Secure Boot is a BIOS feature which prevents malicious software (such as rootkits and cheat software) from running during the startup process, cutting a key loophole used by cheaters to make their software harder to detect. Secure Boot is required for all players on Windows 10 & 11. If you are required to run Secure Boot and do not have it enabled, an error message will appear until you enable the feature in your BIOS.
We've published the final rollout schedule with more details about why we are requiring this in order to improve protection against cheats across matchmaking and official matches on FACEIT.
⚠️Any changes to your BIOS are made at your own risk, we are not responsible for any issues with your PC. If you are not familiar with making changes in your BIOS we recommend contacting a professional.
How to check your current settings
- Press the Windows key
- Type msinfo32 and press Enter
- In the System Information window, BIOS Mode should display UEFI and Secure Boot State should be set to On
How to update your settings
Before any other steps, you must ensure your BIOS mode is set to UEFI - to do so, first check if your OS drive is formatted correctly, using this video. If it is formatted as MBR, make sure to watch this video on converting your drive to GPT. This change is performed at your own risk and could prevent your computer from booting if not done correctly. If in doubt, please contact a professional.
Changing your BIOS Mode to UEFI depends on your motherboard, please check your manufacturer’s website to find out how to do so.
Once your BIOS mode is correctly set to UEFI, you should be able to enable Secure Boot.
Some manufacturers provide support articles on their website about enabling Secure Boot:
There is also some information on Microsoft's website if your motherboard's manufacturer is not listed.
The following suggestions may also help you, depending on your motherboard brand:
- Secure Boot should be set to "Windows UEFI Mode" on ASUS motherboards, it might be called "Standard" on other motherboards.
- If you can select between "UEFI" or "UEFI with CSM", make sure to select "UEFI"
- Gigabyte: set CSM to "Disabled", then you can open the "Secure Boot" menu. After opening it, set "Secure Boot Mode" to "Standard" and "Secure Boot" to "Enabled".
- If that all of the above is correct and it still does not work, you might need to use the "Reset/Restore factory keys" option
Fixing "Secure Boot Violation" Errors on Startup
If you receive a "Secure Boot Violation" or "Invalid Signature Detected" error screen when restarting your PC, your motherboard is actively blocking Windows from loading. This happens because your motherboard's Secure Boot certificates are out of date and do not recognize the signatures used by recent Windows updates.
To resolve this and allow Windows to boot safely with Secure Boot enabled:
Restart your PC, enter your BIOS/UEFI menu, and temporarily disable Secure Boot so you can boot back into Windows.
Update your BIOS to the latest version available on your motherboard manufacturer's website. Modern BIOS updates come with the required 2023 Microsoft certificates pre-installed.
Once your BIOS is fully updated, return to your BIOS/UEFI menu and enable Secure Boot. Windows should now boot normally.
If you already have the latest BIOS and the issue persists:
Sometimes, a BIOS update fails to automatically install the new certificates. Since you are already booted into Windows with Secure Boot temporarily disabled, you can manually apply the certificates using Microsoft's official Secure Boot Recovery tool built into Windows.
Format an empty USB flash drive to FAT32.
On your USB drive, create a new folder named EFI. Inside that EFI folder, create another folder named BOOT (the final path should be EFI\BOOT).
Open File Explorer in Windows and navigate to C:\Windows\Boot\EFI.
Find the file named SecureBootRecovery.efi, copy it, and paste it into the BOOT folder on your USB drive.
Rename the copied file on your USB drive from SecureBootRecovery.efi to bootx64.efi.
Restart your PC, open your Boot Menu during startup (e.g., by pressing F11, F12, or F8 depending on your manufacturer), and select the USB flash drive to boot from.
The Microsoft tool will automatically run, apply the missing 2023 certificates to your motherboard, and restart your system.
Enter your BIOS/UEFI one last time to enable Secure Boot, save your changes, and Windows will boot successfully.
(Note: If you are uncomfortable performing these steps, we recommend contacting a professional IT technician for assistance. Modifying Secure Boot settings is done at your own risk.)