NERFPLZ.LOL
League of Legends error

VAN RESTRICTION 1: Vanguard couldn't verify UEFI Secure Boot

Riot VanguardLeague + VALORANT

The message

VAN: RESTRICTION: 1 - UEFI Secure Boot verification failure.

What it means

Vanguard checked for Secure Boot at startup and couldn't confirm it was on and working, so the game won't launch.

What to try first

Run msinfo32. If Secure Boot State says Off, turn it on in the BIOS. If it already says On, go straight to the BIOS update.

Is it you or Riot? If lots of players are hitting this at once, it's probably the servers. Check League server status before you start reinstalling things.

RESTRICTION: 1 or RESTRICTION: 4?

Two of Riot's restriction codes are about Secure Boot, and their messages are one word apart. Yours has the 1 and says UEFI Secure Boot verification failure. If the number is 4, you want VAN: RESTRICTION: 4 instead; if there's no number, it's the plain VAN: RESTRICTION. The practical difference is in Riot's fix: RESTRICTION: 4 gets the Secure Boot step on its own, while this one adds a BIOS update behind it.

Where the failure comes from

Riot names three causes. Secure Boot is switched off, the PC isn't booting in UEFI mode, or the motherboard firmware is old enough that it needs an update before Vanguard can verify anything. You can see the first two in msinfo32 (BIOS Mode and Secure Boot State). The firmware one has no line of its own there.

Riot's Secure Boot guide spells out that last case. Old firmware can show Secure Boot as on and still fail the policy checks Vanguard runs. So a Secure Boot State of On is no reason to stop; it just means you skip ahead to the BIOS step.

If the Secure Boot switch is grayed out

The same guide says a toggle that's grayed out or won't stay on usually means corrupted or outdated Secure Boot keys, and the fix is restoring the factory keys in the BIOS. That's the procedure on the VAN: STATUS_SB_POLICY page, and it comes with a BitLocker warning you should read first.

Riot's fix, in Riot's order

Riot wants these in order: Secure Boot first, and the BIOS update only if Secure Boot is already on and the restriction is still there.

  1. Turn on Secure Boot

    Run msinfo32. You want BIOS Mode: UEFI and Secure Boot State: On. UEFI with Secure Boot off means flipping one switch in the BIOS.

    If BIOS Mode says Legacy, stop. Your Windows drive has to be converted from MBR to GPT before you switch the BIOS to UEFI, or Windows won't boot at all. Riot's Secure Boot guide covers the conversion and its requirements (64-bit Windows 10 1703 or newer, BitLocker off, no dual boot).

    Riot's guide: Turn on Secure Boot

  2. Update your BIOS

    Find your exact board or laptop model in msinfo32 (System Model or BaseBoard Product) and download the newest BIOS from the maker's support page. Laptops and prebuilts usually get a Windows installer; custom boards use a file on a USB stick and the BIOS's own flash tool (EZ Flash, M-Flash, Q-Flash). Don't power off mid-update.

    Riot's guide: Update your BIOS

Other wordings of the same error

  • VAN RESTRICTION 1
  • Error VAN: RESTRICTION 1
  • VAN: RESTRICTION: 1
  • UEFI Secure Boot verification failure

Source: Riot Games Player Support, Error VAN: RESTRICTION 1, updated June 24, 2026. Riot's steps are paraphrased here, not copied; checked September 25, 2026.