Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

For most Windows users with a compatible UEFI PC, yes: keep Secure Boot enabled. It helps prevent untrusted boot-time software from loading, adding protection against bootkits and other attacks that target a computer before Windows starts. Check your PC’s current setting before changing it; the right choice can differ if you use Linux or a custom bootloader.

What Secure Boot does—and what it does not

Secure Boot is a UEFI firmware feature. Before handing control to the operating system, the firmware checks boot software against its Secure Boot trust policy. Microsoft describes it as a feature that helps prevent malicious software from loading when Windows starts (Microsoft: Windows 11 and Secure Boot).

This protection applies to the startup chain, not everything that runs on your PC. After the bootloader starts, Windows Trusted Boot continues checking the kernel and other startup components (Microsoft Learn: Secure the Windows boot process). Secure Boot is not a general-purpose malware scanner and does not prove that all software on a running system is safe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to check whether it is on

Use Windows System Information

Open Start, search for System Information, and check the Secure Boot State entry. Microsoft also documents checking Secure Boot with PowerShell, including the Confirm-SecureBootUEFI and Get-SecureBootUEFI cmdlets (Microsoft Learn: Windows Secure Boot key creation and management guidance).

#1 Best Overall
NewHail TPM2.0 Module LPC 14Pin Module with Infineon SLB9665 for ASUS Motherboard Compatible with TPM-M R2.0
  • Compatible with TPM-M R2.0
  • Chipset: Infineon SLB9665
  • PIN DEFINE:14Pin
  • Interface:LPC
  • Please check the Pinout of mainboard at the official website and make sure it compatible with the pinout of TPM module before purchasing, thank you.

Open the PC’s UEFI settings

To reach the firmware interface from Windows, go to Settings > System > Recovery > Advanced startup > Restart now. Then select Troubleshoot > Advanced options > UEFI Firmware Settings > Restart. The computer will open its own firmware interface; option names and locations vary by manufacturer (Microsoft: Windows 11 and Secure Boot).

When you may need a different setup

Windows is installed in Legacy BIOS or CSM mode

Secure Boot requires UEFI boot mode. If the firmware uses Legacy BIOS or Compatibility Support Module (CSM) mode, the setting may be unavailable. Microsoft says that when both boot modes are offered, UEFI should be first or the only boot mode. Before changing this, check your PC maker’s instructions—especially if Windows was installed in Legacy mode. A firmware-mode change can prevent that installation from booting as expected.

Rank #2
Sale
Yeiwenl TPM 2.0 Module with 14 Pin, TPM 2.0 Encryption Security Module for ASUS Motherboard Compatible with Win11
  • TPM 2.0 module for Asus motherboard.
  • TPM 2.0 module chip 2.0mm pitch, 2x7P, 14 pin security module
  • LPC 14 Pin for AsusTPM chip is better compatible with DDR4 memory module of motherboard, built in support memory type higher than DDR3! Supported states may vary by motherboard specification.
  • Note: Don't support laptops and motherboards prior to X99; Don't support DDR3 memory.
  • Packing list:1x TPM 2.0 Module for ASUS

You use Linux or a custom bootloader

A non-Microsoft bootloader may need a trusted signature or explicit firmware configuration. Microsoft describes options such as using a certified bootloader, adding a custom bootloader signature to UEFI’s trust database, or disabling Secure Boot (Microsoft Learn: Secure the Windows boot process). The details depend on the Linux distribution and firmware, so do not assume every setup will boot unchanged.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Disabling Secure Boot may allow boot software outside the firmware’s trust policy, but it also removes this layer of protection against bootkits. If you need a custom setup, prefer a narrow trust configuration that admits only the boot software you intend to use, where your device supports it. Follow the manufacturer’s instructions and know how to restore the prior firmware settings if startup fails.

Rank #3
Sale
Yeiwenl TPM 2.0 Module 18 Pin, TPM 2.0 Encryption Security Module for ASROCK Motherboard Compatible with Win11
  • TPM 2.0 module for ASROCK motherboard.
  • TPM 2.0 module chip 2.0mm pitch, 2x9P, 18 pin security module for ASROCK
  • LPC 18 Pin for TPM chip is better compatible with DDR4 memory module of motherboard, built in support memory type higher than DDR3! Supported states may vary by motherboard specification.
  • Note: Don't support laptops and motherboards prior to X99; Don't support DDR3 memory.
  • Packing list:1x TPM 2.0 Module for ASROCK

Secure Boot and Windows 11 eligibility

Microsoft distinguishes between being Secure Boot capable and having Secure Boot enabled. Its Windows 11 upgrade guidance says a Windows 10 PC must be Secure Boot capable with UEFI/BIOS enabled; enabling Secure Boot is recommended for stronger security, but capability and enabled status are not the same thing (Microsoft: Windows 11 and Secure Boot).

