VALORANT Vanguard Error Guide
VALORANT VAN 9003 Fix: Secure Boot and TPM 2.0
Check whether Windows actually detects UEFI, Secure Boot, and TPM 2.0 before changing BIOS settings or reinstalling Riot Vanguard.
Last updated: July 13, 2026
The VALORANT VAN 9003 error usually appears when Riot Vanguard does not detect the required Secure Boot state. On Windows 11, TPM 2.0 should also be checked because VALORANT requires both TPM 2.0 and UEFI Secure Boot.
Do not begin by changing random BIOS options. First use System Information and the TPM Management Console to confirm what Windows currently detects. Change firmware settings only when the Windows results show that Secure Boot or TPM is not active.
Fast VAN 9003 diagnosis
Run msinfo32 → confirm BIOS Mode is UEFI and Secure Boot State is On → run tpm.msc → confirm TPM is ready and Specification Version is 2.0 → change BIOS settings only when one result is incorrect → verify the settings again in Windows → reinstall Vanguard only after the security requirements are confirmed.
Back up the BitLocker recovery key before firmware changes
A firmware or security change can cause an encrypted PC to request its BitLocker recovery key. Confirm that the recovery key is available before changing Secure Boot, CSM, UEFI, or TPM settings. Do not clear the TPM to fix VAN 9003.
Contents
- Use the five-minute diagnosis table
- Understand what causes VAN 9003
- Check Secure Boot with msinfo32
- Check TPM 2.0 with tpm.msc
- Enable Secure Boot and TPM in BIOS
- Handle Legacy BIOS and CSM safely
- Verify that Windows detects the changes
- Reinstall Riot Vanguard when needed
- Continue when VAN 9003 remains
- Avoid risky troubleshooting methods
- Follow the final checklist
- Frequently asked questions
VAN 9003 Five-Minute Diagnosis
| Windows result | Meaning | Next action |
|---|---|---|
| BIOS Mode: UEFI Secure Boot State: On TPM 2.0 ready |
The basic security requirements appear satisfied | Restart fully, update Windows, and reinstall Vanguard if the error remains |
| BIOS Mode: UEFI Secure Boot State: Off |
Secure Boot is disabled | Back up the recovery key and enable Secure Boot in UEFI |
| BIOS Mode: Legacy | The current installation is not booting in UEFI mode | Do not switch immediately; check the disk partition style and manufacturer instructions |
| Secure Boot State: Unsupported | Legacy, CSM, firmware keys, or configuration may be preventing Secure Boot | Check the exact PC or motherboard documentation |
| Compatible TPM cannot be found | Intel PTT, AMD fTPM, or the security device may be disabled | Check UEFI Security or Trusted Computing settings |
| TPM ready, Specification Version below 2.0 | The detected TPM does not meet the Windows 11 requirement | Check official hardware and firmware support |
Confirm the error code before changing anything
VAN 9003 points toward Secure Boot compliance. VAN 57, VAN 1067, and other Vanguard errors can involve different services, restarts, incompatible software, or Vanguard initialization problems.
Why VALORANT VAN 9003 Appears
Riot Vanguard checks whether the Windows security environment meets its requirements. VAN 9003 is associated with Secure Boot, while Windows 11 VALORANT systems should also have TPM 2.0 and UEFI Secure Boot available.
| Condition | Problem state | Check location |
|---|---|---|
| Boot mode | Legacy mode or CSM active | System Information and UEFI |
| Secure Boot | Disabled, unsupported, or missing keys | System Information and UEFI |
| TPM | Disabled or specification below 2.0 | tpm.msc and UEFI Security settings |
| Firmware changes | A BIOS update or reset disabled security options | Recent update history and UEFI |
| Vanguard | Security settings are correct but the installation remains inconsistent | Installed apps and Riot Client |
The error can appear after a BIOS update, motherboard reset, Windows reinstall, storage replacement, dual-boot change, firmware-key reset, or security-setting change. These events can disable Secure Boot, re-enable CSM, or change TPM availability.
1. Check Secure Boot With msinfo32
- Press Windows + R.
- Type msinfo32.
- Press Enter.
- In System Summary, find BIOS Mode.
- Find Secure Boot State.
- Record both results before opening UEFI settings.
| Displayed result | Meaning | Action |
|---|---|---|
| BIOS Mode: UEFI Secure Boot State: On |
Windows detects Secure Boot correctly | Continue to TPM and Vanguard checks |
| BIOS Mode: UEFI Secure Boot State: Off |
Secure Boot is currently disabled | Enable it using model-specific UEFI instructions |
| BIOS Mode: Legacy | Windows is not booting through UEFI | Check MBR or GPT and supported conversion steps first |
| Secure Boot State: Unsupported | The current boot or firmware configuration does not expose Secure Boot to Windows | Review CSM, UEFI mode, and Secure Boot keys |
Do not switch Legacy to UEFI immediately
A Windows installation using a Legacy boot configuration and an MBR system disk may fail to boot after a direct UEFI-only change. Back up important files and follow the PC or motherboard manufacturer’s official migration instructions.
