Quick answer

Open msinfo32 and read BIOS Mode and Secure Boot State. UEFI with Secure Boot off is a single BIOS switch. Legacy means converting the disk with mbr2gpt before CSM goes off, or Windows will not boot. Enabled in the BIOS but still off points at CSM or the keys; restore the factory keys. Save your BitLocker recovery key first.

Call of Duty’s RICOCHET, EA Javelin, Riot Vanguard and FACEIT can all stop a game over Secure Boot. Each says so in its own words, and most of their messages do not say which of four different problems you have. Windows does. Open msinfo32 and read two lines, and the fix picks itself.

Two dates make this urgent. Call of Duty: Modern Warfare 4 opens Campaign Early Access on October 16, 2026, with the full release a week later on October 23, and Activision says TPM 2.0 and Secure Boot are required to play it on PC. FACEIT’s new Windows 10 rule starts on October 14, 2026. It has its own section.

Find your error message

Each row is the publisher’s own wording and the publisher’s own explanation, copied from that publisher’s support page, and the last column is where the fix for that row starts further down this page.

Game or anti-cheatWhat you seeWhat the publisher says it meansFix
Call of Duty (BO7, Warzone, MW4)Secure Attestation Wizard: “Secure Boot: Not Enabled”Secure Boot requirement not metRead msinfo32
Call of Duty“BIOS Boot mode not set to UEFI” or “Boot Partition not set to GPT”Secure Boot cannot run until the PC boots UEFI from a GPT diskLegacy or MBR
Call of Duty“TPM 2.0: Not Enabled”, or tpm.msc shows “Compatible TPM cannot be found”TPM off in the BIOS, or not supportedThe TPM half
Call of DutyThe enrollaik.exe prompt keeps coming back after you click YesAMD firmware 3.*.0.* fails registration; the BIOS needs an updateThe TPM half
Call of Duty“TCG Event Log Failed”Windows is not up to dateCall of Duty
Call of Duty“Failed Attestation Status”Requirements not met; Ranked Play and some playlists are restrictedCall of Duty
EA Javelin games, Battlefield 6 included“The application encountered an unrecoverable error.”Expired or unsigned drivers loading at launch; EA’s fix ends at enabling Secure BootBattlefield 6
Valorant, League (Vanguard)VAN 9003Secure Boot is not enabledRead msinfo32
Valorant, League (Vanguard)VAN 9001Vanguard does not detect TPM 2.0 as enabledThe TPM half
Valorant, League (Vanguard)VAN: STATUS_SB_POLICY, “The secure boot policy on this device could not be verified”A Secure Boot configuration problem, even with Secure Boot onEnabled but not active
FACEIT“Please set Secure Boot preset to “Maximum Security” in your BIOS”Some MSI boards’ default settingsEnabled but not active
FACEIT“TPM attestation failed”A discrete TPM, an old GRUB, a self-signed boot loader or an internet-cafe toolThe TPM half
Easy Anti-Cheat games“Boot validation failed” or “Unable to verify Secure Boot”Measured-boot problemsThe EAC guide
Any PC, at power-on“Secure Boot Violation” or “Invalid Signature Detected”Firmware certificates too old for current Windows boot filesIt will not boot

VAN 1067 is missing on purpose. Riot says it usually means Vanguard “ran into an unexpected issue while starting or checking in” with your system, and its fix list starts with Windows Update and unplugging controllers. It is not a Secure Boot error. The rest of Riot’s codes are in the Vanguard error code table.

Before you touch the BIOS

Three of the fixes below can lock you out of Windows if they go in the wrong order. Do these first.

  1. Get your BitLocker recovery key. From another device, open aka.ms/myrecoverykey and sign in with the Microsoft account you use on this PC. If a key is listed for it, write it down. Microsoft’s list of events that send a PC to the BitLocker recovery screen includes a BIOS or UEFI firmware upgrade, clearing or disabling the TPM, changes to the boot manager and changes to the partition table. Every section below touches at least one of those.
  2. Suspend BitLocker for the BIOS work. In an administrator PowerShell, run Suspend-BitLocker -MountPoint "C:" -RebootCount 0. The 0 matters. Without it, protection resumes after the next restart, and BIOS work takes several. If your Windows disk is MBR, the conversion section asks for encryption to be off rather than suspended, so read it before you choose. Either way, the last section turns protection back on.
  3. Back up anything you would miss. GIGABYTE puts this in its own preparation list, and Riot says the disk conversion “cannot be reversed”.

