Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

If VALORANT shows a Secure Boot, VAN9001, VAN9003, or similar Vanguard compliance error, check Windows before changing firmware settings. Press Win + R, enter msinfo32, and confirm BIOS Mode. If it already says UEFI, disable CSM or Legacy Boot in your UEFI settings and enable Secure Boot. If it says Legacy, convert the Windows system disk from MBR to GPT with Microsoft’s MBR2GPT.exe workflow before switching to UEFI.

Afterward, Windows should report BIOS Mode: UEFI and Secure Boot State: On. If Vanguard also reports a TPM problem, enable Intel PTT, AMD fTPM, or the equivalent firmware TPM and verify it in Windows.

What Secure Boot does for VALORANT

Secure Boot is a security feature enforced by your motherboard or laptop’s UEFI firmware—not a setting inside VALORANT. It checks that trusted, digitally signed boot software is allowed to load before Windows starts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Riot Vanguard uses pre-boot and kernel-level security checks to make it harder for malware or cheat components to compromise Windows before Vanguard starts. However, enabling Secure Boot alone may not resolve the problem if the PC still uses Legacy mode, the system disk is formatted as MBR, TPM 2.0 is disabled, or the firmware’s Secure Boot key database is incomplete. Riot explains Vanguard’s broader security requirements in its Vanguard security update.

#1 Best Overall
Sale
ASUS ROG G700 (2025) Gaming Desktop PC, Intel® Core™ Ultra 7 265F Processor, NVIDIA® GeForce RTX™ 5070, 1TB M.2 NVMe™ PCIe® 4 SSD, 16GB DDR5 RAM, Windows 11 Home, G700TF-DS774
  • Fearless ROG Design – The G700’s dual-glass chassis showcases iconic ROG design with the ROG Slash and Aura Sync RGB lighting. Its 58L capacity supports triple-slot GPUs.
  • Unstoppable Power – Equipped with the Intel Core Ultra 7 265F processor, NVIDIA GeForce RTX 5070 GPU, 16GB DDR5 RAM, and 1TB SSD PCIe 4.0 storage for seamless gaming and multitasking.
  • Optimized Thermals – Stay cool with a quad-fan system, while dust filters and efficient airflow ensure long-term reliability.
  • Advanced Connectivity – Game without lag with 2.5Gbps Ethernet, Wi-Fi 6, and versatile ports. Dolby Atmos audio and AI noise cancellation enhance sound and communication.
  • Ready for Upgrades – Designed with tool-less access, easily swap out components, ensuring future-proof performance for years to come.

Secure Boot is not necessarily required in exactly the same way for every VALORANT installation. Vanguard’s requirements can depend on Windows version, hardware, firmware state, and the specific error shown.

Before changing firmware settings

  • Back up important files.
  • If BitLocker is enabled, save the recovery key and be prepared to suspend protection before an MBR-to-GPT conversion.
  • Record the exact Vanguard error code.
  • Photograph or note your current firmware settings.
  • Check whether Windows already uses UEFI.

Check whether Secure Boot is actually disabled

Check UEFI mode and Secure Boot

  1. Press Win + R.
  2. Enter msinfo32 and press Enter.
  3. In System Summary, find BIOS Mode and Secure Boot State.
Windows result What it means Next step
UEFI and Off Windows is already using the correct firmware mode. Enable Secure Boot, usually after disabling CSM or Legacy Boot.
Legacy Windows is booting through legacy BIOS compatibility, usually from an MBR disk. Back up and validate the disk with MBR2GPT.exe before changing to UEFI.
UEFI and On Secure Boot is already active in Windows. Investigate TPM, Vanguard services, firmware, Windows, or the exact error instead of repeatedly toggling Secure Boot.

Microsoft documents msinfo32 as a way to inspect UEFI and Secure Boot status. See Microsoft’s guide to Windows 11 and Secure Boot.

Check TPM 2.0

  1. Press Win + R.
  2. Enter tpm.msc.
  3. Confirm that the TPM is ready for use and that its specification version is 2.0.

You can also open Windows Security → Device security → Security processor details. Microsoft’s TPM 2.0 guide lists these checks and the relevant firmware options.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Enter your UEFI or BIOS settings

From Windows 11, open Settings → System → Recovery. Beside Advanced startup, select Restart now, then choose Troubleshoot → Advanced options → UEFI Firmware Settings → Restart.

