MBR2GPT - Unable to activate Secure Boot in BIOS

Deepak166 20 Reputation points
2026-06-24T20:35:31.71+00:00

(DHi, i recently changed my boot drive ssd from 256gb to 1tb, i previously managed to activate on my previous drive thanks to the help of someone here.

My disk was MBR so i used cmd to convert it to GPT, everything went fine but at the end of its process it said this:

mbr2gpt: Call WinReReapir to repair WinRE
MBR2GPT: Failed to update ReAgent.xml, please try to manually disable and enable Win

After this i went into BIOS but still no option to enable secureboot. I am currently in Windows UEFI mode and CSM is enabled. In the secureboot tab it said and still says:

Secure boot status: User (this is Greyed out)
Platform Key (PK) State: Loaded (This is greyed out)
OS Type: Windows UEFI Mode (Dropdown menu available with "Other OS" Option)
Key Management (leads to different tab)

CSM Tab:

Launch CSM: Enabled
Boot Device Control: UEFI and Legacy OPROM
Boot from Network Devices: Legacy Only
Boot from Storage Devices: Legacy Only
Boot from PCI-E Expansion Devices: Legacy Only
User's image

(Disk 1 is the drive in question)

Windows for home | Windows 10 | Install and upgrade
0 comments No comments

Answer accepted by question author
Ivan B 124.1K Reputation points Independent Advisor
2026-06-24T21:13:54.81+00:00

Hi,

This is because CSM is enabled and Secure Boot won't load the keys.

Search for msinfo32.exe in the search bar, take a screenshot, and post it here so we can see the correct laptop model or desktop configuration.

First, access the BIOS, go to the boot tab, and see if the SSD is being recognized as Windows Boot Manager or UEFI: and the SSD model.

You have to change all of this to UEFI after disabling CSM.

Boot Device Control: UEFI change to UEFI only. Boot from Network Devices: Legacy Only change to UEFI. Boot from Storage Devices: Legacy Only change to UEFI only. Boot from PCI-E Expansion Devices: here for legacy and UEFI if the option is available.

If so, you must disable CSM, save the BIOS, access the BIOS again, check if the boot, UEFI, or Windows Boot Manager is being recognized, and save the boot in Windows.

After it boots into Windows, restart and access the BIOS again and see if the Secure Boot option is enabled, save it, and boot into Windows.

Then access msinfo32.exe, take a screenshot, and post it here.

Thanks

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.