Desktop Management Guide Business PCs
© Copyright 2007 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. Microsoft, Windows, and Windows Vista are either trademarks or registered trademarks of Microsoft Corporation in the United States and/or other countries. Intel and vPro are trademarks of Intel Corporation in the U.S. and other countries. The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and services.
About This Book This guide provides definitions and instructions for using security and manageability features that are preinstalled on some models. WARNING! Text set off in this manner indicates that failure to follow directions could result in bodily harm or loss of life. CAUTION: Text set off in this manner indicates that failure to follow directions could result in damage to equipment or loss of information. NOTE: Text set off in this manner provides important supplemental information.
iv About This Book
Table of contents 1 Desktop Management Overview 2 Initial Configuration and Deployment HP Software Agent ............................................................................................................................... 2 Altiris Deployment Solution Agent ........................................................................................................ 2 3 Remote System Installation 4 Software Updating and Management HP Client Management Interface .........................................
10 Industry Standards 11 Asset Tracking and Security Password Security .............................................................................................................................. 24 Establishing a Setup Password Using Computer Setup .................................................... 25 Establishing a Power-On Password Using Computer Setup ............................................. 25 Entering a Power-On Password ........................................................................
1 Desktop Management Overview HP Client Management Solutions provides standards-based solutions for managing and controlling desktops, workstations, and notebook PCs in a networked environment. HP pioneered desktop manageability in 1995 with the introduction of the industry’s first fully manageable desktop personal computers. HP is a patent holder of manageability technology.
2 Initial Configuration and Deployment The computer comes with a preinstalled system software image. After a brief software “unbundling” process, the computer is ready to use. You may prefer to replace the preinstalled software image with a customized set of system and application software. There are several methods for deploying a customized software image. They include: ● Installing additional software applications after unbundling the preinstalled software image.
To install Altiris Deployment Solution Agent: 1. Click Start. 2. Click All Programs. 3. For Windows Vista, click Install Altiris DAgent. For Windows XP, click Install Altiris AClient. 4. Follow the onscreen instructions to set up and configure the Altiris client. This agent is a key infrastructure component for enabling Altiris Deployment Solution which is part of the Altiris Client Management Suite.
3 Remote System Installation Remote System Installation allows you to start and set up the system using the software and configuration information located on a network server by initiating the Preboot Execution Environment (PXE).
4 Software Updating and Management HP provides several tools for managing and updating software on desktops, workstations, and notebooks: ● HP Client Management Interface ● HP SoftPaq Download Manager ● HP System Software Manager ● HP ProtectTools Security Manager ● HP Client Configuration Manager ● HP Configuration Management Solution ● HP Client Manager for Altiris ● Altiris Client Management Suite ● HP Client Catalog for SMS ● HP Backup and Recovery Manager ● Intel vPro-branded PCs
HP Client Management Interface used in conjunction with system management software can: ● Request in-depth client inventory information—Capture detailed information about the processors, hard drives, memory, BIOS, drivers, including sensor information (such as fan speed, voltage, and temperature).
HP ProtectTools Security Manager HP ProtectTools Security Manager software provides security features that help protect against unauthorized access to the computer, networks, and critical data.
HP Configuration Management Solution HP Configuration Management Solution is a policy-based solution that enables administrators to inventory, deploy, patch, and continuously manage software and content across heterogeneous client platforms.
For more information on HP Client Manager, visit http://www.hp.com/go/clientmanager. Altiris Client Management Suite Altiris Client Management Suite is an easy-to-use solution for full life-cycle software management of desktops, notebooks, and workstations.
To create the Recovery Disc Set: 1. Click Start > HP Backup and Recovery > HP Backup and Recovery Manager to open the Backup and Recovery Wizard, then click Next. 2. Select Create a set of recovery discs (Recommended) and click Next. 3. Follow the instructions in the wizard. For more information on using HP Backup and Recovery Manager, refer to the HP Backup and Recovery Manager User Guide by selecting Start > HP Backup and Recovery > HP Backup and Recovery Manager Manual.
