{"id":7336,"date":"2026-04-13T01:15:01","date_gmt":"2026-04-13T08:15:01","guid":{"rendered":"https:\/\/www.terabyteunlimited.com\/kb\/?post_type=lsvr_kba&#038;p=7336"},"modified":"2026-05-03T22:26:59","modified_gmt":"2026-05-04T05:26:59","slug":"how-to-enable-uefi-bios-secure-boot-setup-mode","status":"publish","type":"lsvr_kba","link":"https:\/\/www.terabyteunlimited.com\/kb\/kb-articles\/how-to-enable-uefi-bios-secure-boot-setup-mode\/","title":{"rendered":"How to Enable UEFI BIOS Secure Boot Setup Mode"},"content":{"rendered":"<p>UEFI Secure Boot Setup Mode allows modification of authorized and blocked certificates or hashes in UEFI database variables without requiring signatures from Key Exchange Key (KEK) certificates, which are typically provided by vendors such as Microsoft.<\/p>\r\n<p>Setup Mode is required when installing, removing, or otherwise modifying Secure Boot certificates and variables. If a system does not provide a direct option to enter Setup Mode, it can usually be entered by clearing or deleting the Secure Boot keys or variables.<\/p>\r\n<p>Secure Boot Setup Mode must be enabled to install or remove the TeraByte Secure Boot certificate. When the TeraByte Secure Boot Certificate Wizard is used to install or remove the certificate, you will be prompted to reboot into the BIOS as needed. On many systems, this reboot will go directly to the BIOS\/UEFI firmware without requiring you to manually press the BIOS setup key during startup.<\/p>\r\n<p>Several examples for different systems are shown below. While specific model examples are listed, the instructions are often similar for systems from the same manufacturer, such as ASUS, MSI, Dell, Lenovo, and others.<\/p>\r\n<p><strong>Before You Begin<\/strong><\/p>\r\n<ul>\r\n\t<li>Actual BIOS\/UEFI menus and options vary depending on the brand, board, model, and BIOS version.<\/li>\r\n\t<li>Some systems may require Secure Boot to be disabled before Secure Boot keys or variables can be changed.<\/li>\r\n\t<li>Some systems may have an option to automatically load Secure Boot keys and\/or variables.\r\n\r\n<ul>\r\n\t<li>If this type of option is enabled, the system may automatically reload the default keys and leave Setup Mode when restarted.<\/li>\r\n\t<li>Disable this option before clearing keys if the goal is to remain in Setup Mode.<\/li>\r\n<\/ul>\r\n<\/li>\r\n<\/ul>\r\n<p>For information about possible effects of changing Secure Boot settings, including BitLocker recovery prompts and Windows Hello sign-in issues, see the related article: <a href=\"https:\/\/www.terabyteunlimited.com\/kb\/?p=7354\">Impacts of Changing UEFI Secure Boot Settings<\/a><\/p>\r\n<p>It is necessary to enter the BIOS\/UEFI firmware to make the required changes. The usual startup key is shown in the examples below, but it may vary for different models. For general BIOS\/UEFI access instructions, see: <a href=\"\u2022\thttps:\/\/www.terabyteunlimited.com\/kb\/?p=7347\">How to Access BIOS\/UEFI Settings to Configure Your System<\/a><\/p>\r\n<hr \/>\r\n<p><span style=\"color: #005858;\"><strong>ASUS Z890 Board<\/strong><\/span><\/p>\r\n<ol>\r\n\t<li>Enter the UEFI BIOS using <strong>DEL<\/strong> on startup.<\/li>\r\n\t<li>Select <strong>Advanced Mode<\/strong>.<\/li>\r\n\t<li>Select the <strong>Boot<\/strong> section.<\/li>\r\n\t<li>Locate the Secure Boot state. For example, it may show <strong>User<\/strong>.<\/li>\r\n\t<li>For the <strong>Secure Boot Mode<\/strong>, select <strong>Custom<\/strong> to enable the <strong>Key Management<\/strong> item and allow changes.<\/li>\r\n\t<li>Select <strong>Key Management<\/strong>.<\/li>\r\n\t<li>Select <strong>Clear Secure Boot Keys<\/strong> to clear the Secure Boot items and enable Setup Mode.