Disable Driver Signature Enforcement (DSE) on Windows 11, Including CMD
Windows 11 uses driver signature enforcement as an important security mechanism. It helps prevent improperly signed or potentially unsafe kernel-mode drivers from loading. This is particularly important on 64-bit versions of Windows, where Microsoft requires kernel-mode drivers to meet digital-signature requirements.
However, there are situations where you may need to install an older, unsigned, or test driver, especially when working with older hardware, specialized devices, or drivers being tested during development.
Windows 11 provides a temporary Disable Driver Signature Enforcement startup option for this purpose. Microsoft notes that this option applies only to the current Windows session and does not permanently disable enforcement.
The safest approach for most beginners is to use Advanced Startup and Startup Settings rather than permanently changing Windows boot configuration.
Disable Driver Signature Enforcement (DSE) on Windows 11

To disable Driver Signature Enforcement on Windows 11 temporarily, open Settings > System > Recovery, select Restart now beside Advanced startup, then choose Troubleshoot > Advanced options > Startup Settings > Restart. When the Startup Settings screen appears, press 7 or F7 to select Disable Driver Signature Enforcement. Windows will then start normally with driver signature enforcement temporarily disabled for that session.
This method does not permanently turn off Windows driver security. After you restart Windows normally again, driver signature enforcement is restored.
Step 1: Save Your Work and Close Your Programs
Before changing Windows startup settings, save any documents or other work you currently have open. This is important because the computer will restart several times while you access the recovery and startup options.
If you are installing a particular driver, make sure you already have the driver installation file available. It is also a good idea to confirm that the driver is actually intended for your version and hardware. Disabling signature enforcement does not make an incompatible driver compatible with your device.
Because driver signature enforcement protects Windows against improperly signed kernel drivers, you should use this procedure only when you have a specific reason to install or test a driver.
Step 2: Open Windows 11 Recovery Settings
Start by opening the Settings app. You can do this by pressing Windows + I on your keyboard.
In Settings, select System from the left side of the window. Scroll down until you find Recovery, and then select it.
You will see several recovery-related options. Look for the Advanced startup section. This section provides access to the Windows Recovery Environment, where you can change certain startup settings.
Step 3: Select Advanced Startup
Under Advanced startup, find the Restart now button.
Select Restart now.
Windows may display a message explaining that the device will restart. Save anything important if you have not already done so, and confirm the restart.
Your computer will then leave the normal Windows 11 desktop and open the Windows Recovery Environment.
Microsoft documents this route as Settings > System > Recovery > Advanced startup > Restart now for accessing startup options.
Step 4: Open the Troubleshoot Menu
After the computer restarts, you will see a blue recovery screen called Choose an option.
Do not select Continue if your goal is to change the driver-signing setting.
Instead, select Troubleshoot.
The Troubleshoot screen contains several recovery and advanced repair options. For Driver Signature Enforcement, you need to continue to the advanced startup settings.
Step 5: Select Advanced Options
On the Troubleshoot screen, select Advanced options.
You will now see several additional Windows recovery tools. Depending on your Windows 11 installation and device configuration, the available options can vary.
Look for Startup Settings.
Startup Settings is the option you need because it allows you to change certain behaviors that Windows uses while starting. Microsoft specifically lists Disable Driver Signature Enforcement as one of the available Startup Settings options.
Step 6: Open Startup Settings
Select Startup Settings.
Windows will explain that changing startup settings can be useful for troubleshooting. You should also see a Restart button.
Select Restart.
Your computer will restart again. This time, instead of immediately loading the Windows 11 desktop, you will see a numbered Startup Settings menu.
Step 7: Choose Disable Driver Signature Enforcement
Look through the Startup Settings list until you find:
7) Disable Driver Signature Enforcement
You can usually select this option by pressing 7 on the keyboard. Microsoft also documents F7 as the keyboard shortcut for this option.
Press 7 or F7.
Windows will now continue starting normally, but Driver Signature Enforcement will be temporarily disabled for the current session.
This is the important distinction: you are not permanently removing Windows’ driver-signing protection. Microsoft states that the F8-style Disable Driver Signature Enforcement option applies only to the current system session and does not persist after restarting.
Step 8: Install or Test the Required Driver
Once Windows 11 finishes starting, sign in normally.
You can now install or test the driver that previously could not be installed because of its signature.
Follow the driver’s own installation instructions carefully. If it is supplied as an installer, run the installer normally. If it requires Device Manager, open Device Manager, locate the relevant device, and follow the manufacturer’s instructions for updating the driver.
Remember that disabling signature enforcement does not verify that the driver is safe, compatible, or stable. You should obtain drivers from a source you trust and make sure the driver is specifically designed for your hardware.
Microsoft describes this temporary startup option primarily as a mechanism for installing or testing drivers that do not satisfy normal signature requirements.
