Valorant Vanguard / Windows 11

VAN 9003
without the guesswork.

The common advice says “enable Secure Boot.” The real problem is that many PCs show it enabled in BIOS while Windows—or Vanguard—still sees it as inactive. This guide starts with the two checks that actually tell you which path to take.

VANGUARD_DIAGNOSTIC.EXE
ERROR // VAN 9003

This build of Vanguard requires Secure Boot.

Before touching BIOS settings, verify what Windows actually sees.

BIOS ModeUEFI ✓
Secure Boot StateOFF ×
TPM Spec2.0 ✓
Likely issueKeys / CSM state

What VAN 9003 actually means.

Vanguard is checking your Windows security state and is not seeing Secure Boot in the condition it expects. The important part is that a BIOS toggle saying “Enabled” does not always mean Windows sees Secure Boot as active.

1Check BIOS Mode
Should be UEFI
2Check Secure Boot State
Should be On
3Check TPM
TPM 2.0
4Restart + verify
Then launch VALORANT

The quickest way to diagnose it

Open System Informationmsinfo32Step 1
BIOS Mode should sayUEFIRequired
Secure Boot State should sayOnRequired
Check TPM Managementtpm.mscStep 2
If BIOS Mode says Legacy: do not randomly disable CSM or force Secure Boot. Your Windows installation or system disk may need to be prepared for UEFI/GPT first.

Why Secure Boot can look enabled but still fail

Legacy / CSM still activeCommon
Secure Boot keys not installedCommon
TPM 2.0 not activePossible
Firmware setting changed but not activePossible
The goal is simple: Windows must report UEFI, Secure Boot On, and a working TPM 2.0. Once those three are correct, VAN 9003 usually stops being a mystery.

The fix path, visually.

Use this order. It prevents the most common mistake: changing firmware settings before checking whether Windows is already booting in the correct mode.

01 / WINDOWS

Check msinfo32

Confirm BIOS Mode = UEFI and Secure Boot State = On.

02 / TPM

Check tpm.msc

Verify TPM is ready and the specification version reports 2.0.

03 / FIRMWARE

Resolve the mismatch

If Secure Boot is off in Windows, check CSM/Legacy mode and Secure Boot key state.

04 / VERIFY

Reboot + re-check

Do not assume the change worked. Return to Windows and verify the state again.

Check #1 — System Information

Press Win + R, run this, and look for BIOS Mode and Secure Boot State.

msinfo32

Check #2 — TPM Management

Open the TPM console and confirm the platform reports TPM 2.0.

tpm.msc
Important:If Windows currently boots in Legacy/CSM mode or your system disk is MBR, do not blindly disable CSM or force Secure Boot. Vendor guidance warns that Windows may fail to boot until the disk/boot mode is prepared correctly. Back up important data and follow the manual for your exact motherboard model.

Pick your motherboard.

The page changes the path instead of dumping four different BIOS guides into one wall of text.

Selected route

ASUS

Start with Windows verification, then check UEFI/CSM and Secure Boot keys. ASUS documentation also emphasizes GPT + UEFI before forcing Secure Boot.

Windows → msinfo32 → UEFI/GPT → Secure Boot → Key Management

What people are actually stuck on.

Across Reddit and hardware forums, the same failure modes keep appearing: Secure Boot is enabled but not active, CSM is still involved, default keys are missing, or TPM is not in the expected state.

Reddit / ValorantTechSupportRecurring pattern

Secure Boot is enabled in BIOS, but VAN 9003 still appears. A repeated community fix is disabling CSM and making sure Secure Boot is actually active with valid/default keys.

Open discussion ↗
ASUS ROG Forum15K+ views on one thread

Users report “Secure Boot Control” enabled while Windows still sees Secure Boot off; installing factory/default keys is a repeated resolution path.

Open forum thread ↗
Reddit / 2026Still current

New 2026 threads show the same issue remains active: TPM 2.0 and Secure Boot may both appear enabled while VAN 9003 continues.

Open 2026 thread ↗
RedditStrongest recurring, indexable community signal
Motherboard forumsHigh value for brand-specific menu/key issues
Official vendor docsBest source for safe UEFI/GPT/TPM prerequisites
Windows verificationUse msinfo32 and tpm.msc to confirm the firmware changes actually took effect
Best ruleVerify the Windows state first, then change only the firmware setting that is actually wrong

Fast answers.

The common questions people run into after enabling Secure Boot and still seeing VAN 9003.

Secure Boot says “Enabled” in BIOS. Why does VAN 9003 still happen?

Because “enabled” is not always the same as “active.” Windows may still report Secure Boot as off when the machine is booting in Legacy/CSM mode or when Secure Boot keys are missing/not enrolled. Check msinfo32 before doing anything else.

What should I see in msinfo32?

For the normal Windows 11 path, look for BIOS Mode: UEFI and Secure Boot State: On. If the BIOS mode says Legacy, stop and use your motherboard/vendor documentation before changing CSM or boot mode.

Why do some guides say Custom and others say Standard?

Different BIOS implementations expose key enrollment differently. Some boards use a temporary Custom mode to install factory/default keys, while others end in Standard mode. Follow the exact manual for your board rather than copying a different brand’s screenshots.

Should I update BIOS just for VAN 9003?

Not as a first step. Check UEFI, Secure Boot state and TPM first. BIOS updates can be appropriate when the board vendor specifically identifies TPM/Secure Boot firmware fixes for your model, but flashing firmware has its own risk and should be done from the official model support page.

Before you launch VALORANT again.

Open msinfo32 one final time. You want BIOS Mode = UEFI and Secure Boot State = On. Then check tpm.msc and confirm TPM 2.0 is ready.

Run the checks again ↑

Official guides & useful threads.

Use these when your motherboard menus do not match the examples above. Firmware labels vary by model and BIOS version.