To configure Intel vPro systems for AMT or ASF: 1. Turn on or restart the computer. If you are in Microsoft Windows, click Start > Shut Down > Restart. 2. As soon as the computer is turned on, press the hot key, Ctrl+P, when the monitor light turns green. NOTE: If you do not press Ctrl+P at the appropriate time, you must restart the computer and again press Ctrl+P when the monitor light turns green to access the utility.
commercial desktop models. Surveyor licenses for managing PCs may be purchased through your HP representative.
5 ROM Flash The computer's BIOS is stored in a programmable flash ROM (read only memory). By establishing a setup password in the Computer Setup (F10) Utility, you can protect the ROM from being unintentionally updated or overwritten. This is important to ensure the operating integrity of the computer. Should you need or want to upgrade the BIOS, you may download the latest BIOS images from the HP driver and support page, http://www.hp.com/support/files.
6 Boot Block Emergency Recovery Mode Boot Block Emergency Recovery Mode permits system recovery in the unlikely event of a ROM flash failure. For example, if a power failure were to occur during a BIOS upgrade, the ROM flash would be incomplete. This would render the system BIOS unusable. The Boot Block is a flash-protected section of the ROM that contains code that checks for a valid system BIOS image when the system is turned on. ● If the system BIOS image is valid, the system starts normally.
7 Replicating the Setup The following procedures give an administrator the ability to easily copy one setup configuration to other computers of the same model. This allows for faster, more consistent configuration of multiple computers. NOTE: Both procedures require a diskette drive or a supported USB flash media device, such as an HP Drive Key. Copying to Single Computer CAUTION: A setup configuration is model-specific.
NOTE: A bootable diskette is required for this procedure or to create a bootable USB flash media device. If Windows XP is not available to use to create a bootable diskette, use the method for copying to a single computer instead (see Copying to Single Computer on page 15). 1. Create a bootable diskette or USB flash media device. See Supported USB Flash Media Device on page 16 or Unsupported USB Flash Media Device on page 18. CAUTION: Not all computers can be booted from a USB flash media device.
CAUTION: Some older PCs may not be bootable from a USB flash media device. If the default boot order in the Computer Setup (F10) Utility lists the USB device before the hard drive, the computer can be booted from a USB flash media device. Otherwise, a bootable diskette must be used. 1. Turn off the computer. 2. Insert the USB flash media device into one of the computer's USB ports and remove all other USB storage devices except USB diskette drives. 3. Insert a bootable DOS diskette with FDISK.
Unsupported USB Flash Media Device To create a bootable USB flash media device, you must have: ● a USB flash media device ● a bootable DOS diskette with the FDISK and SYS programs (If SYS is not available, FORMAT may be used, but all existing files on the USB flash media device will be lost.) ● a PC that is bootable from a USB flash media device CAUTION: Some older PCs may not be bootable from a USB flash media device.
15. Go to Advanced > PCI Devices and re-enable the PATA and SATA controllers that were disabled in step 6. Put the SATA controller on its original IRQ. 16. Save the changes and exit. The computer will boot to the USB flash media device as drive C. NOTE: The default boot order varies from computer to computer, and it can be changed in the Computer Setup (F10) Utility. Refer to the Computer Setup (F10) Utility for instructions.
8 Dual-State Power Button With Advanced Configuration and Power Interface (ACPI) enabled, the power button can function either as an on/off switch or as a standby button. The standby feature does not completely turn off power, but instead causes the computer to enter a low-power standby state. This allows you to power down quickly without closing applications and to return quickly to the same operational state without any data loss.
9 HP Web Site Support HP engineers rigorously test and debug software developed by HP and third-party suppliers, and develop operating system specific support software, to ensure performance, compatibility, and reliability for HP computers. When making the transition to new or revised operating systems, it is important to implement the support software designed for that operating system.
10 Industry Standards HP management solutions integrate with other systems management applications, and are based on industry standards, such as: 22 ● Web-Based Enterprise Management (WBEM) ● Windows Management Interface (WMI) ● Wake on LAN Technology ● ACPI ● SMBIOS ● Pre-boot Execution (PXE) support Chapter 10 Industry Standards
11 Asset Tracking and Security Asset tracking features incorporated into the computer provide key asset tracking data that can be managed using HP Systems Insight Manager, HP Client Manager, HP Configuration Management Solution, HP Client Configuration Manager, or other system management applications.