Alternatively, restart the computer and repeatedly press the manufacturer’s firmware key. Common keys include F2, Delete, F10, F12, and Esc, but the correct key depends on the manufacturer and model. Microsoft documents both approaches in its firmware and Secure Boot instructions.

Rank #2
CyberPowerPC Gaming PC, AMD Ryzen 5 5500, Radeon RX 6500 XT 4GB
  • System: AMD Ryzen 5 5500 3.6GHz 6 Cores | AMD B550 Chipset | 8GB DDR4 | 500GB PCIe 4.0 NVMe SSD | Windows 11 Home
  • Graphics: AMD Radeon RX 6500 XT 4GB Graphics | 1x HDMI | 1x DisplayPort
  • Connectivity: 4 x USB-A 3.2 | 4 x USB-A 2.0 | 1 x LAN | WiFi 5 | Bluetooth 5.0 | 7.1 Channel Audio
  • Tempered Side Case Panel | Custom RGB Lighting | Keyboard and Mouse
  • 1 Year Parts & Labor Warranty, Free Lifetime Tech Support

Enable Secure Boot when Windows already uses UEFI

Menu names vary between ASUS, MSI, Gigabyte, ASRock, Dell, HP, Lenovo, Acer, and other systems. Look for equivalent settings rather than an identical menu path.

  1. Open the Boot, Security, or Authentication section.
  2. Disable CSM, Legacy Support, or Legacy Boot.
  3. If available, set boot mode to UEFI Only.
  4. Set OS Type to Windows UEFI Mode or the equivalent Windows option.
  5. Set Secure Boot to Enabled.
  6. If prompted, choose Install Default Secure Boot Keys, Restore Factory Keys, or Load Default Keys.
  7. Save changes and restart Windows.
  8. Run msinfo32 again and confirm BIOS Mode: UEFI and Secure Boot State: On.

Do not casually choose Clear Secure Boot Keys. Clearing the keys is not the normal first-line fix and can create additional boot-policy problems.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Common firmware labels

Purpose Possible labels
Switch from Legacy mode Boot Mode, UEFI/Legacy Boot, CSM, Legacy Support
Enable Secure Boot Secure Boot, OS Type, Windows UEFI Mode
Restore keys Install Default Secure Boot Keys, Restore Factory Keys, Load Default Keys
Intel TPM Intel PTT, Platform Trust Technology
AMD TPM AMD fTPM, Firmware TPM, fTPM Switch
Generic TPM TPM Device, Security Device Support, Trusted Computing

If BIOS Mode says Legacy

Do not simply switch a Legacy/MBR Windows installation to UEFI. The usual order is:

Legacy BIOS + MBR → validate MBR2GPT → convert to GPT → UEFI mode → disable CSM → enable Secure Boot

Microsoft’s MBR2GPT.exe is designed to convert a Windows system disk from MBR to GPT without deleting the data, but it has disk-layout requirements and boot conversion can still fail. Back up first.

Check the disk’s partition style

Open PowerShell as administrator and run:

Get-Disk | Format-Table Number, FriendlyName, PartitionStyle

Identify the disk containing Windows. If it reports GPT, MBR2GPT is not needed. If it reports MBR, continue only after backing up and confirming that the disk is eligible.

Rank #3
Sale
WIWB Gaming PC Desktop Computer, GeForce RTX 3050 8GB GDDR6, Ryzen 7 4700LE
  • 8-Core 16-Thread Processing Power – Powered by the Ryzen 7 4700LE processor with Zen 2 architecture, delivering 8 cores and 16 threads with a boost clock up to 4.2GHz. Effortlessly handle multitasking, streaming, content creation, and demanding applications simultaneously without slowdowns.
  • GeForce RTX 3050 8GB Graphics – Equipped with 8GB GDDR6 dedicated VRAM and real-time ray tracing support. Experience smooth 1080p gaming at 55-60 FPS in AAA titles like Cyberpunk 2077, 70+ FPS in Fortnite, and 90-100 FPS in Apex Legends with DLSS enabled. The 8GB buffer handles modern game textures comfortably – a step above 6GB variants
  • High-Speed Memory & Storage – Paired with 16GB of DDR4 3200MHz dual-channel RAM (16GB), the PC ensures responsive multitasking—whether streaming while gaming or editing videos. It also includes a 512 GB NVMe M.2 SSD for lightning-fast boot times, quick game loads, and ample storage for your game library, creative projects, and files.
  • Next-Gen WiFi 6 Connectivity – Stay connected with the latest WiFi 6 technology for faster speeds, lower latency, and improved network efficiency. Whether you're gaming online, streaming 4K content, or joining video conferences, enjoy stable, high-speed wireless connectivity.
  • Ready-to-Use Value Desktop – Pre-built and ready to go right out of the box. Perfect for gamers, students, content creators, and home office users seeking reliable performance without the hassle of building a PC themselves. The mature AM4 platform with DDR4 memory offers excellent value and proven stability.

