Resource icon

Secure Boot enabled versus Secure Boot capable

What it means​

A PC may support UEFI Secure Boot while its firmware setting leaves the feature off. When enabled, Secure Boot checks trusted digital signatures during startup. It is one layer of boot integrity, not a replacement for updates, backups or endpoint protection.

A real-world example​

A Windows compatibility check says the device is Secure Boot capable, but Device security reports the active state differently. The user must inspect the firmware and Windows status separately before concluding protection is on.

What to do​

Check the state in Windows Security and read the hardware manufacturer's instructions before making changes. Prepare encryption recovery information for any firmware adjustment.

The distinction that matters​

Microsoft distinguishes Windows 11 capability requirements from choosing to enable Secure Boot. A firmware change can affect how a configured system starts, so copied internet instructions are not a safe model-specific plan. Microsoft on Windows 11 and Secure Boot Microsoft's Device security view
Posted by
Jack
Views
1
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack