My motherboard originally didn't include a TPM 2.0 module, so I installed one separately. The system uses GPT-formatted drives and is configured for UEFI, but Windows 11 stops booting as soon as I enable Secure Boot or disable CSM, and the computer returns to the BIOS.
With CSM enabled, Windows only starts when video is set to UEFI, storage is set to Legacy, and PCI devices are set to Legacy. If storage is changed to UEFI, the system goes back to the BIOS. I'm using newer SSDs, and the graphics card may support UEFI. I've already tried changing several firmware settings and removing the motherboard battery, but I haven't reinstalled or updated the BIOS yet. What should I check, and is a clean reinstall the best way to get Secure Boot working?
1 Answer
The most reliable solution may be a clean Windows installation in a fully UEFI configuration. First back up everything from the system drive. Then create a bootable Windows installer with Microsoft’s official Media Creation Tool. Shut the PC down and disconnect any other drives, leaving only the target drive connected. In firmware settings, select UEFI-only mode, enable Secure Boot, and boot from the installer USB. During setup, delete the existing partitions on the target drive and install Windows to the resulting unallocated space. This will erase that drive, so make sure your backups are complete before proceeding.

Thanks, I’ll try that. I’m still hoping there might be a way to fix the current installation without reinstalling, but I’ll back everything up first.