AWS Security ChangesHomeSearch

AWS AWSEC2: Add AMI boot mode override to UEFI documentation

Service: AWSEC2 · 2026-09-27 · Documentation low

File: AWSEC2/latest/UserGuide/set-ami-boot-mode.md

Summary

Adds guidance and a CLI procedure for using --boot-mode-override uefi when creating an AMI, plus wording and query quoting fixes.

Security assessment

Documentation-only change describing AMI boot mode override behavior and CLI usage. It does not reference a vulnerability, CVE, or security control, and UEFI boot mode is only indirectly security-adjacent here.

Evidence

+By default, an AMI inherits the boot mode of the EC2 instance used to create the AMI. For example, if you create an AMI from an EC2 instance running on Legacy BIOS, the boot mode of the new AMI is `legacy-bios`. If you create an AMI from an EC2 instance with a boot mode of `uefi-preferred`, the boot mode of the new AMI is `uefi-preferred`. To override the default boot mode to `uefi` when creating an AMI, you can specify a boot mode override. The only supported override value is `uefi`, and the current instance boot mode must be `uefi`. You can use this option to override the boot mode of an AMI from `uefi-preferred` to `uefi`. This prevents instances launched from the AMI from falling back to Legacy BIOS and losing access to UEFI-dependent features. If the instance's boot mode is already `uefi`, specifying an override of `uefi` has no effect. You cannot specify any other overrides (for example, you cannot override `legacy-bios` to `uefi` or `uefi` to `uefi-preferred`).

