Why Are Secure Boot and CSM Grayed Out in My ASUS BIOS?

0
0
Asked By MellowOrbit42 On

I have an ASUS ROG GL553VD and both Secure Boot and CSM are grayed out in the BIOS. CSM is disabled and I cannot enable it. I'm trying to install Windows 11, but the installation is blocked by the Secure Boot and TPM requirements. I've already tried setting an administrator password, restoring the default Secure Boot keys, resetting BIOS settings, and updating the firmware, but the options remain unavailable. I can enter the BIOS through UEFI firmware settings or by pressing Delete during startup.

3 Answers

Answered By PixelHarbor31 On

If the goal is only to install Windows 11, the installer can sometimes be configured to skip the Secure Boot and TPM checks. From the Windows setup screen, Shift+F10 should open Command Prompt, where you can launch Registry Editor and create a LabConfig key under HKEY_LOCAL_MACHINESYSTEMSetup. Add DWORD values named BypassSecureBootCheck and BypassTPMCheck, setting each to 1. If Shift+F10 sends you back to the boot-device screen, the installation media or firmware may not be starting in the expected UEFI setup mode, so recreate the USB installer and boot it explicitly as a UEFI device. Keep a backup first, since changing firmware or reinstalling Windows can cause data loss.

Answered By NorthVale19 On

Try entering the BIOS from a completely powered-off state rather than after a failed boot. Shut the laptop down fully, power it on, and immediately press Delete repeatedly. Some systems restrict firmware changes when they have dropped into the BIOS after failing to find a boot device. If the settings are still gray when entering normally, the firmware or hardware configuration is likely enforcing them rather than the way you entered the BIOS.

MellowOrbit42 -

I’ve tried both entering through the UEFI firmware settings and repeatedly pressing Delete during startup, but Secure Boot and CSM are still unavailable.

Answered By CedarFox7 On

Some security or virtualization settings can lock these options. Check the BIOS Security and Advanced menus for Device Guard, Kernel DMA Protection, or similar protections and disable them if they are available. On some ASUS firmware versions those settings simply aren’t exposed, so the options may remain unavailable. Also make sure the firmware is set to Windows UEFI mode and that the default Secure Boot keys have been restored.

MellowOrbit42 -

I checked the Security menu, but it only shows administrator and user passwords, I/O interface security, and Secure Boot. I couldn’t find Device Guard or Kernel DMA Protection.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.