Free tools Windows power users keep installed
One-click scans. No signup required.
Do not simply disable CSM. If Windows 11 currently boots in Legacy mode from an MBR disk, first convert the Windows system disk to GPT with Microsoft’s MBR2GPT.exe. Then change the firmware to UEFI, select Windows Boot Manager, and enable Secure Boot. If Windows already shows BIOS Mode: UEFI and the system disk is GPT, skip conversion and configure Secure Boot directly.
Choose the correct path first
| BIOS Mode | Windows system disk | What it means | Next step |
|---|---|---|---|
| UEFI | GPT | Correct foundation for Secure Boot | Enable Secure Boot in firmware, then verify it in Windows. |
| UEFI | MBR | Unusual or transitional configuration | Investigate the boot layout before changing firmware settings. |
| Legacy | MBR | Typical older installation | Back up, validate MBR2GPT, convert, then switch firmware to UEFI. |
| Legacy | GPT | Nonstandard or potentially broken boot configuration | Do not guess; inspect boot files and use the manufacturer’s documentation. |
| UEFI | GPT | Secure Boot Off | UEFI is ready; enable Secure Boot. |
| UEFI | GPT | Secure Boot On | Already at the target state. |
Windows normally continues booting in the firmware mode used during installation. UEFI booting generally expects a GPT system disk and an EFI System Partition; CSM (Compatibility Support Module) only lets UEFI firmware emulate legacy BIOS behavior. Secure Boot is separate: it validates trusted boot software after the system is operating in UEFI mode. See Microsoft’s explanations of boot modes, MBR and GPT, and Secure Boot.
Check your current BIOS mode and Secure Boot state
- Press Win + R.
- Type
msinfo32and press Enter. - In System Summary, read BIOS Mode and Secure Boot State.
- BIOS Mode: UEFI means Windows is already using UEFI.
- BIOS Mode: Legacy means Windows is currently using legacy compatibility.
- Secure Boot State: On means Secure Boot is active.
- Secure Boot State: Off means it is disabled or not currently available.
These fields are also the verification method documented by ASUS and Dell.
Check whether the Windows disk is MBR or GPT
Using Disk Management
- Right-click Start and select Disk Management.
- Right-click the disk containing the Windows installation. Select the disk label (for example, Disk 0), not only the C: volume.
- Select Properties, open Volumes, and read Partition style.
The value is either GUID Partition Table (GPT) or Master Boot Record (MBR).
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- Windows 8 Support Ready Upgraded Hardware and Native BIOS Support, with Fast Boot Feature
- GPU Boost Two simple ways to get quick free graphics upgrade
- Anti-Surge Protection Safeguard your device by providing voltage protection to all major onboard components
- UEFI BIOS BIOS control via a Graphical Interface with mouse controlled support featuring unparalleled control options, 2.2TB or higher native HD support, and Quick Boot features
- USB 3.0 Support Fully unleash High Speed Transfer Technology with USB 3.0
Using PowerShell
Open PowerShell as administrator and run:
Get-Disk | Format-Table -Auto
Using DiskPart
diskpart
list disk
An asterisk in the Gpt column indicates GPT; a blank entry indicates MBR. Confirm that you are examining the disk that contains Windows, not a secondary data drive.
Prepare before changing firmware
Back up and collect recovery information
- Back up documents and other irreplaceable files.
- Save your Microsoft account credentials and Windows recovery media details.
- If BitLocker or device encryption is enabled, locate and save the recovery key.
- Confirm that the motherboard or laptop supports UEFI and obtain its model-specific firmware instructions.
MBR2GPT is designed to preserve data, but it changes partition metadata and boot configuration. A backup is still essential.
Suspend BitLocker protection
Microsoft requires BitLocker protection to be suspended before converting an encrypted system disk. Open Manage BitLocker (or your device-encryption controls), suspend protection for the system drive, and keep the recovery key available. Resume protection after Windows boots successfully in UEFI mode.
Convert a Legacy/MBR Windows installation with MBR2GPT
Use this procedure only when Windows reports BIOS Mode: Legacy and the Windows system disk is MBR.
1. Validate without changing the disk
Open Command Prompt as administrator and run:
mbr2gpt /validate /allowFullOS
Validation checks the layout but does not perform conversion. Do not switch the firmware to UEFI if validation fails.
Rank #2
- Supports 7th/6th Generation Intel Core Processors.Intel optane memory ready
- Dual Channel DDR4, 4DIMMs
- Relate ALC887 Codec
- Gigabyte UEFI Dual BIOS
- Pie Gen3 x4 M.2 Connector with up to 32Gb/s Data Transfer
2. Convert after validation succeeds
mbr2gpt /convert /allowFullOS
Microsoft documents MBR2GPT as a supported Windows 10 and Windows 11 tool for converting the attached system disk without deleting its data. It can create or reuse an EFI System Partition, install UEFI boot files, convert the partition metadata to GPT, update Boot Configuration Data, and add a recovery boot entry. It is not a general-purpose converter for arbitrary non-system data disks. Details and options are in Microsoft’s MBR2GPT documentation.
Why validation can fail
Microsoft’s checks include the following:
- The disk is currently MBR and has room for GPT metadata at both ends.
- No more than three primary MBR partitions exist.
- An active system partition exists.
- No extended or logical partitions are present.
- The BCD contains a valid default Windows entry.
- Windows recognizes the partition types.
Record the exact error and correct the layout, or choose a clean installation. Do not force the firmware change.
Switch firmware from CSM/Legacy to UEFI
Enter UEFI firmware settings from Windows 11
- Open Settings → System → Recovery.
- Under Advanced startup, select Restart now.
- Choose Troubleshoot → Advanced options → UEFI Firmware Settings → Restart.
