Option
Description
Password Bypass
Allows you to bypass the System password and the Internal HDD password, when it is set, during a system
restart.
The options are:
•
Disabled
—This option is enabled by default.
•
Reboot bypass
Password Change
Allows you to change the system password when the administrator password is set.
•
Allow Non-Admin Password Changes
By default, this option is enabled.
Non-Admin Setup Changes
Allows you to determine whether changes to the setup options are allowed when an administrator
password is set. If disabled the setup options are locked by the admin password.
•
Allow Wireless Switch Changes
By default, this option is disabled.
UEFI Capsule Firmware
Updates
Allows you to update the system BIOS through UEFI capsule update packages.
•
Enable UEFI Capsule Firmware Updates
By default, this option is enabled.
TPM 2.0 Security
Allows you to enable or disable the Trusted Platform Module (TPM) during POST.
The options are:
•
TPM On
—This option is enabled by default.
•
Clear
•
PPI Bypass for Enable Commands
•
PPI Bypass for Disbale Commands
•
PPI Bypass for Clear Command
•
Attestation Enable
—This option is enabled by default.
•
Key Storage Enable
—This option is enabled by default.
•
SHA-256
—This option is enabled by default.
Absolute®
This field lets you Enable, Disable, or Permanently Disable the BIOS module interface of the optional
Absolute Persistence Module service from Absolute® Software.
Admin Setup Lockout
Allows you to prevent users from entering Setup when an administrator password is set.
•
Enable Admin Setup Lockout
By default, this option is disabled.
Master Password Lockout
Allows you to disable master password support.
•
Enable Master Password Lockout
By default, this option is disabled.
NOTE:
Hard Disk password should be cleared before the settings can be changed.
SMM Security Mitigation
Allows you to enable or disable additional UEFI SMM Security Mitigation protection.
•
SMM Security Mitigation
By default, this option is enabled.
28
System setup