> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://helpdesk.ggcircuit.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Automated Secure Boot Enrollment with ggRock

|| This guide provides a step-by-step walkthrough for enabling Secure Boot Keys Auto-Enrollment, a feature increasingly required by modern PC games and software platforms.

---

## 🛑 Why Enable Secure Boot?

Some PC games and applications now require Secure Boot to be enabled to ensure system integrity and prevent tampering. This means both Secure Boot and its associated keys must be properly configured.

![](https://ggcircuit.atlassian.net/wiki/download/attachments/15860311/image-png-Sep-26-2024-08-45-58-0210-PM.png?version=2&modificationDate=1743612364243&cacheVersion=1&api=v2)

---

## ✅ Step-by-Step Guide

### 1. Enable Auto-Enrollment in ggRock

1. Navigate to `Settings > Secure Boot` in the ggRock web UI.
2. Enable **Secure Boot Keys Auto-Enrollment**.

📸 Example:

![](https://ggcircuit.atlassian.net/wiki/download/attachments/15860311/image-20250402-165032.png?version=1&modificationDate=1743612635419&cacheVersion=1&api=v2)

---

### 2. Enter the BIOS Setup

Access the BIOS/UEFI setup menu on the client machine:

* Common keys: `F2`, `F8`, `F10`, `F12`, `ESC`, or `DEL` (varies by manufacturer).

📸 *Example:*

![](https://ggcircuit.atlassian.net/wiki/download/attachments/15860311/image-png-Sep-26-2024-09-04-27-3710-PM.png?version=2&modificationDate=1743612386968&cacheVersion=1&api=v2)

---

### 3. Configure Secure Boot in BIOS

1. Enable **Secure Boot**.
2. Set the Secure Boot mode to **Custom**.
3. Put the platform in **Setup Mode** by clearing existing Secure Boot keys (i.e., delete all Secure Boot variables).

📸 Example Screenshots:

![](https://ggcircuit.atlassian.net/wiki/download/attachments/15860311/image-png-Sep-26-2024-09-11-59-3749-PM.png?version=2&modificationDate=1743612387228&cacheVersion=1&api=v2)
|| 💡 Tip:
|| Disable any options like “Provision Factory Default Keys” to prevent keys from being auto-restored on reboot.

---

### 4. Auto-Enrollment Process

1. Reboot the PC.
2. During the next boot, the Secure Boot certificates will automatically install.
3. Reboot again. You will now see a **shield icon** in the ggRock UI, indicating Secure Boot is active. 🛡️

📸 Example:

![](https://ggcircuit.atlassian.net/wiki/download/attachments/15860311/image-png-Sep-26-2024-09-35-44-7340-PM.png?version=2&modificationDate=1743612404437&cacheVersion=1&api=v2)

---

## 🔁 Finalizing the BIOS Configuration

Once Secure Boot is confirmed:

1. Disable **Secure Boot Keys Auto-Enrollment** in `Settings > Secure Boot` on ggRock.
2. Reboot the PC.

![](https://ggcircuit.atlassian.net/wiki/download/attachments/15860311/image-png-Sep-26-2024-09-33-32-0033-PM.png?version=2&modificationDate=1743612417814&cacheVersion=1&api=v2)

3. Re-enter BIOS setup (`F10`, `ESC`, or `DEL`).
4. Go to **Boot Options**.
5. Ensure **Secure Boot** is enabled (may be called “Windows UEFI Mode” on some systems).
6. Save changes and exit BIOS.

📸 Example:

![](https://ggcircuit.atlassian.net/wiki/download/attachments/15860311/image-20250501-101653.png?version=1&modificationDate=1746094617241&cacheVersion=1&api=v2)
|| 📌 Note: On certain platforms like HP OMEN, Secure Boot may not auto-enable when setting the PK. Manual configuration may still be required.
![](https://ggcircuit.atlassian.net/wiki/download/attachments/15860311/rbizxHZ3hjp-YlZFtQTB3sPwZptylfyAh2_ctX45kkwT04TluGOVpkXiIdnhCKL2FKcXam9cyi2GgVy9yDoFw1xogAIo_TrbLij0SP31zDsEZmBuIasXMSU4vFi19lYiDMseoOIcoLsd__ymUxG5BIA?version=2&modificationDate=1743612438854&cacheVersion=1&api=v2)

---

## 🧪 Verifying Secure Boot Status

There are two ways to verify that Secure Boot is correctly configured:

### Method 1: `msinfo32`

1. Boot into Windows.
2. Press `Win + R`, type `msinfo32`, and press Enter.
3. Look for:

* **BIOS Mode**: UEFI
* **Secure Boot State**: On

📸 Example:

![](https://ggcircuit.atlassian.net/wiki/download/attachments/15860311/image-png-Aug-20-2024-11-19-12-9858-PM.png%3Fwidth=450%26height=209%26name=image-png-Aug-20-2024-11-19-12-9858-PM.png?version=2&modificationDate=1743612475616&cacheVersion=1&api=v2)

---

### Method 2: PowerShell

Run the following command in an elevated PowerShell window:

```
Confirm-SecureBootUEFI
```

If it returns `True`, Secure Boot is active. ✅ 

---