Read msinfo32 first

Press Windows+R, type msinfo32 and press Enter. On the System Summary page, find BIOS Mode and Secure Boot State. Riot’s, EA’s and FACEIT’s Secure Boot guides start here, and so do MSI’s and GIGABYTE’s.

BIOS ModeSecure Boot StateWhat it meansGo to
UEFIOnSecure Boot is fine. A remaining error is the TPM, attestation or the gameThe TPM half
UEFIOffThe disk is ready. Flip one switchUEFI, Secure Boot off
LegacyOff or UnsupportedThe disk has to be converted before anything elseLegacy or MBR
UEFIUnsupportedA board or firmware limitState Unsupported

The same answer is available in PowerShell. Microsoft documents that Confirm-SecureBootUEFI returns True when Secure Boot is on, False when it is off, and “Cmdlet not supported on this platform” on a BIOS (non-UEFI) computer. It needs an administrator window; without one it answers “Unable to set proper privileges. Access was denied.”

Also check the disk. Open Disk Management, right-click the disk that holds Windows, choose Properties and open the Volumes tab. Partition style reads GPT or MBR. MBR changes the plan.

Legacy or MBR: convert the disk first

This is the step that stops Windows from booting when it goes wrong. Read it twice. If you switch the BIOS to UEFI, or turn CSM off, while the Windows disk is still MBR, Windows will not boot. MSI and GIGABYTE say so, and so does Riot. Riot’s version: “You must convert MBR > GPT before changing anything in BIOS.”

Microsoft’s MBR2GPT tool converts the system disk in place without deleting data. It refuses to run unless the disk passes its checks, including at most three primary partitions, no extended or logical partition, and room for the GPT tables. Riot and Activision add their own conditions: Windows 10 version 1703 or later, 64-bit Windows, no dual boot, firmware that supports UEFI, and Secure Boot off.

Encryption needs a decision first. Microsoft says MBR2GPT converts a BitLocker volume as long as protection is suspended, but to resume BitLocker afterwards the existing protectors have to be deleted and recreated. Activision’s and Riot’s checklists say BitLocker or any other encryption must be turned off, and Microsoft’s return code 6 is a conversion that failed because a volume on the disk is encrypted. I would follow Activision and Riot. In an administrator PowerShell, Disable-BitLocker -MountPoint "C:" removes all key protectors and starts decrypting the drive. Let it finish before you run the conversion.

Decrypting leaves the drive unprotected until you encrypt it again, which is the last step of this page, once Secure Boot reads On. Do not skip it.

Then, in an administrator Command Prompt:

mbr2gpt /validate /allowFullOS
mbr2gpt /convert /allowFullOS

Run the validate line alone first. It changes nothing. It only reports whether the disk can be converted. Without /disk:, both lines act on the system disk. Microsoft lists return code 0 as “Conversion completed successfully”; anything else is a failure with its own meaning in Microsoft’s table.

Riot’s next instruction is to go straight into the BIOS rather than booting Windows. Change Boot Mode from Legacy or CSM to UEFI, disable CSM if that option exists and save. Then confirm Windows starts. Only then turn on Secure Boot, which is the next section.

UEFI with Secure Boot off: switch it on

To get into the firmware from Windows 11, open Settings > System > Recovery and select Restart now beside Advanced startup. Then pick Troubleshoot > Advanced options > UEFI Firmware Settings. The CPU temperature guide walks the same route. Activision lists Del, F2 or F10 at power-on as the other way in.

The switch has a different name on every board. These paths come from each vendor’s own page:

  • ASUS desktop boards. Press Delete, open Advanced Mode, then Boot, Secure Boot, and set OS Type to Windows UEFI mode. ASUS’s own table says Other OS means Secure Boot state is off. The Secure Boot State line is grey and cannot be set by hand.
  • MSI (MAG B550 TOMAHAWK as MSI’s example). Open Settings, Advanced, Windows OS Configuration and switch BIOS CSM/UEFI Mode to UEFI. MSI says the Secure Boot option only appears after that. Enable it, press F10 and reboot.
  • GIGABYTE (AM4 and sTRX4). Open Advanced Mode, Boot, and set CSM Support to Disabled, which makes the Secure Boot menu appear. Under Secure Boot, set Secure Boot Mode to Custom and choose Restore Factory Keys. Answer Yes to “Install Factory Defaults” and Yes to “Reset Without Saving”. Back in the BIOS, the field under Secure Boot should read Active.

