HP Engage Go 10 Maintenance and Service Guide - Page 55

Table 5-2, Save/Restore GPT of System Hard Drive

Page 55 highlights

Table 5-2 Computer Setup Security (continued) Option Description ● Deactivate HP Sure Run: Requires BIOS Administrator password to be configured. ● Local Access Key: Indicates is the key is present. Also lets you clear the keys and reboot. Clear EBAM Local Access Key(s) and Reboot. Deletes all currently established local access keys created for Enhanced BIOS Authentication Mode (EBAM). Physical Presence Interface: When set to enabled, the user is notified at system power up when changes are made to system security policy. The user must manually agree to those changes before the change is confirmed. Default is enabled. Smart Cover: The Smart Cover Lock is a software-controllable solenoid lock that restricts unauthorized access to the system's internal components. (select products only) ● Cover Lock: Default is unlock. ● Cover Removal Sensor: Lets you disable the cover sensor or configure what action is taken if the computer cover is removed. Default is disabled. NOTE: Notify user alerts the user with a POST error on the first boot after the sensor detects removal of the cover. If the password is set, Administrator Password requires that the password be entered to boot the computer if the sensor detects that the cover has been removed. Trusted Execution Technology (TXT) Enables Trusted Execution Technology on select Intel-based systems. Default is disabled. NOTE: Enabling this feature disables OS management of TPM (Embedded Security Device), prevents a reset of the TPM, and constrains the configuration of VTx, VTd, and TPM. Intel Software Guard Extensions (SGX) Intel SGX is a set of processor code instructions from that allows user-level code to allocate private regions of memory, that unlike normal process memory is also protected from processes running at higher privilege levels. ● Software control ● Disable ● Enable Full encryption of main memory (DRAM) (select products only) When selected, the computer stores all data to DRAM in an encrypted format. Utilities Hard Drive Utilities ● Save/Restore GPT of System Hard Drive Enabling this feature saves the GUID Partition Table (GPT) of the system hard drive. If the GPT is subsequently changed, the user is prompted to choose whether to restore GPT. Default is disabled. ● Boot Sector (GPT) Recovery Policy Allows selection of the default action when a GPT event occurs. ● DriveLock/Automatic DriveLock Allows you to assign or modify a master or user password for hard drives. When this feature is enabled, the user is prompted to provide one of the DriveLock passwords during POST. If neither is successfully entered, the hard drive remains inaccessible until one of the passwords is successfully provided during a subsequent cold-boot sequence. NOTE: This selection appears only when at least one drive that supports the DriveLock feature is attached to the system. IMPORTANT: Be aware that these settings take place immediately. It is not necessary to save. Computer Setup Security 47

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93

Table 5-2
Computer Setup Security (continued)
Option
Description
Deactivate HP Sure Run: Requires BIOS Administrator password to be configured.
Local Access Key: Indicates is the key is present. Also lets you clear the keys and reboot.
Clear EBAM Local Access Key(s) and Reboot. Deletes all currently established local access keys
created for Enhanced BIOS Authentication Mode (EBAM).
Physical Presence Interface
: When set to enabled, the user is notified at system power up when changes
are made to system security policy. The user must manually agree to those changes before the change is
confirmed. Default is enabled.
Smart Cover
: The Smart Cover Lock is a software-controllable solenoid lock that restricts unauthorized
access to the system’s internal components. (select products only)
Cover Lock: Default is unlock.
Cover Removal Sensor: Lets you disable the cover sensor or configure what action is taken if the
computer cover is removed. Default is disabled.
NOTE:
Notify user
alerts the user with a POST error on the first boot after the sensor detects
removal of the cover. If the password is set,
Administrator Password
requires that the password be
entered to boot the computer if the sensor detects that the cover has been removed.
Trusted Execution Technology (TXT)
Enables Trusted Execution Technology on select Intel-based systems. Default is disabled.
NOTE:
Enabling this feature disables OS management of TPM (Embedded Security Device), prevents a
reset of the TPM, and constrains the configuration of VTx, VTd, and TPM.
Intel Software Guard Extensions (SGX)
Intel SGX is a set of processor code instructions from that allows user-level code to allocate private
regions of memory, that unlike normal process memory is also protected from processes running at
higher privilege levels.
Software control
Disable
Enable
Full encryption of main memory (DRAM)
(select products only)
When selected, the computer stores all data to DRAM in an encrypted format.
Utilities
Hard Drive Utilities
Save/Restore GPT of System Hard Drive
Enabling this feature saves the GUID Partition Table (GPT) of the system hard drive. If the GPT is
subsequently changed, the user is prompted to choose whether to restore GPT. Default is disabled.
Boot Sector (GPT) Recovery Policy
Allows selection of the default action when a GPT event occurs.
DriveLock/Automatic DriveLock
Allows you to assign or modify a master or user password for hard drives. When this feature is
enabled, the user is prompted to provide one of the DriveLock passwords during POST. If neither is
successfully entered, the hard drive remains inaccessible until one of the passwords is successfully
provided during a subsequent cold-boot sequence.
NOTE:
This selection appears only when at least one drive that supports the DriveLock feature is
attached to the system.
IMPORTANT:
Be aware that these settings take place immediately. It is not necessary to save.
Computer Setup Security
47