Specifications

Table 29. Security(continued)
Option Description
Non-Admin Setup
Changes
Allows you to determine whether changes to the setup options are allowed when an Administrator
Password is set. If disabled the setup options are locked by the admin password.
Allow Wireless Switch Changes
This option is not set by default.
UEFI Capsule Firmware
Updates
Allows you to update the system BIOS via UEFI capsule update packages.
Enable UEFI Capsule Firmware Updates
This option is set by default.
TPM 2.0 Security
Allows you to enable or disable the Trusted Platform Module (TPM) during POST.
The options are:
TPM On—Default
Clear
PPI Bypass for Enable Command—Default
PPI Bypass for Disbale Command
PPI Bypass for Clear Command
Attestation Enable—Default
Key Storage Enable—Default
SHA-256—Default
Absolute (R)
Allows you to activate or disable the optional Computrace software.
The options are:
Deactivate
Disable
Activate—Default
OROM keyboard Access
Allows you to enable or disable Option ROM configuration screens via hotkeys during boot.
Enable—Default
Disable
One Time Enable
Admin Setup Lockout
Allows you to prevent users from entering Setup when an administrator password is set.
Enable Admin Setup Lockout
This option is not set by default.
Master Password Lockout
Allows you to disable master password support.
Enable Master Password Lockout
This option is not set by default.
NOTE: Hard Disk password should be cleared before the settings can be changed.
SMM Security Mitigation
Allows you to enable or disable additional UEFI SMM Security Mitigation protection.
SMM Security Mitigation
This option is not set by default.
28 System setup