Skip to content

Enable TPM 2.0 & Secure Boot on ASRock

This guide walks you through ASRock Phantom Gaming, Steel Legend, and Taichi boards at a calm pace. You will turn on two security settings that Windows and many games look for. TPM options and Secure Boot sit on different tabs—follow each step once, and nothing is final until you save.

Quick Reference

Last verified · 10 Sept 2026

Difficulty & Time

Easy~3 min

BIOS Vendor

AMI Aptio V (ASRock UEFI)

CPU Support

Intel 300 Series, Intel 400 Series, etc.

TPM Terminology

Intel Platform Trust TechnologyAMD fTPM switchAMD CPU fTPMSecurity Device Support

Secure Boot Location

Security → Secure Boot

Supported Chipsets

Intel 300/400/500 Series
Z390B360H370Z490B460Z590B560

On older Intel boards, Intel PTT is under Security → Intel Platform Trust Technology, or sometimes Advanced → Chipset Configuration.

Intel 600/700/800 Series
Z690B660Z790B760Z890B860

On 600-series and newer boards, Intel PTT is usually already enabled under Security.

AMD AM4
B450X470A320B550X570A520

On AM4 boards, use Advanced → CPU Configuration → AMD fTPM switch (AMD CPU fTPM or Disabled).

AMD AM5
B650X670X670EB650EX870X870EB850

On AM5 boards, TPM is under Security → Security Device Support.

Before you begin

Don't worry if your BIOS looks slightly different. Manufacturers often update colours and layouts, but the menu names are usually the same.

1

Enter BIOS

Turn the PC on and tap F2 or Del until you enter BIOS (your motherboard's settings menu). If Windows starts instead, restart and try again a little sooner.

Power On → F2 or Del
2

Switch to Advanced Mode

If you land in EZ Mode, press F6 once to open Advanced Mode. You need the full menu for the steps below.

EZ Mode → F6 → Advanced Mode

Intel steps (Intel PTT)

3

Enable Intel PTT (TPM 2.0)

Open the Security tab. TPM 2.0 is a small security feature Windows checks for; on Intel ASRock boards it is labeled Intel Platform Trust Technology. Set it to Enabled.

Security → Intel Platform Trust Technology → Enabled
4

Disable CSM

Open Boot → CSM (Compatibility Support Module). CSM is an older compatibility layer; Secure Boot needs it turned off. Set CSM to Disabled.

Boot → CSM → Disabled

Important: on some ASRock boards, after you disable CSM you must press F10, reboot, and re-enter BIOS before Secure Boot can be changed from Disabled to Enabled.

5

Enable Secure Boot

Open the Security tab and select Secure Boot. Secure Boot is a check that only trusted software is allowed to start Windows.

Security → Secure Boot → Enabled
  • Set Secure Boot to Enabled.
  • Set Secure Boot Mode to Standard.
  • If you see a User Mode prompt, select Install default Secure Boot keys.
6

Save & Exit

Press F10 and select Yes to save and reboot into Windows.

F10 → Yes

AMD steps (AMD fTPM)

3

Enable AMD fTPM

TPM 2.0 is a small security feature Windows checks for; on AMD ASRock boards it is labeled AMD fTPM.

Advanced → CPU Configuration → AMD fTPM switch → AMD CPU fTPM
  • On AM4, open Advanced → CPU Configuration, then set AMD fTPM switch to AMD CPU fTPM.
  • On AM5, open Security → Security Device Support instead and enable it.
4

Disable CSM

Open Boot → CSM (Compatibility Support Module). CSM is an older compatibility layer; Secure Boot needs it turned off. Set CSM to Disabled.

Boot → CSM → Disabled

Important: on some ASRock boards, after you disable CSM you must press F10, reboot, and re-enter BIOS before Secure Boot can be changed from Disabled to Enabled.

5

Enable Secure Boot

Open the Security tab and select Secure Boot. Secure Boot is a check that only trusted software is allowed to start Windows.

Security → Secure Boot → Enabled
  • Set Secure Boot to Enabled.
  • Set Secure Boot Mode to Standard.
  • If you see a User Mode prompt, select Install default Secure Boot keys.
6

Save & Exit

Press F10 and select Yes to save and reboot into Windows.

F10 → Yes

Screenshots

Secure Boot settings in ASRock UEFI

Secure Boot settings in ASRock UEFI

Things to watch for

Disabling CSM and trying to enable Secure Boot in the same session — some ASRock boards need a save, reboot, and second BIOS entry first.

Troubleshooting

You're done. After Windows starts, press Win + R and run tpm.msc to confirm TPM 2.0 is ready. Then run msinfo32 and check that Secure Boot State shows On.

Was this guide helpful?

Official sources