Dell Inspiron 24 5415 All-in-One Service Manual - Page 74

Table 6. System setup options-Security menu continued, Security, Secure Boot

Page 74 highlights

Table 6. System setup options-Security menu (continued) Security Default: Not Set HDD Password Displays if the HDD password is clear or set. Default: Not Set Password Change Allows you to permit or deny system password or HDD password changes. Default: Permitted SED Block SID Authentication Enables or disables SED Block SID Authentication. Default: Disabled PPI Bypass for SED Block SID Command When there is no drive ownership and this option is enabled, BIOS requires user input while sending the Block SID authentication command to SED drives. When this option is disabled, BIOS does not require user input while sending the Block SID command. Default: Disabled Windows SMM Security Mitigations Table (WSMT) Enables or disables the Windows SMM Security Mitigations Table. It allows the system firmware to confirm to the OS that certain security best practices have been implemented in the System Management Mode (SMM) software. Default: Disabled Firmware TPM Enable or disable the firmware TPM. Default: Enabled PPI Bypass for Clear Command Allows you to control the TPM Physical Presence Interface (PPI). When enabled, this setting will allow the OS to skip BIOS PPI user prompts when issuing the Clear command. Changes to this setting take effect immediately. Default: Disabled Enable Pre-Boot DMA Support Enables or disables pre-boot DMA protection for both internal and external ports. Default: Enabled Enable OS Kernel DMA Support Enables or disables Kernel DMA protection for both internal and external ports. Default: Enabled Secure Boot System Status: Secure Boot Database Secure Boot Mode Default: Installed and Locked Default: Enabled User Customized Security Options Default: No Secure Boot Enables secure boot using only validated boot software. Default: Enabled Select Secure Mode Allows you to modify the behavior of Secure Boot to allow evaluation or enforcement of UEFI driver signatures. Default: Deployed Mode 74 System setup

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82

Table 6. System setup options—Security menu (continued)
Security
Default: Not Set
HDD Password
Displays if the HDD password is clear or set.
Default: Not Set
Password Change
Allows you to permit or deny system password or HDD
password changes.
Default: Permitted
SED Block SID Authentication
Enables or disables SED Block SID Authentication.
Default: Disabled
PPI Bypass for SED Block SID Command
When there is no drive ownership and this option is enabled,
BIOS requires user input while sending the Block SID
authentication command to SED drives. When this option
is disabled, BIOS does not require user input while sending
the Block SID command.
Default: Disabled
Windows SMM Security Mitigations Table (WSMT)
Enables or disables the Windows SMM Security Mitigations
Table. It allows the system firmware to confirm to the OS
that certain security best practices have been implemented
in the System Management Mode (SMM) software.
Default: Disabled
Firmware TPM
Enable or disable the firmware TPM.
Default: Enabled
PPI Bypass for Clear Command
Allows you to control the TPM Physical Presence Interface
(PPI). When enabled, this setting will allow the OS to skip
BIOS PPI user prompts when issuing the Clear command.
Changes to this setting take effect immediately.
Default: Disabled
Enable Pre-Boot DMA Support
Enables or disables pre-boot DMA protection for both
internal and external ports.
Default: Enabled
Enable OS Kernel DMA Support
Enables or disables Kernel DMA protection for both internal
and external ports.
Default: Enabled
Secure Boot
System Status:
Secure Boot Database
Default: Installed and Locked
Secure Boot Mode
Default: Enabled
User Customized Security Options
Default: No
Secure Boot
Enables secure boot using only validated boot software.
Default: Enabled
Select Secure Mode
Allows you to modify the behavior of Secure Boot to allow
evaluation or enforcement of UEFI driver signatures.
Default: Deployed Mode
74
System setup