NERFPLZ.LOL
League of Legends error

VAN 9003: Secure Boot is off

Riot VanguardLeague + VALORANT

The message

VAN9003. This build of Vanguard requires secure boot to be enabled in order to play.

What it means

Vanguard requires Secure Boot, and it isn't enabled on this PC. VALORANT uses the same Vanguard, so it gets blocked by the same check.

What to try first

Run msinfo32 and read BIOS Mode before anything else. On UEFI it's one BIOS switch; on Legacy, don't touch the BIOS until the drive is converted.

Is it you or Riot? If lots of players are hitting this at once, it's probably the servers. Check League server status before you start reinstalling things.

Which kind of VAN 9003 you have

Riot's article for 9003 is one line of explanation and a pointer to its Secure Boot guide. How much work that is depends on a single line in msinfo32. If BIOS Mode reads UEFI, you're a setting away. If it reads Legacy, you've got a drive conversion ahead of you first, and getting that order wrong leaves Windows unable to start.

Riot's guide wants a backup before the conversion, because turning an MBR drive into GPT can't be undone. It also lists a few conditions besides the ones in the step below: no more than three partitions on the MBR disk, a BIOS that supports UEFI, and Secure Boot still off while you convert.

When the Secure Boot option won't turn on

A grayed-out Secure Boot switch, according to Riot, usually points to corrupted or outdated keys. The fix is restoring the factory keys from the BIOS's key management section (the option goes by Restore Factory Keys on some boards, and by Reset to Setup Mode or Install Default Secure Boot Keys on others), then enabling Secure Boot again.

Suspend BitLocker before you reset keys. Riot warns that new keys change the TPM's measurements, which triggers BitLocker recovery on the next boot, and without the recovery key you're locked out of Windows.

Secure Boot says On and 9003 still appears

Riot's explanation is an old BIOS that reports Secure Boot as enabled but fails the policy checks Vanguard runs. Update the BIOS for your exact board, which msinfo32 lists as BaseBoard Manufacturer and BaseBoard Product. If the hardware can't do UEFI or Secure Boot even after that, Riot says it may not meet Vanguard's requirements.

Riot's TPM 2.0 guide also lists VAN 9003 among the codes it helps with, even though the 9003 article itself only links the Secure Boot guide. If you're sorting out firmware settings anyway, check tpm.msc while you're in there. A separate code, VAN: STATUS_SB_POLICY, is the one that points specifically at the key reset.

Riot's fix, in Riot's order

  1. Turn on Secure Boot

    Run msinfo32. You want BIOS Mode: UEFI and Secure Boot State: On. UEFI with Secure Boot off means flipping one switch in the BIOS.

    If BIOS Mode says Legacy, stop. Your Windows drive has to be converted from MBR to GPT before you switch the BIOS to UEFI, or Windows won't boot at all. Riot's Secure Boot guide covers the conversion and its requirements (64-bit Windows 10 1703 or newer, BitLocker off, no dual boot).

    Riot's guide: Turn on Secure Boot

Other wordings of the same error

  • VAN 9003
  • Error VAN 9003
  • VAN 9003 secure boot
  • This build of Vanguard requires secure boot

Source: Riot Games Player Support, Error VAN 9003, updated May 11, 2026. Riot's steps are paraphrased here, not copied; checked September 25, 2026.