Step 9: Restart Windows Normally
After you have finished installing or testing the driver, restart your computer normally.
You do not need to repeat the Startup Settings procedure to turn the feature back on. The temporary Disable Driver Signature Enforcement setting does not persist across a normal restart.
After Windows starts again, its normal driver-signature enforcement behavior is restored.
This makes the Startup Settings method particularly useful for beginners because you do not have to modify permanent boot configuration settings.
What If F7 Does Not Work?
If pressing F7 does not select the option, try pressing the number 7 instead. On some keyboards, function keys can have special functions, so you may need to hold Fn while pressing F7.
Also, make sure you have actually reached the Startup Settings screen. The F7 option will not work from the earlier Troubleshoot or Advanced Options screens.
If the option is available but Windows still refuses to load the driver, the driver may have other compatibility or security problems. For example, newer Windows security mechanisms can block certain drivers independently of the traditional signature-enforcement setting.
Can You Permanently Disable Driver Signature Enforcement?
Windows does provide other driver-testing configurations, including the TESTSIGNING boot option. Microsoft explains that administrators can use BCDEdit to enable or disable loading of test-signed code.
For example, Microsoft’s documented command for enabling test signing is:
bcdedit /set testsigning on
To turn it off again, Microsoft documents:
bcdedit /set testsigning off
However, this is different from simply selecting Disable Driver Signature Enforcement from Startup Settings. TESTSIGNING changes the boot configuration and requires administrator privileges. Microsoft also warns that changing boot configuration settings incorrectly can potentially make a computer inoperable.
For a very new Windows user, the temporary F7 method is generally easier to understand and safer to use for a one-time driver installation or test.
Disable Driver Signature Enforcement (DSE) on Windows 11 Using CMD
If you prefer using Command Prompt, Windows 11 provides BCDEdit commands for changing boot configuration options related to driver signing and test-signed drivers. You must open Command Prompt with administrator privileges because BCDEdit requires elevated permissions.
For most users, the temporary F7 method described above is preferable when you only need to install or test a driver once.
The CMD method is more appropriate when you specifically need a boot configuration change for driver development or testing.
Step 1: Open Command Prompt as Administrator
Press the Windows key on your keyboard and type Command Prompt.
When Command Prompt appears in the search results, right-click it and select Run as administrator.
Windows may display a User Account Control window asking whether you want to allow the app to make changes to your device. Select Yes.
You should now see an elevated Command Prompt window. The title bar may say Administrator: Command Prompt.
Step 2: Check Your Current Boot Configuration
Before changing anything, it is useful to see the current Windows boot configuration.
In the Administrator Command Prompt, type:
bcdedit
Then press Enter.
Windows will display several boot configuration entries. Look for settings such as testsigning or nointegritychecks if they are already present.
Taking note of the current configuration is helpful because you may need to restore the previous settings later. Microsoft documents BCDEdit /set as a tool for changing individual boot configuration values and recommends caution when modifying BCD settings.
Step 3: Enable Test Signing Using CMD
If your purpose is to test a test-signed driver, Microsoft documents the following BCDEdit command:
bcdedit /set testsigning on
Press Enter.
If the command succeeds, you should see a message indicating that the operation completed successfully.
The TESTSIGNING option allows Windows to load test-signed kernel-mode code. Microsoft states that administrator privileges are required and that you must restart the computer before the change takes effect.
It is important to understand that TESTSIGNING is intended for testing and development. It is not simply a replacement for the normal Windows driver-signing process.
Step 4: Restart Windows 11
After successfully running the command, restart your computer.
You can restart Windows from the Start menu, or type the following command in Command Prompt:
shutdown /r /t 0
Press Enter.
Windows will immediately restart.
After restarting, Windows can load test-signed drivers when the appropriate test-signing configuration is enabled. Microsoft notes that Windows normally displays a Test Mode watermark when test signing is enabled.
Step 5: Install or Test the Required Driver
After Windows starts again, you can proceed with your driver installation or testing.
Make sure the driver comes from a trusted source and is designed for your particular hardware and Windows version. Disabling or changing driver-signing protections does not make an unknown driver safe.
If the driver is being developed or tested by you, make sure it has been properly test-signed. Microsoft notes that when Memory Integrity or HVCI is enabled, an unsigned binary is not supported and the binary must be test-signed.
Step 6: Turn Test Signing Off After Testing
When you have finished testing the driver, it is important to return Windows to its normal configuration.
Open Command Prompt as administrator again.
Type:
bcdedit /set testsigning off
Press Enter.
Then restart your computer.
You can use:
shutdown /r /t 0
After the restart, Windows will no longer use the TESTSIGNING configuration. Microsoft specifically documents bcdedit /set testsigning off for disabling test-signed code loading.