Validate before converting

Open Command Prompt as administrator:

mbr2gpt /validate /allowFullOS

For a particular disk, use its actual number:

mbr2gpt /validate /disk:0 /allowFullOS

Do not run conversion unless validation succeeds. Microsoft lists requirements including a supported Windows installation, a compatible system disk, no more than three primary MBR partitions, and sufficient space for an EFI System Partition. See the official MBR2GPT documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Convert the disk

After successful validation, run:

mbr2gpt /convert /allowFullOS

Or specify the disk:

mbr2gpt /convert /disk:0 /allowFullOS

After conversion:

  1. Restart into UEFI firmware settings.
  2. Set boot mode to UEFI Only.
  3. Disable CSM or Legacy Boot.
  4. Choose Windows Boot Manager as the first boot device.
  5. Enable Secure Boot and install default keys if required.
  6. Save and restart.
  7. Verify the result in msinfo32.

If BitLocker is active, suspend protection before conversion and keep the recovery key available. Follow Microsoft’s BitLocker-specific guidance in the MBR2GPT documentation. Never use diskpart clean on the Windows disk for this procedure; it is destructive.

Enable TPM 2.0 if Vanguard requests it

If the Vanguard message specifically mentions TPM 2.0, return to UEFI settings and look for:

  • Intel systems: Intel PTT or Platform Trust Technology.
  • AMD systems: AMD fTPM or Firmware TPM.
  • Other systems: TPM Device, Security Device Support, Trusted Computing, or a similar option.

Most relatively modern Intel and AMD platforms provide firmware TPM support. Do not buy a discrete TPM module unless the motherboard documentation specifically requires one and confirms compatibility.

Save the setting, boot into Windows, and confirm in tpm.msc that the TPM is ready and reports specification version 2.0.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
msi Codex Z2 Gaming Desktop, AMD R7-8700F, RTX 5070, 32GB DDR5, 2TB SSD
  • POWERHOUSE 8-CORE GAMING PERFORMANCE — Driven by the AMD Ryzen 7 8700F with 8 cores and 16 threads, boosting up to 5.0 GHz for smooth, responsive gameplay and the ability to handle AAA titles, streaming, and background tasks all at once
  • NEXT-GEN BLACKWELL ARCHITECTURE — The NVIDIA GeForce RTX 5070 is powered by NVIDIA's cutting-edge Blackwell GPU architecture, delivering a massive generational leap in rasterization and ray tracing performance so you can experience your games the way they were meant to be played.
  • Simplistic Design: Enjoy the latest generation of Windows 11 Home for your everyday needs. *MSI recommends Windows 11 Pro for business use.
  • Cool While Gaming: In conjunction with an ARGB fan Air Cooler, the Codex R2 features four system cooling fans; three in the front and one in the rear to pull in cool air and push heat out of the PC.
  • Turn on the Bright Lights: With the built-in RGB lighting, take your gaming experience to the next level by pressing the MSI LED button to cycle through lighting options. Customize lighting even further with MSI Center software.

Verify the final configuration and launch VALORANT

Your Windows checks should show:

BIOS Mode: UEFI
Secure Boot State: On
TPM: Ready for use
TPM Specification Version: 2.0

Restart Windows completely, then launch VALORANT. If Vanguard still displays the same message, restart once more before reinstalling anything. Record the exact error code and follow Riot’s current instructions, including its Vanguard on-demand security guidance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting

Secure Boot is greyed out

  1. Confirm BIOS Mode: UEFI in msinfo32.
  2. Disable CSM or Legacy Support.
  3. Set the operating-system type to the Windows/UEFI option.
  4. Restore default Secure Boot keys if the firmware offers that option.
  5. Save, reboot into firmware, and try again.

