Table 5-2
Computer Setup—Security (continued)
Option
Description
IMPORTANT:
Clearing the TPM resets it to factory defaults and turns it off. You will lose all created
keys and data protected by those keys.
●
TPM Activation Policy
Select policy as F1 to boot, allow user to reject, or no prompts.
BIOS Sure Start
●
Verify Boot Block on every boot. Default is disabled.
●
BIOS Data Recovery Policy. Default is Automatic.
IMPORTANT:
Only select Manual in situations in which forensic analysis is to be performed before
HP Sure Start Recovery. When this policy is set to manual, HP Sure Start will not correct any issues
that are found until the manual recovery key sequence is entered by the local user. This can result in
a system that is unable to boot after inputting the manual recovery key sequence.
●
Sure Start BIOS Settings Protection. This setting requires setting the BIOS Administrator password.
Default is disabled.
●
Sure Start Secure Boot Keys Protection. Default is enabled.
●
Sure Start Security Event Boot Notification. Default is Require Acknowledgment.
HP Secure Platform Management (SPM)
●
HP Sure Run Current State (Inactive/Active)
●
Deactivate HP Sure Run
●
SPM Current State (Not provisoned/Provisioned)
●
Unprovision SPM
Physical Presence Interface. Notifies the user upon system power up when changes are made to system
security policy. The user must agree to the changes to confirm them. Default is enabled.
Smart Cover (Disable/Notify User)
Lets you set an alert is the computer cover is removed.
Utilities
Hard Drive Utilities
●
Save/Restore MBR of System Hard Drive
NOTE:
Windows 10 systems are generally not formatted to include an MBR. Instead they use GUID
Partition Table (GPT) format, which better supports large hard drives.
Enabling this feature will save the Master Boot Record (MBR) of the system hard drive. If the MBR
gets changed, the user will be prompted to restore the MBR. Default is disabled.
The MBR contains information needed to successfully boot from a disk and to access the data stored
on the disk. Master Boot Record Security may prevent unintentional or malicious changes to the
MBR, such as those caused by some viruses or by the incorrect use of certain disk utilities. It also
allows you to recover the "last known good" MBR, should changes to the MBR be detected when the
system is restarted.
NOTE:
Most operating systems control access to the MBR of the current bootable disk; the BIOS
cannot prevent changes that may occur while the operating system is running.
Restores the backup Master Boot Record to the current bootable disk. Default is disabled.
Only appears if all of the following conditions are true:
–
MBR security is enabled
–
A backup copy of the MBR has been previously saved
–
The current bootable disk is the same disk from which the backup copy was saved
Computer Setup (F10) Utilities
65