You can also hold Shift while selecting Restart and follow the recovery menus.
Change the boot mode
Firmware labels vary. Look for CSM, Launch CSM, Legacy Boot, Legacy Support, Boot List Option, or UEFI/Legacy Boot. Choose the equivalent of:
- CSM Disabled
- UEFI Only
- UEFI instead of Legacy
- Windows UEFI Mode
In the boot-order list, select Windows Boot Manager for the converted Windows disk rather than a legacy entry showing only the raw drive name.
Rank #3
- CPU: Support for Intel Core i7/i5/i3/Pentium/Celeron processors in the LGA1155 package. Chipset: Intel Z77 Express Chipset
- Memory: 4 x 1.5V DDR3 DIMM sockets supporting up to 32 GB of system memory. Dual channel memory architecture. Support for DDR3 1600/1333/1066 MHz memory modules. Support for non-ECC memory modules. Support for Extreme Memory Profile (XMP) memory modules
- Audio: Realtek ALC898 codec. Support for X-Fi Xtreme Fidelity and EAX Advanced HD 5.0 technologies. LAN: 1 x Atheros GbE LAN chip (10/100/1000 Mbit) (LAN1). 1 x Intel GbE LAN chip (10/100/1000 Mbit) (LAN2).
- Support for AMD CrossFireX/ NVIDIA SLI technology. Expension Slots: 1 x PCI Express x16 slot, running at x16. 1 x PCI Express x16 slot, running at x8. 1 x PCI Express x16 slot, running at x4. 3 x PCI Express x1 slots. 1 x PCI slot.
- Storage Interface: 2 x SATA 6Gb/s connectors. 4 x SATA 3Gb/s connectors. 1 x mSATA connector. Support for RAID 0/1/5/10. 2 x Marvell 88SE9172 chips: 3 x SATA 6Gb/s connectors. 1 x eSATA 6Gb/s connector.
Enable Secure Boot
Secure Boot may be under Boot, Security, Authentication, or Windows OS Configuration. Set it to Enabled. Some firmware requires a Windows-specific operating-system type or restoring factory/default Secure Boot keys; use those options only as described by the manufacturer. Save the changes and restart.
Verify the result in Windows
- Press Win + R, enter
msinfo32, and press Enter. - Confirm BIOS Mode: UEFI.
- Confirm Secure Boot State: On.
- Verify that Windows and your applications start normally.
Resume BitLocker protection after this verification. If Secure Boot remains Off, confirm that CSM is disabled, the firmware is using standard/default keys, and the selected boot entry is Windows Boot Manager.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteIf Windows no longer boots
Restore the previous mode temporarily
- Re-enter firmware settings.
- Restore the previous Legacy/CSM setting if that was the original configuration.
- If Windows starts, recheck
msinfo32and the system disk’s partition style.
Do not repeatedly change unrelated firmware settings. Microsoft warns that firmware changes can prevent startup and recommends following the computer manufacturer’s instructions.
“No boot device” after conversion
Check that the firmware boot list contains Windows Boot Manager and the converted disk, and that you are selecting a UEFI entry rather than a legacy drive entry. With multiple drives, temporarily disconnecting nonessential drives can help identify a wrong-disk selection.
BitLocker recovery appears
Firmware, boot-mode, and Secure Boot changes can alter the trusted boot measurement. Enter the saved BitLocker recovery key; do not clear the TPM or keep changing settings as a substitute for the key.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.When a clean installation is the better option
Choose a clean install if validation fails and the layout is difficult to repair, the installation is damaged or unsupported, or you intentionally want to rebuild Windows. This erases the selected Windows disk.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- Back up everything on the intended Windows disk.
- Enter firmware, select UEFI, and disable CSM/Legacy.
- Boot Windows installation media explicitly as a UEFI device.
- At disk selection, delete every partition on the intended Windows disk, then select its unallocated space.
- Continue Setup; Windows creates a GPT layout when Setup itself is booted in UEFI mode.
With multiple drives, identify the correct disk before deleting anything. Microsoft’s clean-install guidance is documented here.
Destructive manual conversion for a clean install only
diskpart
list disk
select disk <disk number>
clean
convert gpt
exit
clean deletes the selected disk’s partition information. Never use these commands as the normal migration method for an existing Windows installation.
Manufacturer-specific menu differences
ASUS
ASUS examples use Boot → Secure Boot, with Windows UEFI mode as the operating-system type and Standard as the Secure Boot mode. Those labels apply to the documented ASUS examples, not every motherboard. See ASUS’s instructions.
Dell
Dell commonly uses F2, then Boot or Boot Sequence, where you change Legacy to UEFI and enable Secure Boot. Dell also gives a broad warning that switching modes can make an existing installation unbootable and may require reinstallation. For supported Windows installations, Microsoft’s MBR2GPT path provides a non-wipe conversion route, but the exact model documentation takes priority. See Dell’s guide.
Other manufacturers
HP, Lenovo, Gigabyte, Acer, MSI, and others use different labels and key combinations. Use the manual or support page for the exact model rather than assuming that “Launch CSM,” “Legacy Support,” or “Windows UEFI Mode” exists on every system.
Quick Recap
Important limitations and decisions
- Use MBR2GPT when the supported Windows installation is Legacy/MBR, UEFI is supported, validation succeeds, and you want to preserve the installation.
- Use a clean install when validation fails, the layout is unusual or damaged, or you are prepared to erase the disk.
- Wait if you have not confirmed BIOS mode and disk style, lack the BitLocker recovery key, rely on multiple operating systems or legacy boot tools, or have not checked model-specific firmware limitations.
- Secure Boot is strongly useful and may be required by a particular game, enterprise policy, or security tool, but Windows 11’s Secure Boot capability requirement is not identical to every installation having Secure Boot switched On.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

