Secure Boot checks trusted startup software before Windows loads. On ASUS computers, the menu names vary between motherboards and laptops, so an option shown in one screenshot may not exist on another model.
Before changing firmware settings, confirm how the current Windows installation starts and make the BitLocker recovery key available. Turning off legacy boot on an MBR installation can prevent that installation from starting.
msinfo32, and record BIOS Mode and Secure Boot State.A separate file backup provides a recovery copy if later installation or conversion work becomes necessary. It does not replace the BitLocker key or automatically undo a firmware setting.
Step 1. Connect external storage, open Qiling Disk Master, and select File backup.
Step 2. Select your documents and work folders in the tree control. Include any files you will need if Windows cannot start after a setting change.
Step 3. Choose the external disk, check the task, and click Proceed. Verify a sample restore and disconnect the backup drive before entering firmware setup.
The exact menu must follow the model's manual. ASUS provides separate motherboard and notebook instructions; its motherboard Secure Boot guide is a useful reference for supported boards.
Secure Boot requires an appropriate UEFI startup configuration. If CSM must be disabled, first confirm that Windows and essential expansion hardware support the resulting configuration.
Reopen msinfo32 after Windows starts and confirm Secure Boot State is On. A firmware menu set to Windows UEFI mode does not by itself prove that all required keys and conditions are in place.
If Windows requests a BitLocker recovery key, use the saved key and investigate the configuration change. Do not clear the TPM to bypass the prompt.
If the PC no longer boots, return to firmware and restore the specific settings you recorded before the change. Do not repeatedly convert disks or reset all firmware options. For a boot-signature warning, verify that the installed operating system and recovery media are supported and properly signed.
Finally, check the other Windows 11 requirements separately. Secure Boot does not add TPM 2.0, change the processor's compatibility, or increase storage capacity.