Enable TPM 2.0 & Secure Boot on Gigabyte / AORUS
This guide walks you through Gigabyte Classic UEFI and AORUS UC BIOS boards. You will turn on two security settings that Windows and many games look for. Gigabyte hides Secure Boot until CSM is off and you save once—plan on a short reboot mid-guide, then finish the remaining steps.
Quick Reference
Last verified · 10 Sept 2026Difficulty & Time
BIOS Vendor
AMI Aptio V (Classic UEFI / AORUS UC BIOS)
CPU Support
Intel 300 Series, Intel 400 Series, etc.
TPM Terminology
Secure Boot Location
Boot → Secure Boot (appears only when CSM Support is Disabled)Supported Chipsets
On Classic UEFI boards, Intel PTT is under Settings → Miscellaneous → Intel Platform Trust Technology (PTT).
On AORUS UC BIOS, TPM options sit under Settings → Computing Security, or sometimes directly under Settings.
On AM4 boards, AMD CPU fTPM is under Settings → Settings / AMD CPU fTPM.
Before you begin
Don't worry if your BIOS looks slightly different. Manufacturers often update colours and layouts, but the menu names are usually the same.
Enter BIOS
Turn the PC on and tap Del during startup until you enter BIOS (your motherboard's settings menu). If Windows starts instead, restart and try again a little sooner.
Switch to Advanced Mode
If you land in EZ Mode, press F2 once to open Advanced Mode. You need the full menu for the steps below.
Intel steps (Intel PTT)
Enable Intel PTT (TPM 2.0)
Open Settings → Miscellaneous (or Settings → Computing Security on newer boards). TPM 2.0 is a small security feature Windows checks for; on Intel Gigabyte boards it is labeled Intel Platform Trust Technology (PTT). Set it to Enabled.
Disable CSM
Open the Boot tab. CSM is an older compatibility layer; Secure Boot stays hidden until it is off. Set CSM Support to Disabled, then save and reboot back into BIOS before continuing.
- Highlight CSM Support and set it to Disabled.
- Press F10 to save and reboot.
- Tap Del again to re-enter BIOS — Secure Boot should now appear under Boot.
Important: on Gigabyte boards, turning CSM Support off does not always reveal Secure Boot until you press F10, reboot, and enter BIOS again. That mid-guide reboot is required.
Enable Secure Boot
Still under the Boot tab, open the Secure Boot submenu that just appeared. Secure Boot is a check that only trusted software is allowed to start Windows.
- If Secure Boot is disabled or greyed out, change Secure Boot Mode from Standard to Custom.
- Select Restore Factory Keys (or Install Factory Defaults).
- Choose Yes on Install Factory Defaults, then Yes on Reset Without Saving.
- Return to Secure Boot and set it to Enabled.
- Confirm Secure Boot Status shows Active.
Warning: enabling Secure Boot without factory keys enrolled can leave the board stuck in a soft-brick loop. Restore factory keys first if Secure Boot is greyed out.
Save & Exit
Press F10 and select Yes to save and reboot into Windows.
AMD steps (AMD fTPM)
Enable AMD fTPM
Open Settings → Settings / AMD CPU fTPM. TPM 2.0 is a small security feature Windows checks for; on AMD Gigabyte boards it is labeled AMD CPU fTPM. Set it to Enabled.
Disable CSM
Open the Boot tab. CSM is an older compatibility layer; Secure Boot stays hidden until it is off. Set CSM Support to Disabled, then save and reboot back into BIOS before continuing.
- Highlight CSM Support and set it to Disabled.
- Press F10 to save and reboot.
- Tap Del again to re-enter BIOS — Secure Boot should now appear under Boot.
Important: on Gigabyte boards, turning CSM Support off does not always reveal Secure Boot until you press F10, reboot, and enter BIOS again. That mid-guide reboot is required.
Enable Secure Boot
Still under the Boot tab, open the Secure Boot submenu that just appeared. Secure Boot is a check that only trusted software is allowed to start Windows.
- If Secure Boot is disabled or greyed out, change Secure Boot Mode from Standard to Custom.
- Select Restore Factory Keys (or Install Factory Defaults).
- Choose Yes on Install Factory Defaults, then Yes on Reset Without Saving.
- Return to Secure Boot and set it to Enabled.
- Confirm Secure Boot Status shows Active.
Warning: enabling Secure Boot without factory keys enrolled can leave the board stuck in a soft-brick loop. Restore factory keys first if Secure Boot is greyed out.
Save & Exit
Press F10 and select Yes to save and reboot into Windows.
Screenshots
We do not have verified BIOS screenshots for Gigabyte / AORUS yet.
If you can share a clear photo of these menus, email bios@bootready.help with your full motherboard or PC model so we can help others.
Things to watch for
Troubleshooting
tpm.msc to confirm TPM 2.0 is ready. Then run msinfo32 and check that Secure Boot State shows On.Was this guide helpful?