I'm trying to play Call of Duty on a Windows 11 PC, but its anti-cheat requires Secure Boot. My system runs normally with Secure Boot disabled, but enabling it in the BIOS causes a red "Secure Boot Violation. Invalid signature detected. Check secure boot policy in setup" message and sends me back to the BIOS. The PC has a Ryzen 5 5600G, RTX 3060 12GB, 16GB of RAM, a 1TB SSD, and a BIOSTAR A520MH 3.0 motherboard. What should I check or change so Secure Boot works without reinstalling Windows?
4 Answers
If the firmware settings are correct but Windows still will not start, try booting from Windows installation or recovery media with Secure Boot enabled and run Startup Repair. Repairing the boot configuration may be necessary if the EFI or BCD entries were created under an older configuration.
Updating the motherboard BIOS would be a good next step. Firmware updates sometimes include Secure Boot or key-database fixes, and newer game anti-cheat checks can expose problems that were not apparent before. Check the BIOSTAR support page for the exact A520MH 3.0 revision and follow its update instructions carefully.
If the current installation uses Legacy mode or an MBR system disk, convert it to UEFI/GPT before enabling Secure Boot. A clean Windows installation with UEFI and Secure Boot enabled from the beginning is the fallback option, but back up important files first because reinstalling can erase the existing system drive.
First boot into Windows with Secure Boot disabled and verify that msinfo32 reports BIOS Mode as UEFI. Also check that the Windows drive uses GPT rather than MBR. In the BIOS, disable CSM or Legacy Boot, install the factory Secure Boot keys, enable Secure Boot, and set Windows Boot Manager as the first boot option. Save the changes and restart.

I tried those steps. Windows starts with the keys cleared, but it still reports Secure Boot as disabled. When I install the keys and enable Secure Boot, the system fails to boot. Clearing the keys or disabling Secure Boot lets Windows start normally.