Skip to content

Enable TPM 2.0 & Secure Boot on MSI

This guide walks you through MSI Click BIOS 5 and Click BIOS X boards at a calm pace. You will turn on two security settings that Windows and many games look for. Security options live under Settings → Security—follow each step once, and nothing is final until you save.

Quick Reference

Last verified · 10 Sept 2026

Difficulty & Time

Easy~3 min

BIOS Vendor

AMI Aptio V (Click BIOS 5 / Click BIOS X)

CPU Support

Intel 300 Series, Intel 400 Series, etc.

TPM Terminology

Security Device SupportPTTAMD CPU fTPMAMD fTPM switch

Secure Boot Location

Settings → Security → Secure Boot

Supported Chipsets

Click BIOS 5 (Intel 300–700, AMD 400–600)
Z390B360Z490B460Z590B560Z690B660Z790B760B450X470B550X570B650X670

Boot mode is under Settings → Advanced → BIOS CSM/UEFI Mode. Trusted Computing holds the TPM options.

Click BIOS X (Intel 800, AMD 800)
Z890B860X870X870EB850

Click BIOS X uses a widescreen layout. Security and Boot Mode appear as top-level tabs rather than nested under Settings.

Before you begin

Don't worry if your BIOS looks slightly different. Manufacturers often update colours and layouts, but the menu names are usually the same.

1

Enter BIOS

Turn the PC on and tap Del during the MSI logo until you enter BIOS (your motherboard's settings menu). If Windows starts instead, restart and try again a little sooner.

Power On → Del
2

Switch to Advanced Mode

If you land in EZ Mode, press F7 once to open Advanced Mode. You need the full menu for the steps below.

EZ Mode → F7 → Advanced Mode
3

Disable CSM

Open Settings → Advanced → BIOS CSM/UEFI Mode. CSM is an older compatibility layer; Secure Boot needs modern UEFI boot instead. Set the mode to UEFI—do not select CSM.

Settings → Advanced → BIOS CSM/UEFI Mode → UEFI

Intel steps (Intel PTT)

4

Enable Intel PTT (TPM 2.0)

Open Settings → Security → Trusted Computing. TPM 2.0 is a small security feature Windows checks for; on Intel MSI boards it is labeled PTT under Trusted Computing.

Settings → Security → Trusted Computing → Security Device Support → Enabled
  • Set Security Device Support to Enabled.
  • Set TPM Device Selection to PTT.
  • Confirm Device Select is set to TPM 2.0.

Warning: Security Device Support is the master switch. Changing only PTT while that master switch stays Disabled will not turn TPM on.

5

Enable Secure Boot

Open Settings → Security → Secure Boot. Secure Boot is a check that only trusted software is allowed to start Windows.

Settings → Security → Secure Boot → Enabled
  • Set Secure Boot to Enabled.
  • If you see an error about factory keys, change Secure Boot Mode to Custom.
  • Select Enroll all Factory Default Keys.
  • Set Secure Boot Mode back to Standard.
6

Save & Exit

Press F10, review the listed changes, then press Enter to confirm and reboot into Windows.

F10 → Save & Exit

AMD steps (AMD fTPM)

4

Enable AMD fTPM

Open Settings → Security → Trusted Computing. TPM 2.0 is a small security feature Windows checks for; on AMD MSI boards it is labeled AMD fTPM under Trusted Computing.

Settings → Security → Trusted Computing → AMD fTPM switch → AMD CPU fTPM
  • Set Security Device Support to Enabled.
  • Set AMD fTPM switch to AMD CPU fTPM.
  • Confirm Device Select is set to TPM 2.0.

Warning: Security Device Support is the master switch. Changing only AMD fTPM while that master switch stays Disabled will not turn TPM on. Early B450 / X470 / B550 BIOS releases also needed AGESA 1.2.0.7 or later to avoid micro-stutters from fTPM.

5

Enable Secure Boot

Open Settings → Security → Secure Boot. Secure Boot is a check that only trusted software is allowed to start Windows.

Settings → Security → Secure Boot → Enabled
  • Set Secure Boot to Enabled.
  • If you see an error about factory keys, change Secure Boot Mode to Custom.
  • Select Enroll all Factory Default Keys.
  • Set Secure Boot Mode back to Standard.
6

Save & Exit

Press F10, review the listed changes, then press Enter to confirm and reboot into Windows.

F10 → Save & Exit

Screenshots

We do not have verified BIOS screenshots for MSI yet.

If you can share a clear photo of these menus, email bios@bootready.help with your full motherboard or PC model so we can help others.

Things to watch for

Turning Secure Boot on while Secure Boot Mode stays Custom without factory keys enrolled — Secure Boot will not actually verify boot.
Changing PTT or AMD fTPM without setting Security Device Support to Enabled first.

Troubleshooting

You're done. After Windows starts, press Win + R and run tpm.msc to confirm TPM 2.0 is ready. Then run msinfo32 and check that Secure Boot State shows On.

Was this guide helpful?

Official sources