Valorant-Spind LogoValorant-Spind
Tech · Vanguard

Valorant: enable Secure Boot & TPM 2.0

Getting VAN 9001 or VAN 9003 at launch? On Windows 11, Riot Vanguard requires TPM 2.0 and UEFI Secure Boot. Here you check in one minute what’s missing and turn both on step by step in the BIOS – with menu paths for ASUS, MSI, Gigabyte and ASRock.

Last updated: October 7, 2026

  • VAN 9001
  • VAN 9003
  • VAN 9090
  • VAN:RESTRICTION
Valorant-Spind app emblem
Valorant-Spind App
Valorant running again? Then check your locker Locker value in VP & euros, shop, Night Market and a coach with heatmaps – free, no login, 100% local.
⬇ Download for free🖥️ For Windows 10 & 11
⚡ Quick answer

On Windows 11, Valorant requires TPM 2.0 and UEFI Secure Boot. Without TPM 2.0, Vanguard shows VAN 9001; without Secure Boot you get VAN 9003. The fix is almost always in the BIOS: turn on Intel PTT or AMD fTPM, disable CSM/legacy, set boot mode to UEFI, enable Secure Boot – and if your drive still uses MBR, convert it to GPT with mbr2gpt first. On Windows 10, Riot currently doesn’t require either.

2required features on Windows 11
4motherboard brands with BIOS paths
10error codes explained
35%already meet every on-demand requirement

Shortcut: 1 click instead of 10 windows

Check your PC with the free Valorant Check

Our free tool SpindTune checks TPM 2.0, Secure Boot, UEFI mode, partition style, memory integrity and Vanguard in 10 to 30 seconds – and shows you the BIOS steps for your exact motherboard. No account, no ads, read only.

⬇ Download SpindTune for free More about SpindTune

SpindTune · Valorant Check
SpindTune Valorant Check: Ready for VALORANT, TPM 2.0 ready, Secure Boot on, boot mode UEFI, partition style GPT

Does Valorant need TPM 2.0 and Secure Boot?

That depends on your Windows version. On the official VALORANT specs page, Riot states that Windows 11 additionally requires TPM 2.0 and UEFI Secure Boot. Riot doesn’t list this requirement for Windows 10. The reason is the anti-cheat system Riot Vanguard: it uses the security chip and the protected boot process to verify that no tampered code was loaded before Windows.

Valorant requirements by Windows version (source: playvalorant.com, Riot Support)
Windows 10Windows 11
Minimum versionbuild 19041 (20H1) or newer, 64-bit64-bit, kept up to date
TPM 2.0currently not normally requiredrequired (otherwise VAN 9001)
UEFI Secure Bootcurrently not normally requiredrequired (otherwise VAN 9003)
Special case VAN:RESTRICTIONcan require Windows updates up to build 19045can require TPM 2.0, Secure Boot, HVCI or IOMMU
Vanguard on-demand modenot availablefrom Windows 11 25H2, only with the full security stack

The good news: almost every PC that officially got Windows 11 already has TPM 2.0 and supports Secure Boot, because Microsoft requires both for Windows 11. On many custom-built PCs they’re simply turned off in the BIOS – or Windows was installed in the old legacy mode. Both can be fixed.

The error codes: VAN 9001, VAN 9003 & co.

Riot Vanguard reports missing security features with fixed codes. Here’s how to read them:

Vanguard error codes related to TPM and Secure Boot (as of Riot Support 2026)
CodeMeaningFix
VAN 9001TPM 2.0 is not enabled or not detectedturn on Intel PTT / AMD fTPM in the BIOS
VAN 9003Secure Boot is not enabledenable UEFI mode + Secure Boot
VAN 9090TPM 2.0 couldn’t initialize, often after the TPM was clearedset up the TPM again, restart
VAN 9006Windows too old – Windows 10 20H1 or newer requiredinstall all Windows updates
VAN:RESTRICTIONVanguard requires a Windows update or a security featureinstall updates, enable TPM 2.0 / Secure Boot / HVCI / IOMMU
VAN:RESTRICTION: 1Secure Boot couldn’t be verified (off, no UEFI or outdated BIOS)check Secure Boot, then update the BIOS
VAN:RESTRICTION: 3game couldn’t be verified from its install drivecheck the install location
VAN:RESTRICTION: 4Secure Boot configuration couldn’t be verifiedenable Secure Boot, restart
VAN:RESTRICTION: 5memory integrity (HVCI/VBS) isn’t running correctlyCore isolation → Memory integrity on
STATUS_SB_POLICYproblem with the Secure Boot configurationreset the Secure Boot keys to factory defaults

By the way: Riot now describes VAN 1067 as a general Vanguard startup error – start with Windows updates, setting the Vanguard service to “Automatic” and a restart there. Every other code is in our overview of VAN error codes.

