Updated: October 2026
Before Windows shows a logo, the firmware on the motherboard has already checked the hardware, picked a disk and handed over control. On any PC that runs Windows 11, that firmware is UEFI, even when the setup screen still says BIOS. Here's what UEFI is, how UEFI vs BIOS plays out on real machines, and how to move an old install over without a reimage.
What Is UEFI?
UEFI stands for Unified Extensible Firmware Interface. It's the firmware that starts a PC: it initializes the hardware, finds a boot loader and hands control to the operating system. It replaced the legacy BIOS that PCs used since the 1980s.
UEFI is a published specification, not a product. Intel started it as EFI for Itanium servers and stopped developing it at version 1.10 in July 2005. The UEFI Forum took over and released UEFI 2.0 in January 2006. Microsoft lists more than 140 companies in the forum, including AMD, Intel, Microsoft, Dell, HP and Lenovo. The current version, 2.11, was published in December 2024.
The naming causes most of the confusion. Motherboard vendors still label the setup screen "BIOS", and techs still say "go into the BIOS". On a modern PC, that screen is UEFI firmware. "Legacy BIOS" means the old boot method, which UEFI can emulate through a Compatibility Support Module (CSM).
UEFI vs BIOS: What Changes on a Real Machine
The two firmware types start a PC in different ways, and that difference touches the disk, security and deployment.
| Legacy BIOS | UEFI | |
|---|---|---|
| Disk partition style it boots from | MBR | GPT (Windows boots UEFI only from GPT) |
| Partitions | 4 primary, more needs an extended partition | 128 in Windows |
| Boot disk size | 2 TB limit on MBR | Beyond 2 TB |
| Where boot code lives | A tiny boot sector at the start of the disk | Files on a FAT32 EFI System Partition (about 100 MB) |
| Secure Boot | No | Yes |
| Windows 11 | Not supported | Required ("UEFI, Secure Boot capable") |
Microsoft's own list of UEFI benefits adds faster boot and resume, multicast deployment and support for firmware drivers. The security side matters most for IT: Secure Boot, Credential Guard and Exploit Guard all require UEFI firmware.
Legacy mode is on its way out. Intel announced in November 2017 that it would drop CSM support from client platforms by 2020. Older desktops and older images still run in legacy mode, though, which is why the next two sections exist.
Chris Titus walks through the same split with a live disk, including how GPT and MBR look side by side:
How to Check Whether a PC Boots in UEFI Mode
Three checks answer the question in under a minute.
Open System Information (msinfo32) and read BIOS Mode. It says UEFI or Legacy. Then check the disk:
powershellGet-Disk | Format-Table Number, FriendlyName, PartitionStyle Confirm-SecureBootUEFI
PartitionStyle shows MBR or GPT for each disk. Confirm-SecureBootUEFI needs an elevated prompt. It returns True or False on a UEFI machine, and "Cmdlet not supported on this platform" on a legacy BIOS one. In WinPE, the registry value PEFirmwareType under HKLM\System\CurrentControlSet\Control returns 0x1 for BIOS and 0x2 for UEFI.
The combination tells you what to do next. UEFI plus GPT is done. Legacy plus MBR on Windows 10 or 11 is a conversion candidate. UEFI switched on in firmware with an MBR boot disk won't boot at all. Changing firmware boot settings before running these checks is how a PC ends up stuck, as in this r/techsupport thread from September 2026:
How to Get Into UEFI Settings From Windows
The vendor key at power-on still works: Esc, Delete, F1, F2, F10, F11 or F12 depending on the manufacturer. Fast boot often skips the prompt, so there are two easier ways.
From Windows, hold Shift while selecting Restart, then go to Troubleshoot > Advanced options > UEFI Firmware Settings. From a command prompt, this restarts straight into the firmware screen:
codeshutdown /r /fw /t 0
The /fw switch sends the next restart to the firmware interface. It's handy on a remote session where nobody can press a key at the right moment, as long as someone is on site to use the screen that follows.
Moving From Legacy BIOS to UEFI With MBR2GPT
Windows ships a tool that converts a system disk from MBR to GPT without deleting data. It lives in Windows\System32 on supported versions of Windows 10 and 11. Microsoft designed it for WinPE, and the /allowFullOS switch lets it run from inside Windows.
Before converting, the disk has to pass Microsoft's checks: MBR style, at most three primary partitions, no extended or logical partitions, one active system partition, and a little free space at the start and end of the disk. Always validate first:
codembr2gpt /validate /disk:0 /allowFullOS mbr2gpt /convert /disk:0 /allowFullOS
Three things catch people out:
- BitLocker. Suspend protection before converting. Microsoft notes you then delete and recreate the protectors, and a BitLocker-encrypted volume that wasn't suspended fails with return code 6. Our BitLocker guide covers escrowing the recovery key first.
- The firmware switch. The tool ends with "Before the new system can boot properly you need to switch the firmware to boot to UEFI mode!" Convert first, then switch the firmware, then turn off CSM.
- There's no undo. The tool warns that the changes can't be undone. Take an image backup before you start.
Configuration Manager and MDT can run the same conversion as part of a task sequence, which is how it scales past a handful of desks.
Secure Boot, Briefly
Secure Boot is the UEFI feature that checks each boot component's signature before it runs. If a boot loader isn't signed by a trusted key, the firmware refuses it. That blocks bootkits, malware that loads before Windows and hides from everything that runs after.
It isn't a solved problem. CVE-2023-24932 is a Secure Boot bypass used by the BlackLotus bootkit, and Microsoft first released protections on May 9, 2023. The certificates behind Secure Boot also expire: Microsoft's KEK CA 2011 on June 24, 2026, UEFI CA 2011 on June 27, 2026 and Windows Production PCA 2011 on October 19, 2026. Devices without the 2023 replacements keep booting, but Microsoft says they lose new early-boot protections, including Boot Manager updates and revocation lists.
Windows 11 also needs TPM 2.0, which lives in the same firmware menus. The TPM 2.0 guide covers turning it on.
UEFI Firmware Updates Across a Fleet
UEFI firmware gets updated like any other code, and it matters more than most because it runs first. Windows can deliver firmware as capsule updates through Windows Update. Vendors also ship their own tools and packages. The firmware update guide covers everything on the board beyond the BIOS itself.
Two habits keep fleet updates quiet. Suspend BitLocker before a firmware update, because firmware and Secure Boot changes are a classic recovery-key trigger. And keep an inventory of boot mode, partition style and Secure Boot state, so you know which machines are still on legacy BIOS before a Windows 11 project starts. OpenFrame can run that check as a script across a client's devices and collect the output in one place.
UEFI, in Short
UEFI is the firmware that starts every Windows 11 PC. It boots from GPT disks, supports Secure Boot and replaces the 16-bit legacy BIOS that some older images still use. Check boot mode with msinfo32, convert legacy installs with MBR2GPT in the right order, and keep the Secure Boot certificates current.
For the next step on the same hardware, read what a BIOS update does before you schedule one.
Content Marketing Lead
Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.
