Service Manual

Table Of Contents
Table 12. System setup optionsSecurity menu (continued)
Security
Key Storage Enable Enables to control whether the Trusted Platform Module (TPM) Storage
Hierarchy is available to the operating system.
By default, the Key Storage Enable option is enabled.
SHA-256 BIOS and the TPM will use the SHA-256 hash algorithm to extend
measurements into the TPM PCRs during BIOS boot.
By default, the SHA-256 option is enabled.
Clear Enables to clear the TPM owner information and returns the TPM to the
default state.
By default, the Clear option is disabled.
PPI ByPass for Clear Commands Controls the TPM Physical Presence Interface (PPI).
By default, the PPI ByPass for clear Commands option is disabled.
Intel Total Memory Encryption
Total Memory Encryption Enable or disable you to protect memory from physical attacks including freeze
spray, probing DDR to read the cycles, and others.
By default, the Total Memory Encryption option is disabled.
Chassis intrusion Controls the chassis intrusion feature.
By default, the On-Silent option is enabled.
SMM Security Mitigation Enable or disable SMM Security Mitigation.
By default, the option is enabled.
Data Wipe on Next Boot
Start Data Wipe Enable or disable the data wipe on next boot.
By default, the option is enabled.
Absolute Enable or disable or permanently disable the BIOS module interface of the
optional Absolute Persistence Module service from Absolute software.
By default, the option is enabled.
UEFI Boot Path Security Controls whether or not the computer will prompt the user to enter the admin
password (if set) when booting to a UEFI boot device from the F12 boot menu.
By default, the Always Except Internal HDD option is enabled.
Table 13. System setup optionsPasswords menu
Passwords
Admin Password Set, change, or delete the administrator password.
System Password Set, change, or delete the computer password.
NVMe SSD0 Set, change, or delete the NVMe SSD0 password.
Password Configuration
Upper Case Letter Reinforces password must have at least one upper case letter.
By default, the option is disabled.
Lower Case Letter Reinforces password must have at least one lower case letter.
By default, the option is disabled.
Digit Reinforces password must have at least one digit.
By default, the option is disabled.
132 BIOS setup