how to enable secure boot on aorus motherboard

just now 1
Nature

To enable Secure Boot on an Aorus motherboard, follow these steps:

  1. Restart the computer and press the Delete key repeatedly when the Aorus logo appears to enter the BIOS/UEFI settings.
  2. Go to the Boot tab and find the "CSM Support" option. Change CSM Support from Enabled to Disabled to switch to UEFI mode.
  3. Scroll down to find the Secure Boot option under the Boot tab. Enter the Secure Boot menu and change it from Disabled to Enabled.
  4. Go to the Settings or Miscellaneous section in BIOS and enable AMD CPU fTPM (for AMD processors) or Intel Platform Trust Technology (for Intel systems) to enable TPM.
  5. Save the changes and exit BIOS. The system will reboot with Secure Boot enabled.
  6. After rebooting, re-enter BIOS and go to Boot > Secure Boot. Set Secure Boot Mode to Custom. Then choose "Restore Factory Keys" and confirm to install default keys.
  7. Reboot again. You can check in BIOS or Windows system information that Secure Boot is now Active.

If the system fails to boot after enabling Secure Boot, it may be due to disk partitioning or boot mode (should be GPT and UEFI). You can revert CSM and Secure Boot settings in BIOS and ensure a GPT partition style on your drive. This process applies generally to Gigabyte Aorus motherboards and has been demonstrated on various models like B550 Aorus Elite. The key steps are disabling CSM, enabling Secure Boot, enabling TPM (fTPM or PTT), and restoring factory keys for Secure Boot to fully activate.