Access Microsoft Surface Boot Settings

to toggle TPM and secure boot

Posted by Trond Aarskog on October 05, 2021

tldr; Press and hold 🔊 (volume-up) when (re-)booting to enter the magical UI

Why would I?

Windows 11 requires secure boot and TPM enabled. As of October 2021 most tools that copy the installation medium to USB requires that you disable secure boot for the USB to be able to boot.


  1. Shutdown your Surface
  2. Press and hold the volume-up button
  3. Press and release the power button (keep pressing volume-up)
  4. Release volume-up when the Admin UI shows up
  5. Do your changes such as enabling TPM and toggle secure boot

Windows 11

If you are installing Windows 11 do the following:

  1. Disable secure boot following the guide above
  2. Insert your USB with the Windows installation
  3. Go through the initial steps setting language, keyboard, etc.
  4. When the installation initiates a restart quickly press and hold volume-up as described above
  5. Enable secure boot and exit to restart