HP PC Commercial BIOS (UEFI) Setup
HP PC Commercial BIOS (UEFI) Setup 
July 2020 
919946-004 
© Copyright 2016-2019 HP Development Company, L.P. 
7 Security Menu (2019 and older) 68 
You cannot provision SPM and activate HP Sure Run directly from the BIOS Setup interface. You can provision SPM using HP 
Client Security Manager Software or the HP Manageability Integration Kit. When provisioned, the controls in this menu can 
be used to deprovision the system or deactivate HP Sure Run. 
Table 42  Secure Platform Management Menu features 
Feature 
Type 
Description 
Default 
Notes 
HP Sure 
Run 
Current 
State 
Setting 
(Display 
Only) 
•  Inactive 
•  Active 
Inactive 
Deactivate 
HP Sure 
Run 
Action 
This action deactivates HP Sure Run without deprovisioning SPM. 
SPM 
Current 
State 
Setting 
(Display 
Only) 
•  Provisioned 
•  Unprovisioned 
Unprovisioned 
Unprovision 
SPM 
Action 
This action deprovisions SPM, which causes HP Sure Run to revert to 
the Inactive state and return HP Sure Recover to default settings. 
7.7 HP Sure Admin Enhanced BIOS Authentication Mode (EBAM) 
This submenu allows the administrator to disable and unprovision the EBAM alternative authentication method and keys 
when this feature is fully enabled by associated software. Initialization and provisioning of the feature may be supported by 
future HP Manageability Integration Kit releases. 
Table 43  Enhanced BIOS Authentication Mode (EBAM) Menu features 
Feature 
Type 
Description 
Default 
Notes 
EBAM Current State: 
 Disabled 
Setting 
(Display 
Only) 
Disable EBAM 
Action 
This action deactivates HP Enhanced 
BIOS Authentication Mode. 
Local Access Key: 
 Not Present 
Setting 
(Display 
Only) 
Local Access Key is the public key 
that is used by BIOS (as part of Sure 
Admin mode) to generate the 
encrypted “Challenge QR-code” that 
is used to control access to F10 
setup ( response PIN is obtained 
using the HP Sure Admin Local 
Access Authenticator to read the 
QR-code and decrypt [if it has 
access to the private Local Access 
Key] it to obtain the response PIN) 
Clear EBAM Local Access Key(s) and 
Reboot 
Action 
This action deletes all currently 
established EBAM Local Access 
Keys. 










