1. See what is actually off
Do this before touching the BIOS — it takes one minute:
- Secure Boot: press Win + R, type
msinfo32, Enter. Look for Secure Boot State = On. Next to it, BIOS Mode must say UEFI (not Legacy). - TPM 2.0: press Win + R, type
tpm.msc. It should say “The TPM is ready for use” with Specification Version 2.0. - Memory integrity: Windows Security › Device security › Core isolation details › Memory integrity.
2. Turn TPM 2.0 on in the BIOS
Most PCs from 2017 onward have a TPM built into the processor — it is just switched off. Its name depends on the platform:
- AMD: “fTPM” or “AMD CPU fTPM” (often under Advanced › AMD fTPM configuration, or Security).
- Intel: “PTT” (Platform Trust Technology), usually under Security or PCH-FW configuration.
- Set it to Enabled, save with F10, restart, then check
tpm.mscagain.
3. Turn Secure Boot on — without breaking your boot
Secure Boot only works when Windows boots in UEFI mode from a GPT disk. If msinfo32 says BIOS Mode = Legacy, read this first:
- Check your disk: Disk Management › right-click the Windows disk › Properties › Volumes › Partition style. MBR must be converted first.
- Convert MBR → GPT without losing data with the Windows tool
mbr2gpt /convert /allowFullOS(in an admin terminal). Back up your files first. - Then in the BIOS: disable CSM (Compatibility Support Module), set Secure Boot to Enabled / Standard (or “Windows UEFI mode”), and if keys are missing choose Restore factory keys.
- Save, restart, check msinfo32: Secure Boot State = On.
Never disable CSM while the disk is still MBR — Windows won't find anything to boot. Convert first, switch second.
4. Memory integrity (HVCI) won't turn on?
Windows lists the drivers that block it right under the switch (“Review incompatible drivers”). They are usually old tools: RGB software, fan controllers, old anti-cheats, overclocking utilities. Update or uninstall the program that installed them, restart, and the switch unlocks.
Some “performance” tweak packs switch Memory integrity off on purpose (through the VBS setting) and it comes back off after every restart. If that is your case, the same setting has to be put back to its Windows default.
5. Still blocked?
- Update the BIOS if it is very old — early firmwares had buggy fTPM and Secure Boot keys.
- Reinstall Vanguard from Riot's website after the changes, then restart.
- Install the latest Windows updates, then restart.
How HKTweaks helps
HKTweaks never switches off Memory integrity, Secure Boot or the TPM. Its PC health page checks all three and says “Vanguard ready” or exactly what is off, and the BIOS guide (Premium & Platinum) detects your motherboard and shows where TPM and Secure Boot live in YOUR brand's menus — it reads, it never writes to the BIOS.
Still stuck? A real staff member answers in a ticket on our Discord.