How to disable Secure Boot on Xiaomi laptop: step-by-step instructions

Owners of Xiaomi and Redmi notebooks often face the need to change boot security settings, which may be required when installing Linux operating systems, using specialized software, or working with certain drivers that do not have a Microsoft digital signature.

Secure Boot is the default activation on all modern Mi Notebook and RedmiBook devices, which checks downloaders’ digital signatures by blocking unverified code from running, and while this is an important security element, some scenarios require deactivation.

The process of changing UEFI settings on Xiaomi laptops has its own features, different from the standard procedures on other brands. In this article, we will discuss in detail how to get into the BIOS, what menu items to find and how to properly perform the shutdown without risk to the system.

Why Disable Secure Boot on Xiaomi

The main reason for deactivation is to run operating systems that do not support secure boot protocol, most often Linux distributions such as Arch, Manjaro or specific Ubuntu builds, and this is required to run some recovery utilities.

Sometimes users encounter errors in the graphics card or peripheral drivers that are blocked by the security system. In such cases, Bootloader prevents the kernel modules from loading, considering them potentially dangerous.

Now, you have to understand that Secure Boot is not just a whim, it's a rootkits and bootkits defense mechanism, and by disabling it, you're reducing the security of the device, allowing any code to run at the bootloader level, and you only do that if you're sure you need to do that.

  • 🐧 Install Linux distributions without signed downloaders.
  • πŸ› οΈ Use of low-level utilities for diagnostics and repair.
  • 🚫 Bypassing driver errors blocked by security policy.

It is important to note that for Windows 11 installation, having an active Secure Boot is a must. If you plan to use this OS, after you have completed the necessary work on other systems, it is recommended to return the settings to the original state.

Preparing for changes in BIOS settings

Before entering the BIOS Setup, several preparatory steps must be taken: Make sure that the Xiaomi laptop is connected to the power source. Accidental power outages during changes in firmware settings can cause the motherboard to malfunction.

Close all applications that are running and shut down the operating system as normal. Do not use hibernation or sleep mode, as they may interfere with the proper start of the boot procedure.

⚠️ Attention: Change of settings BIOS This may cause system instability, and make sure you understand the consequences of disabling security features before starting the procedure.

If you have a password for BIOS login, remember it beforehand. On Xiaomi laptops, the default password is often not, but if the device is corporate or used, access may be limited. Resetting the BIOS password on modern models is difficult.

β˜‘οΈ Checking before entering BIOS

Done: 0 / 1

How to log into the BIOS on Xiaomi laptop

Signing into UEFI settings on Xiaomi devices is done in a standard PC way, but requires accurate timing. Immediately after pressing the turn on button, start quickly and often pressing the F2 key.

If the standard method doesn't work, you can use a key combination. Some RedmiBook and Mi Notebook models require you to press the F2 key before power is turned on, and then press the on button without letting go of F2, which ensures you get into the settings menu.

An alternative login method is available from running Windows 10 or 11. Go to Settings β†’ Update & Security β†’ Recovery. Under Special Download Options, click Reboot Now. After rebooting, select Troubleshooting Search & Resolve β†’ Additional Settings β†’ UEFI Built-in Settings.

Visually, the BIOS interface on Xiaomi laptops is typically presented in blue-gray or black-and-white. Navigation is done using arrow keys, and the selection of items is done with Enter keys. Don't use a touchpad or mouse, they don't work on this menu.

  • ⌨️ Main entry key: F2.
  • πŸ”„ Alternative method: clamp down F2 before powering.
  • πŸ’» Sign in to Windows: through the system recovery menu.

After a successful login, you will see the main menu, which displays information about the processor, RAM and the version of the BIOS. We are interested in the Security or Boot tab, where the necessary settings are located.

Step-by-step instructions to disable Secure Boot

Once you enter the BIOS interface, use the arrow keys to navigate to the Security tab. In some firmware versions, the desired settings may be in the Boot tab. Carefully review the list of options available.

Find a line called Secure Boot. By default, its status is set to Enabled. To change the setting, select this line and press Enter. In the menu that appears, select Disabled and confirm the choice.

On some Xiaomi laptops, the Secure Boot configuration change can be blocked while Admin Password mode is active.If you can't change the setting, first set the BIOS administrator password at the appropriate menu item, change Secure Boot, and then delete the password (leaving the field blank).

⚠️ Note: Some devices may need to reset security keys after disabling Secure Boot. If the system does not boot, search for the Restore Factory Keys or Clear Secure Boot Keys option and execute it.

When you change your status to Disabled, you need to save your settings. Go to the Save & Exit tab or just press F10. Confirm to save the changes by selecting Yes. The laptop will reboot automatically.

What to do if the Secure Boot is not shut down?
If the menu item is not available (gray), try setting the Supervisor Password first. Once you set the password, you will be able to change your security settings. Remember to delete the password when you're done, if you don't need it to protect the BIOS.

Features for different models of laptops

The BIOS interface may vary depending on the model of the laptop and the year of release. On older models of the Mi Notebook Air and Pro 15.6, the menu looks classic, with text strings. On the new RedmiBook Pro and Xiaomi Book, the interface may be more modern, but the logic remains the same.

