Check your PC/laptop model supports Secure Boot
Enter BIOS/UEFI setup
Set BIOS/UEFI mode to UEFI (not Legacy/CSM)
Disable Legacy/CSM and enable UEFI boot
Find Secure Boot setting
Set Secure Boot to Enabled
If prompted, select Install default Secure Boot keys or enroll default keys
Save changes and exit BIOS/UEFI
Verify Secure Boot status in BIOS/UEFI
Verify in Windows (optional): Settings → Update & Security → Windows Security → Device Security → Security processor details → Secure Boot State
If Secure Boot cannot be enabled, update BIOS/UEFI to the latest version and try again
If prompted about keys/ownership, follow on-screen prompts and confirm