For an ASRock or Biostar board, or a Dell, HP or Lenovo PC, use the manual. Activision’s and EA’s articles both link each manufacturer’s own Secure Boot page.

Save with F10, boot into Windows and run msinfo32 again. Secure Boot State should now read On.

Enabled in the BIOS but not active

This case confuses people because the BIOS says Enabled, msinfo32 says Off, and the game keeps refusing to start even after a cold boot and a second look at every menu. The switch is on. The thing it switches is not running. Work these in order:

  1. CSM is still on. Secure Boot cannot run in a Legacy or CSM boot, and on GIGABYTE and MSI boards the Secure Boot menu is hidden until CSM is off. msinfo32 showing BIOS Mode Legacy confirms it. Go back to Legacy or MBR before you change it.
  2. The keys are missing or wrong. ASUS’s fix for a “Not Active” status on desktops is Key Management, Clear Secure Boot Keys, confirm with Yes, then Install Default Secure Boot Keys. On GIGABYTE it is the Restore Factory Keys step in the list above.
  3. The ASUS setting is Other OS. On ASUS desktop boards, the Secure Boot toggle is OS Type, and ASUS says Other OS means Secure Boot state is off.
  4. Vanguard says STATUS_SB_POLICY. Riot says to reset the Secure Boot keys even when Secure Boot is enabled, so that Vanguard can verify the device. That is step 2 again.
  5. FACEIT asks for “Maximum Security”. FACEIT says some MSI boards have a known issue where Secure Boot does not work properly with its default settings, even when it shows as Enabled in both the BIOS and Windows. On a recent MSI BIOS, open Settings, Security, Secure Boot, set Secure Boot Mode to Custom and Secure Boot Preset to Maximum Security. On an older BIOS without that preset, FACEIT’s path is Image Execution Policy, with Removable Media and Fixed Media set to Deny Execute. FACEIT says to update the BIOS if neither option exists.
  6. The firmware is old. Easy Anti-Cheat’s “Unable to verify Secure Boot. Event missing from measured bootlog” kick means no event in the measured boot log confirms Secure Boot, and EAC’s fix is the latest BIOS version for the system. The EAC guide has its boot-validation messages.

Secure Boot State Unsupported

Read the BIOS Mode line beside it. Legacy with Unsupported is the Legacy case, and Riot’s guide sends both “Off” and “Unsupported” there.

UEFI with Unsupported is rarer. EA says to check the motherboard’s specification sheet or manual to see whether Secure Boot is supported. GIGABYTE says that missing fTPM or Secure Boot options can mean an unsupported processor or an incompatible BIOS version, and recommends updating the BIOS. If no update adds it, the board is out. FACEIT says as much about TPM 2.0, and adds that most CPUs and motherboards from the last decade include a firmware TPM.

The TPM half

Secure Boot gets the headlines. Four of the errors in the table are the TPM’s, and none of them clears until tpm.msc reports a TPM that Windows can use. Press Windows+R, type tpm.msc and press Enter. Activision and FACEIT both want Status to read “The TPM is ready for use”, and FACEIT adds that Specification Version should be 2.0. FACEIT also checks Windows Security, Device security, Security processor details, where Attestation and Storage should both read Ready.

“Compatible TPM cannot be found” means the TPM is off in the BIOS or missing. The firmware TPM has a vendor name. Intel calls it PTT, AMD calls it fTPM, and Activision’s floor is Intel 8th gen with PTT or Ryzen 2000 with fTPM. The vendor paths:

  • GIGABYTE AM4. Advanced Mode, Settings, AMD CPU fTPM, set to Enabled.
  • MSI (B550 TOMAHAWK example). Settings, Security, Trusted Computing, then enable Security Device Support.
  • Others. FACEIT says the option usually sits under “Security” or “Trusted Computing”.

Then check the firmware version. In tpm.msc, read Manufacturer Version under TPM Manufacturer Information. Activision says AMD versions matching 3.*.0.* are not compatible with its games and need a firmware update: 3.92.0.5 fails, 3.92.5.5 is fine. That issue can make the enrollaik.exe prompt reappear after you click Yes. For Intel, Activision flags INTC 302.12.*.* and INTC 303.12.*.* as possibly needing a firmware update. In MSI’s B550 TOMAHAWK example, the BIOS update moves AMD fTPM to 3.94.2.5. On Windows 11 25H2 build 26200.9457, read 2026-10-02, tpmtool getdeviceinformation runs without administrator rights and prints a line labelled TPM Manufacturer Version.

FACEIT’s page on “TPM attestation failed” lists four known causes and a general fallback:

  • A discrete TPM module on the board. Switch the BIOS from dTPM to fTPM.
  • An old GRUB in a dual boot. Boot Windows from the firmware boot menu instead, and update GRUB if that clears it.
  • A self-signed boot loader. Pick Windows Boot Manager from the boot menu.
  • CCU Cloud Update in an internet cafe. FACEIT sends that one to CCU’s support.
  • Anything else. Update the BIOS.

Call of Duty and Modern Warfare 4

Activision’s TPM article says TPM 2.0 and Secure Boot are required to play Black Ops 7 and Warzone, and its Modern Warfare 4 PC requirements page says the same for MW4. The MW4 dates are on Call of Duty’s September 29, 2026 PC post: PC preload from October 15, Campaign Early Access from October 16, full release October 23.

Two Activision pages disagree on hardware. That matters. The MW4 minimum spec lists an AMD Ryzen 5 1400 or Intel Core i5-6600. Activision’s TPM article sets the TPM floor at Ryzen 2000 series with fTPM or Intel 8th gen with PTT. Both minimum-spec chips are older than that floor. On one of them, run Activision’s Secure Attestation Wizard (version 1.2.0, updated September 16, 2026) before October 16 rather than finding out at the menu. The operating system floor is clearer: Windows 10 version 22H2 or later, or any Windows 11.

The rest of the Call of Duty messages:

  • “TCG Event Log Failed”: restart and install the latest Windows update.
  • “Authorization Key Failed”: the wizard’s Generate Key button triggers a UAC prompt for enrollaik.exe; select Yes.
  • A CODBrokerInstaller.exe UAC prompt on first launch needs an administrator username and password and Yes. Selecting No means you cannot play. If you get “CODBrokerInstaller.exe authorization declined” with no prompt at all, Activision’s fix is the User Account Control slider: set it to Always notify or the default level below it.
  • “Failed Attestation Status”: Activision restricts the account from some modes, including Ranked Play, and may matchmake it with other players who do not meet the requirements.

Battlefield 6 and EA Javelin

EA’s Battlefield 6 launch post says that to play Battlefield 6 on PC, you must enable Secure Boot, so that EA’s Javelin Anticheat can detect and remove cheaters. The game’s system requirements list TPM 2.0 Enabled and UEFI Secure Boot Enabled at both minimum and recommended. EA’s Secure Boot article says “Some EA games require Secure Boot”, and lists the same prerequisites as everyone else: TPM 2.0 on, a GPT Windows disk and UEFI. Its msinfo32 triage matches the table above. EA’s MBR2GPT lines add /disk:0, and EA notes that the number must match the disk number in your own Disk Management.

For “The application encountered an unrecoverable error.”, EA says it can happen when expired or unsigned drivers load as the game launches. Restart and relaunch first. If it comes back, EA’s next step is enabling Secure Boot. Javelin itself needs Windows 10 20H1 (10.0.19041) or newer.

Valorant and Riot Vanguard

Riot’s codes are tidy. VAN 9003 is Secure Boot off, VAN 9001 is TPM 2.0 not detected, and VAN: STATUS_SB_POLICY is a Secure Boot configuration problem fixed by resetting the keys. Riot’s own Secure Boot guide follows the order on this page and is blunt about step 2: “If you try to force UEFI in your BIOS without converting your drive first, your Windows won’t boot!”

A Vanguard kick with Secure Boot already On points somewhere else. Riot sends that case to its VAN: RESTRICTION guide. The VBS and Memory Integrity side of those restrictions is covered in Memory Integrity on or off, and every other code is in the Vanguard error code table.

