Disabling Secure Boot and TPM 2.0 in BIOS

Two BIOS settings need to be off. This is the single most common reason the tool refuses to run.

First, check where you stand

Press Windows + R, type msinfo32 and hit Enter. Look for two lines:

  • Secure Boot State — should read Off
  • BIOS Mode — usually UEFI, which is fine

Getting into BIOS

Restart and press the key immediately:

BrandKey
ASUSDelete or F2
GigabyteDelete
MSIDelete
ASRockF2 or Delete
HP laptopsF10 or Esc
Lenovo laptopsF2 or Fn+F2

More reliable route: in Windows, hold Shift and click Restart, then Troubleshoot › Advanced options › UEFI Firmware Settings.

Turning off Secure Boot

  • ASUS: F7 for Advanced Mode › Boot › Secure Boot › Secure Boot Control = Disabled
  • Gigabyte: Boot › Secure Boot › Disabled
  • MSI: Settings › Advanced › Windows OS Configuration › Secure Boot = Disabled
  • ASRock: Security › Secure Boot = Disabled

If the option is greyed out, you usually need to set a BIOS admin password first, or put Secure Boot into Custom mode and clear the keys.

Turning off TPM 2.0

The name differs by platform:

  • Intel: "PTT" or "Intel Platform Trust Technology"
  • AMD: "fTPM" or "AMD fTPM switch"

Usually under Advanced › Trusted Computing, or Security. Set it to Disabled.

What actually changes

To be straight with you, these changes are not free:

  • BitLocker. If your drive is encrypted, Windows will demand the recovery key after TPM is disabled. Have that key before you change anything.
  • Windows Hello. Fingerprint and face sign-in may stop working.
  • Some other games. A number of titles with kernel-level anti-cheat now require Secure Boot and will refuse to launch afterwards.
If BitLocker is on, retrieve and write down your recovery key from your Microsoft account before touching BIOS.

Read next