Valorant Vanguard / Secure Boot

Secure Boot ON.
VAN 9003 still there?

This is the annoying version of VAN 9003: BIOS already says Secure Boot is enabled, but VALORANT still refuses to launch. The fix is to check whether Windows sees Secure Boot as actually active—not just whether the BIOS toggle says Enabled.

SECURE_BOOT_STATE.EXE
ERROR // VAN 9003

“But Secure Boot is already enabled.”

Enabled in BIOS does not always mean Active in Windows.

BIOS toggleEnabled ✓
Windows stateOff ×
BIOS ModeUEFI?
Likely issueCSM / Keys

Enabled is not the same as Active.

Your BIOS can show Secure Boot as enabled while Windows still reports it as off. VAN 9003 cares about the security state Windows and Vanguard can actually verify.

UEFIBIOS Mode target
msinfo32
OnSecure Boot State target
Windows
OffCSM / Legacy target
Firmware
KeysFactory/default keys
May be required

The result you want in Windows

BIOS ModeUEFI✓
Secure Boot StateOn✓
TPM2.0 ready✓
VanguardLaunchNext
Important: if Secure Boot says Enabled in BIOS but Secure Boot State = Off in msinfo32, the firmware configuration is not fully active yet.

Most likely causes

CSM / Legacy mode still activeCheck first
Default Secure Boot keys missingCommon
Firmware says Enabled, not ActiveCommon
TPM requirement also failingPossible
The page does not assume every board uses the same menu. The wording changes between ASUS, MSI, GIGABYTE, ASRock, and laptops.

Find the mismatch first.

Do these checks in this order. It tells you whether the problem is Windows boot mode, Secure Boot activation, or TPM.

01 / WINDOWS

Open msinfo32

Check BIOS Mode and Secure Boot State.

02 / BOOT MODE

Confirm UEFI

If BIOS Mode says Legacy, stop here before forcing Secure Boot.

03 / FIRMWARE

Check CSM + keys

Disable CSM only on a properly prepared UEFI/GPT system and verify Secure Boot keys.

04 / VERIFY

Return to Windows

Run msinfo32 again. Secure Boot State must say On.

Check #1 — System Information

Press Win + R, run this, and read the values directly from Windows.

msinfo32

Check #2 — TPM Management

If Secure Boot is correct but Vanguard still complains, confirm TPM 2.0 too.

tpm.msc
Do not rush this:If msinfo32 says BIOS Mode = Legacy, or your system disk is still MBR, do not blindly disable CSM or force Secure Boot. Motherboard vendors warn that Windows may stop booting. Confirm UEFI/GPT compatibility and back up important files first.

Pick your motherboard.

The exact path changes by manufacturer. Use this as a map, then match it to the manual for your exact model and BIOS version.

Selected route

GIGABYTE

GIGABYTE's official AM4 guidance is especially clear: confirm UEFI + GPT first, disable CSM, restore factory Secure Boot keys, and verify the feature reports Active.

UEFI + GPT → CSM Disabled → Secure Boot → Restore Factory Keys → Active

If it still says VAN 9003.

At this point, stop repeating the same Secure Boot toggle. Match your Windows result to the correct next move.

BIOS Mode = LegacyPrepare/convert the Windows boot setup for UEFI before Secure Boot
BIOS Mode = UEFI, Secure Boot = OffCheck CSM and Secure Boot key enrollment
Secure Boot = OnCheck TPM 2.0 with tpm.msc
Everything passesRestart Vanguard/Windows and use Riot Support if VAN 9003 remains

A useful rule

Trust what Windows reports more than the label beside a BIOS toggle. The useful confirmation is:

msinfo32 → BIOS Mode: UEFI
msinfo32 → Secure Boot State: On
tpm.msc → Specification Version: 2.0

If all three are correct, the machine is already presenting the expected security state and repeatedly changing unrelated firmware settings is unlikely to help.

Fast answers.

The specific questions people ask when Secure Boot already looks enabled.

Secure Boot is Enabled in BIOS but msinfo32 says Off. Why?

The setting may be enabled without being fully active. Common causes include CSM/Legacy compatibility still being active or Secure Boot platform/default keys not being enrolled. Your board may describe the final state as Active, User Mode, Standard, or something similar.

Should I disable CSM?

Only after confirming Windows is already using UEFI and the system disk is compatible with UEFI/GPT boot. Vendor documentation warns that forcing Secure Boot on an incompatible Legacy/MBR setup can stop Windows from booting.

What does “Restore Factory Keys” or “Install Default Keys” do?

Secure Boot relies on trusted signing keys stored by the firmware. Some boards need the default/factory Secure Boot keys installed before the feature changes from merely Enabled to actually Active.

msinfo32 already says Secure Boot State = On. Why do I still get VAN 9003?

Check TPM 2.0 using tpm.msc, restart Windows, and make sure Vanguard is current. If BIOS Mode is UEFI, Secure Boot is On, and TPM 2.0 is ready but the error remains, use Riot Support rather than changing random BIOS settings.

The final target.

Do not stop at “Enabled” in BIOS. Stop when Windows itself says Secure Boot State: On.

Run the checks again ↑

Official guides & support.

Use the exact manual for your board whenever menu names differ. Firmware layouts change between models and BIOS versions.