Disabling Secure Boot and TPM 2.0 in BIOS
Two BIOS settings need to be off. This is the single most common reason the tool refuses to run.
First, check where you stand
Press Windows + R, type msinfo32 and hit Enter. Look for two lines:
- Secure Boot State — should read
Off - BIOS Mode — usually
UEFI, which is fine
Getting into BIOS
Restart and press the key immediately:
| Brand | Key |
|---|---|
| ASUS | Delete or F2 |
| Gigabyte | Delete |
| MSI | Delete |
| ASRock | F2 or Delete |
| HP laptops | F10 or Esc |
| Lenovo laptops | F2 or Fn+F2 |
More reliable route: in Windows, hold Shift and click Restart, then Troubleshoot › Advanced options › UEFI Firmware Settings.
Turning off Secure Boot
- ASUS: F7 for Advanced Mode › Boot › Secure Boot › Secure Boot Control = Disabled
- Gigabyte: Boot › Secure Boot › Disabled
- MSI: Settings › Advanced › Windows OS Configuration › Secure Boot = Disabled
- ASRock: Security › Secure Boot = Disabled
If the option is greyed out, you usually need to set a BIOS admin password first, or put Secure Boot into Custom mode and clear the keys.
Turning off TPM 2.0
The name differs by platform:
- Intel: "PTT" or "Intel Platform Trust Technology"
- AMD: "fTPM" or "AMD fTPM switch"
Usually under Advanced › Trusted Computing, or Security. Set it to Disabled.
What actually changes
To be straight with you, these changes are not free:
- BitLocker. If your drive is encrypted, Windows will demand the recovery key after TPM is disabled. Have that key before you change anything.
- Windows Hello. Fingerprint and face sign-in may stop working.
- Some other games. A number of titles with kernel-level anti-cheat now require Secure Boot and will refuse to launch afterwards.
If BitLocker is on, retrieve and write down your recovery key from your Microsoft account before touching BIOS.