The BIOS is firmware on a chip on the motherboard, and the first software a computer runs when power arrives. It wakes the hardware, checks the essential parts answer, then finds something bootable and hands over. Nearly every machine now runs UEFI instead, and almost everyone still calls it the BIOS.
- Runs from flash on the board, not from disk
- POST is the self test it runs first
- Beep codes exist because video may not work yet
- A flat coin cell resets the clock and boot order
- UEFI replaced it, on essentially everything since 2012
On this page
The sequenceWhat happens between the power button and the operating system
Press the button and the BIOS runs a sequence most people never see, because on a healthy computer it takes two seconds and produces one logo.
Power stabilizes. The power supply asserts a signal saying its voltages are good. Until that arrives, nothing else is allowed to start.
The processor starts executing firmware. It begins at a fixed address that maps to the flash chip rather than to memory, because memory has not been configured yet and cannot be trusted to hold anything.
Memory is trained and configured. The firmware reads the description each memory module carries about itself, works out timings, and configures the controller. On a server with a lot of memory this is the step that takes most of the wait.
POST runs. The power on self test checks that the processor, memory, and the essential controllers respond. It is deliberately minimal: enough to know whether continuing is pointless.
Devices are enumerated. The BIOS walks the buses, finds storage controllers, network cards, input devices and graphics, and initializes enough of each to be usable.
A boot target is chosen. The firmware works through the configured boot order looking for something bootable, loads the first stage from it, and jumps into it.
From that jump onward the firmware's job is done. The operating system takes over the hardware it was handed, and on a modern system it reconfigures most of it anyway.
POST, and the noises it makes
POST predates reliable video output, so it was built to report failures without a screen. That is the whole reason for the beeps.
One short beep on most systems means the test passed. A pattern of beeps is a code, and the code means something specific to that firmware vendor: a repeating pattern usually means memory, a long and short combination usually means video. The manual for the board is the only authority on the exact mapping, and every vendor differs.
Modern boards increasingly report through a two digit display or a set of colored lights instead, which is a genuine improvement because it names the stage that failed rather than making you count sounds.
The useful thing to know is what a failed POST tells you. It stops before an operating system exists, so it is never a software fault. A machine that fails POST has a hardware problem, a firmware problem, or something unseated, and no amount of reinstalling anything will help.
The batteryCMOS, the coin cell, and why the clock resets
The firmware itself sits in flash and survives without power. Its settings do not, at least historically.
Settings lived in a small block of memory made with a process called CMOS, which needs a trickle of power to remember anything. That trickle comes from the coin cell battery on the motherboard, and the same cell keeps the real time clock running while the machine is unplugged.
This explains a very specific and very common symptom. A machine that forgets the date, reverts to default boot order and complains about settings every time it starts almost always needs a coin cell, not a motherboard. The cell costs very little and lasts something like five to ten years.
The word CMOS is now imprecise on modern hardware, where settings are usually written back to flash and only the clock still depends on the cell. The symptom stayed the same, so the vocabulary did too.
AccessGetting into BIOS setup
Access to BIOS setup is a key press during the couple of seconds after power on, before the operating system starts. Which key depends on who made the computer.
| Maker | Key for BIOS setup | Key for the boot menu |
|---|---|---|
| Dell | F2 | F12 |
| HP | F10 or Esc | F9 |
| Lenovo | F1 or F2 | F12 |
| ASUS | Delete or F2 | F8 |
| Gigabyte, MSI, ASRock | Delete | F11 or F12 |
| Acer | F2 | F12 |
| Apple with Intel | not applicable | hold Option |
The boot menu in the second column is worth knowing separately. It picks a device for this start only, without changing any setting, which is what you actually want when booting a USB stick once.
When the key does nothing, the reason is almost always fast startup rather than the wrong key. Modern machines boot quickly enough that the window is a fraction of a second, and Windows fast startup makes it shorter still by not fully shutting down in the first place. Three ways around it:
- On Windows, open Settings, then System, then Recovery, and choose Restart now under Advanced startup. Then Troubleshoot, Advanced options, UEFI Firmware Settings. This restarts straight into setup with no timing involved
- Hold Shift while clicking Restart, which reaches the same menu
- Turn off fast startup in the power settings, which also fixes the machine that seems to ignore a full shutdown
If a firmware password is set none of this helps without it, which is the point of setting one. There is no supported way past it on a modern business machine, and the recovery process runs through the manufacturer with proof of ownership.
