User's Manual

ASUS B85-A R2.0
2-39
[Disabled] Disable the CSM to fully support the Windows
®
Security Update and
Security Boot.
The following four items appear when you set Launch CSM to [Enabled].
Boot Devices Control [UEFI and Legacy OPROM]
Allows you to select the type of devices that you want to boot up. Conguration options:
[UEFI and Legacy OPROM] [Legacy OPROM only] [UEFI only]
Boot from Network Devices [Legacy OPROM rst]
Allows you to select the type of network devices that you want to launch. Conguration
options: [Legacy OPROM rst] [UEFI driver rst] [Ignore]
Boot from Storage Devices [Legacy OPROM rst]
Allows you to select the type of storage devices that you want to launch. Conguration
options: [Both, Legacy OPROM rst] [Both, UEFI rst] [Legacy OPROM rst] [UEFI driver
rst] [Ignore]
Boot from PCIe/PCI Expansion Devices [Legacy OPROM rst]
Allows you to select the type of PCIe/PCI expansion devices that you want to launch.
Conguration options: [Legacy OPROM rst] [UEFI driver rst]
2.8.9 Secure Boot
Allows you to congure the Windows
®
Secure Boot settings and manage its keys to protect
the system from unauthorized access and malwares during POST.
OS Type [Windows UE...]
Allows you to select your installed operating system.
[Windows UEFI mode] Executes the Microsoft
®
Secure Boot check. Only select this
option when booting on Windows
®
UEFI mode or other Microsoft
®
Secure Boot compliant OS.
[Other OS] Get the optimized function when booting on Windows
®
non-UEFI
mode, Windows
®
Vista/XP, or other Microsoft
®
Secure Boot
non-compliant OS. Only on Windows
®
UEFI mode that Microsoft
®
Secure Boot can function properly.
The following item appears when OS Type is set to [Windows UEFI mode].
Key Management
This item appears only when you set Secure Boot Mode to [Custom]. It allows you to manage
the Secure Boot keys.
Install Default Secure Boot keys
Allows you to immediately load the default Security Boot keys, Platform key (PK), Key-
exchange Key (KEK), Signature database (db), and Revoked Signatures (dbx). When
the default Secure boot keys are loaded, the PK state will change from Unloaded mode
to loaded mode.