Blog

ShieldGuard in Rainbow Six Siege: Secure Boot for Legend Division

ShieldGuard in Rainbow Six Siege: Secure Boot for Legend Division

R6 ShieldGuard Secure Platform: the biggest security update in Rainbow Six Siege since launch, but it does not lock you out of the whole game. Its three layers check your system only if you want access to Legend Division in ranked on PC. Regular ranked, casual Quick Match, and most other modes keep working without Secure Boot, Core Isolation, and TPM 2.0, and that is the first thing worth understanding before touching anything in BIOS.

We broke down what ShieldGuard consists of, who really needs it, and what happens with builds from our catalog once the requirements kick in. Current options with prices and undetected status are listed on the cheats for Rainbow Six Siege page, and below we cover the ShieldGuard requirements plus what BattlEye checks separately from them.

Ubisoft did not build this in a vacuum. A season before the ShieldGuard announcement, a major exploit hit the game, dumping billions of R6 credits and thousands of alpha packs onto some accounts, and the ban waves that followed caught streamers too, though some of those bans were later reversed. After that, Ubisoft put security updates on the Year 11 roadmap ahead of the season 3 content, and ShieldGuard became the first result of that priority.

What ShieldGuard Secure Platform includes

Ubisoft built the system out of three layers, and each one handles its own link in the PC startup chain.

Secure Boot checks the whole PC startup chain

Secure Boot verifies the legitimacy of every step of the boot process: motherboard firmware, the operating system, and the drivers that load before the game even starts. Secure Boot is meant to catch an unsigned driver or a tampered bootloader before Rainbow Six Siege ever opens its main menu. In practice this also filters out old, forgotten boot tweaks that a player installed years ago and simply forgot about.

Core Isolation moves Windows processes into a separate environment

Core Isolation, also known as Memory Integrity or HVCI, moves the most sensitive Windows processes into an isolated virtual environment that other software on the system should not be able to reach. The idea is simple: even if something else is already running in the background, the critical part of Windows stays out of reach. Some players see older peripheral drivers stumble a bit after enabling Core Isolation, so it is worth updating them to current versions first.

TPM 2.0 confirms the first two layers are not faked

TPM 2.0 works as a cryptographic module: it signs the state of the system and confirms that Secure Boot and Core Isolation are genuinely enabled, not just showing the right checkboxes in settings. Without a working TPM 2.0, the game cannot be sure the first two layers are genuine, which is why all three only work as a set. We covered the mechanics of Secure Boot and TPM from a hardware spoofer's angle in a separate article on how Secure Boot and TPM work against a spoofer.

Why the requirement only applies to Legend Division

This is where expectations usually diverge from how it works in practice. A lot of players assume ShieldGuard is mandatory for the game as a whole, when it is really only about the top rank division on PC.

Rainbow Six Siege differs from Battlefield 6 here, where a similar system called Javelin makes Secure Boot and TPM mandatory across the entire game with no exceptions. We covered that separately in our article on Secure Boot and TPM in Battlefield 6. Ubisoft went softer: regular ranked, casual modes, and most playlists never check the state of Secure Boot, Core Isolation, or TPM at all. The requirement only kicks in the moment you try to enter Legend Division, the very top rank division that, per the roadmap, ships alongside the ShieldGuard update in Y11S3.

The fork in the road: Legend Division or a build without Secure Boot

This is where the practical choice behind the whole topic shows up. Some software on the market physically requires disabled Secure Boot, stripped virtualization, or disabled Hyper-V to work with the game's memory the way its developer intended. Builds in this class do not run in Legend Division not because something catches them there: a system with Secure Boot disabled simply fails the check at the door, before the match even starts. In practice this is more often about tools that hook memory at the kernel level or fake the virtualization state, not harmless overlays with an ability timer.

Software on the market splits into two camps here. One kind requires those changes and locks itself out of Legend Division automatically, the other never touches BIOS or virtualization in the first place and passes the ShieldGuard check without issue. The choice ends up binary: either the top rank division, or software from the first category. You cannot have both at once.

A similar logic applies to a separate Ubisoft system aimed at input spoofing on consoles. We covered separately how MouseTrap ran in shadow mode for several seasons, quietly collecting data on who was faking input, in our article on input spoofers and MouseTrap in R6. Both mechanisms point the same direction: R6 now checks what is running on your PC and how you physically interact with the game.

How to check your system before the season

Checking this does not require any third-party software. The game itself has a Play tab, and inside it a Security Requirements menu that shows the status of each of the three layers on your specific machine.

