How to Fix “Secure Boot Can Be Enabled When System in User Mode” Error: Step-by-Step BIOS Guide

Posted by:

If you’re trying to enable Secure Boot and you’ve seen a message like “Secure Boot can be enabled when system in User Mode. Repeat operation after enrolling platform key,” you’re not alone. This guide explains what this message means, how to fix it, and how to enable Secure Boot in User Mode step-by-step. We’ll keep the language simple, so whether you’re new to BIOS settings or just trying to secure your Windows system, you’ll be able to follow along.

What Is Secure Boot?

Secure Boot is a feature built into most modern computers. It protects your system from malware and unauthorized software during startup. It ensures only trusted software, like Windows or signed Linux distributions, can boot on your machine.

In short, Secure Boot helps to:

  • Prevent rootkits and boot-level malware

  • Keep your OS secure at the hardware level

  • Ensure only signed OS loaders can run at startup

To use Secure Boot, your PC must support UEFI firmware, and the feature must be enabled in BIOS.

Understanding BIOS Modes: Setup Mode vs. User Mode

Before you can enable Secure Boot, it’s important to understand the difference between Setup Mode and User Mode.

  • Setup Mode: This is the default mode when Secure Boot has not been configured. The system doesn’t have a Platform Key (PK) installed. In this mode, Secure Boot is disabled.

  • User Mode: This is when the Platform Key has been added. In this mode, Secure Boot can be enabled.

So, if you see the message:
“Secure Boot can be enabled when system in user mode,”
it means you’re in Setup Mode and need to move to User Mode by enrolling a Platform Key.

What Is a Platform Key (PK)?

The Platform Key (PK) is a special digital signature stored in your BIOS. It helps your system verify the authenticity of the operating system during boot.

When you enroll a Platform Key:

  • Your system enters User Mode

  • Secure Boot becomes available

  • Unauthorized bootloaders are blocked

Enrolling the Platform Key is the step that makes your system trust the OS you’re using.

Why You See the Message

“Secure Boot can be enabled when system in User Mode. Repeat operation after enrolling Platform Key”

This message means your system is still in Setup Mode, and Secure Boot is not yet active. It’s telling you that you must:

  1. Enroll the Platform Key (PK)

  2. Switch from Setup Mode to User Mode

  3. Try enabling Secure Boot again

Only then can Secure Boot be enabled when the system is in User Mode.

How to Check If Your System Is in User Mode or Setup Mode

To find out if your system is in Setup Mode or User Mode, follow these steps:

Windows 11:

  1. Click Start → type System Information → Open it.

  2. Scroll down to the Secure Boot State section.

  3. You’ll see one of the following:

    • “On” → Secure Boot is enabled.

    • “Off” → Secure Boot is off but the system is in User Mode.

    • “Unsupported” or “Setup Mode” → Secure Boot isn’t set up.

How to Enable Secure Boot When System in User Mode

Here’s a step-by-step guide to go from Setup Mode to User Mode and enable Secure Boot:

Step 1: Enter BIOS/UEFI Settings

  1. Restart your computer.

  2. While booting, press the BIOS key (usually Del, F2, or Esc depending on your brand—ASRock, MSI, Gigabyte, etc.).

  3. Go to Security or Boot tab.

Step 2: Disable Compatibility Support Module (CSM)

Secure Boot often requires CSM (Compatibility Support Module) to be disabled.

  1. Find CSM under the Boot tab.

  2. Set it to Disabled.

  3. Save and reboot into BIOS again.

Note: On some systems like MSI and Gigabyte, you may need to disable the CSM in setup repeat operation for Secure Boot to function correctly.

Step 3: Enroll Platform Key (PK)

  1. Find the Secure Boot or Secure Boot Control option.

  2. Select Key Management or Install Default Secure Boot Keys.

  3. Choose Enroll all factory default keys or Enroll Platform Key (PK).

  4. Confirm when prompted.

After doing this, your system will switch from Setup Mode to User Mode.

Step 4: Enable Secure Boot

Now that the Platform Key is enrolled:

  1. Go back to Secure Boot settings.

  2. Change Secure Boot Mode to Standard or Custom.

  3. Set Secure Boot to Enabled.

  4. Save and exit BIOS.

You’ve now successfully enabled Secure Boot in User Mode!

How to Enable User Mode in BIOS

If you’re specifically trying to enable User Mode, the only way to do this is by enrolling the Platform Key as shown above. Once the Platform Key is added, the system automatically switches from Setup Mode to User Mode.

Troubleshooting: Common Issues

1. Secure Boot Cannot Be Enabled in User Mode

This is usually a misread message. You might actually be in Setup Mode, and the message says Secure Boot can be enabled when system is in User Mode. Make sure to enroll the Platform Key.

2. Platform Key Option is Greyed Out

  • Try setting Secure Boot Mode to Custom first

  • Then, the Enroll PK option should become active

3. System in Setup Mode Secure Boot MSI

For MSI motherboards:

  1. Disable CSM

  2. Go to Settings > Advanced > Windows OS Configuration

  3. Select Secure Boot → Choose Install Default Key

  4. Then enable Secure Boot

4. Asrock Secure Boot Can Be Enabled When System in User Mode

For ASRock boards:

  1. Go to Advanced > Security

  2. Set Secure Boot to Enabled

  3. Under Key Management, install default keys

  4. After that, Secure Boot will be available

FAQs

Q: How to put system in User Mode?

A: You must enroll the Platform Key in BIOS. This changes the system from Setup Mode to User Mode.

Q: How to enroll platform key MSI?

A: Go to BIOS → Security → Secure Boot → Set Secure Boot Mode to Custom → Enroll Platform Key or Load Default Keys.

Q: What is Secure Boot User Mode?

A: It’s the state when Secure Boot is ready to be enabled because the Platform Key has been enrolled.

Q: How to enable User Mode in Windows 11?

A: You cannot directly change User Mode in Windows. You must do it via the BIOS by enrolling the Platform Key.

Q: Repeat operation after enrolling PK – what does it mean?

A: It means you tried to enable Secure Boot while still in Setup Mode. After enrolling the Platform Key, repeat the action to enable Secure Boot.

Summary

To wrap up, Secure Boot can be enabled when system in User Mode, but first, your system must enroll the Platform Key. This process is done inside the BIOS, not in Windows. Follow the steps in this guide carefully:

  • Disable CSM

  • Enroll the Platform Key (PK)

  • Enable Secure Boot

  • Exit and boot safely

This way, you protect your system from threats and ensure that only signed software can run on startup.

Remember: You may see different options depending on your BIOS brand like MSI, ASRock, or Gigabyte. But the core steps are always the same.


Leave a Reply

Your email address will not be published. Required fields are marked *