What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
For most VALORANT Vanguard TPM 2.0 or Secure Boot errors, the fix is to enable the missing security feature in UEFI/BIOS and then confirm Windows detects it. First check tpm.msc and msinfo32 to find out what is actually off. If Windows reports BIOS Mode: Legacy, do not simply switch to UEFI: check whether the Windows system disk is MBR or GPT first, or the PC may stop booting.
Identify the Vanguard error
These messages can point to different problems. Use the code or the specific requirement named in the prompt to guide your checks; TPM 2.0 and Secure Boot are separate settings.
| Message | What to check |
|---|---|
VAN9001 |
TPM 2.0 may be disabled, unavailable, or not detected. Check it in tpm.msc. |
VAN9003 |
Secure Boot may be off, or Windows may be booting in a configuration Vanguard does not accept. Check BIOS Mode and Secure Boot State in msinfo32. |
| “This build/version of Vanguard requires TPM 2.0 and Secure Boot…” | Check both settings; one or both may not be accepted by Windows. |
VAN:Restriction |
Follow the controls named in the prompt. Some restrictions involve motherboard firmware or additional pre-boot protections, not just TPM or Secure Boot. Riot says a restriction does not necessarily mean cheating; a security configuration or firmware issue may be involved. See Riot’s Vanguard security update. |
If Secure Boot appears enabled in firmware but Windows reports it as Off, verify the boot mode, boot entry and key configuration rather than relying on the BIOS screen alone.
Check whether TPM 2.0 is enabled
Use TPM Management
- Press Windows key + R.
- Enter
tpm.mscand press Enter. - Check that the status says The TPM is ready for use and that Specification Version is
2.0.
- If both values are present, TPM is probably not the setting causing the error.
- If Windows says a compatible TPM cannot be found, it may be disabled in firmware, unsupported, or affected by a firmware issue.
- If the version is 1.2, it does not meet a TPM 2.0 requirement.
- If the console will not open or you need another view, open Windows Security > Device security > Security processor details and check the specification version. If the Security processor section is missing, consult the PC or motherboard maker’s support information.
Microsoft documents this check and common firmware setting names in its TPM 2.0 guide; the alternate Windows Security path is described in Windows Security device security.
#1 Best Overall
- Fearless ROG Design – The G700’s dual-glass chassis showcases iconic ROG design with the ROG Slash and Aura Sync RGB lighting. Its 58L capacity supports triple-slot GPUs.
- Unstoppable Power – Equipped with the Intel Core Ultra 7 265F processor, NVIDIA GeForce RTX 5070 GPU, 16GB DDR5 RAM, and 1TB SSD PCIe 4.0 storage for seamless gaming and multitasking.
- Optimized Thermals – Stay cool with a quad-fan system, while dust filters and efficient airflow ensure long-term reliability.
- Advanced Connectivity – Game without lag with 2.5Gbps Ethernet, Wi-Fi 6, and versatile ports. Dolby Atmos audio and AI noise cancellation enhance sound and communication.
- Ready for Upgrades – Designed with tool-less access, easily swap out components, ensuring future-proof performance for years to come.
Check Secure Boot and Windows boot mode
- Press Windows key + R.
- Enter
msinfo32and press Enter. - In System Information, locate BIOS Mode and Secure Boot State.
The expected Windows-reported result is:
BIOS Mode: UEFI
Secure Boot State: On
- UEFI / On: Windows reports the expected Secure Boot state.
- UEFI / Off: Secure Boot may still need enabling or correct configuration in firmware.
- Legacy: Check the system disk’s partition style before changing firmware to UEFI.
- Unsupported: The PC may be in Legacy/CSM mode, firmware may lack Secure Boot support, or a firmware update may be needed.
Microsoft explains that Secure Boot is a UEFI feature and that switching from Legacy/CSM to UEFI is normally required for it to work: Secure Boot and Windows.
Enter UEFI/BIOS from Windows
On Windows 11, use the recovery menu rather than guessing which startup key applies to your PC:
- Open Settings > System > Recovery.
- Beside Advanced startup, select Restart now.
- Choose Troubleshoot > Advanced options > UEFI Firmware Settings > Restart.
If that option is absent, use the startup key documented for your exact PC or motherboard. Keys vary; Delete, F2 and F10 are examples, not universal choices. Microsoft’s Secure Boot instructions also describe the Windows recovery route.
Rank #2
- System: AMD Ryzen 5 5500 3.6GHz 6 Cores | AMD B550 Chipset | 8GB DDR4 | 500GB PCIe 4.0 NVMe SSD | Windows 11 Home
- Graphics: AMD Radeon RX 6500 XT 4GB Graphics | 1x HDMI | 1x DisplayPort
- Connectivity: 4 x USB-A 3.2 | 4 x USB-A 2.0 | 1 x LAN | WiFi 5 | Bluetooth 5.0 | 7.1 Channel Audio
- Tempered Side Case Panel | Custom RGB Lighting | Keyboard and Mouse
- 1 Year Parts & Labor Warranty, Free Lifetime Tech Support
Enable TPM 2.0 in firmware
Firmware labels and menu locations differ by manufacturer, model and firmware version. Look in sections such as Advanced, Security or Trusted Computing for a platform TPM option.
