Option
Description
UEFI Capsule Firmware Updates
This option controls whether this system allows BIOS updates via UEFI capsule update packages.
This option is selected by default. Disabling this option will block BIOS updates from services such as
Microsoft Windows Update and Linux Vendor Firmware Service (LVFS)
Computrace(R)
This field lets you Activate or Disable the BIOS module interface of the optional Computrace Service
from Absolute Software. Enables or disables the optional Computrace service designed for asset
management.
•
Deactivate Computrace - This option is selected by default.
•
Activate Computrace
•
Disable Computrace
TPM 2.0 Security
Allows you to control whether the Trusted Platform Module (TPM) is visible to the operating
system.
•
TPM On (default)
•
PPI Bypass for Enable Commands (default)
•
PPI Bypass for Disable Commands
•
PPI Bypass for Clear Commands
•
Attestation Enable (default)
•
Key Storage Enable (default)
•
SHA-256 (default)
•
TPM
Enabled
(default)
Intel SGX
Software Guard Extensions (SGX) provide a secured environment for running code/storing sensitive
information in the context of the main OS.
Software Control
(enabled by default)
SMM Security Mitigation
Allows you to enable or disable additional UEFI SMM Security Mitigation protections. This option is
not set by default.
Passwords
Table 34. Passwords
Option
Description
Enable Strong Passwords
Enforces stricter rules for admin and system passwords.
Password Configuration
Allows you to set the minimum and maximum number of characters allowed for admin and system
passwords.
Admin Password
Allows you to set, change or delete the administrator password.
System Password
Allows you to reset the system password.
Enable Master Password Lockout
Disabled
(default)
Secure boot
Table 35. Secure Boot
Option
Description
Enable Secure Boot
Allows you to enable or disable Secure Boot feature
•
Secure Boot Enable
This option is selected by default.
Secure Boot Mode
Allows you to modify the behavior of Secure Boot to allow evaluation or enforcement of UEFI
driver signatures.
•
Deployed Mode (default)
•
Audit Mode
System setup
29