Enable or disable Secure Boot via the ASUS UEFI BIOS utility

By default, Secure Boot is enabled on ASUS motherboards using UEFI BIOS. However, if you want to install dual-boot, you will have to disable Secure Boot.

By default, Secure Boot is enabled on ASUS motherboards using UEFI BIOS. However, if you want to install dual-boot, you will have to disable Secure Boot. In the following article, Network Administrator will guide you through steps to disable Secure Boot on UEFI BIOS on Asus X99-Deluxe motherboard.

Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 1Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 1

In addition, readers can refer to the steps to disable Secure Boot on the BIOS here. Or if you want to have Secure Boot check enabled on your computer, can you read here?

1. Prerequisites for Windows UEFI Mode: GPT partition

Installing Windows on UEFI - the system platform requires the hard drive partition type to support UEFI Mode or at least Legacy BIOS mode - compatible mode.

And if the following error message is displayed on the screen, it means your computer is started in UEFI mode but the hard drive does not support UEFI mode:

' Windows không thể được cài đặt để đĩa này. Máy ảnh đã chọn không phải là kiểu kiểu GPT

Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 2Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 2

GPT partitions on hard drives are required for UEFI Mode. Also the advantage of GPT partition is that users can set up drives larger than 4 GB and have more partitions.

The easiest way to apply GPT partitions on your hard drive is through Command Prompt using the installation drive or tool on Widows.

2. Use Command Prompt to convert hard drive into GPT partition

  1. Insert the Windows setup drive or USB drive and boot up your computer in UEFI mode.
  2. After booting from Windows setup, press Shift + F10 to open the Command Prompt window.
  3. Next open the disk partition tool with diskpart .
  4. List and confirm the format drive (format) with list disk .
  5. Select the drive to format and convert to GPT:

select disk

clean

convert gpt

exit

  1. Close the Command Prompt window and continue.

Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 3Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 3

3. Use Windows Partition Manager Tool to convert hard drive into GPT partition

You can also convert to GPT without having to use Command Prompt using the Windows partition manager tool from EaseUS.

EaseUS partition master can help you convert hard drive to GPT. Also you can create, merge, delete partition or wipe partion. In addition the tool also assists you in recovering data in case if the data is deleted or the partition is lost.

4. Steps to backup Existing Keys and disable Secure Boot

  1. Insert the USB drive into your computer.
  2. Restart the computer and access BIOS mode by pressing the DEL key (or use the other key, paying attention on the first instruction window). This to open the UEFI BIOS interface.
  3. Access Advanced Mode (press the F7 key or another specified key).

Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 4Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 4

  1. Go to the Secure Boot option under Boot.

Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 5Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 5

  1. Make sure that the correct OS Type is selected, then access Key Management.

Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 6Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 6

  1. Select Save Secure Boot Keys and press Enter.

Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 7Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 7

  1. Select the USB drive when asked to Select a File System.

Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 8Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 8

  1. 4 keys named PK, KEK, DB and DBX will be saved to the USB drive.

Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 9Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 9

  1. Delete the Platform Key (PK) to disable Secure Boot (note not to delete other keys).

Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 10Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 10

  1. Save and restart to apply settings (usually using F10 key).

Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 11Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 11

5. Restore the key and activate Secure Boot

  1. Follow steps 1 to 5 above. Use a USB drive containing backup of keys.
  2. Access Load Default PK and press Enter. And you will have 2 options to set up a new key.

Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 12Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 12

  1. Select Yes to load the default key. Once completed, save the configuration and reboot to activate Secure Boot.
  2. Select No to load the backup keys:

Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 13Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 13

  1. Select the USB drive containing the backup files.

Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 14Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 14

  1. Select file to restore (in this case PK).

Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 15Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 15

  1. Validation is UEFI Secure Variable.

Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 16Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 16

  1. Confirm that you want to update (update) the PK file.

Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 17Enable or disable Secure Boot via the ASUS UEFI BIOS utility Picture 17

  1. Save changes and restart. Secure Boot will be activated.

Refer to some of the following articles:

  1. How to check Secure Boot has been enabled on your computer or not?
  1. How to turn off Secure Boot mode and open Boot Legacy mode
  1. How to fix the screen error of Windows 7/8 / 8.1 / 10 is black

Good luck!

4 ★ | 491 Vote