Diff

diff --git a/AWSEC2/latest/UserGuide/set-ami-boot-mode.md b/AWSEC2/latest/UserGuide/set-ami-boot-mode.md
index 11579783a..09ea23049 100644
--- a//AWSEC2/latest/UserGuide/set-ami-boot-mode.md
+++ b//AWSEC2/latest/UserGuide/set-ami-boot-mode.md
@@ -9 +9 @@
-By default, an AMI inherits the boot mode of the EC2 instance used to create the AMI. For example, if you create an AMI from an EC2 instance running on Legacy BIOS, the boot mode of the new AMI is `legacy-bios`. If you create an AMI from an EC2 instance with a boot mode of `uefi-preferred`, the boot mode of the new AMI is `uefi-preferred`.
+By default, an AMI inherits the boot mode of the EC2 instance used to create the AMI. For example, if you create an AMI from an EC2 instance running on Legacy BIOS, the boot mode of the new AMI is `legacy-bios`. If you create an AMI from an EC2 instance with a boot mode of `uefi-preferred`, the boot mode of the new AMI is `uefi-preferred`. To override the default boot mode to `uefi` when creating an AMI, you can specify a boot mode override. The only supported override value is `uefi`, and the current instance boot mode must be `uefi`. You can use this option to override the boot mode of an AMI from `uefi-preferred` to `uefi`. This prevents instances launched from the AMI from falling back to Legacy BIOS and losing access to UEFI-dependent features. If the instance's boot mode is already `uefi`, specifying an override of `uefi` has no effect. You cannot specify any other overrides (for example, you cannot override `legacy-bios` to `uefi` or `uefi` to `uefi-preferred`).
@@ -11 +11 @@ By default, an AMI inherits the boot mode of the EC2 instance used to create the
-When you register an AMI, you can set the boot mode of the AMI to `uefi`, `legacy-bios`, or `uefi-preferred`.
+To convert an existing Legacy BIOS-based instance to UEFI, or an existing UEFI-based instance to Legacy BIOS, you must first modify the instance's volume and operating system to support the selected boot mode. Then, create a snapshot of the volume. Finally, register an AMI from the snapshot. When you register an AMI, you can set the boot mode of the AMI to `uefi`, `legacy-bios`, or `uefi-preferred`.
@@ -24,2 +23,0 @@ If you set the AMI boot mode to `uefi-preferred`, the operating system must supp
-To convert an existing Legacy BIOS-based instance to UEFI, or an existing UEFI-based instance to Legacy BIOS, you must first modify the instance's volume and operating system to support the selected boot mode. Then, create a snapshot of the volume. Finally, create an AMI from the snapshot.
-
@@ -28 +26 @@ To convert an existing Legacy BIOS-based instance to UEFI, or an existing UEFI-b
-  * Setting the AMI boot mode parameter does not automatically configure the operating system for the specified boot mode. You must first make suitable modifications to the instance's volume and operating system to support booting using the selected boot mode. Otherwise, the resulting AMI is not usable. For example, if you are converting a Legacy BIOS-based Windows instance to UEFI, you can use the [MBR2GPT](https://learn.microsoft.com/en-us/windows/deployment/mbr-to-gpt) tool from Microsoft to convert the system disk from MBR to GPT. The modifications that are required are operating system-specific. For more information, see the manual for your operating system.
+  * Setting the AMI boot mode parameter does not automatically configure the operating system for the specified boot mode. You must first make suitable modifications to the instance's volume and operating system to support booting using the selected boot mode. Otherwise, the resulting AMI is not usable. For example, if you are converting a Legacy BIOS-based Windows instance to UEFI, you can use the [MBR2GPT](https://learn.microsoft.com/en-us/windows/deployment/mbr-to-gpt) tool from Microsoft to convert the system disk from MBR to GPT. The required modifications are operating system-specific. For more information, see the manual for your operating system.
@@ -42 +40 @@ AWS CLI
-  1. Make suitable modifications to the instance's volume and operating system to support booting by using the selected boot mode. The modifications that are required are operating system-specific. For more information, see the manual for your operating system.
+  1. Make suitable modifications to the instance's volume and operating system to support booting by using the selected boot mode. The required modifications are operating system-specific. For more information, see the manual for your operating system.
@@ -52 +50 @@ If you don't perform this step, the AMI will not be usable.
-        --query Reservations[].Instances[].BlockDeviceMappings
+        --query 'Reservations[].Instances[].BlockDeviceMappings'
@@ -95 +93 @@ The following is example output.
-        --query Snapshots[].State \
+        --query 'Snapshots[].State' \
@@ -130 +128,50 @@ The following is example output.
-        --query Images[].BootMode \
+        --query 'Images[].BootMode' \
+        --output text
+
+The following is example output.
+    
+        uefi
+
+
+
+
+###### To set the boot mode of an AMI to UEFI
+
+  1. Make suitable modifications to the instance's volume and operating system to support booting by using the selected boot mode. The required modifications are operating system-specific. For more information, see the manual for your operating system.
+
+###### Warning
+
+If you don't perform this step, the AMI will not be usable.
+
+  2. To confirm that the current instance boot mode is UEFI, use the [describe-instances](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-instances.html) command.
+    
+        aws ec2 describe-instances \
+        --instance-ids i-1234567890abcdef0 \
+        --query 'Reservations[].Instances[].CurrentInstanceBootMode' \
+        --output text
+
+The following is example output.
+    
+        uefi
+
+If the output is `legacy-bios`, you cannot create an AMI with a boot mode of `uefi` from this instance. See the preceding procedure, **To set the boot mode of an AMI** , instead.
+
+  3. To create a new AMI, use the [create-image](https://docs.aws.amazon.com/cli/latest/reference/ec2/create-image.html) command with the `--boot-mode-override` parameter set to `uefi`.
+    
+        aws ec2 create-image \
+        --instance-id i-1234567890abcdef0 \
+        --name "my-image" \
+        --description "my image" \
+        --boot-mode-override uefi
+
+The following is example output.
+    
+        {
+        "ImageId": "ami-0123456789abcdef0"
+    }
+
+  4. (Optional) To verify that the newly-created AMI has the boot mode that you specified, use the [describe-images](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-images.html) command.
+    
+        aws ec2 describe-images \
+        --image-id ami-1234567890abcdef0 \
+        --query 'Images[].BootMode' \
@@ -145 +192 @@ PowerShell
-  1. Make suitable modifications to the instance's volume and operating system to support booting by using the selected boot mode. The modifications that are required are operating system-specific. For more information, see the manual for your operating system.
+  1. Make suitable modifications to the instance's volume and operating system to support booting by using the selected boot mode. The required modifications are operating system-specific. For more information, see the manual for your operating system.