FACEIT on Windows 10

FACEIT’s FAQ, updated October 1, 2026, sets the rule. From October 14, 2026, Windows 10 needs version 22H2 with Extended Security Updates enabled. Windows 11 becomes the requirement after Windows 10 support ends in October 2027, although FACEIT adds that some devices may have to upgrade sooner, depending on several configuration factors it does not list. Check the FAQ again before October 14.

On Windows 10, three checks before October 14:

  1. Version. Press Windows+R and run winver. FACEIT’s page on missing security updates supports Windows 10 builds 22H2 (19045) and higher.
  2. ESU. Microsoft’s consumer ESU program runs to October 12, 2027. Open Settings, Update & Security, Windows Update and select Enroll now if your PC qualifies. Microsoft lists three ways in: free if you sync your PC settings, 1,000 Microsoft Rewards points, or a one-time $30 purchase.
  3. Security features. FACEIT’s Enabling Secure Boot and Enabling TPM 2.0 pages require both for all players on Windows 10 and 11. It is enforcing IOMMU in waves, and it requires VBS to support IOMMU. Secure Boot and TPM are above. The VBS decision is in Memory Integrity on or off.

If FACEIT says your system is missing important Windows security updates, its fix is Windows Update, and on Windows 10 that means ESU.

If the PC will not boot after the change

Do not reinstall Windows. Go back into the BIOS and undo the last change. GIGABYTE’s recovery is to disable Secure Boot, or set CSM Support back to Enabled, to restore the previous state. FACEIT’s order is the same: revert, update the BIOS, then re-enable one feature at a time.

The usual cause is the MBR disk. FACEIT says boot failures after enabling Secure Boot are “usually caused by a mismatched partition scheme (UEFI with MBR)”. Convert with mbr2gpt, then switch to UEFI, then turn on Secure Boot.

A “Secure Boot Violation” or “Invalid Signature Detected” screen is different. FACEIT says the board’s Secure Boot certificates are too old to recognize recent Windows boot files. Its fix is to turn Secure Boot off long enough to boot, update the BIOS, which brings the 2023 Microsoft certificates, and turn Secure Boot back on. FACEIT notes that a BIOS update sometimes fails to install the new certificates. For a board already on its latest BIOS with the error still there, FACEIT describes copying Microsoft’s SecureBootRecovery.efi from C:\Windows\Boot\EFI to a FAT32 USB stick as EFI\BOOT\bootx64.efi and booting from it to apply the certificates. FACEIT says modifying Secure Boot settings is done at your own risk, and recommends a professional IT technician if you are uncomfortable with these steps.

One myth to drop. The certificate expiry does not switch Secure Boot off by itself. Microsoft says a device without the new certificates “will still start and operate normally”, and that Secure Boot “should not be disabled to work around certificate expiration”.

If BitLocker asks for the recovery key on the first boot afterwards, that is the key from the first step. Enter it and let Windows start.

After Secure Boot reads On: protect the drive again

Run msinfo32 one more time. With Secure Boot State reading On, put the encryption back the way you found it.

  • You suspended BitLocker. Run Resume-BitLocker -MountPoint "C:" in an administrator PowerShell. Microsoft says the cmdlet has no effect on a volume that is not suspended, so it does nothing for a drive you decrypted.
  • You turned BitLocker off for the conversion, on Windows Pro. Sign in as an administrator, type BitLocker in Start and select Manage BitLocker, then select Turn on BitLocker beside the drive. Microsoft’s steps then ask how the drive should open at startup, and for a backup of the recovery key. The key is new. Save it again.
  • You turned Device Encryption off, on Windows Home. Open Settings, Privacy & security, Device encryption, and use the toggle to turn it On. Microsoft notes that the entry is missing if the device does not support it or you are signed in with a standard account.

