Can't Play Valorant? How to Fix VAN-9001 & Secure Boot Errors

A gamer playing VALORANT in front of a monitor with a keyboard and mouse.

By GPU Sniper Team | pctechsniper.com
Last Updated: July 2025 | Questions? Contact Us

Quick Summary

If you've been hit with errors like VAN-9001, VAN-9003, or similar messages in Valorant, you're not alone. Riot Games has updated its Vanguard anti-cheat system to require Secure Boot and TPM 2.0 to be active on your system. This guide will walk you through why these changes were made and, more importantly, how to enable these settings in your PC's BIOS so you can get back to clutching rounds.

Why Does Vanguard Need Secure Boot & TPM 2.0?

The short answer is: to make cheating much, much harder. Riot Vanguard, Valorant's aggressive anti-cheat software, operates at a very deep level of your operating system (the kernel) to detect foul play. However, sophisticated cheats can also use low-level exploits, like malicious or modified drivers, to load before Vanguard even starts. This allows them to hide from detection effectively.

  • Secure Boot: This is a security standard developed for the UEFI (the modern replacement for BIOS). When enabled, it ensures that your PC only boots using software and drivers that are trusted by the manufacturer. It creates a "chain of trust," preventing unauthorized code—like a rootkit used for cheating—from loading during startup.
  • TPM 2.0 (Trusted Platform Module): This is a dedicated microchip on your motherboard that provides hardware-based security functions. It securely stores cryptographic keys and attests to the integrity of your system's boot process. For Vanguard, the TPM helps verify that the system hasn't been tampered with and that Secure Boot is genuinely active.

By enforcing these two features, Riot Games raises the bar for cheat developers significantly, creating a more secure and fair environment for everyone.

Step 1: Check if Secure Boot and TPM are Enabled

Before diving into your BIOS, let's quickly check your system's current status. It only takes a few seconds.

  1. Press Windows Key + R to open the Run dialog.
  2. Type msinfo32 and press Enter. This will open the System Information window.
  3. In the System Summary view, you can either scroll to find the lines or use the "Find what" box at the bottom. Search for Secure Boot State and then TPM to check their status quickly.

If Secure Boot State is "On" and you can confirm TPM 2.0 is present and enabled, you shouldn't be getting these errors. If either is "Off," "Unsupported," or "Not Found," you'll need to proceed to your BIOS.

Screenshot of msinfo32 showing Trusted Platform Module 2.0 as OK.

Step 2: How to Enable Secure Boot & TPM in BIOS/UEFI

Enabling these settings requires entering your PC's BIOS/UEFI menu. The exact steps vary by motherboard manufacturer, but the general process is the same.

How to Enter BIOS/UEFI:

Restart your computer and press the designated key repeatedly as it boots up. Common keys are Delete, F2, F10, or F12. The correct key is usually displayed on the splash screen when your PC first starts.

For ASUS Motherboards:

  • TPM: Go to Advanced > AMD fTPM configuration (for AMD CPUs) or PCH-FW Configuration (for Intel CPUs) and enable TPM Device Selection.
  • Secure Boot: Go to the Boot tab > Secure Boot. Set Secure Boot Mode to Standard or Windows UEFI mode. Ensure CSM (Compatibility Support Module) is disabled under the Boot tab, as it conflicts with Secure Boot.

For MSI Motherboards:

  • TPM: Go to Settings > Security > Trusted Computing. Enable Security Device Support. The AMD fTPM switch or Intel Platform Trust Technology (PTT) should then become available to enable.
  • Secure Boot: Go to Settings > Advanced > Windows OS Configuration. Set Secure Boot to Enabled.

For GIGABYTE/AORUS Motherboards:

  • TPM: Go to Settings > Miscellaneous. Enable AMD CPU fTPM (for AMD) or Intel Platform Trust Technology (PTT) (for Intel).
  • Secure Boot: Go to the Boot tab. Make sure CSM Support is Disabled. Then find the Secure Boot option on the same page and set it to Enabled.
GIGABYTE BIOS showing Secure Boot enabled.

Remember to save your changes and exit the BIOS. Your PC will restart, and hopefully, Valorant will now launch without errors!

Common Pitfalls & Solutions

Pitfall 1: Secure Boot is Enabled, but Keys are Invalid

Sometimes, Secure Boot can be enabled, but it won't be truly "active" because the required cryptographic keys are not loaded. This is common on custom-built PCs or if you've recently cleared your CMOS.

The Solution: Restore Factory Keys

Deep within the Secure Boot menu in your BIOS, you should find an option like Key Management, Install default Secure Boot keys, or Restore Factory Keys. Select this option to load the default keys that came with your motherboard. After doing this and saving, Secure Boot should become fully active.

Pitfall 2: CSM is Enabled

GIGABYTE BIOS showing CSM Support enabled. (Needs to be disabled)

CSM, or Compatibility Support Module, is a feature that allows newer UEFI systems to boot older, legacy hardware and operating systems. Secure Boot cannot function when CSM is enabled. If you see a CSM option in your BIOS, you must disable it before you can properly enable Secure Boot.

Still Having Trouble?

BIOS settings can be tricky, and every motherboard is a little different. If this guide didn't solve your issue, or if you have tips for other motherboard brands, feel free to reach out. Your feedback helps us keep our guides up-to-date for the entire community.

Contact Support