VALORANT stops at VAN 9001 or VAN 9003, Battlefield 6 shows a Secure Boot error, Call of Duty reports a Failed Attestation Status, or FACEIT shows an error. All of them want TPM 2.0 and Secure Boot switched on in the PC's firmware. Microsoft notes that most retail motherboards for self-built PCs ship with the TPM off "even though it is almost always available to be enabled", so check before you buy anything. The traps on the way are BitLocker and an MBR system disk.
What the anti-cheat is checking
Secure Boot "helps prevent malicious software from loading when a Windows PC starts up", Microsoft says, by letting only trusted, digitally signed software run during boot. Its target is rootkits: Microsoft says they start before the operating system, "which means they can completely hide themselves".
The TPM turns that into evidence. FACEIT explains that it performs a "Measured Boot", recording a fingerprint of every component in the boot chain, and can give the anti-cheat a signed report, called attestation, that start-up was clean. FACEIT also states that "TPM and Secure Boot do not impact performance".
Who asks for what, as of October 2026
| Game or platform | What it asks for |
|---|---|
| Riot Vanguard (VALORANT, League of Legends) | VAN 9001: TPM 2.0 not detected as enabled. VAN 9003: Secure Boot not enabled. VAN: RESTRICTION names the missing item, which can also be memory integrity, IOMMU or a newer Windows build |
| Battlefield 6 | "TPM 2.0 Enabled, UEFI SECURE BOOT Enabled, HVCI Capable, VBS Capable", in the minimum and recommended specifications |
| Call of Duty: Black Ops 7, Warzone | Both; without them, restricted from some modes, Ranked Play included, and possibly matched separately |
| Call of Duty: Modern Warfare 4 | Both; without them, no online game mode |
| FACEIT | Both, for every player on Windows 10 and 11; IOMMU with VBS enforced in waves |
Windows 11 asks only for a "Secure Boot capable" PC, not for Secure Boot to be on.
Check what you have
System Information. Press Windows + R, type msinfo32, press Enter and read BIOS Mode and Secure Boot State. Riot's guide reads them like this:
| BIOS Mode | Secure Boot State | What it means |
|---|---|---|
| UEFI | On | Already active |
| UEFI | Off | Only the firmware switch is left |
| Legacy | Off or Unsupported | Check the disk first: an MBR disk must be converted |
TPM Management. Run tpm.msc: you want "The TPM is ready for use" and a Specification Version of 2.0 under TPM Manufacturer Information. Microsoft reads "Compatible TPM cannot be found" as a TPM that may be disabled.
Windows Security. Under Device security > Security processor details, FACEIT wants Attestation and Storage both "Ready". No Security processor entry at all, Microsoft says, likely means no TPM or one switched off in the firmware.
On a Legacy PC, Disk Management shows the Windows disk's Partition style: in the bottom pane, right-click that disk's number, such as Disk 0, then Properties > Volumes.
w0a reads the six requirements and shows where each switch is; CS2 low FPS and stutter covers the list.
Before you change anything: BitLocker
BitLocker protects the drive against "data theft or exposure from lost, stolen, or inappropriately decommissioned devices", and changes to how the PC starts can make it ask for its 48-digit recovery key. Microsoft's triggers include clearing the TPM, boot manager and partition table changes, and "a BIOS or UEFI firmware upgrade", so several steps below are on the list. Device encryption, BitLocker's automatic form, can switch itself on once a PC qualifies, "for example, by turning on Secure Boot", Microsoft says.
- Before the first restart into the firmware, find your recovery key and keep it off this PC. For a Microsoft account, Microsoft's page points to
aka.ms/myrecoverykey; Microsoft Support "doesn't have the ability to retrieve, provide, or recreate a lost BitLocker recovery key." - If Control Panel > BitLocker Drive Encryption shows the drive protected, select Suspend protection before each restart into the firmware. The drive stays encrypted, but its key is held in the clear until protection resumes automatically at the next restart.