A firmware administrator or supervisor password may also be required. If Windows is installed in Legacy/MBR mode, use the MBR2GPT workflow instead of forcing the setting.

Windows will not boot after changing to UEFI

Return to firmware and temporarily restore the previous boot mode. Check whether the system disk is MBR, whether the correct disk was converted, and whether Windows Boot Manager is first in the UEFI boot order. Do not repeatedly change unrelated firmware settings. If the machine contains important data, contact the manufacturer or a qualified technician.

BIOS says Secure Boot is on, but Windows says it is off

Treat msinfo32 as the operational check. The change may not have been saved, the PC may still be booting through CSM, the wrong firmware profile may have been changed, or the firmware may have a compatibility problem. Confirm both BIOS Mode: UEFI and Secure Boot State: On.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Secure Boot and TPM are already enabled

Check the exact Vanguard error rather than toggling settings repeatedly. Possible causes include an unrecognized TPM, outdated BIOS or chipset firmware, pending Windows updates, a Vanguard service problem, a recent hardware change, or another attestation requirement involving virtualization, VBS, IOMMU, or pre-boot DMA protection.

Best Value
KOTIN Prebuilt Gaming PC RTX 5070 12GB, Ryzen 7 9700X, 32GB DDR5, 1TB SSD
  • POWERED BY RTX 5070 12GB + RYZEN 7 9700X - The GeForce RTX 5070 12GB GDDR7 graphics card pairs with an 8-core AMD Ryzen 7 9700X processor to drive smooth 1440p and 4K gameplay, giving this gaming PC the headroom for modern titles, streaming, and creative work.
  • 32GB DDR5 6000MHz MEMORY & 1TB NVMe SSD - 32GB of high-speed DDR5 memory and a 1TB PCIe 4.0 NVMe solid state drive deliver quick load times, smooth multitasking, and generous storage, keeping this prebuilt gaming desktop responsive under heavy workloads.
  • BUILT-IN 11.3-INCH Smart DISPLAY - An integrated smart screen shows real-time CPU and GPU temperatures, usage, and weather while you play, adding a distinctive and functional touch to your battlestation.
  • 850W 80+ GOLD POWER SUPPLY, 360MM LIQUID COOLING & WiFi 7 - An 850W 80 Plus Gold certified power supply provides stable, efficient power with headroom for future upgrades, while a 360mm AIO liquid cooler, WiFi 7, and an ARGB mid-tower case keep the Ryzen 7 CPU cool and connected in a clean build.
  • READY TO PLAY OUT OF THE BOX - Arrives fully assembled and tested with Windows 11 Home pre-installed, so your prebuilt gaming computer is ready to set up in minutes. Assembled in the USA, and backed by a one-year limited warranty and lifetime free technical support.

Update firmware only when the computer or motherboard manufacturer’s instructions make it relevant. Use the exact model’s official support page, stable power, and save BitLocker recovery information first. Microsoft’s guidance also notes that Secure Boot certificate and key policies are being updated beginning in 2026; unusual key-database errors should be checked against current Microsoft and manufacturer guidance rather than treated as a simple toggle issue.

The PC has no Secure Boot or TPM 2.0 option

Check for a model-specific BIOS/UEFI update and confirm whether the processor and motherboard support firmware TPM. Do not assume an update will add these capabilities. If the platform genuinely lacks the required features, the practical options are manufacturer support, supported hardware replacement, or using a system that meets the current Windows and Vanguard requirements.

Linux dual-boot or unsigned bootloaders

Secure Boot can prevent unsigned bootloaders, drivers, utilities, or older operating systems from starting. Verify that your Linux bootloader and other operating systems support Secure Boot before enabling it. Microsoft describes these compatibility limitations in its Device Security guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When to get help

Use the computer or motherboard manufacturer’s official support channel if MBR2GPT validation fails, BitLocker recovery information is unavailable, the firmware has no clear recovery path, the PC will not boot after conversion, or the device is managed by an employer or school. Official support is preferable to generic BIOS-repair utilities because firmware menus and recovery procedures are model-specific.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.