Skip to content

Enable TPM 2.0 & Secure Boot on ASUS

This guide walks you through ASUS ROG, TUF, and Prime boards at a calm pace. You will turn on two security settings that Windows and many games look for. Each step is one clear action—nothing here is permanent until you save at the end.

Quick Reference

Last verified · 10 Sept 2026

Difficulty & Time

Easy~3 min

BIOS Vendor

AMI Aptio V (ROG/TUF/Prime UEFI)

CPU Support

Intel 300 Series, Intel 400 Series, etc.

TPM Terminology

Intel PTTPTTAMD CPU fTPMFirmware TPM

Secure Boot Location

Boot → Secure Boot → OS Type

Supported Chipsets

Intel 300/400/500 Series
Z390B360H370H310Z490B460Z590B560

Intel PTT sits under Advanced → PCH-FW Configuration. CSM is often still turned on by default on these boards.

Intel 600/700/800 Series
Z690B660Z790B760Z890B860

Intel PTT is usually already enabled when you open the menu. On Intel 12th–15th Gen boards with integrated graphics, CSM is locked off by the firmware.

AMD AM4
B450X470A320B550X570A520

Older AM4 firmware lets you choose Discrete TPM or Firmware TPM under TPM Device Selection.

AMD AM5
B650X670X670EB650EX870X870EB850

AM5 boards usually ship with AMD CPU fTPM already enabled. Trusted Computing appears as its own submenu instead of the older TPM picker.

Before you begin

Don't worry if your BIOS looks slightly different. Manufacturers often update colours and layouts, but the menu names are usually the same.

1

Enter BIOS

Turn the PC on and tap Del or F2 repeatedly until you enter BIOS (your motherboard's settings menu). If Windows starts instead, restart and try again a little sooner.

Power On → Del or F2
2

Switch to Advanced Mode

If you land in EZ Mode, press F7 once to open Advanced Mode. You need the full menu for the steps below.

EZ Mode → F7 → Advanced Mode

Intel steps (Intel PTT)

3

Enable Intel PTT (TPM 2.0)

Open Advanced → PCH-FW Configuration. TPM 2.0 is a small security feature Windows checks for; on Intel ASUS boards it is labeled Intel PTT (or TPM Device Selection).

Advanced → PCH-FW Configuration → TPM Device Selection
  • Select TPM Device Selection (or PTT).
  • Choose Enable Firmware TPM (or set PTT to Enabled).
  • If a warning prompt appears, select OK.

On 600/700/800 series boards, PTT is often already Enabled. Confirm the setting, then continue.

4

Disable CSM

Open Boot → CSM (Compatibility Support Module). CSM is an older compatibility layer; Secure Boot needs it turned off. Set Launch CSM to Disabled.

Boot → CSM → Launch CSM → Disabled

Important: if your graphics card does not support UEFI (the modern boot standard), turning CSM off can leave you with a black screen. Confirm your GPU supports UEFI before you save.

5

Enable Secure Boot

Open Boot → Secure Boot. Secure Boot is a check that only trusted software is allowed to start Windows.

Boot → Secure Boot → OS Type → Windows UEFI Mode
  • Change OS Type from Other OS to Windows UEFI Mode.
  • Confirm Secure Boot Mode is set to Standard.
  • If Key Management shows no active keys, open Key Management → Install Default Secure Boot Keys.

Warning: leaving OS Type on Other OS skips driver signature checks even when Secure Boot looks enabled. If keys look corrupted or missing, use Install Default Secure Boot Keys under Key Management.

6

Save & Exit

Press F10, review the listed changes, then select OK to save and reboot into Windows.

F10 → Save & Exit

AMD steps (AMD fTPM)

3

Enable AMD fTPM

Open Advanced → AMD fTPM configuration. TPM 2.0 is a small security feature Windows checks for; on AMD ASUS boards it is labeled AMD fTPM (or Firmware TPM).

Advanced → AMD fTPM configuration → AMD CPU fTPM → Enabled
  • On AM4, set TPM Device Selection to Firmware TPM.
  • On AM5, confirm AMD CPU fTPM is set to Enabled.

AM5 boards (B650 / X670E / X870E) usually ship with AMD CPU fTPM already enabled. Confirm the setting, then continue.

4

Disable CSM

Open Boot → CSM (Compatibility Support Module). CSM is an older compatibility layer; Secure Boot needs it turned off. Set Launch CSM to Disabled.

Boot → CSM → Launch CSM → Disabled

Important: if your graphics card does not support UEFI (the modern boot standard), turning CSM off can leave you with a black screen. Confirm your GPU supports UEFI before you save.

5

Enable Secure Boot

Open Boot → Secure Boot. Secure Boot is a check that only trusted software is allowed to start Windows.

Boot → Secure Boot → OS Type → Windows UEFI Mode
  • Change OS Type from Other OS to Windows UEFI Mode.
  • Confirm Secure Boot Mode is set to Standard.
  • If Key Management shows no active keys, open Key Management → Install Default Secure Boot Keys.

Warning: leaving OS Type on Other OS skips driver signature checks even when Secure Boot looks enabled. If keys look corrupted or missing, use Install Default Secure Boot Keys under Key Management.

6

Save & Exit

Press F10, review the listed changes, then select OK to save and reboot into Windows.

F10 → Save & Exit

Screenshots

We do not have verified BIOS screenshots for ASUS yet.

If you can share a clear photo of these menus, email bios@bootready.help with your full motherboard or PC model so we can help others.

Things to watch for

Leaving OS Type on Other OS — Secure Boot can look on while signature checks are still skipped.
Missing or corrupted Platform Keys — use Install Default Secure Boot Keys under Key Management if Secure Boot will not stay active.

Troubleshooting

You're done. After Windows starts, press Win + R and run tpm.msc to confirm TPM 2.0 is ready. Then run msinfo32 and check that Secure Boot State shows On.

Was this guide helpful?

Official sources