Secure Boot is a UEFI security feature that helps make sure the PC starts using only trusted, digitally signed boot software. It helps protect against boot-level malware.
For a Windows 10 home PC, the alert usually means one of these:
- Secure Boot is turned off.
- Secure Boot is on, but the device may need updated Secure Boot certificates.
To check or change it:
- In Windows, hold Shift and select Restart.
- Go to Troubleshoot > Advanced options > UEFI Firmware Settings.
- In the firmware or BIOS menu, look for Secure Boot. It is commonly under Security, Boot, or Authentication.
- If it is Disabled, change it to Enabled.
- Save changes and restart.
If the PC is a Surface and Secure Boot is off, the device can show a red bar with an unlocked lock icon. On Surface, Secure Boot can be turned on in UEFI under Security by selecting a Secure Boot certificate keyset such as Microsoft only, then restarting.
Important:
- Software cannot change Secure Boot settings directly; this must be done in the UEFI or BIOS firmware menu.
- If the setting is missing or cannot be changed, contact the device manufacturer for model-specific steps.
- If Secure Boot is already enabled, the alert can be related to certificate updates. Keep Windows updated because Secure Boot relies on certificates stored in firmware that must remain up to date.
References: