Back to News
CS2 logoCS2Competitive

How to Enable Secure Boot for VALORANT and FACEIT CS2

Here’s a tutorial to enable UEFI Secure Boot for VALORANT and FACEIT Counter-Strike players, plus some info on TPM 2.0 settings.

PostShare
Gabby DeSena
Gabby DeSenaContent Lead
3 Aug 20267 min read
How to Enable Secure Boot for VALORANT and FACEIT CS2

VALORANT and Counter-Strike players need to enable Secure Boot to enter some competitive matches. Image Credits: Riot Games, FACEIT via Websites

Are you locked out of queueing VALORANT or Counter-Strike because you need to enable Secure Boot? Here’s a quick guide on how to turn the UEFI Secure Boot mode on, plus some handy info about TPM 2.0.

What is Secure Boot and Why Do I Need It for VALORANT and CS2?

If you’re a true FPS fiend, you’ll want to play VALORANT and CS2 at a competitive level. The best way to prevent hackers in these games is a kernel-level anti-cheat, which accesses the deepest parts of your PC and flags suspicious activity.

VALORANT straight up requires this kernel-level method, and all players have to download Riot Games’ Vanguard anti-cheat. This is a seperate software that pairs with the studio’s games, and it goes live every single time you play.

Does Counter-Strike Need Secure Boot?

Valve’s base Counter-Strike platform, including Premier, does not require Secure Boot. However, many Ranked players rely on third-party platforms like FACEIT to prevent going up against cheaters. FACEIT requires an identity verification as part of its registration process, and the program also features its own anti-cheat (which just got a huge Human Input Detection anti-AI update). FACEIT needs Secure Boot to run correctly.

Why is VALORANT/FACEIT Asking Me to Enable Secure Boot?

To give these kernel-level programs the access they need to function, you need to shift your PC to a state called ‘UEFI Secure Boot.’ You can do this through your PC’s BIOS or UEFI. (Basically, a UEFI has expanded capabilities from a BIOS.) This funky little program on your motherboard controls how your PC starts up, and what permissions programs have during its ‘boot’ function. That’s why VALORANT or FACEIT may give you a pop-up before you can queue ranked, saying ‘Enable UEFI Secure Boot.’

Human Input Detection adds another layer to FACEIT's anti-cheat system. Image Credits: @FACEIT via YouTube
Human Input Detection adds another layer to FACEIT’s anti-cheat system. Image Credits: @FACEIT via YouTube

Does VALORANT Vanguard Collect My Data?

It can be scary to give a program this level of PC access. However, it’s also currently the most effective way to prevent cheats. It’s just the tradeoff you’ll have to make to ensure higher-quality matches and safer Ranked play. Vanguard does collect some data, such as in-match actions, voice and text comms, and more.

If you’re concerned about how your data is being used, you can check out the Riot Games Privacy Notice here. Riot maintains that Vanguard (the VALORANT anti-cheat) aims not to collect data beyond what is necessary for the game to run and to enforce legit competition.

Does FACEIT CS2 Anti-Cheat Collect My Data?

FACEIT’s kernel level anticheat also collects some data from your computer. Mainly, it monitors your in-game Counter-Strike behavior, key inputs, and IP addresses. This is mostly just to prevent ban evasion and hacking. FACEIT won’t go into any of your personal files on your PC or monitor what you’re doing while the program isn’t active.

To play certain levels of FACEIT competition, you will need to complete an ID verification. You can use personal documents like a driver’s license or ID card for this. The process occurs on a 3rd-party platform called DAON, and none of it is kept or stored directly with FACEIT. You can also check out FACEIT’s Privacy Policy here.

How Do I Know if Secure Boot is Enabled?

Your PC might already have Secure Boot enabled, and there’s an easy way to check. Follow these steps:

  • Press Windows + R.
  • Type msinfo32. Press Enter.
  • Use the Search bar at the bottom of the screen and search for BIOS Mode.
  • This should say ‘UEFI’. If BIOS Mode is not UEFI, Secure Boot is not enabled.
  • Next, search for Secure Boot State.
  • This should say ‘On.’ If Secure Boot State is not On, Secure Boot is not enabled.

