Service Manual

Table 7. System setup optionsSecurity menu (continued)
Security
PPI Bypass for Disable Commands Enables or disables The OS to skip BIOS PPI user prompts when issuing TPM
PPI Disable and Deactivate commands.
Default: OFF.
PPI Bypass for Clear Commands Enables or disables the operating system to skip BIOS Physical Presence
Interface (PPI) user prompts when issuing the Clear command.
Default: OFF.
Attestation Enables Enables to control whether the TPM Endorsement Hierarchy is available to the
OS. Disabling this setting restricts the ability to use the TPM for signature
operations.
Default: ON.
Key Storage Enable Enables to control whether the TPM Endorsement Hierarchy is available to the
OS. Disabling this setting restricts the ability to use the TPM for storing owner
data.
Default: ON.
SHA-256 Enables or disables the BIOS and the TPM to use the SHA-256 hash algorithm
to extend measurements into the TPM PCRs during BIOS boot.
Default: ON.
Clear Enables or disables the computer to clear the PTT owner information, and
returns the PTT to the default state.
Default: OFF.
TPM State Enables or disables the TPM. This is the normal operating state for the TPM
when you want to use its complete array of capabilities.
Default: Enabled.
Intel SGX Enables or disables the Intel Software Guard Extensions (SGX) to provide a
secured environment for running code/storing sensitive information.
Default: Software Control
SMM Security Mitigation Enables or disables additional UEFI SMM Security Mitigation protections.
Default: OFF.
NOTE: This feature may cause compatibility issues or loss of functionality
with some legacy tools and applications.
Enable Strong Passwords Enables or disables strong passwords.
Default: OFF.
Password Configuration Control the minimum and maximum number of characters that are allowed for
Admin and System passwords.
Admin Password Sets, Changes, or deletes the administrator (admin) password (sometimes
called the "setup" password).
System Password Sets, Changes, or deletes the system password.
Enable Master Password Lockout Enables or disables the master password support.
Default: OFF.
Table 8. System setup optionsSecure Boot menu
Secure Boot
Enable Secure Boot Enables or disables the computer to boos using only validated boot software.
System setup 43