SettingsThe settings that actually matter
BIOS setup has hundreds of options and perhaps eight that change anything on a normal computer.
Boot order. Which device the BIOS tries first. The single most common reason a machine will not start is that it is trying to boot from something that is not the disk.
Secure Boot. On is the correct default. It is turned off far more often than it should be, usually to install something once, and then never turned back on.
Virtualization support. Called VT-x, AMD-V, or something in that family, and controlled from BIOS setup. Off by default on a surprising number of machines, and required for virtual machines, for Windows Subsystem for Linux, and for several Windows security features.
The TPM. A small chip or a firmware equivalent that holds keys. Required for disk encryption to work without a password at every boot, and a hard requirement for Windows 11.
Memory profile. Memory runs at a conservative speed until you enable the profile it advertises. Enabling it is free performance and occasionally the cause of an unstable system.
Power management. Whether the machine returns to its previous state after a power cut, which matters for anything in a rack or a cupboard.
Fan curves. Worth setting once on anything that lives near people.
A firmware password. Stops someone with physical access rebooting the machine from a USB stick and reading the disk. Free, and almost never set.
ServersOn a server, you do not walk up to it
Everything above assumes a keyboard and a monitor. In a rack that assumption breaks, so servers carry a second computer whose only job is to give you access to the first one.
It goes by a different name per vendor. Dell calls it iDRAC, HP calls it iLO, Lenovo calls it XClarity, and the vendor neutral standard underneath is IPMI, now largely replaced by an interface called Redfish. They all do the same four things.
Power control at a level below the operating system. Power on, power off, and a hard reset for a machine that has stopped answering everything else.
A remote console that shows the actual screen from the moment power arrives, including POST and the firmware setup, which is the whole point. You can change a boot order on a machine in another country.
Virtual media, which presents an image file over the network as though a disk were plugged in, so an operating system can be installed on a server nobody is standing next to.
Health and inventory, reporting fans, temperatures, power draw, disk status and the firmware versions of every component, usually with alerting.
Two things follow, and the second is the important one.
The first is that firmware settings on a server become manageable at scale. The same interface is scriptable, so Secure Boot or a boot order can be set across a rack from a script rather than a screen at a time.
The second is that this controller is a full computer with network access, its own credentials and its own firmware, and it is powered whenever the server is plugged in, including when the server itself is off.
That makes it the most complete access anyone can have to the hardware, and it should never be reachable from a general network. It belongs on a separate management network, with default credentials changed, with its own firmware patched, and with nobody assuming that turning the server off has turned it off.
UpdatesUpdating firmware, and the honest risk
Firmware updates fix real problems: memory compatibility, processor support, security vulnerabilities in the firmware itself, and occasionally power management that was wrong at launch.
They also carry the one risk normal software does not. A firmware update that fails partway can leave a machine that will not start at all, and no operating system exists to help. Modern boards mitigate this with a backup copy or a recovery mode, and the risk is much smaller than it was, but it is not zero.
A reasonable rule: update when a specific problem is fixed by a specific version, when a security advisory names the machine, or when new hardware needs support. Do not update because a newer number exists.
And two practical points. Never update on battery power alone. And read the release notes for the ones that say settings will reset, because a machine that comes back with default boot order and Secure Boot off looks broken in a way that has nothing to do with the update failing.
PitfallsWhere people go wrong
Blaming software for a POST failure. If it stops before the operating system loads, reinstalling the operating system cannot help.
Replacing a motherboard for a dead coin cell. The symptom is a machine that forgets the time and its settings. The part costs less than a coffee.
Leaving CSM enabled on a new install. It disables Secure Boot and caps the boot disk, and nobody notices until they try to enable disk encryption or fit a larger drive.
Turning Secure Boot off and forgetting. It gets disabled for one driver installation and stays off for the life of the machine.
Treating the BIOS as unreachable by attackers. It is software, it has vulnerabilities, and malware that lives there survives a disk wipe. It deserves the same patching attention as anything else, and a firmware password.