2. Check TPM 2.0 With tpm.msc
- Press Windows + R.
- Type tpm.msc.
- Press Enter.
- Confirm that the status says the TPM is ready for use.
- Under TPM Manufacturer Information, find Specification Version.
- Confirm that the displayed version is 2.0.
When Windows says that a compatible TPM cannot be found, the firmware-based TPM may be disabled. Intel systems commonly label it PTT or Intel Platform Trust Technology. AMD systems commonly use AMD fTPM, AMD PSP fTPM, or a similar name.
The menu may not be named TPM
Look under Security, Advanced, Trusted Computing, Security Device Support, Computing Trust, PTT, or fTPM. The exact name and location depend on the motherboard, laptop model, and firmware version.
3. Enable Secure Boot and TPM in UEFI
Enter firmware settings only after Windows has shown which requirement is missing. Use the official support page for the exact PC, laptop, or motherboard model.
| Firmware option | Expected state | Notes |
|---|---|---|
| Boot Mode | UEFI | Do not force this change on a Legacy installation without preparation |
| CSM or Legacy Boot | Disabled when the system is ready for UEFI-only boot | Secure Boot may remain unavailable while CSM is active |
| Secure Boot | Enabled | Some systems require Standard mode or default Secure Boot keys |
| Intel PTT | Enabled | Firmware TPM on many Intel systems |
| AMD fTPM | Enabled | Firmware TPM on many AMD systems |
.png)
Secure Boot is enabled but not active
Some firmware separates Enabled from Active. CSM may still be on, the boot mode may remain Legacy, or the default Secure Boot keys may not be installed. Check the manufacturer’s model-specific instructions before changing key-management options.
4. Handle Legacy BIOS and CSM Safely
When msinfo32 shows Legacy, Secure Boot cannot simply be enabled in the current configuration. The system disk may use MBR, Windows may have been installed in Legacy mode, or CSM may be required by the current boot setup.
- Back up important files.
- Confirm that the BitLocker recovery key is available.
- Open Disk Management.
- Check the partition style of the Windows system disk.
- Find the exact motherboard or PC model.
- Read the official UEFI migration instructions.
- Do not disable CSM until the Windows installation is prepared to boot through UEFI.
- Stop and restore the original setting if Windows no longer boots.
Avoid random MBR-to-GPT instructions
Disk conversion changes the boot structure. Use Microsoft and manufacturer documentation for the exact configuration, and do not perform it without a verified backup and recovery plan.
5. Verify the Changes in Windows
A firmware menu showing Enabled does not prove that Windows detects the feature correctly. Always confirm the result after saving and restarting.
- Save the firmware changes and exit.
- Confirm that Windows starts normally.
- Run msinfo32.
- Confirm BIOS Mode: UEFI.
- Confirm Secure Boot State: On.
- Run tpm.msc.
- Confirm that TPM is ready for use.
- Confirm Specification Version: 2.0.
- Restart the PC one more time before launching VALORANT.
Successful security baseline
The expected Windows results are BIOS Mode: UEFI, Secure Boot State: On, TPM ready for use, and Specification Version: 2.0.
6. Reinstall Riot Vanguard Only After Verification
Reinstalling Vanguard cannot enable Secure Boot or TPM. Use this step only when Windows already reports the correct security state and VAN 9003 still appears.
- Close VALORANT and the Riot Client.
- Open Settings → Apps → Installed apps.
- Find Riot Vanguard.
- Uninstall Riot Vanguard.
- Restart the PC.
- Launch VALORANT from the Riot Client.
- Allow Vanguard to install again.
- Restart the PC when prompted.
- Launch VALORANT and check whether VAN 9003 returns.
VALORANT launches but runs poorly?
Use the VALORANT FPS and stuttering guide after the security error is fixed. FPS settings do not resolve VAN 9003.
