Users Guide

Table Of Contents
System Configuration Lockdown mode
System Configuration Lockdown mode helps in preventing unintended changes after a system is provisioned. Lockdown mode
is applicable to both configuration and firmware updates. When the system is locked down, any attempt to change the system
configuration is blocked. If any attempts are made to change the critical system settings, an error message is displayed. Enabling
System lockdown mode blocks the firmware update of third party I/O cards using the vendor tools.
System Lockdown mode is only available for Enterprise licensed customers.
In 4.40.00.00 release, System lockdown functionality is extended to NIC's also.
NOTE: Enhanced Lockdown for NIC's only includes firmware lockdown to prevent firmware updates. Configuration (x-
UEFI) lockdown is not supported.
NOTE: After the System Lockdown mode is enabled, you cannot change any configuration settings. System settings fields
are disabled.
Lockdown mode can be enabled or disabled using the following interfaces:
iDRAC web interface
RACADM
WSMan
SCP (System Configuration Profile)
Redfish
Using F2 during POST and selecting iDRAC Settings
Factory System Erase
NOTE:
To enable Lockdown mode, you must have iDRAC Enterprise or Datacenter license and Control and Configure
system privileges.
NOTE: You may be able to access vMedia while system is in Lockdown mode but configuring remote file share is not
enabled.
NOTE: The interfaces like OMSA, SysCfg, and USC can only check the settings but cannot modify the configurations.
The following table lists the functional and nonfunctional features, interfaces, and utilities that are affected by Lockdown mode:
NOTE:
Changing the boot order using iDRAC is not supported when Lockdown mode is enabled. However, boot-control
option is available in vConsole menu, which has no effect when iDRAC is in Lockdown mode.
Table 32. Items affected by Lockdown mode
Disabled Remains functional
Deleting Licenses
DUP updates
SCP import
Reset to defaults
OMSA/OMSS
IPMI
DRAC/LC
DTK-Syscfg
Redfish
OpenManage Essentials
BIOS (F2 settings become read-only)
Group manager
Select network cards
Power Operations - Power ON/OFF, Reset
Power cap setting
Power priority
Identify devices (Chassis or PERC)
Part replacement, Easy Restore, and system board replacement
Running diagnostics
Modular operations (FlexAddress or Remote-Assigned Address)
Group Manager passcode
All vendor tools that have direct access to the device (excludes
selected NIC's)
License export
PERC
PERC CLI
DTK-RAIDCFG
F2/Ctrl+R
9
System Configuration Lockdown mode 163