My Windows 11 PC currently boots in UEFI mode, and both SSDs use GPT partitioning. However, Windows reports that Secure Boot is disabled even though the firmware settings appear to show it as enabled. When I change the firmware OS Type from "Other OS" to "UEFI Mode," save, and restart, I get a red warning screen and the computer will not boot until I switch the setting back. I need Secure Boot working for games that require it. The system has an ASUS PRIME A320M-K motherboard, although the firmware interface appears to be labeled Gigabyte. What should I check or change to resolve this?
3 Answers
Try setting the firmware to UEFI mode while leaving Secure Boot disabled first. If Windows starts normally that way, the bootloader or Secure Boot keys may need to be repaired or restored before Secure Boot can be enabled. Also verify that the firmware is actually using the correct motherboard configuration, since the ASUS board and Gigabyte firmware description don’t seem to match.
The GPT setup sounds correct: in Disk Management or DiskPart, the system disk should be GPT and the computer should be using the Windows Boot Manager entry. Since you already confirmed the disks show GPT, the more likely issue is the Secure Boot configuration or bootloader rather than the partition style.
A red Secure Boot warning can indicate that the installed bootloader or Secure Boot certificates aren’t being accepted by the firmware. Check the Secure Boot key-management options and look for an option such as restoring the factory or default keys. Windows should be booting through the standard UEFI Windows Boot Manager rather than a legacy drive entry.

I checked with DiskPart, and both drives have the GPT indicator. The problem only happens when I change the firmware OS Type setting.