Vanguard Security Guide

VALORANT VAN9003 Fix 2026: Secure Boot and TPM 2.0

Check the Windows security state first, protect your recovery key and change only the firmware setting your system actually needs.

By 11 min read
Check firstWindows status
Secure BootState must be On
TPMSpecification 2.0
Quick Answer

Verify UEFI, Secure Boot and TPM 2.0 before touching BIOS.

Open msinfo32 and confirm BIOS Mode is UEFI and Secure Boot State is On. Then open tpm.msc and confirm the TPM is ready with Specification Version 2.0. If a value is wrong, save the BitLocker recovery key and follow the exact guide for your PC or motherboard.

What the VALORANT VAN9003 error means

VAN9003 is a Riot Vanguard security restriction commonly connected to the boot security state that Windows reports. It is not the same as a normal game crash, a bad graphics setting or a server outage. Reinstalling VALORANT repeatedly will not correct a firmware state that Windows still reports as unsupported.

The useful question is not which BIOS button another player clicked. The useful question is which of the three platform checks fails on your own PC. Windows can reveal that answer before you enter firmware settings.

Boot modeUEFI

Modern boot mode required for an active Secure Boot configuration.

Boot trustSecure Boot On

Windows must report the feature as active, not merely available.

Security chipTPM 2.0 Ready

The security processor must be detected and ready for use.

Do not copy a random BIOS path. Menu names and the safe conversion process differ between laptops, prebuilt PCs and custom motherboards.

Check Windows before changing firmware

Start with read only checks. They take less than a minute and show whether the problem is UEFI mode, Secure Boot, TPM 2.0 or something later in the Vanguard chain.

Windows security snapshotTarget state
01msinfo32BIOS Mode: UEFI

If it says Legacy, pause before changing CSM or boot mode.

02msinfo32Secure Boot State: On

Unsupported or Off needs device specific investigation.

03tpm.mscSpecification: 2.0

The status should also say the TPM is ready for use.

Open System Information

Press Windows and R, enter msinfo32, then read BIOS Mode and Secure Boot State in System Summary.

Open TPM Management

Press Windows and R, enter tpm.msc, then check Status and Specification Version.

Check Device Security

Open Windows Security and select Device security. Confirm that Windows detects the security processor and review any warning shown there.

Stop if BIOS Mode says Legacy. Blindly disabling CSM or forcing UEFI can make an existing Windows installation fail to boot when the system disk and boot configuration are not ready.

The safest VAN9003 fix order

Firmware changes can affect disk encryption and the Windows boot path. Prepare a recovery route before changing anything. Microsoft warns that hardware, firmware or software changes can trigger a BitLocker recovery prompt.

01Update WindowsInstall supported Windows updates and restart once before deeper changes.
02Save BitLocker keyConfirm that the recovery key is accessible outside the affected PC.
03Find the exact manualUse the PC, laptop or motherboard model, not a similar screenshot.
04Change one stateSave, reboot and verify Windows after each necessary change.
  • Record the current firmware settings with photos before editing them.
  • Keep the device on stable power and do not interrupt a firmware update.
  • Use the manufacturer support page for Legacy to UEFI or Secure Boot key guidance.
  • Never clear TPM as the first fix because stored keys and encrypted data can be affected.

If this is a work, school or managed PC, stop and contact the administrator. Security policies, recovery keys and firmware access may be controlled by the organization.

Enable Secure Boot without breaking the boot path

If Windows already reports BIOS Mode as UEFI but Secure Boot State is Off, the next step is usually inside UEFI firmware. Enter it through Windows Advanced startup or the startup key documented by the manufacturer. Change only the Secure Boot related setting required by that exact model.

If Windows reports Legacy mode, the job is more complex. Secure Boot depends on UEFI, and an older installation may use an MBR system disk or a boot layout that cannot simply be switched. Back up important data and follow the manufacturer or Microsoft conversion process that matches the PC.

Good stateUEFI plus Secure Boot On

Save the setting, restart Windows and verify the new status in msinfo32.

Needs researchLegacy, CSM or Setup Mode

Check disk layout, Secure Boot keys and device instructions before changing boot mode.

Enabled is not always active. If the firmware says Secure Boot is enabled but Windows still reports Off, the system may be in Setup Mode, keys may not be enrolled or Legacy compatibility may still be active. Use the device manual for the correct key enrollment procedure.