ComparisonLegacy BIOS and UEFI, where the difference actually shows
| Criterion | Legacy BIOS | UEFI |
|---|---|---|
| Boot disk format | MBR, which caps a boot disk at 2 TB | GPT, with no practical size limit |
| Partitions on a boot disk | Four primary | Effectively unlimited |
| Processor mode while running | 16 bit real mode | 32 or 64 bit |
| Where the boot loader lives | A hidden sector at the front of the disk | A file in a normal partition |
| Verifying what it boots | Nothing, it runs what it finds | Secure Boot checks a signature |
| Drivers before the operating system | Limited to what the firmware knows | Loadable modules, including network |
| Interface | Text, keyboard only | Graphical, mouse, usually |
| Managing many machines | Painful, one screen at a time | Scriptable from the operating system |
Every machine sold today ships UEFI, and almost everyone still calls it the BIOS. The distinction matters in four places. The two that change decisions are disk size and Secure Boot. A boot disk larger than 2 TB requires UEFI, full stop.
And Secure Boot, which checks that the loader is signed by a key the firmware trusts, is a requirement in a growing number of compliance regimes and a prerequisite for some Windows security features.
Most firmware can still boot the old way, usually under a setting called CSM or Legacy Boot. Turning that on to rescue an old installation is reasonable. Leaving it on for a new one is not, because it quietly disables Secure Boot and caps the disk.
FAQFrequently asked questions
What is a BIOS in simple terms?
The BIOS is the first program a computer runs, stored on a chip on the motherboard. It wakes the hardware, checks it works, and finds an operating system to start.
Is BIOS software or hardware?
The BIOS is software, of a kind called firmware, because it lives on a chip rather than on a disk. The chip is hardware; what it holds is not.
What is the difference between BIOS and UEFI?
UEFI is the replacement. It boots from GPT disks with no 2 TB limit, runs in a modern processor mode, loads its own drivers, and can verify the signature on what it boots. Almost every machine since about 2012 is UEFI even when the screen says BIOS.
How do I access the BIOS?
Press the key shown briefly at power on, usually Delete, F2, F10 or F12 depending on the vendor. On Windows you can also restart into firmware settings from the recovery options, which avoids the timing problem entirely.
What does POST mean?
Power on self test. The check the firmware runs before anything else, to confirm the processor, memory and essential controllers respond.
Why does my computer beep and not start?
The beeps are a POST failure code. The pattern names the subsystem, and only the board manual gives the exact meaning. It is a hardware fault, not a software one.
Why does my clock keep resetting?
The coin cell on the motherboard is flat. It also holds the firmware settings, which is why the boot order resets at the same time.
Is it safe to update the BIOS?
Usually, and it is the one update that can leave a machine unable to start if it fails. Update for a named fix, not for a newer number, and never on battery alone.
Can a BIOS get a virus?
Yes. Firmware malware exists, and it survives reformatting the disk because it does not live there. Signed firmware updates, Secure Boot and a firmware password are the defenses.
What is CMOS?
The small block of powered memory that historically held the settings, kept alive by the coin cell. On modern hardware settings usually live in flash and only the clock still depends on the battery.
Should Secure Boot be on?
Yes, unless something specific requires it off, and then it should go back on. It is a requirement for several operating system security features and for a growing number of compliance checks.
How do I access the BIOS on a server in a rack?
Through the management controller, called iDRAC on Dell, iLO on HP or XClarity on Lenovo. It gives a remote console from the moment power arrives, so firmware setup is reachable over the network. Keep it on a separate management network.
Why is virtualization disabled by default?
Vendor caution rather than any good reason. It needs turning on before virtual machines, containers on Windows or several Windows security features will work.
Keep readingRelated concepts
Read next · Disks and drives SSD vs HDD The 2 TB boot limit is a firmware limit, and this is the drive it applies to. Open this next12 min- Firmware and boot · 10 min Checksum Errors, and Why the Battery Is Usually the Answer What the BIOS is, before the error.
- Identification · 9 min How to Check Which Motherboard You Have, and Why WMIC No Longer Works Finding the motherboard make and model from inside Windows, which is what a firmware version has to be matched against.
- Firmware and boot · 10 min What a BIOS Update Does, and Why the Old Advice Changed What is being updated.
- Firmware and boot · 15 min How to Enable Secure Boot, and What to Check Before You Do The setting this page keeps recommending, and how to turn it on.
- Firmware and boot · 10 min UEFI vs BIOS The generation that replaced it, and what changed at the handoff.
- Disks and drives · 10 min MBR vs GPT The partition table behind the 2 TB boot limit described above.
- Firmware and boot · 9 min What Is ROM, and Why Read Only Is No Longer Accurate What is stored in it.