Secure Boot ON.
VAN 9003 still there?
This is the annoying version of VAN 9003: BIOS already says Secure Boot is enabled, but VALORANT still refuses to launch. The fix is to check whether Windows sees Secure Boot as actually active—not just whether the BIOS toggle says Enabled.
“But Secure Boot is already enabled.”
Enabled in BIOS does not always mean Active in Windows.
Enabled is not the same as Active.
Your BIOS can show Secure Boot as enabled while Windows still reports it as off. VAN 9003 cares about the security state Windows and Vanguard can actually verify.
The result you want in Windows
Most likely causes
Find the mismatch first.
Do these checks in this order. It tells you whether the problem is Windows boot mode, Secure Boot activation, or TPM.
Open msinfo32
Check BIOS Mode and Secure Boot State.
Confirm UEFI
If BIOS Mode says Legacy, stop here before forcing Secure Boot.
Check CSM + keys
Disable CSM only on a properly prepared UEFI/GPT system and verify Secure Boot keys.
Return to Windows
Run msinfo32 again. Secure Boot State must say On.
Check #1 — System Information
Press Win + R, run this, and read the values directly from Windows.
Check #2 — TPM Management
If Secure Boot is correct but Vanguard still complains, confirm TPM 2.0 too.
Pick your motherboard.
The exact path changes by manufacturer. Use this as a map, then match it to the manual for your exact model and BIOS version.
GIGABYTE
GIGABYTE's official AM4 guidance is especially clear: confirm UEFI + GPT first, disable CSM, restore factory Secure Boot keys, and verify the feature reports Active.
If it still says VAN 9003.
At this point, stop repeating the same Secure Boot toggle. Match your Windows result to the correct next move.
A useful rule
Trust what Windows reports more than the label beside a BIOS toggle. The useful confirmation is:
msinfo32 → Secure Boot State: On
tpm.msc → Specification Version: 2.0
If all three are correct, the machine is already presenting the expected security state and repeatedly changing unrelated firmware settings is unlikely to help.
Fast answers.
The specific questions people ask when Secure Boot already looks enabled.
Secure Boot is Enabled in BIOS but msinfo32 says Off. Why?
The setting may be enabled without being fully active. Common causes include CSM/Legacy compatibility still being active or Secure Boot platform/default keys not being enrolled. Your board may describe the final state as Active, User Mode, Standard, or something similar.
Should I disable CSM?
Only after confirming Windows is already using UEFI and the system disk is compatible with UEFI/GPT boot. Vendor documentation warns that forcing Secure Boot on an incompatible Legacy/MBR setup can stop Windows from booting.
What does “Restore Factory Keys” or “Install Default Keys” do?
Secure Boot relies on trusted signing keys stored by the firmware. Some boards need the default/factory Secure Boot keys installed before the feature changes from merely Enabled to actually Active.
msinfo32 already says Secure Boot State = On. Why do I still get VAN 9003?
Check TPM 2.0 using tpm.msc, restart Windows, and make sure Vanguard is current. If BIOS Mode is UEFI, Secure Boot is On, and TPM 2.0 is ready but the error remains, use Riot Support rather than changing random BIOS settings.
The final target.
Do not stop at “Enabled” in BIOS. Stop when Windows itself says Secure Boot State: On.
Official guides & support.
Use the exact manual for your board whenever menu names differ. Firmware layouts change between models and BIOS versions.