What UEFI Secure Boot does and why you might need to disable it
UEFI Secure Boot is a security feature built into your computer's firmware that checks whether your operating system and startup files are legitimate before your computer boots. It prevents unauthorized software from running during startup. Most computers ship with Secure Boot turned on.
You may need to disable it if you're installing a different operating system, using older hardware that isn't compatible with Secure Boot, or troubleshooting startup problems. Some specialized software or custom configurations also require Secure Boot to be off. Disabling it is a normal maintenance task, though your computer will lose that particular layer of startup protection while it's off.
Key Takeaways
- You access Secure Boot settings through your computer's firmware menu, which you reach by restarting and pressing a specific key during startup — usually Delete, F2, F10, or F12 depending on your manufacturer.
- The exact steps and menu names vary between Dell, HP, Lenovo, ASUS, and other manufacturers, so you may need to look up your specific model's firmware key.
- Some computers require you to set an administrator password in firmware before you can change Secure Boot, and some ask you to confirm the change by typing a code on the next restart.
- After disabling Secure Boot, your computer will boot normally, but you lose the security benefit of startup file verification until you turn it back on.
Finding your firmware menu and the correct startup key
The first step is getting into your computer's firmware settings, where Secure Boot lives. This is different from Windows settings or Mac System Preferences — it's a layer below your operating system. To reach it, you restart your computer and press a specific key repeatedly during the startup process, before Windows or your operating system loads.
The key you press depends on your computer's manufacturer. Dell computers typically use Delete or F2. HP and Lenovo often use F2 or F10. ASUS uses Delete or F2. Apple computers use Command+R or Command+Option+R to reach recovery mode, which is different from firmware settings. If you're not sure which key your computer uses, restart it and watch the screen carefully during startup — most computers display a message like "Press F2 to enter Setup" or "Press Delete for BIOS Settings" for a few seconds.
If you miss the window, let your computer finish booting and try again. You may need to restart several times to catch the message. Some newer computers with fast startup times make this window very brief. If you still can't find the key, search online for your exact computer model and "firmware key" or "BIOS key" — manufacturer support pages list this information.
Navigating the firmware menu to find Secure Boot
Once you're in the firmware menu, you'll see a text-based interface with several tabs or sections. The menu looks different depending on your manufacturer, but the structure is similar. You'll typically see sections like Main, Advanced, Security, Boot, or System Configuration. Secure Boot settings are almost always in the Security section.
Use your keyboard arrow keys to navigate — the mouse usually doesn't work in firmware menus. Move to the Security tab or section and press Enter. Look for an option labeled "Secure Boot," "Secure Boot Control," or "Secure Boot Mode." You may also see related options like "Secure Boot State" or "UEFI Secure Boot." The setting you want to change is the main Secure Boot toggle, not the related options.
If you can't find Secure Boot in the Security section, check the Boot section or look for a System Configuration tab. Some manufacturers hide it in different places. If your firmware menu looks completely different from what you expected, take a screenshot or note the exact model name and search for a firmware walkthrough specific to your computer.
Disabling Secure Boot and handling administrator passwords
Highlight the Secure Boot option and press Enter. You'll see a dropdown menu or a Yes/No prompt. Select "Disabled" or "Off" — the exact wording varies. Some computers show options like "Enabled," "Disabled," or "Custom Mode." Choose "Disabled" to turn it off completely.
Some computers require you to set a firmware administrator password before you can change Secure Boot. If you see a message asking for a password and you haven't set one, you'll need to create one first. The firmware will prompt you to enter a new password, then confirm it. Write this password down somewhere safe — you'll need it if you want to change firmware settings again later. If you forget it, you may need to contact the manufacturer or take the computer to a technician.
After you select "Disabled," the firmware menu will ask you to save and exit. Look for a "Save and Exit" or "Exit and Save Changes" option, usually near the bottom of the menu or in a separate tab. Press Enter to confirm. Your computer will restart.
Confirming the change and what happens next
Some computers, particularly newer Dell and HP models, will display a confirmation screen after restart asking you to press a specific key or type a code to confirm that you intentionally disabled Secure Boot. This is a security measure to prevent accidental changes. Follow the on-screen instructions — you may need to press F10, Enter, or type a displayed code. If you don't confirm, Secure Boot will turn back on automatically.
After confirmation, your computer will boot normally into Windows or your operating system. Secure Boot is now off. You won't see any obvious change in how your computer works — it will start up and run the same way it did before. The difference is that your computer is no longer verifying the authenticity of startup files.
If you need to turn Secure Boot back on later, follow the same steps: restart, enter firmware, navigate to Security, find Secure Boot, select "Enabled," save, and exit. You can toggle it on and off as many times as you need.
Troubleshooting if you can't find or change Secure Boot
If you enter the firmware menu and don't see Secure Boot anywhere, your computer may not have it. Older computers built before 2012 typically don't have UEFI Secure Boot — they use older BIOS firmware instead. If that's the case, you don't need to disable anything. You can exit the firmware menu by pressing Escape or selecting "Exit Without Saving."
If you see Secure Boot but can't change it, check whether a firmware password is blocking changes. Look for a "Set Administrator Password" or "Set Supervisor Password" option and create one. Some computers also have a "Secure Boot Mode" setting separate from the main toggle — make sure you're changing the right one. If you're still stuck, search for your exact computer model and "disable Secure Boot" to find manufacturer-specific instructions.
If your computer won't boot after disabling Secure Boot, restart and enter firmware again to turn it back on. This usually means the operating system or software you're trying to use isn't compatible with Secure Boot off, or there's a different startup problem. Turning Secure Boot back on will restore your previous startup behavior.
Frequently Asked Questions
Will disabling Secure Boot make my computer less secure?
Secure Boot protects against unauthorized code running during startup, but it's one of many security layers. Disabling it removes that specific protection, but your computer still has antivirus, Windows Defender, and other security features. If you're only disabling it temporarily to install something specific, you can turn it back on afterward.
Can I disable Secure Boot on a Mac?
Macs use a different system called Secure Boot that works differently than Windows UEFI Secure Boot. On newer Macs with Apple Silicon, you access it through Recovery Mode by restarting and holding Command+R, then going to Utilities and Startup Security Utility. On Intel Macs, Secure Boot settings are in the firmware, but the process is different from Windows computers.
What if I forgot my firmware administrator password?
If you set a firmware password and forgot it, you'll need to contact your computer manufacturer's support line with proof of ownership. Some manufacturers can reset it remotely or provide instructions. In some cases, a technician may need to reset the firmware, which can be time-consuming. Write down any firmware passwords you create and store them somewhere safe.
Do I need to disable Secure Boot to install Windows?
No. Modern versions of Windows work with Secure Boot on. You only need to disable it if you're installing an older version of Windows, a different operating system like Linux, or if the installation is failing and you've been told to turn it off. Most of the time, leaving it on is the better choice.
Will my computer be slower with Secure Boot off?
No. Secure Boot has minimal impact on startup speed or overall performance. Disabling it won't make your computer noticeably faster or slower. The only difference is the security check that happens during startup — removing it doesn't change how your computer runs once it's booted.