All guides Anti-cheat · 6 min read · updated 9 October 2026

VALORANT “VAN: RESTRICTION”: TPM 2.0, Secure Boot and Memory integrity, fixed

On Windows 11, Riot Vanguard checks that your PC boots in a trusted way before VALORANT (and League of Legends) can start. When one of those checks fails, you get a VAN: RESTRICTION message, often with a code like VAN 9001 (TPM 2.0 and Secure Boot) or VAN 9003 (Secure Boot). Some accounts are also asked to keep Memory integrity (HVCI) on. Here is how to check each one and switch it back on.

1. See what is actually off

Do this before touching the BIOS — it takes one minute:

  • Secure Boot: press Win + R, type msinfo32, Enter. Look for Secure Boot State = On. Next to it, BIOS Mode must say UEFI (not Legacy).
  • TPM 2.0: press Win + R, type tpm.msc. It should say “The TPM is ready for use” with Specification Version 2.0.
  • Memory integrity: Windows Security › Device security › Core isolation details › Memory integrity.

2. Turn TPM 2.0 on in the BIOS

Most PCs from 2017 onward have a TPM built into the processor — it is just switched off. Its name depends on the platform:

  • AMD: “fTPM” or “AMD CPU fTPM” (often under Advanced › AMD fTPM configuration, or Security).
  • Intel: “PTT” (Platform Trust Technology), usually under Security or PCH-FW configuration.
  • Set it to Enabled, save with F10, restart, then check tpm.msc again.

3. Turn Secure Boot on — without breaking your boot

Secure Boot only works when Windows boots in UEFI mode from a GPT disk. If msinfo32 says BIOS Mode = Legacy, read this first:

  • Check your disk: Disk Management › right-click the Windows disk › Properties › Volumes › Partition style. MBR must be converted first.
  • Convert MBR → GPT without losing data with the Windows tool mbr2gpt /convert /allowFullOS (in an admin terminal). Back up your files first.
  • Then in the BIOS: disable CSM (Compatibility Support Module), set Secure Boot to Enabled / Standard (or “Windows UEFI mode”), and if keys are missing choose Restore factory keys.
  • Save, restart, check msinfo32: Secure Boot State = On.

Never disable CSM while the disk is still MBR — Windows won't find anything to boot. Convert first, switch second.

4. Memory integrity (HVCI) won't turn on?

Windows lists the drivers that block it right under the switch (“Review incompatible drivers”). They are usually old tools: RGB software, fan controllers, old anti-cheats, overclocking utilities. Update or uninstall the program that installed them, restart, and the switch unlocks.

Some “performance” tweak packs switch Memory integrity off on purpose (through the VBS setting) and it comes back off after every restart. If that is your case, the same setting has to be put back to its Windows default.

5. Still blocked?

  • Update the BIOS if it is very old — early firmwares had buggy fTPM and Secure Boot keys.
  • Reinstall Vanguard from Riot's website after the changes, then restart.
  • Install the latest Windows updates, then restart.

How HKTweaks helps

HKTweaks never switches off Memory integrity, Secure Boot or the TPM. Its PC health page checks all three and says “Vanguard ready” or exactly what is off, and the BIOS guide (Premium & Platinum) detects your motherboard and shows where TPM and Secure Boot live in YOUR brand's menus — it reads, it never writes to the BIOS.

Still stuck? A real staff member answers in a ticket on our Discord.