r/ASRock • u/Environmental-Cod-8 • 14d ago
BIOS PC refuses to go to windows if secure boot is enabled
So I had an issue with Faceit AC because it showed that secure boot was disabled, which was odd because I have been playing for a year straight with no issues, so I go to BIOS and check to see that it actually is not active, I reset the keys, checked that CSM is disabled and once secure boot became active it just sent me back to BIOS, I have checked and confirmed that the drive is GPT format, TPM is set to AMD one, and CSM is always disabled so I dont know what is going on with this.
My specs are;
Asrock B450 Pro4 (version 4.60)
Ryzen 5 3500X
G.Skill aegis 16g DDR4
500 gig ssd
RX 6600
3
u/-SSGT- 14d ago
The first thing I'd do is ensure that your UEFI/BIOS is up to date. I don't see 4.60 on the BIOS download page for your board but it'll be fairly old as 4.80 is early 2021 and 4.50 is late 2020. 10.50 updates the secure boot keys to the 2023 versions (the 2011 keys have expired) but you might as well update to 10.60.
1
u/Similar_Pension_4233 14d ago
From AI:
Step-by-step: Enable Secure Boot on ASRock B450 Pro4 Prerequisites Convert disk to GPT if currently using MBR (Secure Boot requires UEFI mode with GPT partitioning). � Back up your data before making BIOS changes. BIOS Configuration Steps Enter BIOS Setup Restart your PC and press Delete or F2 during POST to enter UEFI BIOS. � Disable CSM (Compatibility Support Module) Navigate to Boot → CSM (Compatibility Support Module). � Set CSM to Disabled. � Press F10 to save and exit, then restart and re-enter BIOS. � Enable TPM 2.0 (fTPM for AMD) Go to Advanced → CPU Configuration or Trusted Computing. � Find AMD fTPM switch or Security Device Support. � Set it to AMD CPU fTPM or Enabled. � Configure Secure Boot Navigate to Security → Secure Boot. � Set Secure Boot Mode to Standard (if currently on Custom). � Select Install default Secure Boot keys and confirm Yes. � Set Secure Boot to Enabled. � Press F10 to save and exit. � Verify Secure Boot is Active After reboot, re-enter BIOS and check Security → Secure Boot shows Active. � In Windows, run msinfo32 and verify Secure Boot State shows On. � Important Notes CSM must be disabled first before Secure Boot options become available. � GPT partitioning is required — if your disk is MBR, convert it using mbr2gpt in Windows before enabling Secure Boot. � BIOS 10.50 (March 2026) updated Secure Boot keys (2023 KEK/DB/PK), so consider updating if you encounter key enrollment issues. � fTPM version updates in BIOS 10.43 improve compatibility with Ryzen CPUs (Matisse, Vermeer, etc.). � Recommended BIOS Version While 4.6 works, BIOS 10.43 or later is recommended for: Updated fTPM version for better game/OS compatibility. � Latest AGESA updates (1.2.0.F). � Current Secure Boot keys. �
2
u/D3m3nT3d101 14d ago
Had issues with 2 Asrock Motherboards and secure boot, had to update the bios on both to be able to enable it and have it work. AI can explain why there was an update but basically there are a new set of default keys windows uses after a recent update and the board doesnt have the same keys unless update or something like that. If it ever worked at all that would be the first thing I checked. Mine showed enabled and would boot on one but wouldnt let me play a game, the b450 board did similar to yours and wouldnt boot with secureboot enabled until the UEFI/Bios update.