Specifications

Table 22. Security (continued)
Option Description
system. When enabled, the BIOS will turn On the TPM during POST so that it can be
used by the operating system. This option is Enable by default.
NOTE: Disabling this option does not change any settings you may have made to
the TPM, nor does it delete or change any information or keys you may have stored
there. It simply turns Off the TPM so that it cannot be used. When you re-enable
this option, the TPM will function exactly as it did before it was disabled.
NOTE: Changes to this option take effect immediately.
UEFI Capsule Firmware Updates This option controls whether this system allows BIOS updates via UEFI capsule update
packages. Enabled (Default Setting)
CPU XD Support This option enables or disables the Execute Disable mode for the processor. Enabled
(Default Setting)
OROM Keyboard Access This option determines whether users are able to enter Option ROM configuration
screens via hotkeys during boot.
Table 23. Boot
Option Description
Boot List Option
Default Setting: Legacy
Secure Boot This option enables or disables the Secure Boot feature.
Disabled (Default Setting) - Windows 10)
Enabled - Windows 10
Load Legacy Option ROM This option enables or disables the Load Legacy Option ROM
feature.
Enabled (Default Setting) - Windows 10
Disabled - Windows 10
Expert Key Management Expert Key Management allows the PK, KEK, db, and dbx security
key databases to be manipulated. Disabled (Default Setting)
Intel Software Guard Extensions Intel SGX Enabled: Enables Intel Software Guard Extensions (SGX)
to provide a secured environment for running code/storing sensitive
information in the context of the main OS. Enabled (Default
Setting)
Set Boot Priority Allows you to change the order in which the computer attempts to
find an operating system:
1 st Boot Priority [ CD/DVD/CD-RW Drive]
2nd Boot Priority [Network]
3rd Boot Priority [mini SSD]
4th Boot Priority [USB Storage Device
5th Boot Priority [Hard Drive]
6th Boot Priority [Diskette Drive]
Adapter Warnings Lets you choose whether the system displays warning messages
when you use certain power adapters. Enabled (Default Setting)
SupportAssist OS Recovery Enables for disables the boot flow for SupportAssist OS Recovery
tool in the event of certain errors. Enabled (Default Setting)
Keypad (embedded) Lets you choose one of two methods to enable the keypad that is
embedded in the internal keyboard. Fn Key Only Enabled by default.
Fastboot This option can speed up the boot process by bypassing some
compatibility steps. Minimal (Default Setting)
Extend BIOS POST Time Creates an additional pre-boot delay to see POST messages.
System Setup 21