I recently reinstalled Windows 11 after troubleshooting some problems. The installation works normally with TPM 2.0 enabled and Secure Boot disabled, but enabling Secure Boot causes the computer to return straight to the BIOS instead of loading Windows. Windows Boot Manager is already set as the first boot option, and manually selecting it from the boot menu only pauses briefly before returning to the menu. What should I check or change so Windows will boot with Secure Boot enabled?
3 Answers
If BitLocker or device encryption is enabled, turn it off or suspend it before changing Secure Boot settings. Boot into Windows with Secure Boot disabled, handle the encryption setting, restart, and then enable Secure Boot. Also check for a motherboard firmware update, since some systems need updated Secure Boot certificate databases.
Before converting partitions or changing firmware options, make sure your important files are backed up. If the disk is already GPT, confirm that legacy or compatibility support is disabled in the firmware, the system is booting in pure UEFI mode, and the default Secure Boot keys are installed. Then Windows Boot Manager should be the selected UEFI boot entry.
Check whether your Windows drive uses GPT or MBR. If Windows was installed in legacy mode, the drive may be MBR, which generally won’t boot with UEFI Secure Boot. In Disk Management, right-click the disk, open Properties, and check the Volumes tab for the partition style. If it’s MBR, back up your files first, then you can usually convert it with the mbr2gpt tool from an administrator Command Prompt. Afterward, make sure the firmware is set to UEFI mode and select Windows Boot Manager.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures