Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
For most Windows users with a compatible UEFI PC, yes: keep Secure Boot enabled. It helps prevent untrusted boot-time software from loading, adding protection against bootkits and other attacks that target a computer before Windows starts. Check your PC’s current setting before changing it; the right choice can differ if you use Linux or a custom bootloader.
What Secure Boot does—and what it does not
Secure Boot is a UEFI firmware feature. Before handing control to the operating system, the firmware checks boot software against its Secure Boot trust policy. Microsoft describes it as a feature that helps prevent malicious software from loading when Windows starts (Microsoft: Windows 11 and Secure Boot).
This protection applies to the startup chain, not everything that runs on your PC. After the bootloader starts, Windows Trusted Boot continues checking the kernel and other startup components (Microsoft Learn: Secure the Windows boot process). Secure Boot is not a general-purpose malware scanner and does not prove that all software on a running system is safe.
How to check whether it is on
Use Windows System Information
Open Start, search for System Information, and check the Secure Boot State entry. Microsoft also documents checking Secure Boot with PowerShell, including the Confirm-SecureBootUEFI and Get-SecureBootUEFI cmdlets (Microsoft Learn: Windows Secure Boot key creation and management guidance).
#1 Best Overall
- Compatible with TPM-M R2.0
- Chipset: Infineon SLB9665
- PIN DEFINE:14Pin
- Interface:LPC
- Please check the Pinout of mainboard at the official website and make sure it compatible with the pinout of TPM module before purchasing, thank you.
Open the PC’s UEFI settings
To reach the firmware interface from Windows, go to Settings > System > Recovery > Advanced startup > Restart now. Then select Troubleshoot > Advanced options > UEFI Firmware Settings > Restart. The computer will open its own firmware interface; option names and locations vary by manufacturer (Microsoft: Windows 11 and Secure Boot).
When you may need a different setup
Windows is installed in Legacy BIOS or CSM mode
Secure Boot requires UEFI boot mode. If the firmware uses Legacy BIOS or Compatibility Support Module (CSM) mode, the setting may be unavailable. Microsoft says that when both boot modes are offered, UEFI should be first or the only boot mode. Before changing this, check your PC maker’s instructions—especially if Windows was installed in Legacy mode. A firmware-mode change can prevent that installation from booting as expected.
Rank #2
- TPM 2.0 module for Asus motherboard.
- TPM 2.0 module chip 2.0mm pitch, 2x7P, 14 pin security module
- LPC 14 Pin for AsusTPM chip is better compatible with DDR4 memory module of motherboard, built in support memory type higher than DDR3! Supported states may vary by motherboard specification.
- Note: Don't support laptops and motherboards prior to X99; Don't support DDR3 memory.
- Packing list:1x TPM 2.0 Module for ASUS
You use Linux or a custom bootloader
A non-Microsoft bootloader may need a trusted signature or explicit firmware configuration. Microsoft describes options such as using a certified bootloader, adding a custom bootloader signature to UEFI’s trust database, or disabling Secure Boot (Microsoft Learn: Secure the Windows boot process). The details depend on the Linux distribution and firmware, so do not assume every setup will boot unchanged.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteDisabling Secure Boot may allow boot software outside the firmware’s trust policy, but it also removes this layer of protection against bootkits. If you need a custom setup, prefer a narrow trust configuration that admits only the boot software you intend to use, where your device supports it. Follow the manufacturer’s instructions and know how to restore the prior firmware settings if startup fails.
Rank #3
- TPM 2.0 module for ASROCK motherboard.
- TPM 2.0 module chip 2.0mm pitch, 2x9P, 18 pin security module for ASROCK
- LPC 18 Pin for TPM chip is better compatible with DDR4 memory module of motherboard, built in support memory type higher than DDR3! Supported states may vary by motherboard specification.
- Note: Don't support laptops and motherboards prior to X99; Don't support DDR3 memory.
- Packing list:1x TPM 2.0 Module for ASROCK
Secure Boot and Windows 11 eligibility
Microsoft distinguishes between being Secure Boot capable and having Secure Boot enabled. Its Windows 11 upgrade guidance says a Windows 10 PC must be Secure Boot capable with UEFI/BIOS enabled; enabling Secure Boot is recommended for stronger security, but capability and enabled status are not the same thing (Microsoft: Windows 11 and Secure Boot).
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Certificate updates matter in 2026
Microsoft says Secure Boot certificates originally issued in 2011 begin expiring in June 2026, and that supported Windows versions receive updates automatically. The update path can depend on Windows version, firmware, and manufacturer support. Check Microsoft’s current certificate guidance and your PC maker’s information for your specific device (Microsoft Support: Secure Boot certificate updates; Microsoft Learn: Windows Secure Boot key creation and management guidance).
Quick Recap
Best Value
- TPM modules are suitable for GIGABYTE for Windows 11 motherboards.
- Some motherboards require a TPM module inserted or an update to the latest BIOS to enable the TPM option.
- 12Pin Remote Card Encryption Security Module Is Easy To Use, No Complicated Procedures Are Required, And It Can Be Used Immediately After Installation.
- Interface: LPC
- Packing list:1x TPM 2.0 Module for GIGABYTE
Rank #4
- Compatible with ASUS motherboards with 20-1 pin TPM header; Please check your motherboard manual to confirm the presence of a 20-1pin TPM header before purchasing. Not compatible with ASUS X570-P or other models with other TPM header
- TPM 2.0 module 2.54mm pitch, 2x10P, 20-1 pin security module
- LPC 20-1Pin for AsusTPM chip is better compatible with DDR4 memory module of motherboard, built in support memory type higher than DDR3! Supported states may vary by motherboard specification.
- Note: Don't support laptops and motherboards prior to X99; Don't support DDR3 memory.If you are unsure whether your motherboard is compatible with our TPM module, please verify with us before making a purchase. Thank you.
- Packing list:1x TPM 2.0 Module for ASUS (Doesn't fit the connector on a ASUS Prime X570-P motherboard)
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →