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Certificate updates matter in 2026

Microsoft says Secure Boot certificates originally issued in 2011 begin expiring in June 2026, and that supported Windows versions receive updates automatically. The update path can depend on Windows version, firmware, and manufacturer support. Check Microsoft’s current certificate guidance and your PC maker’s information for your specific device (Microsoft Support: Secure Boot certificate updates; Microsoft Learn: Windows Secure Boot key creation and management guidance).

Quick Recap

Bestseller No. 1
NewHail TPM2.0 Module LPC 14Pin Module with Infineon SLB9665 for ASUS Motherboard Compatible with TPM-M R2.0
NewHail TPM2.0 Module LPC 14Pin Module with Infineon SLB9665 for ASUS Motherboard Compatible with TPM-M R2.0
Compatible with TPM-M R2.0; Chipset: Infineon SLB9665; PIN DEFINE:14Pin; Interface:LPC
$24.99
SaleBestseller No. 2
Yeiwenl TPM 2.0 Module with 14 Pin, TPM 2.0 Encryption Security Module for ASUS Motherboard Compatible with Win11
Yeiwenl TPM 2.0 Module with 14 Pin, TPM 2.0 Encryption Security Module for ASUS Motherboard Compatible with Win11
TPM 2.0 module for Asus motherboard.; TPM 2.0 module chip 2.0mm pitch, 2x7P, 14 pin security module
$23.74
SaleBestseller No. 3
Yeiwenl TPM 2.0 Module 18 Pin, TPM 2.0 Encryption Security Module for ASROCK Motherboard Compatible with Win11
Yeiwenl TPM 2.0 Module 18 Pin, TPM 2.0 Encryption Security Module for ASROCK Motherboard Compatible with Win11
TPM 2.0 module for ASROCK motherboard.; TPM 2.0 module chip 2.0mm pitch, 2x9P, 18 pin security module for ASROCK
$23.74
SaleBestseller No. 4
SaleBestseller No. 5
Yeiwenl TPM 2.0 Encryption Security Module with 12 pin Compatible with Windows 11 for GIGABYTE Motherboard
Yeiwenl TPM 2.0 Encryption Security Module with 12 pin Compatible with Windows 11 for GIGABYTE Motherboard
TPM modules are suitable for GIGABYTE for Windows 11 motherboards.; Interface: LPC; Packing list:1x TPM 2.0 Module for GIGABYTE
$23.74
Best Value
Sale
Yeiwenl TPM 2.0 Encryption Security Module with 12 pin Compatible with Windows 11 for GIGABYTE Motherboard
  • TPM modules are suitable for GIGABYTE for Windows 11 motherboards.
  • Some motherboards require a TPM module inserted or an update to the latest BIOS to enable the TPM option.
  • 12Pin Remote Card Encryption Security Module Is Easy To Use, No Complicated Procedures Are Required, And It Can Be Used Immediately After Installation.
  • Interface: LPC
  • Packing list:1x TPM 2.0 Module for GIGABYTE
Rank #4
Sale
Yeiwenl TPM 2.0 Module with 20-1 Pin, TPM 2.0 Encryption Security Module for ASUS Motherboard Compatible with Win11
  • Compatible with ASUS motherboards with 20-1 pin TPM header; Please check your motherboard manual to confirm the presence of a 20-1pin TPM header before purchasing. Not compatible with ASUS X570-P or other models with other TPM header
  • TPM 2.0 module 2.54mm pitch, 2x10P, 20-1 pin security module
  • LPC 20-1Pin for AsusTPM chip is better compatible with DDR4 memory module of motherboard, built in support memory type higher than DDR3! Supported states may vary by motherboard specification.
  • Note: Don't support laptops and motherboards prior to X99; Don't support DDR3 memory.If you are unsure whether your motherboard is compatible with our TPM module, please verify with us before making a purchase. Thank you.
  • Packing list:1x TPM 2.0 Module for ASUS (Doesn't fit the connector on a ASUS Prime X570-P motherboard)

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.