HP EliteBook 735 PC Commercial BIOS UEFI Setup - Page 27

BIOS Sure Start Menu

Page 27 highlights

HP PC Commercial BIOS (UEFI) Setup July 2020 919946-004 4.4 BIOS Sure Start Menu Settings menu for enhanced hardware-based assurance that only HP approved Embedded Controller firmware will run on the HP Embedded Controller and that only HP approved BIOS will run on the host CPU. Table 14 BIOS Sure Start Menu features Feature  Verify Boot Block on Every Boot BIOS Data Recovery Policy Network Controller Configuration Restore  Prompt on Network Controller Configuration Change  Dynamic Runtime Scanning of Boot Block  Sure Start BIOS Settings Protection Type Setting Setting Action Setting Setting Setting Description When not checked, HP Sure Start verifies the integrity of HP firmware in the nonvolatile (flash) memory before resume from Sleep, Hibernate, or Off. When checked, HP Sure Start verifies the integrity of HP firmware in the nonvolatile (flash) memory across operating system restart (warm reset) in addition to resume from Sleep, Hibernate Off. This setting provides higher security assurance but could increase the time required to restart operating system. The following settings are possible for HP Sure Start- Recovery Policy: • Automatic • Manual Automatic: HP Sure Start automatically repairs any HP firmware integrity issues in the nonvolatile (flash) memory. Manual: HP Sure Start will not repair any HP firmware integrity issues in the nonvolatile (flash) memory until the Windows +Up Arrow+ Down Arrow keys are pressed. NOTE: Manual recovery is intended for use by the system administrator in the event forensic investigation is desired before HP Sure Start repairs the issue. It is not recommended for the typical user. Network Controller Configuration Restore This action restores the network controller parameters to the factory state saved in the HP Sure Start Private nonvolatile (flash) memory. NOTE: This process can take up to 30 seconds. You need to restore this only when the Network Controller Configuration mismatch warning is set. When enabled, HP Sure Start will monitor the network controller configuration and prompt the local user if any changes are detected compared to the factory configuration. The local user has the option to ignore the prompt or restore the network controller to the factory configuration when prompted. When checked, allows HP Sure Start verifies the integrity of the HP firmware in the nonvolatile (flash) memory every 15 minutes while the system is on and the operating system is running. Protects critical BIOS Settings by saving a backup copy and restoring them if altered. Default Unchecked Automatic Checked Checked Unchecked Notes Reboot Required Reboot Required Reboot Required Intel Only Reboot Physical Presence Required Not accessible with no Admin credentials set © Copyright 2016-2020 HP Development Company, L.P. 4 Security Menu 27

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105

HP PC Commercial BIOS (UEFI) Setup
July 2020
919946-004
© Copyright 2016-2020 HP Development Company, L.P.
4 Security
Menu
27
4.4
BIOS Sure Start Menu
Settings menu for enhanced hardware-based assurance that only HP approved Embedded Controller firmware will run on
the HP Embedded Controller and that only HP approved BIOS will run on the host CPU.
Table 14
BIOS Sure Start Menu features
Feature
Type
Description
Default
Notes
Verify Boot Block
on Every Boot
Setting
When not checked, HP Sure Start verifies the integrity of
HP firmware in the nonvolatile (flash) memory before
resume from Sleep, Hibernate, or Off.
When checked, HP Sure Start verifies the integrity of HP
firmware in the nonvolatile (flash) memory across
operating system restart (warm reset) in addition to
resume from Sleep, Hibernate Off. This setting provides
higher security assurance but could increase the time
required to restart operating system.
Unchecked
Reboot
Required
BIOS Data Recovery
Policy
Setting
The following settings are possible for HP Sure Start
Recovery Policy:
Automatic
Manual
Automatic
: HP Sure Start automatically repairs any HP
firmware integrity issues in the nonvolatile (flash)
memory.
Manual
: HP Sure Start will not repair any HP firmware
integrity issues in the nonvolatile (flash) memory until
the Windows +Up Arrow+ Down Arrow keys are pressed.
NOTE:
Manual recovery is intended for use by the
system administrator in the event forensic investigation
is desired before HP Sure Start repairs the issue. It is not
recommended for the typical user.
Automatic
Reboot
Required
Network Controller
Configuration
Restore
Action
Network Controller Configuration Restore
This action restores the network controller parameters
to the factory state saved in the HP Sure Start Private
nonvolatile (flash) memory.
NOTE:
This process can take up to 30 seconds. You need
to restore this only when the Network Controller
Configuration mismatch warning is set.
Reboot
Required
Prompt on
Network Controller
Configuration
Change
Setting
When enabled, HP Sure Start will monitor the network
controller configuration and prompt the local user if any
changes are detected compared to the factory
configuration. The local user has the option to ignore the
prompt or restore the network controller to the factory
configuration when prompted.
Checked
Intel Only
Reboot
Physical
Presence
Required
Dynamic Runtime
Scanning of Boot
Block
Setting
When checked, allows HP Sure Start verifies the integrity
of the HP firmware in the nonvolatile (flash) memory
every 15 minutes while the system is on and the
operating system is running.
Checked
Sure Start BIOS
Settings Protection
Setting
Protects critical BIOS Settings by saving a backup copy
and restoring them if altered.
Unchecked
Not accessible
with no Admin
credentials set