Step 1: check TPM and Secure Boot in Windows

Before you go into the BIOS, check in Windows what’s actually missing. It takes one minute:

  1. Check the TPM: Press Win + R, type tpm.msc and hit Enter. Under “Status” it should say “The TPM is ready for use”, and under “TPM Manufacturer Information” the specification version should be 2.0. If you see “Compatible TPM cannot be found”, the chip is turned off in the BIOS.
  2. Check Secure Boot: Win + R → msinfo32 → Enter. In System Summary, “BIOS Mode” must say UEFI and “Secure Boot State” must say On. If BIOS Mode says “Legacy”, Windows runs in the old legacy mode.
  3. Check the partition style: right-click Start → Disk Management → right-click “Disk 0” → Properties → Volumes. “Partition style” must say GUID Partition Table (GPT). “Master Boot Record (MBR)” means: convert it before enabling Secure Boot.
Faster with SpindTune: The Valorant Check tests all three plus memory integrity, virtualization, IOMMU, BIOS version and Vanguard at once – and detects your motherboard to show you the matching BIOS path. See how the Valorant Check works.

How to get into the BIOS (UEFI)

On Windows 11 the most reliable way is through Windows itself: Settings → System → Recovery → Advanced startup → Restart now, then Troubleshoot → Advanced options → UEFI Firmware Settings → Restart. Alternatively, press the BIOS key repeatedly while the PC turns on. In the BIOS you usually save with F10 (“Save & Exit”).

Typical BIOS keys by manufacturer
ManufacturerKey at startup
ASUSDel or F2
MSIDel
GigabyteDel
ASRockF2 or Del
DellF2
HPEsc, then F10
LenovoF1 or F2 (some laptops: Novo button)
AcerF2
Important with BitLocker: If your drive is protected by BitLocker or device encryption, Windows may ask for the recovery key after TPM or Secure Boot changes. Back it up first – you’ll find it at aka.ms/myrecoverykey in your Microsoft account – or suspend BitLocker for one restart (PowerShell as admin: Suspend-BitLocker -MountPoint "C:" -RebootCount 1).

Enable TPM 2.0: Intel PTT and AMD fTPM

Most PCs from around 2017 onward have a built-in firmware TPM – you don’t need to buy a chip. On Intel it’s called Intel PTT (Platform Trust Technology), on AMD AMD fTPM. Riot points out that a discrete TPM chip is enough for VAN 9001, but VAN:RESTRICTION can require a firmware TPM. Here’s where to find the switch on the big motherboard brands:

Turning on TPM 2.0 in the BIOS – typical menu paths (may differ by board and BIOS version)
MotherboardIntelAMD
ASUSAdvanced → PCH-FW Configuration → PTT to “Enable”Advanced → AMD fTPM configuration → TPM Device Selection to “Firmware TPM”
MSISettings → Security → Trusted Computing → Security Device Support to “Enable”, then TPM Device Selection “PTT” (Intel) or AMD fTPM switch “AMD CPU fTPM” (AMD)
GigabyteSettings → Miscellaneous → Intel Platform Trust Technology (PTT) to “Enabled”Settings → Miscellaneous → AMD CPU fTPM to “Enabled”
ASRockSecurity → Intel Platform Trust Technology to “Enabled”Advanced → CPU Configuration → AMD fTPM switch to “AMD CPU fTPM”
Dell / HP / Lenovo / Acerusually under “Security”: “TPM 2.0 Security”, “TPM Embedded Security” or “Security Chip” to “On”/“Enabled” – depending on the model

After saving, the PC restarts. Open tpm.msc again: if it says “The TPM is ready for use” with version 2.0, VAN 9001 is solved. If you only see “TPM 1.2”, that’s too old for Valorant on Windows 11 – a BIOS update that switches many boards to 2.0 helps, or use the firmware TPM instead of an old plug-in module.

