A greyed-out Secure Boot setting is commonly caused by firmware configuration rather than Windows itself. Based on the available guidance, the most common cause is that CSM/Legacy Support is enabled, which prevents Secure Boot from being activated normally.
What to check:
- In BIOS/UEFI, look for CSM, Legacy Support, or legacy boot options.
- If CSM is enabled, change legacy-related boot options to UEFI only where available.
- Disable CSM/Legacy Support.
- Save changes and reboot back into BIOS.
- Check whether the Secure Boot option is now selectable.
Also verify these prerequisites:
- The system must be booting in UEFI mode.
- In Windows, open msinfo32 and check BIOS Mode. It should show UEFI.
- If the firmware has an option to load or restore Secure Boot keys, that may be required on some PCs before Secure Boot becomes available.
Important:
- Be careful when changing BIOS settings. Incorrect firmware changes can prevent the PC from starting correctly.
- If the BIOS keeps re-enabling CSM or the Secure Boot option remains greyed out after saving changes, that points to a firmware or manufacturer-specific limitation. In that case, manufacturer support is the next step.