Windows

"The PC Must Support Secure Boot"? How to Enable It for Windows 11

Updated Sources linked 4 min read October 3, 2026 · by Ryan Bennett

PC Health Check or Windows 11 Setup says “The PC must support Secure Boot” or shows Secure Boot State: Off — even on a fairly modern machine.

Why: Most PCs from the last several years are fully Secure Boot capable; the feature is just disabled in UEFI firmware, or the disk is still booting in Legacy BIOS / CSM mode, where Secure Boot can’t be turned on at all. Check the state and the manufacturer’s supported firmware options before changing boot mode. Compatibility, disk layout and encryption need verifying; not every PC can be fixed by a firmware toggle.

Fix 1: Check the current Secure Boot state

  1. Press Win + R, type msinfo32, press Enter to open System Information.
  2. On the System Summary page, read these two lines:
    • BIOS Mode — must say UEFI. If it says Legacy, that’s your blocker (see Fix 3).
    • Secure Boot State — On means you’re done (your Windows 11 block is something else, like TPM or CPU). Off means it’s disabled in firmware — continue to Fix 2. Unsupported usually means Legacy/MBR.

Before firmware or disk-layout changes: back up important data, keep a verified BitLocker/device-encryption recovery key somewhere accessible outside this PC, and check the manufacturer’s instructions. Suspend BitLocker protection when its documented procedure requires it; a saved key alone does not replace the required suspension. Do not clear the TPM.

Fix 2: Turn on Secure Boot in UEFI

  1. Go to Settings → System → Recovery, then under Advanced startup click Restart now.
  2. After reboot, choose Troubleshoot → Advanced options → UEFI Firmware Settings → Restart.
  3. In the firmware, open the Boot or Security section and set Secure Boot to Enabled. (Wording varies by maker — Asus, Dell, HP, Lenovo, etc. all label it slightly differently; check your manufacturer’s support page if you can’t find it.)
  4. Save and exit (usually F10). Back in Windows, re-check msinfo32 — Secure Boot State should now read On.

A greyed-out control can reflect Legacy/CSM mode or another firmware prerequisite. Confirm BIOS Mode and consult the model’s manual rather than assuming disk conversion is required.

Fix 3: Plan a Legacy/MBR conversion before changing boot mode

A normal Windows UEFI system disk uses GPT. Do not switch a Legacy Windows installation to UEFI-only before preparing its disk and boot files. First confirm the PC supports UEFI and the manufacturer’s procedure, back up the disk/data and verify a recovery route.

Microsoft’s MBR2GPT can convert eligible system disks in place, but it has layout requirements. In Command Prompt as administrator, its validation-only check is:

mbr2gpt /validate /allowFullOS

Do not continue if validation fails; inspect the reported requirement rather than deleting partitions to force it through. For a BitLocker-encrypted system disk, Microsoft requires protection suspended before conversion and the existing protectors deleted/re-created after conversion before protection is resumed. Follow the current documented encryption procedure or have an administrator handle it; do not improvise protector removal without verified recovery access.

Once backups, disk eligibility, encryption preparation and the firmware plan are confirmed, the full-OS conversion command is:

mbr2gpt /convert /allowFullOS

After a successful conversion, set firmware to the appropriate UEFI boot mode using the manufacturer’s instructions. Confirm Windows boots, complete the documented BitLocker protector/protection procedure if applicable, then enable Secure Boot and recheck msinfo32. If conversion or boot repair fails, use the saved recovery route rather than repeating disk operations.

FAQ

Do I actually need Secure Boot for Windows 11, or just “capable”? To upgrade, the PC needs to be Secure Boot capable (UEFI-based). Microsoft recommends actually turning it on for the security benefit, and PC Health Check flags it when it’s off.

Will enabling Secure Boot stop my PC from booting? A standard Windows install boots fine with Secure Boot on. The risk is dual-boot Linux or unsigned bootloaders — and on a BitLocker-encrypted drive, firmware changes can prompt for your recovery key, so have it ready.

Is mbr2gpt safe? It’s Microsoft’s supported in-place converter and keeps your data, but any disk operation carries risk — back up before running it, and only convert the system disk.

Sources: Microsoft Learn — MBR2GPT requirements and BitLocker procedure, Microsoft Support — Windows 11 and Secure Boot, Microsoft Support — Windows 11 system requirements

↑↓ navigate · ↵ open · Esc close See all results →