Free tools Windows power users keep installed
One-click scans. No signup required.
- AMD: Look for
AMD fTPM,AMD PSP fTPMorFirmware TPM. - Intel: Look for
Intel PTTorIntel Platform Trust Technology. - Either platform: Settings may also be called
TPM Device,TPM StateorSecurity Device Support.
Set the relevant option to Enabled, save changes and restart. Then check tpm.msc again. Microsoft lists common AMD and Intel names in its TPM 2.0 instructions. If you cannot find the setting, check the manual and official support page for the exact computer or motherboard model. Do not buy an add-on TPM before checking: firmware TPM is often available, and physical modules are not interchangeable across motherboard headers.
Enable Secure Boot without risking a boot failure
Proceed only after confirming Windows is configured to boot through UEFI. If System Information says Legacy, first follow the MBR/GPT check below. For a UEFI installation, the usual firmware sequence is:
Rank #3
- 8-Core 16-Thread Processing Power – Powered by the Ryzen 7 4700LE processor with Zen 2 architecture, delivering 8 cores and 16 threads with a boost clock up to 4.2GHz. Effortlessly handle multitasking, streaming, content creation, and demanding applications simultaneously without slowdowns.
- GeForce RTX 3050 8GB Graphics – Equipped with 8GB GDDR6 dedicated VRAM and real-time ray tracing support. Experience smooth 1080p gaming at 55-60 FPS in AAA titles like Cyberpunk 2077, 70+ FPS in Fortnite, and 90-100 FPS in Apex Legends with DLSS enabled. The 8GB buffer handles modern game textures comfortably – a step above 6GB variants
- High-Speed Memory & Storage – Paired with 16GB of DDR4 3200MHz dual-channel RAM (16GB), the PC ensures responsive multitasking—whether streaming while gaming or editing videos. It also includes a 512 GB NVMe M.2 SSD for lightning-fast boot times, quick game loads, and ample storage for your game library, creative projects, and files.
- Next-Gen WiFi 6 Connectivity – Stay connected with the latest WiFi 6 technology for faster speeds, lower latency, and improved network efficiency. Whether you're gaming online, streaming 4K content, or joining video conferences, enjoy stable, high-speed wireless connectivity.
- Ready-to-Use Value Desktop – Pre-built and ready to go right out of the box. Perfect for gamers, students, content creators, and home office users seeking reliable performance without the hassle of building a PC themselves. The mature AM4 platform with DDR4 memory offers excellent value and proven stability.
- Enter UEFI/BIOS and locate boot settings.
- Disable CSM, Legacy Boot or similarly named compatibility mode, if enabled, and select UEFI boot mode.
- If offered, choose a Windows or UEFI operating-system type.
- In the Secure Boot menu, set Secure Boot to Enabled.
- If the firmware indicates Secure Boot keys are missing or misconfigured, use its Install default keys or Restore factory keys option. Do not change key databases without a reason.
- Make Windows Boot Manager the first boot option, if shown.
- Save changes and restart. Confirm the result in
msinfo32.
Menu names such as Launch CSM, Legacy Support, OS Type and Secure Boot Control vary. Use the manual for your exact system; Microsoft’s Secure Boot guide explains the UEFI requirement.
If BIOS Mode is Legacy, check MBR or GPT first
Changing a Legacy installation to UEFI without preparing the system disk can leave Windows unable to boot. GPT is the normal partition style for UEFI boot; an MBR Windows system disk usually needs conversion first.
Check the system disk’s partition style in Windows Disk Management before changing firmware mode. If it is MBR, Microsoft’s MBR2GPT.exe can convert a qualifying system disk, but it has prerequisites and conversion is not risk-free. Back up important files and follow Microsoft’s complete MBR2GPT documentation. For an advanced user following that procedure, validation in a full Windows session uses:
Rank #4
- POWERHOUSE 8-CORE GAMING PERFORMANCE — Driven by the AMD Ryzen 7 8700F with 8 cores and 16 threads, boosting up to 5.0 GHz for smooth, responsive gameplay and the ability to handle AAA titles, streaming, and background tasks all at once
- NEXT-GEN BLACKWELL ARCHITECTURE — The NVIDIA GeForce RTX 5070 is powered by NVIDIA's cutting-edge Blackwell GPU architecture, delivering a massive generational leap in rasterization and ray tracing performance so you can experience your games the way they were meant to be played.
