What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Enrolling the Platform Key (PK) is a UEFI firmware operation, not a Windows 11 setting. On a typical PC, use the firmware’s factory or default Secure Boot key option to install the PK and related keys, then enable Secure Boot and save the changes.
Before changing firmware settings, check whether Windows boots in UEFI mode and keep your BitLocker or Device Encryption recovery key available. Menu names vary by manufacturer, so use the instructions for your exact PC or motherboard.
What the Platform Key does
Secure Boot uses a chain of UEFI keys and databases:
| Item | Purpose |
|---|---|
| PK | Platform Key; establishes the platform owner’s trust relationship with firmware. |
| KEK | Key Enrollment Keys; authorize updates to Secure Boot databases. |
| db | Signatures and certificates that are allowed to boot. |
| dbx | Revoked signatures and certificates that must not boot. |
When the PK is absent, firmware is in Setup Mode. Enrolling the PK changes it to User Mode. On supported systems, installing factory defaults provisions the full set of PK, KEK, db, and dbx keys. Secure Boot may still need to be enabled separately.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
Before you enroll the key
- Back up important files. Firmware changes can affect whether an operating system starts.
- Save your BitLocker or Device Encryption recovery key. A firmware or boot-configuration change can trigger BitLocker recovery.
- Check your boot mode. Press Windows + R, enter msinfo32, and check BIOS Mode. Secure Boot requires UEFI rather than Legacy/CSM boot.
- Record current firmware settings. Photograph boot order, storage-controller mode, and any other settings you may need to restore.
- Check for nonstandard boot software. Older operating systems, unsigned bootloaders, some Linux configurations, or certain option ROMs may not work with Secure Boot enabled.
- Keep the charger connected. Do not interrupt a firmware key operation or firmware update.
Open UEFI firmware from Windows 11
- Open Settings.
- Go to System > Recovery.
- Under Advanced startup, select Restart now.
- After the recovery screen appears, select Troubleshoot > Advanced options > UEFI Firmware Settings.
- Select Restart.
If that option is unavailable, restart and use the firmware access key documented for your PC model. Common keys include F2, Delete, Esc, or F10. You can also hold Shift while selecting Power > Restart, then follow the recovery-screen path above.
Enroll the Platform Key in UEFI
Firmware menus vary. Look under Security, Boot, or Secure Boot for Key Management or a similar submenu. Factory-key options may be called Install Default Secure Boot Keys, Restore Factory Keys, Load Factory Default Keys, or Enroll Factory Defaults.
- Confirm Windows is installed for UEFI booting before changing any Legacy/CSM setting.
- Set boot mode to UEFI and disable CSM or Legacy Boot, if present.
- Open the firmware’s Secure Boot menu. On some systems, you must change Secure Boot Mode from Standard to Custom to expose key-management options.
- Select the factory/default-key operation and confirm it. Do not manually create or import a PK unless you are deliberately managing a custom Secure Boot key system.
- Verify that firmware reports a PK or shows nonzero key counts for PK, KEK, db, and dbx, if it provides that information.
- Set Secure Boot to Enabled, if necessary.
- Save changes and exit, commonly with F10, then reboot.
Example: ASRock firmware
ASRock documents this example path. Exact screens can vary by model and firmware version:
- Press F2 during startup.
- Go to Security > Secure Boot.
- Set Secure Boot Mode to Custom.
- Open Key Management and select Install Default Secure Boot Keys.
- Confirm, enable Secure Boot, and press F10 to save.
If the install option is greyed out, the keys may already be loaded. Check the firmware’s key status before clearing or replacing anything.
Recommended Free Tools
Rank #2
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
If Windows is installed in Legacy/MBR mode
Do not switch directly from Legacy/CSM to UEFI: a Windows installation using an MBR system disk may no longer boot. Microsoft’s MBR2GPT tool can convert a system disk from MBR to GPT if validation succeeds. Suspend BitLocker protection first, save the recovery key, and follow Microsoft’s instructions for the conversion.
- Open Command Prompt as administrator.
- Validate the system disk with mbr2gpt /validate /allowFullOS.
- If validation succeeds, run mbr2gpt /convert /allowFullOS.
- Reboot into firmware, switch boot mode to UEFI, then enroll the factory Secure Boot keys.
Do not proceed if validation fails; consult Microsoft’s MBR2GPT documentation or your PC manufacturer.
Verify the result in Windows
Use System Information
Press Windows + R, enter msinfo32, and check System Summary. Confirm BIOS Mode: UEFI and Secure Boot State: On.
Use PowerShell
Open PowerShell as administrator and run:
Confirm-SecureBootUEFI
True means Secure Boot is enabled. False means it is supported but disabled. The cmdlet requires administrator privileges and is not supported on non-UEFI systems.
Rank #3
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
To inspect the PK and related variables, run these commands in an elevated PowerShell window:
Get-SecureBootUEFI -Name PK
You can also inspect SetupMode, SecureBoot, KEK, db, and dbx with the same command, replacing the name. These commands read UEFI variables; the manufacturer’s factory-key option is the normal way to provision default keys.