Disable Integrity Checks Using CMD
Another BCDEdit setting that is sometimes used in troubleshooting guides is nointegritychecks.
Microsoft’s BCDEdit documentation describes the option as disabling integrity checks and notes that it cannot be set when Secure Boot is enabled.
If you have a specific testing requirement that calls for this configuration, the command is:
bcdedit /set nointegritychecks on
After making a BCDEdit change, restart Windows for the configuration to take effect.
To restore the normal integrity-checking setting, use:
bcdedit /set nointegritychecks off
Then restart the computer.
Because nointegritychecks changes a boot security setting, it should not be treated as a routine solution for installing random unsigned drivers. Microsoft recommends using Startup Settings as an alternative to BCDEdit when possible because of the risks associated with modifying boot configuration.
Important Difference Between F7 and CMD Methods
The F7 method and CMD method should not be confused.
When you choose Disable Driver Signature Enforcement from Startup Settings, the setting applies to the current Windows session and does not persist after a normal restart. Microsoft documents this specifically as a temporary mechanism for testing or installing an unsigned driver.
The CMD/BCDEdit method, on the other hand, modifies the Boot Configuration Data. For example, TESTSIGNING ON remains configured until you turn it off again with TESTSIGNING OFF.
For a very new user who only needs to install a driver once, the F7 Startup Settings method is simpler. For driver development and repeated testing, BCDEdit and TESTSIGNING may be appropriate when used carefully.
Important Note About Secure Boot
If BCDEdit displays an error such as “The value is protected by Secure Boot policy and cannot be modified or deleted” when you try to enable test signing, Microsoft explains that Secure Boot can prevent this configuration change. Microsoft also notes that BitLocker may affect the ability to modify the setting.
Do not disable Secure Boot simply because a driver installation failed. First determine whether the driver has a properly signed version available from the manufacturer. Secure Boot is an important security feature, and changing it can reduce protection against certain boot-level threats.
Which CMD Command Should You Use?
If your goal is driver development or testing, the Microsoft-documented command is:
bcdedit /set testsigning on
After testing, restore the normal configuration with:
bcdedit /set testsigning off
If you specifically need to change the integrity-check boot setting, BCDEdit documents:
bcdedit /set nointegritychecks on
and:
bcdedit /set nointegritychecks off
The latter option has additional restrictions, including the fact that it cannot be enabled when Secure Boot is enabled.
FAQs
What is Driver Signature Enforcement in Windows 11?
Driver Signature Enforcement is a Windows security mechanism that checks whether kernel-mode drivers meet required digital-signature policies before they are loaded. This helps reduce the risk of unsafe or untrusted drivers running at a highly privileged level.
Does disabling DSE permanently turn off driver security?
No. Selecting Disable Driver Signature Enforcement from Startup Settings is temporary. Microsoft states that this setting applies only to the current Windows session and does not persist after a restart.
Which key should I press to disable Driver Signature Enforcement?
When the Startup Settings screen appears, press 7 or F7 to disable Driver Signature Enforcement.
Will my files be deleted?
No. Using the Startup Settings option does not normally delete your personal files. It changes how Windows starts for that particular session.
Nevertheless, it is always sensible to save your work before restarting the computer.
Why does Windows block unsigned drivers?
Unsigned or improperly signed kernel drivers can introduce security vulnerabilities, instability, or malicious code into the operating system. Windows therefore uses driver-signing requirements to help protect the kernel.
Why does Windows still reject my driver after I press F7?
The driver may have another compatibility problem, may not support your Windows version or processor architecture, or may be blocked by another Windows security mechanism. Disabling traditional signature enforcement does not guarantee that every driver will load.
Windows 11 also has newer Windows Driver Policy protections that can block drivers that do not meet applicable signing requirements. Microsoft recommends obtaining a properly signed driver from the driver publisher rather than disabling security protections when possible.
Is the F7 method better than using BCDEdit?
The two methods serve different purposes. F7 provides a temporary startup option for the current session, while BCDEdit TESTSIGNING changes boot configuration and is primarily intended for driver development and testing. For a beginner who needs to install a driver once, the temporary Startup Settings approach is simpler.
Summary
Disabling Driver Signature Enforcement on Windows 11 can be useful when you need to install or test a driver that Windows normally refuses because of its signature. The simplest method is to open Settings > System > Recovery, select Restart now under Advanced startup, and then navigate through Troubleshoot > Advanced options > Startup Settings > Restart. When the Startup Settings menu appears, press 7 or F7 to select Disable Driver Signature Enforcement.
Once Windows starts, you can install or test the required driver. After you restart Windows normally, the temporary setting is removed and normal driver-signature enforcement resumes.
Because driver signing is an important security layer, it is preferable to use a properly signed and compatible driver whenever one is available.