- Simplistic Design: Enjoy the latest generation of Windows 11 Home for your everyday needs. *MSI recommends Windows 11 Pro for business use.
- Cool While Gaming: In conjunction with an ARGB fan Air Cooler, the Codex R2 features four system cooling fans; three in the front and one in the rear to pull in cool air and push heat out of the PC.
- Turn on the Bright Lights: With the built-in RGB lighting, take your gaming experience to the next level by pressing the MSI LED button to cycle through lighting options. Customize lighting even further with MSI Center software.
mbr2gpt /validate /allowFullOS
Only if validation succeeds and the documented requirements are met, conversion uses:
mbr2gpt /convert /allowFullOS
After conversion, restart into firmware and change the boot mode to UEFI. If BitLocker is enabled, save the recovery key and suspend protection before changing partitions, boot mode or firmware settings. Keep the recovery key available in case Windows requests it.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Verify the settings, then test VALORANT
After the firmware changes and a Windows restart, confirm both requirements from Windows:
Best Value
- POWERED BY RTX 5070 12GB + RYZEN 7 9700X - The GeForce RTX 5070 12GB GDDR7 graphics card pairs with an 8-core AMD Ryzen 7 9700X processor to drive smooth 1440p and 4K gameplay, giving this gaming PC the headroom for modern titles, streaming, and creative work.
- 32GB DDR5 6000MHz MEMORY & 1TB NVMe SSD - 32GB of high-speed DDR5 memory and a 1TB PCIe 4.0 NVMe solid state drive deliver quick load times, smooth multitasking, and generous storage, keeping this prebuilt gaming desktop responsive under heavy workloads.
- BUILT-IN 11.3-INCH Smart DISPLAY - An integrated smart screen shows real-time CPU and GPU temperatures, usage, and weather while you play, adding a distinctive and functional touch to your battlestation.
- 850W 80+ GOLD POWER SUPPLY, 360MM LIQUID COOLING & WiFi 7 - An 850W 80 Plus Gold certified power supply provides stable, efficient power with headroom for future upgrades, while a 360mm AIO liquid cooler, WiFi 7, and an ARGB mid-tower case keep the Ryzen 7 CPU cool and connected in a clean build.
- READY TO PLAY OUT OF THE BOX - Arrives fully assembled and tested with Windows 11 Home pre-installed, so your prebuilt gaming computer is ready to set up in minutes. Assembled in the USA, and backed by a one-year limited warranty and lifetime free technical support.
tpm.msc: TPM is ready for use; Specification Version is2.0.msinfo32: BIOS Mode is UEFI; Secure Boot State is On.
Then launch VALORANT. If Vanguard still blocks it, fully shut down and restart the PC before trying repair steps; a game-only restart may not reload firmware security state.
If both checks pass but Vanguard still blocks VALORANT
Use this escalation order so a reinstall does not distract from a firmware requirement:
- Recheck the exact Vanguard code and any specific controls named in the prompt. Riot’s December 18, 2025 security update describes newer restrictions that may require motherboard firmware updates or other pre-boot protections, including IOMMU-related controls.
- Install available Windows updates and chipset drivers from the PC or motherboard manufacturer.
- Check the official support page for the exact computer or motherboard model and revision for a BIOS/UEFI update. A firmware update may address compatibility or a pre-boot security issue, but it is not guaranteed to resolve every error. Record current settings first; firmware updates can reset boot order, TPM, Secure Boot and other options. Never install firmware for a similar-looking model.
- If the firmware state is correct and the prompt persists, reinstall Riot Vanguard, then restart and test again. Reinstall VALORANT only if the Vanguard and firmware checks do not resolve the issue.
- If blocked, contact Riot Support with the exact error, a screenshot, PC or motherboard and CPU models, Windows version/build, BIOS version, and the results shown by
tpm.mscandmsinfo32. Riot’s restriction information is at Vanguard Restrictions.
What to avoid
- Do not switch Legacy to UEFI until you have checked whether the system disk is MBR or GPT.
- Do not clear the TPM as a routine detection fix. Clearing it can affect BitLocker, Windows Hello and other stored security credentials; it is not the same as enabling TPM.
- Do not flash firmware from a different motherboard model or hardware revision.
- Do not rely on compatibility mode, registry hacks, administrator mode or disabling Vanguard to bypass a firmware enforcement error.
- Do not expect reinstalling VALORANT to change TPM or Secure Boot settings.
When the PC cannot meet the requirement
If the exact PC platform does not support TPM 2.0 or Secure Boot, there is no responsible software bypass for a Vanguard firmware requirement. The practical option is a supported PC or platform upgrade. Windows 10 support ended on October 14, 2025, according to Microsoft; that lifecycle date is separate from the cause of an individual Vanguard error, but users should consider a supported operating system. See Microsoft’s TPM and Windows security guidance.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