VAN 9003 Still Appears
| Situation | Possible cause | Next action |
|---|---|---|
| UEFI says Secure Boot enabled, but msinfo32 says Off | CSM, key state, boot mode, or firmware configuration | Check CSM and Secure Boot mode using model-specific documentation |
| TPM 2.0 is missing | PTT or fTPM disabled, unsupported, or hidden | Check Security Device or Trusted Computing settings |
| All Windows security results are correct | Vanguard, Windows update, or firmware recognition issue | Update Windows, restart fully, and reinstall Vanguard |
| The error began after a BIOS update | Security options or keys were reset | Recheck Secure Boot, CSM, PTT, and fTPM |
| Windows no longer starts | Unsupported Legacy-to-UEFI change or boot configuration | Restore the original firmware setting and use manufacturer support |
| BitLocker recovery screen appears | Firmware or security change triggered recovery | Use the matching recovery key and do not clear the TPM |
- Install pending Windows updates.
- Restart Windows fully.
- Confirm that the error code is still VAN 9003.
- Capture msinfo32 and tpm.msc screenshots.
- Record the PC or motherboard model and BIOS version.
- Check the manufacturer’s latest support instructions.
- Submit the collected information to Riot Support when all requirements appear correct.
Useful information for support
Include the exact error message, Windows version, motherboard or laptop model, BIOS version, BIOS Mode, Secure Boot State, TPM status, TPM specification version, recent firmware changes, and whether Vanguard was reinstalled.
Troubleshooting Methods to Avoid
| Avoid | Risk | Use instead |
|---|---|---|
| Unofficial Vanguard patch files | Malware, account risk, and unsupported changes | Official Riot Client installation |
| Changing many BIOS settings together | Boot failure and unclear cause | Change only confirmed Secure Boot or TPM settings |
| Switching Legacy to UEFI immediately | Windows may stop booting | Check the disk and official conversion process |
| Deleting the Vanguard folder manually | Permissions and incomplete removal | Use Installed apps and restart |
| Clearing or resetting the TPM | BitLocker, Windows Hello, and encryption access problems | Check only TPM readiness and version |
| Updating BIOS without the exact model | Wrong firmware and possible boot failure | Verify model, version, and manufacturer notes |
| Reinstalling Windows immediately | Large time cost without fixing firmware settings | Check msinfo32, tpm.msc, and UEFI first |
VALORANT VAN 9003 Checklist
Step 1 — Run msinfo32 and record BIOS Mode and Secure Boot State.
Step 2 — Run tpm.msc and confirm TPM readiness and Specification Version 2.0.
Step 3 — Back up the BitLocker recovery key before firmware changes.
Step 4 — Use exact manufacturer instructions for the PC or motherboard.
Step 5 — Enable Secure Boot and PTT or fTPM only when Windows shows they are missing.
Step 6 — Do not force Legacy-to-UEFI conversion without a backup and plan.
Step 7 — Save firmware changes and verify them again in Windows.
Step 8 — Install Windows updates and restart fully.
Step 9 — Reinstall Riot Vanguard only after UEFI, Secure Boot, and TPM are correct.
Step 10 — Contact Riot or the hardware manufacturer with recorded results when the error remains.
Key takeaway
VAN 9003 should be diagnosed in Windows before BIOS changes. Confirm UEFI and Secure Boot with msinfo32, confirm TPM 2.0 with tpm.msc, back up the BitLocker recovery key, use model-specific firmware instructions, verify the result again in Windows, and reinstall Vanguard only after the security requirements are correct.
Frequently Asked Questions
Can reinstalling VALORANT fix VAN 9003?
Not when Secure Boot or TPM is disabled. Check msinfo32 and tpm.msc before reinstalling the game or Vanguard.
Secure Boot is enabled in BIOS. Why does VAN 9003 continue?
Windows may still report Secure Boot as Off because CSM is active, the system boots in Legacy mode, or Secure Boot keys are not active. Check msinfo32 rather than relying only on the firmware menu.
Does VAN 9003 require TPM 2.0?
VAN 9003 primarily points to Secure Boot. On Windows 11, VALORANT also requires TPM 2.0, so both should be verified.
What should I do when BIOS Mode shows Legacy?
Do not switch directly to UEFI. Check the system-disk partition style, back up important files, confirm the recovery key, and follow official migration instructions.
Why is the Secure Boot option gray?
CSM or Legacy Boot may still be enabled, or the firmware may require Standard Secure Boot mode and default keys. Check documentation for the exact model.
Should I clear the TPM to fix VAN 9003?
No. Clearing the TPM can affect BitLocker, Windows Hello, and stored security keys. VAN 9003 troubleshooting normally requires checking whether TPM is enabled and version 2.0, not resetting it.
Do I have to update the BIOS?
Not automatically. First check whether the current firmware can enable Secure Boot and TPM correctly. Update only when the manufacturer documents a relevant fix for the exact model.
Why did VAN 9003 appear after a BIOS update?
The update may have reset Secure Boot, CSM, PTT, fTPM, or security keys to default values. Check all four areas again.
Related guides
Official references
.png)