What Secure Boot does and why you might disable it
Secure Boot is a security feature built into your computer's firmware that checks whether your operating system and startup files have been tampered with before your computer fully starts. It works by verifying digital signatures — essentially a seal that proves the software came from a trusted source and hasn't been altered.
Most people leave Secure Boot on. You might need to turn it off if you're installing a different operating system, using older hardware that doesn't support it, or running specialized software that conflicts with it. Disabling it makes your computer slightly more vulnerable to certain types of malware, but only if someone with physical access to your machine tries to install something malicious during startup.
The process differs depending on whether you have a Windows PC or a Mac, and even between different PC manufacturers. This guide covers the most common scenarios.
Key Takeaways
- Secure Boot verification happens in your computer's firmware settings, not in Windows or macOS itself, so you must restart and enter a special menu to change it.
- On Windows PCs, you access firmware settings through System Settings or by pressing a specific key during startup — the key varies by manufacturer (often F2, F10, or Del).
- On Macs with Apple Silicon chips, you use Recovery Mode and the Startup Security Utility to adjust security settings, not a traditional Secure Boot toggle.
- After disabling Secure Boot, your computer will start more slowly the first time because it skips the verification step, but subsequent startups return to normal speed.
- If you cannot remember your firmware password or get stuck, you may need to reset your computer's CMOS battery or contact the manufacturer for help.
Disabling Secure Boot on a Windows PC
On most Windows computers, you enter firmware settings by restarting and pressing a key during the boot process. The key depends on your computer's manufacturer: Dell and Lenovo often use F2, HP and Asus use F10, and some older systems use Del or Esc. Your computer usually displays the correct key on the startup screen for a few seconds, or you can check your manufacturer's support page before you restart.
Restart your computer and watch for the prompt. Press the correct key repeatedly as soon as you see it — you have only a few seconds. You'll enter a screen called BIOS Setup, UEFI Settings, or Firmware Settings depending on your manufacturer. Look for a section labeled "Security," "Boot," or "Startup." Inside that section, find "Secure Boot" and change it from "Enabled" to "Disabled." Save your changes (usually by pressing F10 or selecting "Save and Exit") and your computer will restart.
If you cannot access firmware settings by pressing a key, try entering Windows Settings instead. Go to Settings > System > Recovery, then under "Advanced startup" click "Restart now." When your computer restarts, select "Troubleshoot" > "Advanced options" > "UEFI Firmware Settings" > "Restart." This takes you directly to firmware settings without needing to time a key press.
Disabling Secure Boot on a Mac with Apple Silicon
Macs with Apple Silicon chips (M1, M2, M3, and newer) don't have a traditional Secure Boot setting. Instead, they use Startup Security Utility, which you access through Recovery Mode. Shut down your Mac completely, then press and hold the power button until you see "Loading startup options." Click "Options," then "Continue," and sign in with your Apple ID.
Once in Recovery Mode, go to Utilities > Startup Security Utility from the menu bar. You'll see three security options: "Full Security" (the default, most restrictive), "Reduced Security" (allows some unsigned software), and "Permissive Security" (allows any software). Choose the level you need, then restart. If you've set a firmware password, you'll need to enter it to make changes.
Most people who need to disable security restrictions on a Mac are installing a different operating system or running specialized software. Reduced Security is usually sufficient for these tasks and keeps your Mac safer than Permissive Security.
What happens after you disable Secure Boot
Your computer will start normally, but the first startup after disabling Secure Boot may take longer because your system is no longer skipping the verification step — it's now checking that you intentionally disabled it. Subsequent startups return to normal speed.
You may see warning messages or notices during startup. These are normal and don't indicate a problem. If you installed a different operating system or are running software that required Secure Boot to be off, it should now work without errors.
If you want to turn Secure Boot back on later, follow the same steps and change the setting back to "Enabled" or "Full Security." You can toggle it as many times as you need.
Troubleshooting if you cannot access firmware settings
If you're stuck at the Windows login screen and cannot restart into firmware settings, try this: hold Shift and click the power icon in the bottom right, then click "Restart." Your computer will restart into the advanced startup menu, where you can select "Troubleshoot" > "Advanced options" > "UEFI Firmware Settings."
If you set a firmware password and forgot it, you cannot change Secure Boot without resetting it. On a Windows PC, this usually requires opening the computer case and removing the CMOS battery for a few minutes, then reinstalling it. On a Mac, you'll need to contact Apple Support or visit an Apple Store. This is intentional — it prevents someone else from changing your security settings without your permission.
If your computer won't start at all after disabling Secure Boot, restart and turn it back on using the same process. Some older hardware or certain operating systems genuinely require Secure Boot to be enabled.
When you should and shouldn't disable Secure Boot
Disable Secure Boot if you're installing Linux, Windows on a Mac, or other non-standard operating systems. You should also disable it if you're using specialized hardware or software that explicitly requires it and you've confirmed this with the manufacturer's documentation.
Do not disable Secure Boot if you're just trying to speed up your computer's startup — it has minimal impact on boot time. Do not disable it to fix a software problem unless the software's support documentation specifically tells you to. And do not disable it on a shared computer or a work device without permission from the device owner or IT department.
If you're unsure whether you need to disable Secure Boot, check the documentation for the software or hardware you're trying to use. Most modern software works fine with Secure Boot enabled.
Frequently Asked Questions
Will disabling Secure Boot make my computer unsafe?
Disabling Secure Boot removes one layer of protection against malware that tries to run during startup, but only if someone with physical access to your computer tries to install it. For most people, the risk is very low. If you're concerned, re-enable it as soon as you're done with whatever required it to be off.
Can I disable Secure Boot without restarting?
No. Secure Boot is a firmware-level setting, which means it lives in your computer's hardware, not in Windows or macOS. You must restart and enter firmware settings to change it. There is no way to do it from within your operating system.
Why does my computer ask for a password when I try to change Secure Boot?
You've set a firmware password, which protects your security settings from being changed without permission. If you remember it, enter it. If you don't, you'll need to reset it through your manufacturer's process, which usually involves opening the computer case or contacting support.
Do I need to disable Secure Boot to install Windows 11?
No. Windows 11 requires Secure Boot to be on. If you're installing Windows 11 and it's telling you Secure Boot is off, turn it back on before continuing with the installation.
What's the difference between Secure Boot and TPM?
Secure Boot verifies that your operating system hasn't been tampered with during startup. TPM (Trusted Platform Module) is a separate security chip that encrypts sensitive data on your drive. They work together but are independent features. You can disable one without affecting the other.