User's Guide

Table Of Contents
DisabledisthedefaultvaluewhenOSOptimizedissettoDisabled.Enabledisthedefaultvaluewhen
OSOptimizedissettoEnabled.
Note:ToenableSecureBoot,youneedtosetthestartupsettingasUEFIOnlyandsetCSMSupport
asNo.
PlatformMode
Values:SetupMode,UserMode
Descriptions:Specifythesystemoperatingmode.
SecureBootMode
Values:StandardMode,CustomMode
Descriptions:SpecifytheSecureBootmode.
ResettoSetupMode
Descriptions:ThisoptionisusedtoclearthecurrentplatformkeyandputthesystemintoSetupMode.
YoucaninstallyourownplatformkeyandcustomizetheSecureBootsignaturedatabasesinSetup
Mode.SecureBootmodewillbesettoCustomMode.
RestoreFactoryKeys
Descriptions:UsethisoptiontorestoreallkeysandcertificatesinSecureBootdatabasestothefactory
defaults.AnycustomizedSecureBootsettingswillbeerased,andthedefaultPlatformKeywillbe
re-establishedalongwiththeoriginalsignaturedatabasesincludingcertificatefortheoperatingsystems.
ClearAllSecureBootKeys
Descriptions:UsethisoptiontoclearallkeysandcertificatesinSecureBootdatabasesandinstall
yourownkeysandcertificates.
Intel(R)SGX
Intel(R)SGXControl
Values:Disabled,Enabled,SoftwareControlled
Descriptions:EnableordisabletheIntelSoftwareGuardExtensions(SGX)function.Ifyouselect
SoftwareControlled,SGXwillbecontrolledbytheoperatingsystem.
ChangeOwnerEPOCH
Value:Enter
Descriptions:ChangeOwnerEPOCHtoarandomvalue.UsethisoptiontoclearSGXuserdata.
Note:Thissub-menuisavailableonmodelswithanIntelCPU.
Startupmenu
Note:TheBIOSmenuitemsmightchangewithoutnotice.Dependingonthemodel,thedefaultvalue
mightvary.
Boot
Descriptions:Definethestartupsequence.
NetworkBoot
Descriptions:SelectthebootdevicewhenthesystemwakesfromLAN.IfWakeOnLANisenabled,the
networkadministratorcanturnonallofthecomputersinaLANremotelythroughnetworkmanagement
software.
UEFI/LegacyBoot
Values:Both,UEFIOnly,LegacyOnly
Descriptions:Definethesystembootcapability.
Chapter6.Advancedconfiguration57