<\/li>\r\n\t<li>Confirm you want to clear the keys.<\/li>\r\n\t<li>Select the <strong>Exit<\/strong> section.<\/li>\r\n\t<li>Select <strong>Save Changes &amp; Reset<\/strong> to restart the system.<\/li>\r\n\t<li>Confirm saving and restarting. The BIOS may indicate that no changes were made.<\/li>\r\n\t<li>After restart, the Secure Boot state should now be <strong>Setup<\/strong>.<\/li>\r\n<\/ol>\r\n<p><span style=\"color: #005858;\"><strong>MSI Z790 Board<\/strong><\/span><\/p>\r\n<ol>\r\n\t<li>Enter the UEFI BIOS using <strong>DEL<\/strong> on startup.<\/li>\r\n\t<li>Select <strong>Advanced Mode<\/strong>.<\/li>\r\n\t<li>Select <strong>Settings<\/strong>.<\/li>\r\n\t<li>Select <strong>Security<\/strong>.<\/li>\r\n\t<li>For <strong>Secure Boot Mode<\/strong>, select <strong>Custom<\/strong> to enable the <strong>Key Management<\/strong> item.<\/li>\r\n\t<li>Select <strong>Key Management<\/strong>.<\/li>\r\n\t<li>Disable <strong>Provision Factory Default keys<\/strong> if it is enabled.\r\n\r\n<ul>\r\n\t<li>If this option is not disabled, the BIOS may automatically reload the factory default keys on restart and the system will no longer be in Setup Mode.<\/li>\r\n<\/ul>\r\n<\/li>\r\n\t<li>Select <strong>Delete All Secure Boot variables<\/strong>.<\/li>\r\n\t<li>A confirmation message will be displayed:\r\n\r\n<ul>\r\n\t<li><em>Deleting all variables will reset the System to Setup Mode. Do you want to proceed?<\/em><\/li>\r\n<\/ul>\r\n<\/li>\r\n\t<li>Select <strong>Yes<\/strong> to proceed.<\/li>\r\n\t<li>You may be asked if you want to reset without saving:\r\n\r\n<ul>\r\n\t<li>Select <strong>Yes<\/strong> to restart the system immediately. Any other BIOS changes will not be saved.<\/li>\r\n\t<li>Select <strong>No<\/strong> if other changes need to be saved, such as disabling <strong>Secure Boot<\/strong> or disabling <strong>Provision Factory Default keys<\/strong>.<\/li>\r\n<\/ul>\r\n<\/li>\r\n\t<li>If you selected <strong>No<\/strong> in the previous step, exit the BIOS and save the changes.<\/li>\r\n\t<li>Upon restart, the system should be in Setup Mode.<\/li>\r\n<\/ol>\r\n<p><strong><span style=\"color: #005858;\">Lenovo IDEAPAD<\/span><\/strong><\/p>\r\n<ol>\r\n\t<li>Enter the UEFI BIOS using <strong>F2<\/strong> on startup.<\/li>\r\n\t<li>Select the <strong>Security<\/strong> section.<\/li>\r\n\t<li>Review the current Secure Boot status. For example:\r\n\r\n<ul>\r\n\t<li>Platform Mode = User Mode<\/li>\r\n\t<li>Secure Boot Mode = Standard.<\/li>\r\n<\/ul>\r\n<\/li>\r\n\t<li>Select <strong>Reset to Setup Mode<\/strong>.<\/li>\r\n\t<li>Confirm the Setup Mode reset.<\/li>\r\n\t<li>Select <strong>Save and Exit<\/strong> to apply the changes (<strong>F10<\/strong>).<\/li>\r\n<\/ol>\r\n<p><strong><span style=\"color: #005858;\">Dell Inspiron 15<\/span><\/strong><\/p>\r\n<ol>\r\n\t<li>Enter the UEFI BIOS using <strong>F2<\/strong> on startup.<\/li>\r\n\t<li>On left side, click <strong>Boot Configuration<\/strong>.<\/li>\r\n\t<li>Ensure <strong>Expert Key Management<\/strong> is enabled.<\/li>\r\n\t<li>Under <strong>Expert Key Management<\/strong>, select <strong>Delete All Keys<\/strong>.<\/li>\r\n\t<li>Select <strong>Exit<\/strong> to reboot.<\/li>\r\n\t<li>After restart, the system should be in Setup Mode.<\/li>\r\n<\/ol>\r\n<p>\u00a0\u00a0\u00a0\u00a0To enable Secure Boot again:<\/p>\r\n<ol>\r\n\t<li>Boot back into the BIOS.<\/li>\r\n\t<li>Select <strong>Boot Configuration<\/strong>.<\/li>\r\n\t<li>Select the option to use <strong>Deployed Mode<\/strong>.<\/li>\r\n\t<li>Exit and save changes to reboot.<\/li>\r\n<\/ol>\r\n<p><strong><span style=\"color: #005858;\">Surface 7<\/span><\/strong><\/p>\r\n<ol>\r\n\t<li>Enter the UEFI BIOS by doing the following:\r\n\r\n<ol type=\"a\">\r\n\t<li>Shut down the Surface completely.