Enable TPM 2.0 with the correct firmware label

Many modern PCs already include firmware TPM support but use a vendor specific name. Intel systems often call it PTT, while AMD systems often call it fTPM. A laptop or prebuilt menu can use a broader label such as Security Device Support.

PlatformCommon labelWhat to verify
IntelIntel PTTEnable the platform trust technology, then verify TPM 2.0 in Windows.
AMDAMD CPU fTPMEnable firmware TPM, save and confirm the ready state after reboot.
OEM or laptopSecurity DeviceUse the exact model support guide because labels and access controls vary.

After saving, return to tpm.msc. Do not assume the firmware toggle worked until Windows reports that the TPM is ready and the Specification Version is 2.0.

Do not clear TPM. Clearing the processor is a separate destructive security action, not a normal way to turn it on. Protect recovery keys and follow Microsoft guidance if a real TPM reset is ever required.

If VAN9003 remains after Secure Boot and TPM are ready

When msinfo32 and tpm.msc show the correct state, move from firmware troubleshooting to software troubleshooting. Restart Windows fully, install supported Windows and device firmware updates, then test VALORANT again.

Restart after every platform change

A full restart lets Windows and Vanguard read the new security state. Do not rely on a sleeping session.

Update from trusted sources

Use Windows Update and the official device or motherboard support page. Avoid third party driver packs.

Reinstall Riot Vanguard only now

Uninstall Riot Vanguard from Windows Apps, restart, open Riot Client to reinstall it, then restart again when requested.

Collect logs and contact Riot

If the restriction remains, use Riot’s support and log collection process instead of changing unrelated security settings.

A firmware update can reset or alter Secure Boot and TPM settings. If VAN9003 returns after an update, repeat the read only Windows checks before making new changes.

Final VAN9003 checklist

  • BIOS Mode: msinfo32 reports UEFI.
  • Secure Boot State: msinfo32 reports On.
  • TPM status: tpm.msc reports ready for use.
  • TPM specification: tpm.msc reports version 2.0.
  • Recovery key: BitLocker key is backed up and accessible.
  • Vanguard: Windows was restarted after the final change or reinstall.
  • No bypasses: no modified drivers, registry packs or unofficial security workarounds are installed.

If all checks pass and VAN9003 still appears, take screenshots of msinfo32 and tpm.msc with personal identifiers hidden, note the PC model and open a Riot Support ticket. That gives support useful evidence without risking more firmware changes.

VALORANT VAN9003 FAQ

What does VAN9003 mean in VALORANT?

VAN9003 is a Riot Vanguard security restriction commonly connected to the Windows boot security state. Check UEFI mode, Secure Boot and TPM 2.0 before reinstalling the game or changing unrelated settings.

How do I fix VAN9003 on Windows 11?

Open System Information and TPM Management first. Confirm that BIOS Mode is UEFI, Secure Boot State is On and TPM Specification Version is 2.0. Back up the BitLocker recovery key before making any firmware change, then follow the exact instructions from the PC or motherboard manufacturer.

How can I check Secure Boot without entering BIOS?

Press Windows and R, enter msinfo32 and open System Summary. BIOS Mode should read UEFI and Secure Boot State should read On. If either value is different, do not change firmware settings until you have checked BitLocker and the manufacturer guide.

How do I check TPM 2.0 for VALORANT?

Press Windows and R, enter tpm.msc and inspect the status and Specification Version. The TPM should be ready for use and the specification should be 2.0.

Why is Secure Boot enabled in BIOS but off in Windows?

The system may still use Legacy or CSM boot mode, Secure Boot keys may not be enrolled, or the firmware setting may not have been saved correctly. The correct fix depends on the device, so use the manufacturer documentation instead of copying a generic BIOS path.

Should I clear TPM to fix VAN9003?

No. Clearing TPM is not a safe first troubleshooting step and can affect stored security keys. Verify TPM status, save the BitLocker recovery key and follow Microsoft or manufacturer instructions before any TPM reset.

Can reinstalling Riot Vanguard fix VAN9003?

A Vanguard reinstall can repair damaged Vanguard files, but it cannot turn on UEFI, Secure Boot or TPM 2.0. Confirm the platform security checks first, then reinstall Vanguard only if the correct Windows states are already visible.

Can I bypass VAN9003?

Do not use unofficial bypasses, modified drivers or registry packs. They can weaken Windows security, create new Vanguard restrictions and put the system or Riot account at risk. Fix the supported security state or contact Riot Support.