Table 5. Security (continued)
Option
Description
●
PPI Bypass for Clear Command
(disabled by default)
●
Attestation Enable
(enabled by default)
●
Key Storage Enable
(enabled by default)
●
SHA-256
(enabled by default)
Absolute
This field lets you Enable, Disable, or Permanently Disable the BIOS module interface of the
optional Absolute Persistence Module service from Absolute Software.
The options are:
●
Enabled
(enabled by default)
●
Disabled
(disabled by default)
●
Permanently disabled
(disabled by default)
WARNING:
The Permanently Disabled option can only be selected once. When
Permanently Disabled is selected, Absolute Persistence cannot be reenabled. No
further changes to the Enable or Disable state are allowed.
OROM Keyboard Access
This option determines whether users are able to enter Option ROM Configuration screens via
hotkeys during boot. Specifically this setting is capable of preventing access to Intel RAID (Ctrl+I)
or Intel Management Engine BIOS Extension (Ctrl+P/F12).
The options are:
●
Enabled
(enabled by default)
●
Disabled
(disabled by default)
●
One Time Enable
(disabled by default)
Admin Setup Lockout
Allows you to prevent users from entering Setup when an admin password is set.
The
Enable Admin Setup Lockout
option disabled by default.
Master Password
Lockout
Allows you to disable master password support.
The
Enable Master Password Lockout
option is disabled by default.
NOTE:
Hard Disk password should be cleared before the settings can be changed.
SMM Security
Mitigation
Allows you to enable or disable additional UEFI SMM Security Mitigation protection.
The
SMM Security Mitigation
option is disabled by default.
HDD Security
This section defines special security features that shall be available for Self-Encrypting Drives
(SED) that supports either Opal or Pyrite specification requirements. It is not available for regular
storage devices.
The
SED Block SID Authentication
option is enabled by default.
The
PPI Bypass for SED Block SID Command
option is disabled by default.
Secure Boot
Table 6. Secure Boot
Option
Description
Secure Boot Enable
Allows you to enable or disable the Secure Boot Feature.
The
Secure Boot Enable
option is disabled by default.
Secure Boot Mode
Changes to the Secure Boot operation mode modifies the
behavior of Secure Boot to allow evaluation or enforcement
of UEFI driver signatures.
62
System setup