Option
Description
Master Password Lockout
Allows you to disable master password support.
•
Enable Master Password Lockout
This option is not set by default.
NOTE:
Hard Disk password should be cleared before the settings can be changed.
SMM Security Mitigation
Allows you to enable or disable additional UEFI SMM Security Mitigation protection.
•
SMM Security Mitigation
This option is not set by default.
Secure Boot
Table 27. Secure Boot
Option
Description
Secure Boot Enable
Allows you to enable or disable the Secure Boot Feature.
•
Secure Boot Enable
—Default
Secure Boot Mode
Changes to the Secure Boot operation mode modifies the
behaviour of Secure Boot to allow evaluation of UEFI driver
signatures.
Choose one of the option:
•
Deployed Mode
—Default
•
Audit Mode
Expert Key Management
Allows you to enable or disable Expert Key Management.
•
Enable Custom Mode
This option is not set by default.
The Custom Mode Key Management options are:
•
PK
—Default
•
KEK
•
db
•
dbx
Intel Software Guard Extensions options
Table 28. Intel Software Guard Extensions
Option
Description
Intel SGX Enable
This field allows you to provide a secured environment for running
code/storing sensitive information in the context of the main
operating systems.
Click one of the following options:
•
Disabled
•
Enabled
•
Software controlled
—Default
Enclave Memory Size
This option sets
SGX Enclave Reserve Memory Size
Click one of the following options:
System setup
29