How to Enable UEFI Secure Boot

Okay, now that we’ve given you the big explainer, we can get movin’ on a guide. To enable Secure Boot, you’re going to need to go into your PC’s BIOS/UEFI settings. It’s important to note that if you mess with the BIOS settings too much, you can fry your little computer’s brain and accidentally make it stop working. But hey, no pressure!

Just in case the process goes wrong (especially if it’s your first time doing this), you should back up all of your current files. In addition, grab a flash drive and download the latest version of your BIOS/UEFI for your current model. If you accidentally wipe anything, you can easily restore what you’ve lost. Plus, if your computer gets corrupted, you can just flash the BIOS back to its default settings.

There are a few things to remember before we get started:

  • Your PC should be on Windows 11 to run the necessary settings.
  • You need to have your PC set to GPT (GUID Partition Table) partition style for Secure Boot to work. You can check which partition style your PC is using by going to Disk Management in your Windows search bar. In the pop-up window, right click the drive Windows is installed on. Select Properties, go to the Volume tab, and select Partition Style. Some drives use MBR (Master Boot Record). If your drive is using this, you’ll have to convert it.

Getting Into the BIOS/UEFI Settings

You can typically get into a Windows PC’s BIOS by following these steps:

By Restarting

  • Restart your PC.
  • While the screen is still black, mash your access key. We’re talking butterfly click SPAM. This varies depending on your PC model, but is usually F2, Delete, F10, or F12. Look up your specific PC brand (Asus, HP, MSI, Acer, Lenovo, Dell, etc) for more info.
  • Your BIOS/UEFI settings should open. This will look very different from your usual PC launch.

By Using Windows Key

  • Open Windows Start Menu.
  • Go to Settings.
  • Click on Update and Security or System/Windows Update.
  • Click Advanced Startup and Restart Now.
  • Click Troubleshoot.
  • Click Advanced Options.
  • Click UEFI Firmware Settings, and select Restart.

Enabling UEFI Secure Boot

Congratulations. You’ve entered the mainframe, and you are now a super-secret hacker. The BIOS contains the deepest, innermost mechanisms of your PC: it’s like staring into its brain.

Every PC’s BIOS/UEFI will look different. If you can, find a situational guide to navigate yours. It might help to look up the BIOS for your specific PC model, or for your specific motherboard or processor.

Usually, the UEFI Secure Boot setting is located in a tab called Boot, Security, or Authentication. In some cases, you’ll have to change your boot mode. Look for a Boot Options setting, and make sure it’s changed from Legacy or CSM to UEFI.

Then, you should find a ‘Secure Boot’ setting. Sometimes, this appears right below when you set your Boot Mode to UEFI. It should have a switch or tab enabling it. Switch Secure Boot from Off to On.

Don’t leave just yet! After this is done, you still need to save your changes. Otherwise, your BIOS will revert back to how it was before and you still won’t be able to play. Bummer.

Press your BIOS’ Save button or use the Save key. Usually, this is F10. Next, restart your PC and boot it up normally. This should put all the changes into effect, and you should be good to go.

Turning On the TPM 2.0 Module (Required In Some Cases)

If you’re still having trouble or have a picky BIOS model, you might have to turn on the TPM 2.0 module for VALORANT or FACEIT CS2 to work. TPM 2.0 helps block malware and stores encrypted data, so it can potentially interact with your anti-cheats. Basically, it adds enhanced security measures.

You can check if TPM 2.0 is enabled by following these steps:

  • Press Windows + R.
  • Type tpm.msc. Press Enter.
  • The status message should say, ‘The TPM is ready for use.’ You can check the Specification Version to make sure it’s TPM 2.0.

If your TPM isn’t working or updated, boot up your BIOS like in the previous tutorial. You should see a tab called Advanced, Security, or Trusted Computing.

  • On an Intel CPU, go to Intel PTT. Switch this setting to ‘Enabled.’
  • On an AMD CPU, go to AMD fTPM switch or AMD CPU fTPM. Switch it to ‘Enabled’ or ‘Firmware TPM’.
  • Your PC may vary, so again, feel free to look up specific tutorials for your processor model.
  • Make sure to save this setting with F10 or the ‘Save’ button before rebooting again!

After this change, your VALORANT or FACEIT Counter-Strike journey awaits.

Hopefully, this tutorial cleared up your questions about UEFI Secure Boot for VALORANT and Counter-Strike! Good luck on your matches, and stay tuned for more esports and in-game news.