Based on support tickets, two situations come up most often. Core Isolation is turned off in the "Windows Security" section of the OS and gets enabled there manually, no reinstall needed. Or the motherboard firmware is outdated and does not support the required Secure Boot version, in which case a BIOS update from the board manufacturer usually fixes it.

Per the Y11S3 roadmap, the ShieldGuard updates themselves land in the same season as a targeted Villa map update, the Operator Mastery mode, and 3v3 Arcade, but that is content for the season, not a security requirement, and we do not mix the two topics in our catalog listings.

ShieldGuard and BattlEye check different things

One thing gets confused more than anything else: passing the ShieldGuard requirements has nothing to do with a build's status on BattlEye. Secure Boot, Core Isolation, and TPM look at the state of your PC at boot and decide access to Legend Division, while BattlEye runs during the match itself and watches process memory and known signatures. These are two independent layers, and compatibility with one says nothing about the other. We keep the current undetected status for every build on its product page and update it after patches, not derive it from ShieldGuard requirements. We cover ban waves after patches, and how BattlEye shapes them, in our article on BattlEye ban waves in R6.

What to pick from the ForgeCheats catalog for this exact task

Real requirements across the builds in our catalog differ, and they do not close the path to Legend Division the same way.

  • If BIOS is already on UEFI with Secure Boot enabled: UDP specifically asks for UEFI mode and does not conflict with Secure Boot being on, priced from $4 a day up to $40 a month. We covered the full feature set in our UDP review.
  • If you would rather not touch firmware at all: ANCIENT has no BIOS requirements whatsoever, entry from $3 a day. Its full feature list is in our ANCIENT review.
  • If you don't need ESP or aim, just recoil control: MACROS also leaves BIOS alone, because it is a recoil macro tool with no injection into the game, $17 a month.
  • If you run an NVIDIA card and only want model highlighting: COVCHEG requires NVIDIA but not disabling any protection, entry from $2.5 a day.

Buying software on its own does not open Legend Division automatically: the BIOS requirements of the builds listed above simply do not interfere with passing the ShieldGuard check, and from there it is up to the player what to prioritize.

The full list of current options with prices, undetected status, and system requirements is on the cheats for Rainbow Six Siege → page. The catalog gets updated after every Siege patch and every Year 11 seasonal update.

If it is not clear which build fits your specific system, ask in our community: Telegram (200+ members) and Discord (637+ members).

Frequently asked questions about ShieldGuard in Rainbow Six Siege

Is ShieldGuard mandatory for the whole game or only for ranked?

Only for access to Legend Division on PC. The rest of Rainbow Six Siege, including regular ranked and casual playlists, works fine without Secure Boot, Core Isolation, and TPM 2.0. That is a major difference from systems in other titles, where the requirements apply to the whole client. At ForgeCheats we factor in exactly this difference when picking a build.

How do I know if my system is ready for the ShieldGuard requirements?

Open the Play tab in the game itself and go to the Security Requirements menu: it shows the status of each of the three layers. If Core Isolation is off, you turn it on in the "Windows Security" section. If the issue is Secure Boot, updating the motherboard firmware from the manufacturer usually helps.

Can I use a build that requires disabling Secure Boot and still play Legend Division?

No. If the software needs disabled Secure Boot, stripped virtualization, or disabled Hyper-V to work, the system physically fails the ShieldGuard check at the door to Legend Division. The choice only goes one way at a time: either that rank division, or that class of software, you cannot combine them.

If a build is compatible with ShieldGuard, does that mean it won't get banned?

No, these are separate checks. ShieldGuard looks at the state of your PC and decides whether to let the system into Legend Division, while BattlEye separately watches memory and signatures during matches. Compatibility with ShieldGuard requirements says nothing about status on BattlEye. We keep the current undetected status for every listing in our R6 cheats catalog and update it after patches.

Which builds in the ForgeCheats catalog need no BIOS changes at all?

ANCIENT has no firmware requirements whatsoever, and neither does MACROS, since it is a recoil macro tool with no injection into the game. COVCHEG does not require disabling any protection, but it does need an NVIDIA card. UDP has a BIOS requirement, UEFI mode, but it does not conflict with Secure Boot being enabled.

Why did the ShieldGuard requirements show up right now?

Ubisoft rolled out stronger protection gradually rather than in one patch. The main trigger was a major late-2025 exploit that led to ban waves hitting thousands of accounts. Year 11 got its security updates ahead of the new season 3 content, and ShieldGuard together with Legend Division are a direct result of that priority.