Jump to content

Secure Boot & Windows 11 Installation - question

Go to solution Solved by Alan G,

I finally found the solution!!!!  The ASUS documentation is misleading as they say doing the BIOS flash to the newer version automatically sets both secure boot and the Intel TPM.  I spent several hours yesterday looking at a bunch of "possible" solutions including a chat with ASUS support whose suggestion was to role back to the previous driver and manually set things up.  I reflashed to 2606 which was the BIOS the board came with.  This still showed secure boot enabled by default and interestingly enough no way to turn it off.  I manually set TPM and went into Windows to double check the settings.  Secure boot was still off as per msinfo but TPM was now OK.

 

The problem was the setting for the operating system that was set to "Other OS" instead of "Windows UEFI Mode"   I have no idea why ASUS has "Other OS" as the default since they are promoting the BIOS update as ready for Windows 11.  Once I made that change in the BIOS it fixed the problem. I found a bunch of posts over on Reddit with the same issue.  In the past week I updated both a Gigabyte and MSI BIOS for Windows 11 and in both of those cases the secure boot had the correct OS listed. 

I just updated the BIOS on my ASUS Z-390 motherboard to make it compatible with Windows 11.  I ran the PC check and everything says ready to go, however Windows Update says it still is not ready.  I ran msinfo and it says secure boot is turned off but that is not right according the BIOS which said it is enabled.  The Intel TPM was activated during the BIOS flash.  I don't want to go down any rabbit holes trying to update to Windows 11 if there is an issue.  How to I deal with the conflicting information on secure boot? 

 

Just as an aside, I updated two other PCs to Win 11 without issue.

Workstation PC Specs: CPU - i7 8700K; MoBo - ASUS TUF Z390; RAM - 32GB Crucial; GPU - Gigabyte RTX 1660 Super; PSU - SeaSonic Focus GX 650; Storage - 500GB Samsung EVO, 3x2TB WD HDD;  Case - Fractal Designs R6; OS - Win10

Link to post
Share on other sites

I finally found the solution!!!!  The ASUS documentation is misleading as they say doing the BIOS flash to the newer version automatically sets both secure boot and the Intel TPM.  I spent several hours yesterday looking at a bunch of "possible" solutions including a chat with ASUS support whose suggestion was to role back to the previous driver and manually set things up.  I reflashed to 2606 which was the BIOS the board came with.  This still showed secure boot enabled by default and interestingly enough no way to turn it off.  I manually set TPM and went into Windows to double check the settings.  Secure boot was still off as per msinfo but TPM was now OK.

 

The problem was the setting for the operating system that was set to "Other OS" instead of "Windows UEFI Mode"   I have no idea why ASUS has "Other OS" as the default since they are promoting the BIOS update as ready for Windows 11.  Once I made that change in the BIOS it fixed the problem. I found a bunch of posts over on Reddit with the same issue.  In the past week I updated both a Gigabyte and MSI BIOS for Windows 11 and in both of those cases the secure boot had the correct OS listed. 

Workstation PC Specs: CPU - i7 8700K; MoBo - ASUS TUF Z390; RAM - 32GB Crucial; GPU - Gigabyte RTX 1660 Super; PSU - SeaSonic Focus GX 650; Storage - 500GB Samsung EVO, 3x2TB WD HDD;  Case - Fractal Designs R6; OS - Win10

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×