Sources

Frequently asked questions

Why does it say Secure Boot is not enabled when it is enabled in the BIOS?
The BIOS switch and the running state are two different things. Secure Boot only runs when the PC boots in UEFI mode with CSM off and with the Secure Boot keys installed. On ASUS desktop boards the switch is OS Type, and Other OS means off. ASUS’s fix for a ’not active’ state is to clear the Secure Boot keys and then install the default keys, and GIGABYTE’s is Restore Factory Keys under Secure Boot Mode set to Custom. Riot gives the same key reset for VAN: STATUS_SB_POLICY. Check the result in msinfo32, where Secure Boot State should read On.
What does Secure Boot State Unsupported mean?
With BIOS Mode reading Legacy, it means Windows booted the old way and cannot see Secure Boot at all, so Riot’s guide sends you to convert the disk from MBR to GPT first. With BIOS Mode reading UEFI, EA says to check the motherboard’s specification sheet or manual to see whether Secure Boot is supported. Microsoft’s Confirm-SecureBootUEFI cmdlet prints ‘Cmdlet not supported on this platform’ on a computer that does not support Secure Boot or is a BIOS (non-UEFI) computer.
Can turning on Secure Boot stop Windows from booting?
Yes. MSI, GIGABYTE and Riot all warn that switching to UEFI or forcing Secure Boot on a disk that is still MBR can leave Windows unbootable. Convert the disk with mbr2gpt first, then switch the BIOS to UEFI, then enable Secure Boot. If it already happened, GIGABYTE says to go back into the BIOS and turn Secure Boot off or set CSM Support back to Enabled to restore the previous state.
Will changing Secure Boot or TPM settings trigger BitLocker recovery?
It can. Microsoft’s list of events that send a PC to the BitLocker recovery screen includes clearing or disabling the TPM, a BIOS or UEFI firmware upgrade, changes to the boot manager and changes to the partition table. Find your recovery key at aka.ms/myrecoverykey before you start. To suspend protection across several restarts, run Suspend-BitLocker -MountPoint ‘C:’ -RebootCount 0 in an administrator PowerShell, then Resume-BitLocker when you are done. If you turned BitLocker off for an MBR conversion instead, Resume-BitLocker does nothing; turn encryption back on from Manage BitLocker or Device encryption once Secure Boot reads On.
Does Secure Boot or TPM 2.0 lower FPS?
FACEIT’s FAQ says TPM and Secure Boot do not impact performance. It says IOMMU and VBS can have a minor performance impact in some cases, particularly on older systems or systems with immature firmware. VBS and Memory Integrity are a separate decision from Secure Boot.
Can I still play FACEIT on Windows 10?
For now. FACEIT’s FAQ, updated October 1, 2026, says that from October 14, 2026, Windows 10 needs version 22H2 with Extended Security Updates enabled, and that Windows 11 will be required after Windows 10 support ends in October 2027. Microsoft’s consumer ESU program runs to October 12, 2027, and you enroll from Settings, Update & Security, Windows Update.
Does the 2026 Secure Boot certificate expiry turn Secure Boot off?
No. Microsoft says a device that reaches the expiry date without the new 2023 certificates will still start and operate normally, but stops receiving new early-boot security protections. Microsoft also says Secure Boot should not be disabled to work around certificate expiration. If a Secure Boot Violation screen appears at power-on, FACEIT’s fix is a BIOS update, which ships the 2023 certificates.
Is VAN 1067 a Secure Boot error?
No. Riot says VAN 1067 usually means Riot Vanguard ran into an unexpected issue while starting or checking in with your system, and its fix list starts with Windows Update, unplugging controllers and running the Riot Client as administrator. Riot’s Secure Boot error is VAN 9003, and its TPM error is VAN 9001.

Sources and corrections

Last updated
Methodology
See our methodology for research and review standards. It draws on 34 cited sources, listed below, each checked against the original page on the date above. Every publisher page, motherboard vendor page and Microsoft document below was opened on 2026-10-02 and the error strings, menu labels, dates and commands on this page were copied from them. The GIGABYTE, MSI and Easy Anti-Cheat pages were read in a browser, because the first two refuse scripted requests and the third renders its answers client-side. ASRock’s FAQ did not load, so this page carries no ASRock menu path. The Windows facts in the TPM section (tpmtool running without administrator rights and printing a TPM Manufacturer Version line) were read on 2026-10-02 on Windows 11 Home 25H2, build 26200.9457, with read-only commands and no setting changed.
Sources
Update log
  • 2026-10-02 — Page updated.
Corrections
Spotted an error or a stale number? Email contact@techfuelhq.com. Confirmed corrections are added to the update log above.

About the author

Written by Lowell K. Wood IV, who builds and runs TechFuelHQ from St. Louis, Missouri.