. Microsoft mandated Secure Boot and the Trusted Platform Module (TPM) 2.0 as essential hardware requirements for Windows 11. If you attempt to install or upgrade to Windows 11 without these enabled, the PC Health Check tool will flag your system as incompatible. Additionally, many modern multiplayer games require Secure Boot to be enabled to prevent players from using low-level kernel cheats.
Prerequisites Before You Begin
You cannot simply flip a switch and expect Secure Boot to work in every scenario. There are two critical prerequisites that often trip up users. If you ignore these, you will likely encounter an error message stating that the system cannot enable Secure Boot.
1. Your Partition Style Must Be GPT
Secure Boot requires your Windows installation drive to be formatted using the GUID Partition Table (GPT) style, rather than the older Master Boot Record (MBR) style. If your drive is currently MBR, attempting to enable Secure Boot will result in a system that fails to boot because the firmware cannot locate the bootloader.
2. UEFI Mode Must Be Active
Secure Boot is a feature of the UEFI (Unified Extensible Firmware Interface) environment. If your motherboard is currently running in “Legacy” or “CSM” (Compatibility Support Module) mode, Secure Boot will be greyed out or inaccessible. You must disable CSM to proceed.
How to Enable Secure Boot on ASRock Motherboard: Step-by-Step
Follow these steps carefully to navigate your ASRock UEFI BIOS. Please note that while most ASRock boards share a similar interface, the exact menu placement may vary slightly depending on your specific model and BIOS version.
Step 1: Access the UEFI BIOS
Restart your computer. As soon as the ASRock logo appears on your screen, repeatedly press the “F2” or “Delete” key on your keyboard. Do not wait for the Windows loading screen, or you will have to restart the process. Once you are inside the BIOS utility, you may want to press “F6” to enter Advanced Mode if you are currently in the simplified Easy Mode interface.
Step 2: Disable CSM (Compatibility Support Module)
This is the most common hurdle. Navigate to the “Boot” tab using your arrow keys or mouse.
- Look for an option labeled “CSM” or “Compatibility Support Module.”
- Select it and ensure it is set to “Disabled.”
- If you see a warning that your graphics card or boot device is not UEFI compatible, this confirms that your drive is likely MBR. You will need to convert your drive to GPT using the MBR2GPT tool in Windows before proceeding.
Step 3: Locate the Security Settings
Once CSM is disabled, navigate to the “Security” tab. In some ASRock BIOS versions, this may also be located under the “Boot” tab in a sub-menu labeled “Secure Boot.”
Step 4: Enable Secure Boot
Within the Secure Boot menu, you will see an option labeled “Secure Boot.” By default, it is likely set to “Disabled.”
- Change the setting to “Enabled.”
- If the option remains greyed out, verify that you have created or installed the “Default Secure Boot Keys.” Most modern ASRock boards have a button or option that says “Install Default Secure Boot Keys.” Clicking this populates the necessary certificates required for the feature to function.
Step 5: Save and Exit
After you have enabled the setting, do not simply turn off your computer. You must save your changes. Press “F10” on your keyboard, which is the standard shortcut for “Save and Exit.” Confirm your choice, and the computer will restart.
Troubleshooting Common Issues
Even when you follow the steps perfectly, technology can occasionally be temperamental. Here are some common scenarios you might encounter when learning how to enable secure boot on ASRock motherboard systems.
The “System Cannot Boot” Scenario
If you disable CSM and enable Secure Boot, but your computer fails to load Windows, it is almost certainly because your drive is still partitioned as MBR. You do not need to reinstall Windows to fix this. You can use the Windows Command Prompt to run the following command while booted into Windows:
mbr2gpt /validate /allowFullOS
If the validation passes, run mbr2gpt /convert /allowFullOS. This will safely convert your drive to GPT, allowing you to enable Secure Boot without losing your data.
The “Secure Boot State is Unsupported” Error
Sometimes, the BIOS will report that the Secure Boot state is “Unsupported” even if you have enabled the setting. This often happens if your graphics card does not support UEFI GOP (Graphics Output Protocol). If you are using a very old GPU, you may need to update the card’s firmware or replace it with a more modern component to take full advantage of secure boot features.
Summary of BIOS Settings
To help you keep track of the changes, refer to the table below for the typical configuration required for a successful Secure Boot setup:
| Setting | Required Status |
|---|---|
| CSM (Compatibility Support Module) | Disabled |
| Secure Boot | Enabled |
| Secure Boot Mode | Standard (or User) |
| Partition Style | GPT |
Benefits of Maintaining Secure Boot
Beyond meeting the requirements for Windows 11 and modern gaming software, keeping Secure Boot enabled provides tangible security benefits. In an era where malware is becoming increasingly sophisticated, hardware-level security is a necessity rather than a luxury.
By verifying the integrity of the boot process, you are effectively closing the door on bootkits. A bootkit is a particularly nasty type of malware that hides in the boot sector of your hard drive. Because it loads before the operating system and the antivirus software, it is notoriously difficult to detect and remove. Secure Boot prevents these programs from executing entirely, keeping your kernel and system files safe from the moment you press the power button.
Expert Tips for ASRock Users
ASRock motherboards are known for their user-friendly BIOS updates. If you find that your BIOS menu looks completely different from the descriptions above, you might be running an outdated BIOS version. It is always a good idea to visit the official ASRock support website, search for your motherboard model, and check if there is a newer BIOS release. Newer versions often include improved compatibility for Windows 11 and better support for Secure Boot configurations.
Furthermore, if you are a power user who frequently adjusts overclocking settings, remember that enabling Secure Boot does not interfere with your XMP or EXPO profiles. You can safely run your RAM at its advertised speeds while maintaining the security benefits of a signed boot process. Just be sure to perform your stability testing after any BIOS changes to ensure the system remains reliable.
Final Thoughts
Learning how to enable secure boot on ASRock motherboard units is a valuable skill for any PC enthusiast. It bridges the gap between older legacy systems and the modern requirements of Windows 11, while simultaneously hardening your system against low-level threats. While the process requires a bit of attention to detail—specifically regarding your drive partition style and CSM settings—the peace of mind provided by a verified boot sequence is well worth the effort.
If you encounter any persistent issues, remember that the ASRock community forums and the official support documentation are excellent resources. By following this guide, you should be able to navigate the UEFI interface with confidence, ensuring your system is both secure and fully compliant with the latest software standards.