<\/li>\r\n\t<li>Press and hold the <strong>Volume Up<\/strong> button.<\/li>\r\n\t<li>While still holding <strong>Volume Up<\/strong>, press and release the <strong>Power<\/strong> button.<\/li>\r\n\t<li>Continue holding <strong>Volume Up<\/strong> until the UEFI screen appears.<\/li>\r\n<\/ol>\r\n<\/li>\r\n\t<li>On left side, select <strong>Security<\/strong>.<\/li>\r\n\t<li>Under <strong>Secure Boot Change Configuration<\/strong>, select <strong>None<\/strong> to place the system in Setup Mode.<\/li>\r\n\t<li>Exit and save changes to reboot.<\/li>\r\n\t<li>After restart, the system should be in Setup Mode.<\/li>\r\n<\/ol>\r\n<p><strong><span style=\"color: #005858;\">Intel Visual BIOS<\/span><\/strong><\/p>\r\n<ol>\r\n\t<li>Enter the UEFI BIOS using <strong>F2<\/strong> on startup.<\/li>\r\n\t<li>Select <strong> Advanced Setup<\/strong> at the top.<\/li>\r\n\t<li>Select <strong>Boot<\/strong> at the top.<\/li>\r\n\t<li>Select the <strong>Secure Boot<\/strong> tab.<\/li>\r\n\t<li>Check the box for <strong>Clear Secure Boot Data<\/strong>.<\/li>\r\n\t<li>Reboot the system. On reboot, the firmware will clear the Secure Boot data and enter Setup Mode.<\/li>\r\n<\/ol>\r\n<ul>\r\n\t<li><strong>Note:<\/strong> Should the Platform Key (PK) not be installed after installing or removing the TeraByte Secure Boot Certificate, there is an <strong>Install Intel Platform Key<\/strong> option on the same screen as step 5 that can be used to install it.<\/li>\r\n<\/ul>\r\n<hr \/>\r\n<p><strong>Summary<\/strong><\/p>\r\n<p>Entering Setup Mode typically involves one or more of the following actions:<\/p>\r\n<ul>\r\n\t<li>Switching Secure Boot to <strong>Custom Mode<\/strong>.<\/li>\r\n\t<li>Opening <strong>Key Management<\/strong>.<\/li>\r\n\t<li>Disabling automatic factory key provisioning, if present.<\/li>\r\n\t<li>Clearing or deleting Secure Boot keys or variables.<\/li>\r\n\t<li>Restarting the system.<\/li>\r\n<\/ul>\r\n<p>Once the system is in Setup Mode, Secure Boot databases can be modified as needed.<\/p>","protected":false},"excerpt":{"rendered":"<p>UEFI Secure Boot Setup Mode allows modification of authorized and blocked certificates or hashes in UEFI database variables without requiring signatures from Key Exchange Key (KEK) certificates, which are typically provided by vendors such as Microsoft. Setup Mode is required when installing, removing, or otherwise modifying Secure Boot certificates and variables. If a system does [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"lsvr_kba_cat":[1808],"lsvr_kba_tag":[],"class_list":["post-7336","lsvr_kba","type-lsvr_kba","status-publish","hentry","lsvr_kba_cat-hardware-or-bios"],"_links":{"self":[{"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/lsvr_kba\/7336","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/lsvr_kba"}],"about":[{"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/types\/lsvr_kba"}],"author":[{"embeddable":true,"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/comments?post=7336"}],"version-history":[{"count":5,"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/lsvr_kba\/7336\/revisions"}],"predecessor-version":[{"id":7357,"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/lsvr_kba\/7336\/revisions\/7357"}],"wp:attachment":[{"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/media?parent=7336"}],"wp:term":[{"taxonomy":"lsvr_kba_cat","embeddable":true,"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/lsvr_kba_cat?post=7336"},{"taxonomy":"lsvr_kba_tag","embeddable":true,"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/lsvr_kba_tag?post=7336"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}