Table 11-1 Security Features Overview (continued) Option Description Password Options Allows you to specify whether the password is required for warm boot (Ctrl +Alt+Del). (This selection will appear only if a power-on password is set.) See the Troubleshooting Guide for more information. Pre-Boot Authorization Allows you to enable/disable the Smart Card to be used in place of the PowerOn Password. Smart Cover (some models) Allows you to: ● Enable/disable the Cover Lock.
specifically prevents unauthorized access to Computer Setup, and can also be used as an override to the power-on password. That is, when prompted for the power-on password, entering the setup password instead will allow access to the computer. A network-wide setup password can be established to enable the system administrator to log in to all network systems to perform maintenance without having to know the power-on password, even if one has been established.
Entering a Setup Password If the system is equipped with an embedded security device, refer to the HP ProtectTools Security Manager Guide at http://www.hp.com. If a setup password has been established on the computer, you will be prompted to enter it each time you run Computer Setup. 1. Turn on or restart the computer. If you are in Windows, click Start > Shut Down > Restart. 2. As soon as the computer is turned on, press F10 when the monitor light turns green to enter Computer Setup.
Deleting a Power-On or Setup Password If the system is equipped with an embedded security device, refer to the HP ProtectTools Security Manager Guide at http://www.hp.com. 1. Turn on or restart the computer. If you are in Windows, click Start > Shut Down > Restart the Computer. 2. To delete the Power-On password, go to step 3. To delete the Setup password, as soon as the computer is turned on, press F10 when the monitor light turns green to enter Computer Setup.
DriveLock DriveLock is an industry-standard security feature that prevents unauthorized access to the data on ATA hard. DriveLock has been implemented as an extension to Computer Setup. It is only available when hard drives that support the ATA Security command set are detected. DriveLock is intended for HP customers for whom data security is the paramount concern.
passwords is much greater than the value of the data DriveLock has been designed to protect. Access to Computer Setup and DriveLock can be restricted through the Setup password. By specifying a Setup password and not giving it to end users, system administrators are able to restrict users from enabling DriveLock. Smart Cover Sensor CoverRemoval Sensor, available on some models, is a combination of hardware and software technology that can alert you when the computer cover or side panel has been removed.
Locking the Smart Cover Lock To activate and lock the Smart Cover Lock, complete the following steps: 1. Turn on or restart the computer. If you are in Windows, click Start > Shut Down > Restart. 2. As soon as the computer is turned on, press F10 when the monitor light turns green to enter Computer Setup. Press Enter to bypass the title screen, if necessary.
Fingerprint Identification Technology Eliminating the need to enter user passwords, HP Fingerprint Identification Technology tightens network security, simplifies the login process, and reduces the costs associated with managing corporate networks. Affordably priced, it is not just for high-tech, high-security organizations anymore. NOTE: Support for Fingerprint Identification Technology varies by model. For more information, visit: http://h18004.www1.hp.com/products/security/.
Index A access to computer, controlling 23 Active Management Technology, Intel vPro-branded PCs with 10 Altiris AClient 2 Deployment Solution Agent 2 asset tracking 23 B BIOS Boot Block Emergency Recovery Mode 14 HPQFlash 13 Remote ROM Flash 13 Boot Block Emergency Recovery Mode 14 bootable device creating 16 DiskOnKey 16, 18 HP Drive Key 16, 18 USB flash media device 16 C cable lock provision 30 cautions cover lock security 29 FailSafe Key 30 protecting ROM 13 change notification 12 changing operating syst
PCN (Proactive Change Notification) 12 power button configuring 20 dual-state 20 power supply, surge-tolerant 31 power-on password changing 26 deleting 27 entering 25 setting 25 Preboot Execution Environment (PXE) 4 preinstalled software image 2 Proactive Change Notification (PCN) 12 protecting hard drive 31 protecting ROM, caution 13 ProtectTools Security Manager 7 PXE (Preboot Execution Environment) 4 R Recovery Mode, Boot Block Emergency 14 recovery, software 2 Remote ROM Flash 13 remote setup 4 Remote S