If we find PCs that are too cheat-capable (e.g., because of outdated Windows or specific configurations that are conducive to allow cheating), Vanguard will restrict that PC's access to VALORANT and display an error message. The VAN: RESTRICTION error message tells you what settings are necessary to remove the restriction.
IMPORTANT: About editing your BIOS settings
If you’re not familiar with navigating through your BIOS, please reach out to a professional. Incorrectly configuring BIOS settings can cause issues with your computer–including failure to start up.
The BIOS is highly variable depending on the brand and type of computer or motherboard you are using. So we highly recommend that you reach out to your computer or motherboard manufacturer's support resources to assist you.
Use this diagram to understand the dependencies between the tasks.
For your actual checklist of tasks, refer to the specific VAN: RESTRICTION error message you received from Vanguard.
1️⃣ Enable TPM 2.0
How do I check if Trusted Platform Module (TPM) is enabled or disabled?
- Press Windows Key + R.
- Type tpm.msc and press Enter.
- Look at the status. If it's enabled/ready for use, you're good to go! If it's disabled, follow these steps:
Enable TPM:
- Press Windows Key + R.
- Type msinfo32 and press Enter. Identify your motherboard brand and CPU.
- Find videos for steps on "How to enable TPM on (insert motherboard name) with (insert CPU name)" or visit the manufacturer's website for your motherboard and follow their instructions.
TPM 2.0 help for common motherboards
Please note: The resources included in this guide are not monitored or owned by Riot Games, so use them at your own risk!
Here are a few support resources with steps on how to enable TPM 2.0:
Microsoft also has a general page on how to enable TPM 2.0: https://support.microsoft.com/en-us/windows/enable-tpm-2-0-on-your-pc-1fd5a332-360d-4f46-a1e7-ae6b0c90645c#bkmk_enable_tpm
Potential Issues:
🛠️ Issue 1: Cannot load management console
- Go to Windows Defender and click Device Security > Security processor details for TPM status. If nothing shows up, your TPM may still be turned off.
- If your console management still won't load, it is a bug on your CPU/Motherboard brand. To resolve:
- Identify your motherboard brand and exact board name via msinfo32.
- Search for the latest BIOS update for your motherboard.
- Visit the manufacturer's website for your motherboard and follow their instructions for updating the BIOS.
2️⃣ Switch to UEFI
How to check the Secure Boot state and BIOS Mode?
- Press Windows Key + R.
- Type msinfo32 and press Enter.
- Look at Secure Boot State and BIOS Mode.
If it says BIOS Mode: UEFI and Secure Boot State: On you're good to go.📷 Screenshot
If it says BIOS Mode: Legacy, check if your OS Drive is on MBR or GPT for the OS drive. If it's MBR (Master Boot Record), you might need to convert it to GPT (GUID Partition Table).
If your BIOS Mode is Legacy: How to check if your OS Drive is using MBR or GPT partition style
- Search disk management in your Windows search bar and press Enter.
- Right-click your disk(s) in the bottom grid and click Properties.
📷 Screenshot
- In the Properties window, click the Volumes tab and find the Partition styles row. If it's GPT (GUID Partition Table), you can proceed to switch to UEFI. If it's MBR (Master Boot Record), you'd need to take steps to convert to GPT safely.
Resources to help
HOW TO CHECK IF A DISK/DRIVE IS MBR OR GPT
Convert MBR to GPT without loss DATA | Windows 11/10
Please note: The resources included in this guide are not monitored or owned by Riot Games, so use them at your own risk!
IMPORTANT: If your BIOS mode is set to LEGACY
Check whether your OS drive is on MBR or GPT before making any changes to your BIOS settings. Failure to do so may result in an inability to boot your system if you enable Secure Boot or switch to UEFI mode. If your OS drive is on GPT, then you can proceed with enabling Secure Boot/UEFI mode. Remember to exercise caution and ensure that your settings are properly configured.
To Switch to UEFI:
- Identify your motherboard brand and CPU via msinfo32.
- Find videos for "How to switch to UEFI on (insert motherboard brand) with (insert CPU brand)" or visit the manufacturer's website for your motherboard and follow their instructions.
3️⃣ Enable Secure Boot
To Enable Secure Boot:
- Press Windows Key + R.
- Type msinfo32 and press Enter. Identify your motherboard brand and CPU.
