MSI Statement on Secure Boot
Motherboards
MSI implemented the Secure Boot mechanism in our motherboard products by following the design guidance defined by Microsoft and AMI before the launch of Windows 11. We preemptively set Secure Boot as Enabled and "Always Execute" as the default setting to offer a user-friendly environment that allows multiple end-users the flexibility to choose from thousands of different components (or even more) that include built-in option ROM, including OS images, resulting in higher compatibility configurations. For users who are highly concerned about security, they can still set “Image Execution Policy” as "Deny Execute" or other options manually to meet their security needs.
MSI will be rolling out new BIOS files for motherboards with ”Deny Execute” as the default setting for higher security levels. MSI will also keep a fully functional Secure Boot option in the BIOS for end-users so that they can modify it according to their needs.
▲ “Image Security Policy” can be found in “Security\ Secure Boot” or “Settings\ Security\ Secure Boot” with “Security Boot Mode” set to “Custom”.