Skip to content

Enable TPM 2.0 & Secure Boot on ASUS ROG Desktops

ASUS ROG desktops use the same BIOS layout as retail ROG boards — your PC's settings menu before Windows starts. After Advanced Mode, you enable TPM, disable CSM, then turn on Secure Boot. The menus match what DIY builders see.

Quick Reference

Last verified · 10 Sept 2026

Difficulty & Time

Easy~3 min

BIOS Vendor

AMI Aptio V (ASUS ROG UEFI — full parity with DIY ROG motherboards)

CPU Support

Intel 8th Gen, Intel 9th Gen, etc.

TPM Terminology

PTTAMD CPU fTPM

Secure Boot Location

Boot → Secure Boot → OS Type

Supported Chipsets

ASUS ROG Prebuilt (All generations)
Intel 8th–15th GenAMD Ryzen 3000–9000

Same menu structure as retail ASUS ROG motherboards.

Before you begin

Don't worry if your BIOS looks slightly different. Manufacturers often update colours and layouts, but the menu names are usually the same.

1

Enter BIOS

Turn on your PC and press F2 or Del until the BIOS opens — your PC's settings menu before Windows starts.

Power On → F2 or Del
2

Switch to Advanced Mode

If you see EZ Mode, press F7 to switch to Advanced Mode. The full settings list appears there.

EZ Mode → F7 → Advanced Mode

Intel steps (Intel PTT)

3

Enable Intel PTT (TPM 2.0)

Open Advanced → PCH-FW Configuration and set PTT to Enable. This turns on TPM 2.0 for Intel systems.

Advanced → PCH-FW Configuration → PTT → Enable
4

Disable CSM

Open Boot → CSM and set Launch CSM to Disabled. Secure Boot needs this legacy mode turned off first.

Boot → CSM → Disabled
5

Enable Secure Boot

Open Boot → Secure Boot and set OS Type to Windows UEFI Mode.

Boot → Secure Boot → OS Type → Windows UEFI Mode

Leave OS Type on Windows UEFI Mode. Other OS can make Secure Boot look enabled while games still report it as off.

6

Save & Exit

Press F10, then select OK to save and restart.

F10 → OK

AMD steps (AMD fTPM)

3

Enable AMD fTPM

Open Advanced → AMD fTPM configuration and set AMD CPU fTPM to Enabled. This turns on TPM 2.0 for AMD systems.

Advanced → AMD fTPM configuration → AMD CPU fTPM → Enabled
4

Disable CSM

Open Boot → CSM and set Launch CSM to Disabled. Secure Boot needs this legacy mode turned off first.

Boot → CSM → Disabled
5

Enable Secure Boot

Open Boot → Secure Boot and set OS Type to Windows UEFI Mode.

Boot → Secure Boot → OS Type → Windows UEFI Mode

Leave OS Type on Windows UEFI Mode. Other OS can make Secure Boot look enabled while games still report it as off.

6

Save & Exit

Press F10, then select OK to save and restart.

F10 → OK

Screenshots

We do not have verified BIOS screenshots for ASUS ROG Desktops yet.

If you can share a clear photo of these menus, email bios@bootready.help with your full motherboard or PC model so we can help others.

Things to watch for

Leaving OS Type on Other OS can make Secure Boot look enabled while signature checks are still bypassed.

Troubleshooting

You're done. After Windows starts, press Win + R and run tpm.msc to confirm TPM 2.0 is ready. Then run msinfo32 and check that Secure Boot State shows On.

Was this guide helpful?

Official sources