The table below shows the differences in navigation for Xiaomi’s popular laptop series:

Laptop modelLocation of Secure BootEntry keyFeatures
Mi Notebook AirSecurity β†’ Secure BootF2Admin password required
RedmiBook 14/15Boot β†’ Secure BootF2Sensitive to timing
Mi Notebook ProSecurity β†’ Secure BootF2There's a Fast Boot mode.
Xiaomi Book SUEFI Windows settingsVolume +ARM-architecture

For ARM-based devices such as the Xiaomi Book S 12.4, the procedure may be different, and settings are often available through the Windows Restore interface, as there is no classic BIOS in the usual sense.

If you are a Redmi G game series owner, make sure that along with Secure Boot you do not disable other important virtualization features if you need them for emulators or virtual machines.

πŸ“Š Have you been able to disable Secure Boot the first time?
I found the instructions and did: It took several attempts: It didn’t work out, there was an error.

Solving problems when disconnecting

A common problem is that the laptop stops seeing boot devices after disabling Secure Boot. This happens if there are no installed OSes in Legacy/CSM mode, in which case you need to switch the boot mode back to UEFI in the same Boot menu tab.

Sometimes the change doesn't last after the power is turned off, which may indicate a dead CMOS battery, but on modern Xiaomi laptops, this is rare, and more often the problem is solved by a full reset cycle: turn off, turn off the power, press the power button for 30 seconds.

If the system says "Security Boot Fail" at startup, then the settings apply, but the OS bootloader does not pass the check. You will need to reinstall the operating system or update the bootloader of the current OS to the version that supports Secure Boot, or leave the function disabled.

  • πŸ”‹ Full Reset Static Voltage (Power Cycle).
  • πŸ’Ύ Check the priority of boot devices in Boot Menu.
  • πŸ”„ Reset BIOS Load Default Settings (Load Default Settings).

In rare cases, updating the BIOS to the latest version from Xiaomi's official support site helps.Manufacturers often fix bugs in UEFI that can block changing security settings.

πŸ’‘

Before making changes, take a picture of the current BIOS settings on your phone, which will quickly return all settings to their original state in case of an error.

Checking the status of Secure Boot after the reboot

After successfully booting the operating system, it is recommended to make sure that the changes are applied correctly. In Windows, this can be done through the System Information utility. Press Win + R, type msinfo32 and press Enter.

In the window that opens, look for the Secure Boot State line. If you did everything right, it will show Off. If it says On, then the settings have not been saved or reset.

For Linux users, you can check status through the terminal. The bootctl status command or the /sys/firmware/efi/efivars/SecureBoot-* file check will show the current state. In some distributions, mokutil also gives this information.

On Xiaomi laptops, the status of Secure Boot in the BIOS and the OS should be the same. If the BIOS is Disabled, and the OS writes Enabled, perhaps emulation or caching of settings is used.

Make sure that your computer boots up steadily after the feature is turned off. If you experience cyclic reboots or a black screen, go back to the BIOS and restore the factory settings (Load Optimized Defaults).

πŸ’‘

Properly disabling Secure Boot requires not only changing the flag in the BIOS, but also adjusting the operating system boot loader accordingly.

Return to factory security settings

If you don’t need to disable Secure Boot, for example, after installing Linux, you’re back on Windows 11, the feature should be activated back, which will increase your Xiaomi laptop’s protection against low-level malware.

To return, go to the BIOS as instructed above, look for Secure Boot and set the Enabled value. You may also need to activate the Restore Factory Keys option to download Microsoft's standard keys.

After turning on, be sure to check the system. Windows should boot without errors. If there is a message about an incorrect signature, you may need to restore the Windows bootloader through the installation flash drive using bootrec commands.

Keep in mind that security is a balance between convenience and protection. Use a disabled Secure Boot only when it is really necessary for your tools or operating system to work.

Can I turn off Secure Boot without logging in to the BIOS?
Windows standard means you can not disable Secure Boot, as it is a feature of the UEFI hardware layer. However, you can initiate a transition to the UEFI interface through the Windows Restore menu, which is described in the section about logging into the BIOS.
Does the Secure Boot shutdown affect Xiaomi’s warranty?
Changing the BIOS settings by itself is not usually a reason to deny warranty unless you have damaged the device’s software irreversibly, but if the motherboard fails due to user actions, the service center may refuse free repairs.
Why is the Secure Boot item gray and inactive?
Most often, this means that the BIOS has a Supervisor Password, so you go to Security, set the password, and then the Secure Boot field becomes editable, and you can delete the password once you change the settings.
Do I need to disable Fast Boot with Secure Boot?
Not necessarily, but often recommended. Fast Boot mode reduces boot time by skipping some hardware checks. When installing new OS or drivers, disabling it helps avoid conflicts and gives more time for keys to react when booting.
Is it safe to use a laptop with the Secure Boot turned off?
For normal home use, the risks are minimal unless you visit suspicious sites and run unknown software. However, the level of protection against bootkits and rootkits is reduced.