HP mt21 PC Commercial BIOS UEFI Setup - Page 61

Table 36, Feature, Description, Default, Notes

Page 61 highlights

HP PC Commercial BIOS (UEFI) Setup Table 36 Security Menu features Feature Create BIOS Administrator Password Or Change BIOS Administrator Password Create POST Power-On Password Or Change POST PowerOn Password Password Policies Administrator Authentication Policies  Fingerprint Reset on Reboot Type Setting Setting Menu Menu Action Description The administrator password controls access to the setup menu (F10), 3rd Party Option ROM Management (F3), Update System ROM, WMI commands that change system settings, and the BIOS Configuration Utility (BCU). When no administrator password is set, anyone can change the system settings, add 3rd Party Option ROM, or update the system ROM. When the power-on password is set, use the administrator password as an alternative to power-on the system. Recommendation: Set an administrator password when a power-on password is set. When a power-on password is forgotten, an administrator can reset the power-on password by using Restore Security Settings to Factory Defaults. Password required to power-on the PC, independent of the OS password. When no password is set, anyone can turn on the PC. In addition to the administrator password, there is only one power-on password. Recommendation: Set an administrator password when a power-on password is set. When a power-on password is forgotten, an administrator can reset the power-on password by using Restore Security Settings to Factory Defaults. Allows the administrator to set password requirements for BIOS administration and power-on regarding the use of symbols, numbers, case, and spaces. Allows the administrator to determine whether the administrator password is required to access various boot menus through hot keys at boot time, or to update the firmware through Windows Update. NOTE: the settings in this menu were previously located in the Password Policies menu. When checked, resets the fingerprint on the next reboot. After reboot, this will be unchecked again. Default Unchecked TPM Embedded Security Menu The Trusted Platform Module (TPM) is a dedicated microprocessor that provides security functions for secure communication and software and hardware integrity. BIOS Sure Start Menu Settings that control the behavior of HP Sure Start. HP Sure Start is a built-in hardware security system that protects your BIOS from accidental or malicious corruption by (1) detecting BIOS corruption and then (2) automatically restoring the BIOS to its last installed HP-certified version. Some platforms in 2019 have the capability to recover Intel ME as well. Secure Platform Management (SPM) Menu Options for managing HP Sure Run and HP Sure Recover and Sure Admin July 2020 919946-004 Notes © Copyright 2016-2019 HP Development Company, L.P. 7 Security Menu (2019 and older) 61

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105

HP PC Commercial BIOS (UEFI) Setup
July 2020
919946-004
© Copyright 2016-2019 HP Development Company, L.P.
7
Security Menu
(2019 and older)
61
Table 36
Security Menu features
Feature
Type
Description
Default
Notes
Create BIOS Administrator
Password
Or Change BIOS
Administrator Password
Setting
The administrator password controls access to the
setup menu (F10), 3
rd
Party Option ROM Management
(F3), Update System ROM, WMI commands that
change system settings, and the BIOS Configuration
Utility (BCU). When no administrator password is set,
anyone can change the system settings, add 3
rd
Party
Option ROM, or update the system ROM. When the
power-on password is set, use the administrator
password as an alternative to power-on the system.
Recommendation
: Set an administrator password
when a power-on password is set. When a power-on
password is forgotten, an administrator can reset the
power-on password by using Restore Security
Settings to Factory Defaults.
Create POST Power-On
Password
Or Change POST Power-
On Password
Setting
Password required to power-on the PC, independent
of the OS password. When no password is set, anyone
can turn on the PC. In addition to the administrator
password, there is only one power-on password.
Recommendation
: Set an administrator password
when a power-on password is set. When a power-on
password is forgotten, an administrator can reset the
power-on password by using Restore Security
Settings to Factory Defaults.
Password Policies
Menu
Allows the administrator to set password
requirements for BIOS administration and power-on
regarding the use of symbols, numbers, case, and
spaces.
Administrator
Authentication Policies
Menu
Allows the administrator to determine whether the
administrator password is required to access various
boot menus through hot keys at boot time, or to
update the firmware through Windows Update.
NOTE
: the settings in this menu were previously
located in the Password Policies menu.
Fingerprint Reset on
Reboot
Action
When checked, resets the fingerprint on the next
reboot. After reboot, this will be unchecked again.
Unchecked
TPM Embedded Security
Menu
The Trusted Platform Module (TPM) is a dedicated
microprocessor that provides security functions for
secure communication and software and hardware
integrity.
BIOS Sure Start
Menu
Settings that control the behavior of HP Sure Start.
HP Sure Start is a built-in hardware security system
that protects your BIOS from accidental or malicious
corruption by (1) detecting BIOS corruption and then
(2) automatically restoring the BIOS to its last
installed HP-certified version. Some platforms in
2019 have the capability to recover Intel ME as well.
Secure Platform
Management (SPM)
Menu
Options for managing HP Sure Run and HP Sure
Recover and Sure Admin