Turn them on, in this order
- If the disk is MBR, convert it first, from Windows. Riot: "If you switch your BIOS to UEFI without converting your drive first, Windows will not boot." Microsoft's MBR2GPT converts the system disk "without modifying or deleting data on the disk", but its output warns "These changes cannot be undone!", so back up first and make sure the PC supports UEFI. On an encrypted drive, MBR2GPT needs BitLocker suspended and its protectors recreated afterwards; Riot and Activision ask for encryption to be turned off instead, leaving the drive unprotected until it is back on. In an administrator Command Prompt run
mbr2gpt /validate /allowFullOS, then, if it passes,mbr2gpt /convert /allowFullOS, and go straight to the firmware. - Open the firmware settings. In Windows 11, go to Settings > System > Recovery and select Restart now next to Advanced startup (Windows 10: Settings > Update & Security > Recovery), then Troubleshoot > Advanced options > UEFI Firmware Settings > Restart. Or press the firmware key at power-on; Riot lists Del, F2 or F10.
- Boot mode UEFI, CSM off. Where UEFI and Legacy/CSM can both be enabled, Microsoft says to choose "for UEFI to be the first or only option"; Riot and Activision say to disable CSM if the setting exists.
- Enable the firmware TPM. Microsoft says it sometimes sits under Advanced, Security or Trusted Computing, labelled Security Device, Security Device Support, TPM State, AMD fTPM switch, AMD PSP fTPM, Intel PTT or Intel Platform Trust Technology. For VAN: RESTRICTION, Riot needs the firmware TPM, not a discrete module alone.
- Set Secure Boot to Enabled. On ASUS boards, FACEIT says to use "Windows UEFI Mode". If it is greyed out, Activision says to select UEFI mode, save and reopen the firmware; if it stays grey, Riot's fix is Restore Factory Keys under Key Management, which, with BitLocker on, "will change your TPM measurements and trigger BitLocker recovery on next boot".
- Save, start Windows, check again. BIOS Mode UEFI, Secure Boot State On, TPM ready at 2.0; EA notes that some versions of Windows may need one more restart.
If it is on and the game still says no
- Old firmware. Riot: "An old BIOS can report Secure Boot as "enabled" but fail policy checks that Vanguard requires." Install the latest BIOS for your exact board, which msinfo32 names under BaseBoard Manufacturer and BaseBoard Product.
- AMD TPM version
3.*.0.*. If tpm.msc shows AMD with a Manufacturer Version such as 3.92.0.5, FACEIT and Activision both point to a BIOS update. - Boot loops or crashes after a change. FACEIT's advice: revert the last firmware change, update the BIOS, then re-enable features one at a time.
- "Secure Boot Violation" or "Invalid Signature Detected". FACEIT says the board's Secure Boot certificates are out of date, and that modern BIOS updates come with "the required 2023 Microsoft certificates". Its route switches Secure Boot off only to boot and update; while it is off, the PC lacks that protection, and Microsoft recommends re-enabling it once the issue is resolved.
The 2026 certificate change
The Microsoft certificates Secure Boot relies on were issued in 2011 and began expiring on June 24, 2026; the last expires on October 19. The 2023 replacements come through Windows Update: "For most users on supported Windows systems, no action is needed." Since April 2026, Windows Security has been rolling out a certificate status under Device security > Secure Boot; Microsoft warns that "A green checkmark alone does not confirm your certificates are updated", so look for the line saying all required certificate updates have been applied.
What does not help
- Turning Secure Boot off to silence a warning. Microsoft: "Secure Boot should not be disabled to work around certificate expiration"; it "significantly reduces device protection, removes safeguards against boot-level malware". The games above stop too.
- Turning off AMD's fTPM to cure stutter. Riot says AMD fixed the fTPM stutter of early Ryzen systems in later BIOS updates, and that turning fTPM off costs you Vanguard games.
- Clearing the TPM as a first fix. It can trigger BitLocker recovery, and Microsoft says to back up your data first.
Related
- CS2 low FPS and stutter: a measured checklist
- Memory integrity back on
- Resizable BAR and Smart Access Memory: what it is, how to check
- Intel 13th and 14th gen crashes in games: the fix that matters
- Windows 11 gaming settings that actually matter
Did this page help?
What was missing, or what did not work? We read every one of these.
If this page did not solve it, write to us — say which article you read, and we will fix the article.