Skip to content

Enable TPM 2.0 & Secure Boot on Gigabyte / AORUS

This guide walks you through Gigabyte Classic UEFI and AORUS UC BIOS boards. You will turn on two security settings that Windows and many games look for. Gigabyte hides Secure Boot until CSM is off and you save once—plan on a short reboot mid-guide, then finish the remaining steps.

Quick Reference

Last verified · 10 Sept 2026

Difficulty & Time

Medium~5 min

BIOS Vendor

AMI Aptio V (Classic UEFI / AORUS UC BIOS)

CPU Support

Intel 300 Series, Intel 400 Series, etc.

TPM Terminology

Intel Platform Trust Technology (PTT)AMD CPU fTPM

Secure Boot Location

Boot → Secure Boot (appears only when CSM Support is Disabled)

Supported Chipsets

Intel 300/400/500 Series (Classic UEFI)
Z390B360H370Z490B460Z590B560

On Classic UEFI boards, Intel PTT is under Settings → Miscellaneous → Intel Platform Trust Technology (PTT).

Intel 600/700/800 & AMD AM5 (AORUS UC BIOS)
Z690B660Z790B760Z890B860B650X670X670EX870X870EB850

On AORUS UC BIOS, TPM options sit under Settings → Computing Security, or sometimes directly under Settings.

AMD AM4
B450X470A320B550X570A520

On AM4 boards, AMD CPU fTPM is under Settings → Settings / AMD CPU fTPM.

Before you begin

Don't worry if your BIOS looks slightly different. Manufacturers often update colours and layouts, but the menu names are usually the same.

1

Enter BIOS

Turn the PC on and tap Del during startup until you enter BIOS (your motherboard's settings menu). If Windows starts instead, restart and try again a little sooner.

Power On → Del
2

Switch to Advanced Mode

If you land in EZ Mode, press F2 once to open Advanced Mode. You need the full menu for the steps below.

EZ Mode → F2 → Advanced Mode

Intel steps (Intel PTT)

3

Enable Intel PTT (TPM 2.0)

Open Settings → Miscellaneous (or Settings → Computing Security on newer boards). TPM 2.0 is a small security feature Windows checks for; on Intel Gigabyte boards it is labeled Intel Platform Trust Technology (PTT). Set it to Enabled.

Settings → Miscellaneous → Intel Platform Trust Technology (PTT) → Enabled
4

Disable CSM

Open the Boot tab. CSM is an older compatibility layer; Secure Boot stays hidden until it is off. Set CSM Support to Disabled, then save and reboot back into BIOS before continuing.

Boot → CSM Support → Disabled → F10 (Save & Reboot)
  • Highlight CSM Support and set it to Disabled.
  • Press F10 to save and reboot.
  • Tap Del again to re-enter BIOS — Secure Boot should now appear under Boot.

Important: on Gigabyte boards, turning CSM Support off does not always reveal Secure Boot until you press F10, reboot, and enter BIOS again. That mid-guide reboot is required.

5

Enable Secure Boot

Still under the Boot tab, open the Secure Boot submenu that just appeared. Secure Boot is a check that only trusted software is allowed to start Windows.

Boot → Secure Boot → Enabled
  • If Secure Boot is disabled or greyed out, change Secure Boot Mode from Standard to Custom.
  • Select Restore Factory Keys (or Install Factory Defaults).
  • Choose Yes on Install Factory Defaults, then Yes on Reset Without Saving.
  • Return to Secure Boot and set it to Enabled.
  • Confirm Secure Boot Status shows Active.

Warning: enabling Secure Boot without factory keys enrolled can leave the board stuck in a soft-brick loop. Restore factory keys first if Secure Boot is greyed out.

6

Save & Exit

Press F10 and select Yes to save and reboot into Windows.

F10 → Yes

AMD steps (AMD fTPM)

3

Enable AMD fTPM

Open Settings → Settings / AMD CPU fTPM. TPM 2.0 is a small security feature Windows checks for; on AMD Gigabyte boards it is labeled AMD CPU fTPM. Set it to Enabled.

Settings → AMD CPU fTPM → Enabled
4

Disable CSM

Open the Boot tab. CSM is an older compatibility layer; Secure Boot stays hidden until it is off. Set CSM Support to Disabled, then save and reboot back into BIOS before continuing.

Boot → CSM Support → Disabled → F10 (Save & Reboot)
  • Highlight CSM Support and set it to Disabled.
  • Press F10 to save and reboot.
  • Tap Del again to re-enter BIOS — Secure Boot should now appear under Boot.

Important: on Gigabyte boards, turning CSM Support off does not always reveal Secure Boot until you press F10, reboot, and enter BIOS again. That mid-guide reboot is required.

5

Enable Secure Boot

Still under the Boot tab, open the Secure Boot submenu that just appeared. Secure Boot is a check that only trusted software is allowed to start Windows.

Boot → Secure Boot → Enabled
  • If Secure Boot is disabled or greyed out, change Secure Boot Mode from Standard to Custom.
  • Select Restore Factory Keys (or Install Factory Defaults).
  • Choose Yes on Install Factory Defaults, then Yes on Reset Without Saving.
  • Return to Secure Boot and set it to Enabled.
  • Confirm Secure Boot Status shows Active.

Warning: enabling Secure Boot without factory keys enrolled can leave the board stuck in a soft-brick loop. Restore factory keys first if Secure Boot is greyed out.

6

Save & Exit

Press F10 and select Yes to save and reboot into Windows.

F10 → Yes

Screenshots

We do not have verified BIOS screenshots for Gigabyte / AORUS yet.

If you can share a clear photo of these menus, email bios@bootready.help with your full motherboard or PC model so we can help others.

Things to watch for

Enabling Secure Boot before factory keys are restored — this can soft-brick the board into a boot loop.
Looking for Secure Boot while CSM Support is still Enabled — Gigabyte hides the menu entirely.
Skipping the mid-guide reboot — disable CSM, press F10, reboot, then re-enter BIOS before Secure Boot appears.

Troubleshooting

You're done. After Windows starts, press Win + R and run tpm.msc to confirm TPM 2.0 is ready. Then run msinfo32 and check that Secure Boot State shows On.

Was this guide helpful?

Official sources