If key enrollment is missing or does not work
The default-key option is missing or greyed out
Possible reasons include keys already being installed, firmware set to Standard mode, a manufacturer-specific menu label, or a firmware limitation. Check whether firmware reports PK loaded, User Mode, Deployed Mode, or nonzero key counts. Do not clear keys just to make the option appear.
Secure Boot is unavailable
Secure Boot generally cannot be enabled while booting in Legacy/CSM mode. Confirm the Windows installation uses UEFI. If the disk is MBR, follow the conversion guidance above rather than switching modes blindly.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Rank #4
- 5 in 1 Connectivity: The USB C Multiport Adapter is equipped with a 4K HDMI port, a 100W USB C PD port, a 5 Gbps USB A data port, and two 480 Mbps USB A ports
Windows no longer boots after enabling Secure Boot
Possible causes include a Legacy/MBR installation, a missing or damaged EFI System Partition or Windows Boot Manager, a changed boot entry, an untrusted boot driver, or BitLocker recovery. Return to firmware and restore the previous boot configuration if needed. Do not delete Secure Boot keys as a first troubleshooting step.
The firmware shows no keys after a BIOS update
Use the firmware’s Install Default Secure Boot Keys, Restore Factory Keys, or equivalent option. If it is absent, check for a BIOS update for the exact PC or motherboard model and consult the manufacturer’s instructions.
Is Enroll EFI Image the same as enrolling a PK?
No. Enroll EFI Image normally adds an EFI image hash to the authorized-signature database, db. It does not establish platform ownership and should not be used to load a boot manager as the PK.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Current Secure Boot certificate change
Microsoft’s Secure Boot certificates issued in 2011 began expiring in June 2026, and Microsoft is transitioning supported devices to newer 2023 certificates. As of August 2026, use the latest firmware and vendor-supported factory key package rather than importing arbitrary keys. This certificate transition is separate from enrolling the PK.
Best Value
- Portable and powerful USB-C HUB: BENFEI USB Type-C HUB, with super-soft and knot-free silicone woven design cable, meets most mobile office needs. Compact, lightweight, stylish, and powerful portable USB C Hub equipped with 1 x HDMI port, 1 x 100W charging, and 3 x USB ports. 18-month warranty, 24-hour response, to ensure you feel at ease when using our product.
- Design centered on comfort and reliability: Thanks to BENFEI's end-to-end in-house cable production capability, in-house PCBA and assembly capability, using the industry's most advanced silicone woven design and process, 20cm cable in length, no knots, super-soft, the HUB is easy to use in all scenarios: laptop, tablet, stand etc. Super-soft, 25000+ life cycles, to meet your daily carrying and office needs.
- 100W Charging: Support up to 90W USB C pass-through charging via Type-C port to keep your laptop powered. 10W is reserved for other interface operations. No data and video function on the Type-C port.
- 4K HDMI Display: The HDMI port supports media display at resolutions up to 4K 30Hz, keeping every incredible moment detailed and ultra vivid. Please note that the C port of the Host device needs to support video output.
- Transfer Files in Seconds: Transfer files and from your laptop at speeds up to 10 Gbps with USB A 3.2 port. Extra 2 USB A 2.0 ports are perfectly for your keyboards and mouse.
FAQ
Is Enroll Platform Key required for Windows 11?
It is not a Windows 11 setting or a universal installation requirement. Windows 11 requires a Secure Boot-capable PC with UEFI enabled for supported configurations; the current Secure Boot state is distinct from capability. Enroll the PK when firmware is in Setup Mode and you want to establish the normal Secure Boot trust hierarchy.
Where is Enroll Platform Key in Windows 11?
There is no Windows menu with that name. Open Settings > System > Recovery > Advanced startup > Restart now, then choose Troubleshoot > Advanced options > UEFI Firmware Settings. Find the option in the firmware’s Secure Boot or Key Management section.
Can I enroll the Platform Key from PowerShell?
PowerShell can read UEFI variables with commands such as Get-SecureBootUEFI. The normal way to install the manufacturer’s default PK is the UEFI factory-key option; there is no universal command for enrolling a vendor’s default key.
Why does the firmware say Setup Mode after I installed the keys?
The PK may not have been committed, the wrong key-management option may have been selected, or firmware may have been reset. Check the key status, use the vendor’s default-key option if appropriate, save changes, and reboot.
Does Enroll EFI Image enroll the Platform Key?
No. It normally adds an EFI image hash to db, not to PK. Use the firmware’s factory/default Secure Boot key option for PK enrollment.
The Bottom Line
Open your PC’s UEFI firmware, select its factory/default Secure Boot key option, enable Secure Boot if needed, save, and reboot. Verify UEFI mode and Secure Boot status in msinfo32. If Windows uses Legacy/MBR boot or the key option is unavailable, consult your PC or motherboard manufacturer before changing settings.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