- Find videos for steps on "How to enable Secure Boot on (insert motherboard brand) with (insert CPU brand)" or visit the manufacturer's website for your motherboard and follow their instructions.
Secure Boot help for common motherboards
Please note: The resources included in this guide are not monitored or owned by Riot Games, so use them at your own risk!
Here are a few support resources with steps on how to enable Secure Boot:
Microsoft also has a general page on how to enable Secure Boot: https://support.microsoft.com/en-us/windows/windows-11-and-secure-boot-a8ff1202-c0d9-42f5-940f-843abef64fad
Potential Issues:
🛠️ Issue 1: Secure Boot doesn't enable. You may need to update your BIOS.
- Identify your motherboard brand and exact board name via msinfo32.
- Download the latest BIOS update from the manufacturer’s website.
- Follow manufacturer instructions to update BIOS.
4️⃣ Enable IOMMU
To Enable IOMMU:
- Press Windows Key + R.
- Type msinfo32 and press Enter. Identify your motherboard brand and CPU.
- Find steps on "How to enable IOMMU on (insert motherboard brand) with (insert CPU brand)" or visit the manufacturer's website for your motherboard and follow their instructions.
Here are some common ones:
ASUS MOTHERBOARDS
AMD Platform:
- Enter BIOS/UEFI
- Navigate to Advanced → AMD_CBS.
- Locate and set IOMMU from Disabled/AUTO to ENABLE.
📷 Screenshot
- Locate and set IOMMU from Disabled/AUTO to ENABLE.
- If available after enabling IOMMU:
Advanced\AMD_CBS → NBIO Common options.- Set DMA Protection from Disabled/AUTO to ENABLE.
- Set DMAr Support from Disabled/AUTO to ENABLE.
Intel Platform:
- Enter BIOS/UEFI
- Navigate to Advanced → System Agent SA Configuration.
- Set Control IOMMU Pre-boot behavior to Enable IOMMU during boot.
- If the Enable IOMMU during boot option is unavailable, choose Enable IOMMU.
📷 Screenshot
MSI MOTHERBOARDS
AMD Platform:
- Enter BIOS/UEFI
- Navigate to Overclocking → Advanced CPU Configuration → AMD CBS
- Under AMD CBS - NBIO Common Options, set IOMMU from Disabled/AUTO to ENABLED.
- If available, also set:
- Set DMA Protection from Disabled/AUTO to ENABLE.
- Set DMAr Support from Disabled/AUTO to ENABLE.
📷 Screenshot
Intel Platform:
- Enter BIOS/UEFI
- Navigate to Overclocking → CPU Features.
- Set Control IOMMU Pre-boot Behavior to Enable IOMMU during boot
- If the Enable IOMMU during boot option is unavailable, choose Enable IOMMU.
📷 Screenshot
5️⃣ Enable HVCI/VBS Memory Integrity (Core Isolation)
How to enable HVCI:
- Click the Windows Start menu, then ⚙️Settings.
- Go to Update & Security > Windows Security > Device Security.
- Under Core isolation, find Memory Integrity.
- Toggle the switch on.
- Restart your system when prompted.
Potential Issues:
🛠️ Issue 1: If you see “Page not available"
Your BIOS Virtualization is disabled. You still need to enable it.
🛠️ Issue 2: incompatible drivers/conflicting drivers
If you encounter driver issues, you can try contacting the manufacturer and uninstalling/disabling the problematic drivers, or try a clean reinstall.
🛠️ Issue 3: Blue screen error (BSOD), when enabling or auto disables the option
- Update Windows:
- Ensure your system is up to date with the latest Windows updates.
- Run SFC and DISM:
- Press the Windows key, type PowerShell, right-click on it, select Run as administrator.
- Paste and run the following:
sfc /scannow; DISM /Online /Cleanup-Image /ScanHealth; DISM /Online /Cleanup-Image /RestoreHealth; DISM /Online /Cleanup-Image /StartComponentCleanup
- Paste and run the following:
- Press the Windows key, type PowerShell, right-click on it, select Run as administrator.
- Update BIOS (if needed):
- Press Windows Key + R.
- Type msinfo32 and press Enter. Identify your motherboard details.
- Download the latest BIOS update from the manufacturer’s website.
- Follow manufacturer instructions to update BIOS.
6️⃣ Update Windows
Check the requirements and update accordingly: [Microsoft] Update Windows
Related articles