Enable Secure Boot: UEFI instead of legacy

Secure Boot only works in UEFI mode and only with a drive in GPT format. That’s why the order matters: if you simply switch the BIOS to UEFI while Windows still sits on an MBR drive, your PC won’t boot anymore. Riot explicitly warns about this.

  1. Check the partition style: GPT? Go on with step 3. MBR? Do step 2 first.
  2. Convert MBR to GPT (see next section) – still in the old mode, before you change anything in the BIOS.
  3. Disable CSM: In the BIOS, turn off “CSM” (Compatibility Support Module) or “Legacy Boot” and set the boot mode to “UEFI”.
  4. Enable Secure Boot: set “Secure Boot” to “Enabled”, OS type “Windows UEFI mode”, mode “Standard”. If there are no keys, install the default or factory keys.
  5. Verify: after the restart, check msinfo32: BIOS Mode “UEFI”, Secure Boot State “On”.
Turning on Secure Boot in the BIOS – typical menu paths (may differ by board and BIOS version)
MotherboardHow to
ASUSBoot → CSM → Launch CSM “Disabled” · Boot → Secure Boot → OS Type “Windows UEFI mode” · Secure Boot Mode “Standard”; if “Custom”: Key Management → “Install Default Secure Boot keys”
MSISettings → Advanced → Windows OS Configuration → BIOS UEFI/CSM Mode “UEFI” · Settings → Security → Secure Boot → “Enable” (some boards: under Windows OS Configuration), mode “Standard”
GigabyteBoot → CSM Support “Disabled” · Boot → Secure Boot → “Enabled”; Secure Boot Mode “Custom” → “Restore Factory Keys” → Yes, then check that it says “Active”
ASRockBoot → CSM “Disabled” · Security → Secure Boot → “Enabled” (mode “Standard”; if “Custom”: “Install Default Secure Boot keys”)
Dell / HP / Lenovo / Acerboot mode “UEFI” (legacy off), then Secure Boot “Enable”; on Acer you often have to set a supervisor password first, otherwise the switch is locked

Convert MBR to GPT – without reinstalling

Windows has its own tool for this: mbr2gpt (Windows 10 version 1703 and later). It converts the system drive without deleting data – but the step can’t be undone. So back up your important files first.

  1. Requirements: no more than three partitions on the MBR drive, no dual boot with another operating system, BitLocker suspended or off.
  2. Validate: open Command Prompt as administrator and run mbr2gpt /validate /allowFullOS. If you get “Validation completed successfully”, you can convert.
  3. Convert: run mbr2gpt /convert /allowFullOS and wait for the success message.
  4. Switch over: now turn off CSM, turn on UEFI and enable Secure Boot in the BIOS – as described above.
Tip: SpindTune can run the mbr2gpt /validate check for you and show the result – SpindTune deliberately doesn’t do the actual conversion. That decision is yours.

Still VAN 9001, 9003 or 9090? Try this

VAN 9090

Set up the TPM again

The TPM was cleared or isn’t fully set up. Restart the PC, check the status in tpm.msc and let Windows finish the setup.

STATUS_SB_POLICY

Reset the keys

Secure Boot is on, but the configuration is off. Reset the Secure Boot keys to factory defaults in the BIOS – suspend BitLocker first.

RESTRICTION: 1

Update the BIOS

If Secure Boot is already on, Riot recommends a BIOS update. Only get the file from your motherboard maker’s support page.

RESTRICTION: 5

Turn on memory integrity

Windows Security → Device security → Core isolation → turn on Memory integrity and restart. Old drivers can block it.

Windows

Install all updates

Run Windows Update completely and restart. Vanguard needs current security and system services.

Vanguard

Reinstall Vanguard

If nothing helps: uninstall Riot Vanguard, restart and launch the game – Vanguard then installs fresh.

