GUIDES

Secure Boot and TPM 2.0 for anti-cheat: check and turn them on

VAN 9001 or 9003 in VALORANT, or Battlefield 6, Call of Duty or FACEIT asking for TPM 2.0 and Secure Boot? How to check both, the order to turn them on, and how to avoid a BitLocker lockout.

VALORANT stops at VAN 9001 or VAN 9003, Battlefield 6 shows a Secure Boot error, Call of Duty reports a Failed Attestation Status, or FACEIT shows an error. All of them want TPM 2.0 and Secure Boot switched on in the PC's firmware. Microsoft notes that most retail motherboards for self-built PCs ship with the TPM off "even though it is almost always available to be enabled", so check before you buy anything. The traps on the way are BitLocker and an MBR system disk.

What the anti-cheat is checking

Secure Boot "helps prevent malicious software from loading when a Windows PC starts up", Microsoft says, by letting only trusted, digitally signed software run during boot. Its target is rootkits: Microsoft says they start before the operating system, "which means they can completely hide themselves".

The TPM turns that into evidence. FACEIT explains that it performs a "Measured Boot", recording a fingerprint of every component in the boot chain, and can give the anti-cheat a signed report, called attestation, that start-up was clean. FACEIT also states that "TPM and Secure Boot do not impact performance".

Who asks for what, as of October 2026

Game or platformWhat it asks for
Riot Vanguard (VALORANT, League of Legends)VAN 9001: TPM 2.0 not detected as enabled. VAN 9003: Secure Boot not enabled. VAN: RESTRICTION names the missing item, which can also be memory integrity, IOMMU or a newer Windows build
Battlefield 6"TPM 2.0 Enabled, UEFI SECURE BOOT Enabled, HVCI Capable, VBS Capable", in the minimum and recommended specifications
Call of Duty: Black Ops 7, WarzoneBoth; without them, restricted from some modes, Ranked Play included, and possibly matched separately
Call of Duty: Modern Warfare 4Both; without them, no online game mode
FACEITBoth, for every player on Windows 10 and 11; IOMMU with VBS enforced in waves

Windows 11 asks only for a "Secure Boot capable" PC, not for Secure Boot to be on.

Check what you have

System Information. Press Windows + R, type msinfo32, press Enter and read BIOS Mode and Secure Boot State. Riot's guide reads them like this:

BIOS ModeSecure Boot StateWhat it means
UEFIOnAlready active
UEFIOffOnly the firmware switch is left
LegacyOff or UnsupportedCheck the disk first: an MBR disk must be converted

TPM Management. Run tpm.msc: you want "The TPM is ready for use" and a Specification Version of 2.0 under TPM Manufacturer Information. Microsoft reads "Compatible TPM cannot be found" as a TPM that may be disabled.

Windows Security. Under Device security > Security processor details, FACEIT wants Attestation and Storage both "Ready". No Security processor entry at all, Microsoft says, likely means no TPM or one switched off in the firmware.

On a Legacy PC, Disk Management shows the Windows disk's Partition style: in the bottom pane, right-click that disk's number, such as Disk 0, then Properties > Volumes.

w0a reads the six requirements and shows where each switch is; CS2 low FPS and stutter covers the list.

Before you change anything: BitLocker

BitLocker protects the drive against "data theft or exposure from lost, stolen, or inappropriately decommissioned devices", and changes to how the PC starts can make it ask for its 48-digit recovery key. Microsoft's triggers include clearing the TPM, boot manager and partition table changes, and "a BIOS or UEFI firmware upgrade", so several steps below are on the list. Device encryption, BitLocker's automatic form, can switch itself on once a PC qualifies, "for example, by turning on Secure Boot", Microsoft says.

  1. Before the first restart into the firmware, find your recovery key and keep it off this PC. For a Microsoft account, Microsoft's page points to aka.ms/myrecoverykey; Microsoft Support "doesn't have the ability to retrieve, provide, or recreate a lost BitLocker recovery key."
  2. If Control Panel > BitLocker Drive Encryption shows the drive protected, select Suspend protection before each restart into the firmware. The drive stays encrypted, but its key is held in the clear until protection resumes automatically at the next restart.

Turn them on, in this order

  1. If the disk is MBR, convert it first, from Windows. Riot: "If you switch your BIOS to UEFI without converting your drive first, Windows will not boot." Microsoft's MBR2GPT converts the system disk "without modifying or deleting data on the disk", but its output warns "These changes cannot be undone!", so back up first and make sure the PC supports UEFI. On an encrypted drive, MBR2GPT needs BitLocker suspended and its protectors recreated afterwards; Riot and Activision ask for encryption to be turned off instead, leaving the drive unprotected until it is back on. In an administrator Command Prompt run mbr2gpt /validate /allowFullOS, then, if it passes, mbr2gpt /convert /allowFullOS, and go straight to the firmware.
  2. Open the firmware settings. In Windows 11, go to Settings > System > Recovery and select Restart now next to Advanced startup (Windows 10: Settings > Update & Security > Recovery), then Troubleshoot > Advanced options > UEFI Firmware Settings > Restart. Or press the firmware key at power-on; Riot lists Del, F2 or F10.
  3. Boot mode UEFI, CSM off. Where UEFI and Legacy/CSM can both be enabled, Microsoft says to choose "for UEFI to be the first or only option"; Riot and Activision say to disable CSM if the setting exists.
  4. Enable the firmware TPM. Microsoft says it sometimes sits under Advanced, Security or Trusted Computing, labelled Security Device, Security Device Support, TPM State, AMD fTPM switch, AMD PSP fTPM, Intel PTT or Intel Platform Trust Technology. For VAN: RESTRICTION, Riot needs the firmware TPM, not a discrete module alone.
  5. Set Secure Boot to Enabled. On ASUS boards, FACEIT says to use "Windows UEFI Mode". If it is greyed out, Activision says to select UEFI mode, save and reopen the firmware; if it stays grey, Riot's fix is Restore Factory Keys under Key Management, which, with BitLocker on, "will change your TPM measurements and trigger BitLocker recovery on next boot".
  6. Save, start Windows, check again. BIOS Mode UEFI, Secure Boot State On, TPM ready at 2.0; EA notes that some versions of Windows may need one more restart.

If it is on and the game still says no

The 2026 certificate change

The Microsoft certificates Secure Boot relies on were issued in 2011 and began expiring on June 24, 2026; the last expires on October 19. The 2023 replacements come through Windows Update: "For most users on supported Windows systems, no action is needed." Since April 2026, Windows Security has been rolling out a certificate status under Device security > Secure Boot; Microsoft warns that "A green checkmark alone does not confirm your certificates are updated", so look for the line saying all required certificate updates have been applied.

What does not help

Related

Did this page help?

What was missing, or what did not work? We read every one of these.

If this page did not solve it, write to us — say which article you read, and we will fix the article.