Home/Troubleshooting guide
VALORANT VAN9003 guide

Valorant VAN9003 on Windows 11? Check Secure Boot first

Confirm the exact Riot code and read the Secure Boot state from Windows before entering firmware. A game launch block should not become a no-boot or BitLocker recovery problem.

Unbranded Windows gaming setup with shield, firmware chip, and warning symbols on the monitor
Short answer. Riot says VAN9003 means Secure Boot is not enabled as Vanguard requires. Press Windows key + R, enter msinfo32, and check BIOS Mode and Secure Boot State before opening firmware settings. A normal Windows 11 result is BIOS Mode: UEFI and Secure Boot State: On. If the PC uses Legacy or CSM boot, is encrypted without an accessible recovery key, or already reports the required state, stop and use the exact manufacturer or Riot support path.
Protect the boot path first. Do not clear the TPM, reset Secure Boot keys, convert a disk, change storage-controller mode, flash firmware, disable security controls, or reinstall Windows from a generic game guide. Confirm the exact PC or motherboard model and make sure the matching BitLocker recovery key is available outside the affected computer before an authorized firmware change.

Confirm VAN9003, not a nearby Vanguard code

Copy the exact code and message before changing anything. Riot says VAN9003 appears when Vanguard requires Secure Boot and does not find it enabled. VAN9001 is the nearby TPM 2.0 code, so the numbers should not be treated as interchangeable.

This guide covers VALORANT on Windows 11 when Riot Vanguard stops the game before normal play. A game that passes Vanguard and then freezes, closes, or shows a graphics error belongs in a broader game crash diagnosis. A VAN: RESTRICTION message also has its own Riot requirements.

Record the full message, Windows edition and version, whether the PC is personally owned or managed, and whether the error began after a Windows, Riot, firmware, or hardware change. Timing is evidence, but it does not prove what caused the block.

Read BIOS Mode and Secure Boot State in Windows

Press Windows key + R, enter msinfo32, and press Enter. In System Information, find BIOS Mode and Secure Boot State. This is a read-only check. Save the two values with the exact System Model and BaseBoard Product shown on the same screen.

Windows resultWhat it means for this guideNext step
BIOS Mode: UEFI
Secure Boot State: On
Windows already reports the state Riot asks for.Do not toggle firmware settings. Preserve the mismatch for Riot or the manufacturer.
BIOS Mode: UEFI
Secure Boot State: Off
The disk and boot mode may already support Secure Boot, but the setting is not active in Windows.Verify recovery access and use the exact model's current manufacturer instructions.
BIOS Mode: Legacy
Secure Boot State: Off or Unsupported
Secure Boot requires UEFI, and the current boot path may not be ready for a direct switch.Stop. Use manufacturer or qualified support before any disk or firmware conversion.
Secure Boot State is unavailable or unclearThe evidence is incomplete.Do not guess. Confirm the exact hardware and current support documentation.

Riot's current Windows 11 specifications also require TPM 2.0 and UEFI Secure Boot. That does not make TPM the cause of VAN9003. Keep the exact error code attached to the correct requirement.

Check encryption and the recovery key before firmware

Firmware and Secure Boot changes can alter the measurements used by device encryption. Riot warns that resetting Secure Boot keys can trigger BitLocker recovery. Before an authorized change, identify whether BitLocker or Device Encryption is active and confirm access to the matching 48-digit recovery key from another device.

Do not place the key in a screenshot, chat, support post, or article comment. Keep it in the Microsoft account, work or school account, printout, USB file, or administrator-managed location where it was originally stored. The BitLocker recovery guide explains how to match a recovery key ID if a recovery screen is already present.

Stop if the key cannot be found, the computer is managed, the system uses more than one operating system, the machine has custom Secure Boot keys, or the storage layout is unclear. A VALORANT launch block is less serious than losing access to Windows or encrypted files.

Use the exact PC or motherboard instructions

Riot says firmware menus vary and tells players to follow the manufacturer for the exact device. Use System Information to record System Manufacturer, System Model, BaseBoard Manufacturer, and BaseBoard Product. Then open the support page for that exact model.

If Windows reports UEFI with Secure Boot Off, the manufacturer's instructions may describe where the supported Secure Boot control appears. Follow the current document for the exact model and firmware revision. Record the old value, change only the documented setting, save once, and let Windows start normally.

Do not copy a firmware sequence from a different motherboard, laptop, or video. Names such as CSM, Windows UEFI Mode, Platform Key, Standard Mode, and Factory Keys can have different consequences across vendors. Avoid any guide that asks for unrelated security reductions or several changes at once.

After Windows starts, reopen msinfo32. Confirm BIOS Mode and Secure Boot State again, then launch VALORANT once. Keep the before and after values. A successful launch supports the state change, but it does not prove that every future Vanguard error has the same cause.

If Windows already says Secure Boot is On

Do not turn Secure Boot off and on as a blind reset. Do not clear the TPM or reset Secure Boot keys. Capture the VAN9003 message, System Information values, exact device model, current firmware version, Windows version, Riot Client version, Vanguard version when available, and when the error appeared.

Riot says outdated firmware or incomplete Secure Boot support can leave a setting that looks enabled but does not pass the required policy checks. Check the exact manufacturer's support page for a current firmware notice. Firmware updates carry power and recovery risk, so use only the manufacturer's file and instructions after backups and recovery access are confirmed.

If the current state already matches Riot's requirement and no model-specific notice applies, submit the redacted record to Riot Support. Remove the BitLocker key, Riot ID, email address, serial number, device name, personal paths, and unrelated account data before sharing screenshots or logs.

Where OmniMend fits

On a supported Windows 10 or 11 x64 PC that still starts normally, OmniMend can help collect and organize read-only system and application evidence. Keep the exact Riot code, Windows version, BIOS Mode, Secure Boot State, device model, encryption status, change history, and support result together.

OmniMend does not enter firmware, enable Secure Boot, clear the TPM, reset keys, convert disks, recover a BitLocker key, bypass Vanguard, or guarantee that VALORANT will launch. The current product does not support Windows Arm as a host. A managed or nonbooting PC belongs with the administrator, manufacturer, or qualified support.

If a separate evidence record would help on a supported PC, review OmniMend's diagnostic scope or download OmniMend. Read the privacy information before sharing any report or screenshot.

Editorial sources

Checked September 20, 2026 against Riot Games Support's VAN9003 definition, Secure Boot guide, and VALORANT PC requirements, plus Microsoft's BitLocker recovery-key guidance. Riot supplies the exact-code meaning, Windows state checks, manufacturer boundary, Legacy boot warning, and Secure Boot key warning. Microsoft supplies the recovery-key location and protection facts. Recent matching reports were reviewed for current symptom language only. They do not establish a universal cause or safe firmware recipe. OmniMend added the evidence table, stop conditions, privacy limits, internal routing, and product scope. OmniMend is not affiliated with Riot Games, VALORANT, Microsoft, or any PC manufacturer.

Read the Windows state first.
Protect the recovery path.

A clean evidence record is safer than guessing through firmware menus.

Get OmniMend