Secure Boot certificates 2026: Microsoft is replacing the Secure Boot certificates from 2011. According to Microsoft they expire as follows: KEK CA 2011 on June 24, 2026, UEFI CA 2011 on June 27, 2026 and Windows Production PCA 2011 on October 19, 2026. They’re replaced by new 2023 certificates that most PCs get automatically via Windows Update or a BIOS update. Devices without the new certificates keep booting normally but no longer get new security updates for the boot process. Riot hasn’t linked this to Valorant errors so far. SpindTune’s Valorant Check shows whether your PC already has the new certificates.

Vanguard on-demand: what the new mode requires

Since June 2026, Riot offers an optional mode where Vanguard no longer starts with Windows but only with a Riot game – and shuts down afterwards. Riot calls the compatibility check “Vanguard Pre-Check”; you start it from the Vanguard icon in the system tray. The requirements are strict:

According to Riot, about 35% of players already meet every requirement. On-demand mode isn’t needed for normal play – if you don’t use it, just let the Vanguard service start automatically as before.

Windows 10 and Valorant: what applies?

On Windows 10, Valorant runs from build 19041 (version 20H1) – Riot currently doesn’t normally require TPM 2.0 and Secure Boot there. However, Microsoft ended regular support for Windows 10 on October 14, 2025, and Riot can require newer builds via VAN:RESTRICTION. According to Riot, updating to build 19045 is sometimes enough on Windows 10; if Vanguard requires build 26100 or newer, that only works on Windows 11. If you’re switching anyway, set up TPM and Secure Boot right away.

Optimize Windows 11 for gaming – without upsetting Vanguard

Once Valorant launches again, the next question is usually: how do I get more FPS and less input lag out of my PC? Many “optimize Windows 11 for gaming” guides recommend flipping exactly the switches Vanguard needs. If you play Valorant, optimize your PC for gaming without tearing down the security baseline you just set up. These settings are safe and make a real difference:

Safe – go ahead and change these

  • Turn on Game Mode: Settings → Gaming → Game Mode. Windows prioritizes the running game and, for example, holds back driver installs through Windows Update.
  • Correct refresh rate: Settings → System → Display → Advanced display. Many 144 or 240 Hz monitors run at only 60 Hz out of the box – the most common and easiest mistake of all.
  • Set the GPU per game: Settings → System → Display → Graphics. Add Valorant and choose “High performance” – important on laptops with two graphics chips.
  • Keep graphics drivers current: New NVIDIA and AMD drivers regularly bring game optimizations and bug fixes.
  • Clean up startup apps: Every program that starts with Windows costs memory and CPU time while you play.
  • Keep disk space free: A nearly full system drive slows down updates and Valorant’s patch downloads.

Hands off – this can block Valorant

  • Turning TPM 2.0 or Secure Boot back off: on Windows 11, VAN 9001 or VAN 9003 follows right away.
  • Disabling Memory Integrity (HVCI): Microsoft lists it as a possible gaming tweak, but Vanguard can require it via VAN:RESTRICTION 5, and on-demand mode depends on it.
  • “Debloat” scripts from the internet: many switch off Windows Update, services or security features Vanguard needs to start.
  • Registry cleaners and “FPS boosters”: Microsoft explicitly does not support registry cleaners, and they don’t deliver measurable FPS.
  • Pausing Windows updates for good: Vanguard can force newer builds via VAN:RESTRICTION.

Memory Integrity deserves a closer look: in its support article on gaming performance in Windows 11, Microsoft writes that Memory Integrity and the Virtual Machine Platform (VMP) can cost performance in some configurations and allows turning them off for gaming – noting that the PC is then more vulnerable. For Valorant, that’s playing with fire: if Vanguard requires the feature, the game simply won’t start. Our advice: leave Memory Integrity on. You’ll gain FPS more safely with the points in the “Safe” list above.

Optimize your PC for gaming in one click: the Gaming Check in SpindTune covers twelve areas – from Game Mode and refresh rate to power plan, driver age, startup apps, network and ping – and explains every point in plain language. SpindTune leaves Memory Integrity and everything Vanguard needs untouched.

Free · Windows 10 & 11

One click shows what your PC is missing for Valorant

The Valorant Check in SpindTune explains every item, names the BIOS path for your motherboard, looks up 27 VAN codes and restarts your PC straight into the BIOS if you want. Plus cleanup, updates and a Gaming Check. No account, no ads, no telemetry.

