Check if Secure Boot is Enabled or Disabled in Windows 10

    Check if Secure Boot is Enabled or Disabled in Windows 10

    How to Check if Secure Boot is Enabled or Disabled in Windows 10
    Published by Category: Security System
    07 Nov 2017
    Designer Media Ltd

    Published by


    Brink's Avatar
    Administrator

    Posts: 25,191

    Show Printable Version 


    How to Check if Secure Boot is Enabled or Disabled in Windows 10

    information   Information
    Secure Boot is a security standard developed by members of the PC industry to help make sure that your PC boots using only software that is trusted by the PC manufacturer. Support for Secure Boot was introduced in Windows 8, and also supported by Windows 10.

    When the PC starts, the firmware checks the signature of each piece of boot software, including firmware drivers (Option ROMs), EFI applications, and the operating system. If the signatures are good, the PC boots, and the firmware gives control to the operating system.

    For more information about Secure Boot, see:

    This tutorial will show you how to check if Secure Boot is currently enabled, disabled, or unsupported in Windows 10.


    CONTENTS:
    • Option One: To Check if Secure Boot is Enabled or Disabled in System Information
    • Option Two: To Check if Secure Boot is Enabled or Disabled in PowerShell





    Check if Secure Boot is Enabled or Disabled in Windows 10 OPTION ONE Check if Secure Boot is Enabled or Disabled in Windows 10
    To Check if Secure Boot is Enabled or Disabled in System Information

    1. Press the Win+R keys to open Run, type msinfo32 into Run, and click/tap on OK to open System Information.

    2. In the right pane of System Summary in System Information, see if the Secure Boot State item has a value of On, Off, or Unsupported. (see screenshots below)

    Value Description
    On PC supports Secure Boot and Secure Boot is currently enabled
    Off PC supports Secure Boot and Secure Boot is currently disabled
    Unsupported PC does not support Secure Boot or Windows is installed with legacy BIOS.
    Name:  Secure_Boot_state_On_msinfo32.jpg
Views: 1257
Size:  101.7 KB
    Name:  Secure_Boot_state_Off_msinfo32.png
Views: 1216
Size:  22.7 KB
    Name:  Secure_Boot_state__unsupported_msinfo32.png
Views: 1208
Size:  24.1 KB





    Check if Secure Boot is Enabled or Disabled in Windows 10 OPTION TWO Check if Secure Boot is Enabled or Disabled in Windows 10
    To Check if Secure Boot is Enabled or Disabled in PowerShell

    1. Open an elevated PowerShell.

    2. Enter the command below into the elevated PowerShell, and press Enter.

    Confirm-SecureBootUEFI

    3. You will now know if Secure Boot is currently enabled, disabled, or unsupported based on what this cmdlet returns. (see screenshots below)

    Cmdlet Return Description
    True PC supports Secure Boot and Secure Boot is currently enabled
    False PC supports Secure Boot and Secure Boot is currently disabled
    "Cmdlet not supported on this platform" error PC does not support Secure Boot or Windows is installed with legacy BIOS.
    Name:  Secure_Boot_state_True_PowerShell.png
Views: 1193
Size:  19.6 KB
    Name:  Secure_Boot_state_False_PowerShell.png
Views: 1204
Size:  19.7 KB
    Name:  Secure_Boot_state_unsupported_PowerShell.jpg
Views: 1210
Size:  41.8 KB


    That's it,
    Shawn


  1.    26 May 2017 #1
    Join Date : Oct 2014
    Arnold, MD
    Posts : 28,962
    Triple boot - Win 10 Pro, Win 10 Pro Insider (2) - (and a sprinkling of VMs)

    Shawn....

    This line from the beginning of your tut caught my eye:

    PC boots using only software that is trusted by the PC manufacturer

    If I take that literally, it may explain an oddball situation I have with this machine. Although the standards of what Secure Boot should do are the same for all, do different manufacturers have different criteria and/or "lists" of what they think is "secure"? Different methodologies? A recent BIOS update to my system now requires me to turn Secure Boot off in order to boot a Win install thumb. Previous BIOS did not. Same thumb boots fine with it on in my Surface Pro 3.

    I've seen many posts where different people have different experiences with Secure Boot. Works on HP with it on, but not Dell. Or vice versa. Lenovo is fine, but HP is not. Inconsistent, at best.

    I have brought all of this to the attention of the Alienware (Dell) engineers, and they agree their BIOS update from 1.04 > 1.05 may have been over-aggressive.

    I was simply wondering if different manufacturers do, in fact, think differently about what is or is not Secure.
      My ComputersSystem Spec
  2.    26 May 2017 #2
    Join Date : Oct 2013
    Posts : 25,191
    64-bit Windows 10 Pro build 17040
    Thread Starter

    Hey Dick,

    Correct. It will depend on the firmware, so it can vary a bit for each manufacturer.
      My ComputersSystem Spec
  3.    26 May 2017 #3
    Join Date : Oct 2014
    Arnold, MD
    Posts : 28,962
    Triple boot - Win 10 Pro, Win 10 Pro Insider (2) - (and a sprinkling of VMs)

    Quote Originally Posted by Brink View Post
    Hey Dick,

    Correct. It will depend on the firmware, so it can vary a bit for each manufacturer.
    Thanks, Shawn. I'll bet that's not a widely known thing. Confirms my thoughts. Very interesting.........
      My ComputersSystem Spec

 


Similar Threads
Tutorial Category
Solved UEFI with secure boot disabled
I ran a Belarc analysis and it showed a notification that the " UEFI with secure boot is disabled ".Is this a default setting or does it need to be enabled?I looked at the boot settings but was unable to figure out how to resolve this issue.I am not...
AntiVirus, Firewalls and System Security
Security System Verify if Credential Guard is Enabled or Disabled in Windows 10
How to Verify if Credential Guard is Enabled or Disabled in Windows 10 Credential Guard uses virtualization-based security to isolate secrets so that only privileged system software can access them. Unauthorized access to these secrets can lead...
Tutorials
Security System Verify if Device Guard is Enabled or Disabled in Windows 10
How to Verify if Device Guard is Enabled or Disabled in Windows 10 Device Guard is a combination of enterprise-related hardware and software security features that, when configured together, will lock a device down so that it can only run trusted...
Tutorials
Solved UEFI bios enabled but no secure boot on windows 10?
So i had secure boot up and running on my windows 8.1 machine after a clean install, but now since microsoft upgraded me to windows 10 it seems as my secure boot is off again, but it's enabled in my bios is so weird, it's enabled in bios but off in...
General Support
Belarc reporting secure boot isn't enabled
Should I be worried or happy regarding this? I know for instance that it can cause problems with dual booting. What is the advantage of having it enabled?
AntiVirus, Firewalls and System Security
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd
All times are GMT -5. The time now is 15:04.
Find Us
Twitter Facebook Google+ Ten Forums iOS App Ten Forums Android App



Windows 10 Forums