⬇ Download SpindTune for free

Look up VAN error code
SpindTune VAN error code lookup with VAN 9001, VAN 9003, VAN 9090 and more codes

Verdict: back in the game in 15 minutes

VAN 9001 and VAN 9003 sound dramatic, but they’re almost always just two switches in the BIOS: firmware TPM on (Intel PTT or AMD fTPM) and Secure Boot on. It only gets tricky if Windows is still installed in legacy mode on an MBR drive – then the rule is: convert with mbr2gpt first, then switch to UEFI.

Check in Windows first what’s missing, back up your recovery key if you use BitLocker and stick to the order. Or skip the hunt: SpindTune’s free Valorant Check shows you in seconds what’s missing and where the switch sits on your motherboard.

Valorant, TPM 2.0 and Secure Boot FAQ

Does Valorant need TPM 2.0?

On Windows 11, yes: Riot requires TPM 2.0 there, otherwise you get VAN 9001. On Windows 10, TPM 2.0 currently isn’t normally required, but it can be required via VAN:RESTRICTION.

Does Valorant need Secure Boot?

On Windows 11, yes: without active UEFI Secure Boot, Vanguard reports VAN 9003. Secure Boot only works in UEFI mode with a GPT drive.

What does VAN 9001 mean?

VAN 9001 means Vanguard requires TPM 2.0 but doesn’t detect it as enabled. Usually the firmware TPM (Intel PTT or AMD fTPM) is turned off in the BIOS.

What does VAN 9003 mean?

VAN 9003 means Secure Boot isn’t enabled. In the BIOS, turn off CSM/legacy, set boot mode to UEFI and enable Secure Boot – on an MBR drive, convert it to GPT with mbr2gpt first.

How do I check whether TPM 2.0 is enabled?

Press Win + R, type tpm.msc and confirm. If it says “The TPM is ready for use” and specification version 2.0, you’re all set.

How do I check whether Secure Boot is on?

Open msinfo32 with Win + R. In System Summary, “BIOS Mode” must say UEFI and “Secure Boot State” must say On.

Do I have to reinstall Windows to use Secure Boot?

Usually not. If Windows sits on an MBR drive, convert it to GPT without data loss using the Windows tool mbr2gpt, then switch the BIOS to UEFI and Secure Boot. A backup beforehand is still a must.

Can changing TPM or Secure Boot damage my PC?

The switches themselves can’t. There are two traps: if you switch to UEFI while Windows still sits on an MBR drive, the PC won’t boot – switching back fixes it. And with BitLocker on, Windows may ask for the recovery key, so back it up first.

Where do I find TPM in the BIOS?

On Intel the option is usually called “Intel PTT” or “Platform Trust Technology”, on AMD “AMD fTPM”. Depending on the brand it sits under Security, Trusted Computing, Advanced or Miscellaneous.

What is Vanguard on-demand mode?

An optional mode since June 2026: Vanguard only starts with a Riot game instead of with Windows. It requires Windows 11 25H2 or newer, TPM 2.0, Secure Boot, VBS, memory integrity (HVCI) and IOMMU. It isn’t needed for normal play.

Can I play Valorant on Windows 10 without TPM?

Currently, usually yes – Riot only requires TPM 2.0 and Secure Boot on Windows 11. However, Vanguard can require newer builds or security features via VAN:RESTRICTION, and regular support for Windows 10 ended on October 14, 2025.

Sources: Riot Games – VALORANT specs (playvalorant.com/specs), Riot Support articles “Enable TPM 2.0”, “Secure Boot”, “Error VAN 9001”, “Error VAN 9003”, “Error VAN 9090”, “Error VAN 9006”, “Error VAN 1067”, “Error VAN: RESTRICTION” (incl. 1, 3, 4, 5), “VAN: STATUS_SB_POLICY” and “Vanguard Pre-Check” (February to July 2026); Microsoft KB5062710 “Windows Secure Boot certificate expiration and CA updates”; Microsoft Support “Options to optimize gaming performance in Windows 11” and KB2563254 (registry cleaners); Tom’s Hardware, June 25, 2026. BIOS paths: manufacturer information, may differ by board and BIOS version. Retrieved October 7, 2026. You make changes to the BIOS/UEFI and partitions at your own risk – see the disclaimer.