Security#
General#
More information at Lenovo Support - types of password
Supervisor Password#
Display only
Possible options:
- Not Installed - password disabled. Default.
- Installed - password enabled.
Power-On Password#
Display only
Possible options:
- Not Installed - password disabled. Default.
- Installed - password enabled.
System Management Password#
Display only
Possible options:
- Not Installed - password disabled. Default.
- Installed - password enabled.
Set Supervisor Password#
Set, change, or delete the Supervisor Password.
Attention
To delete Supervisor Password, enter blank fields for each new password line item.
Enter and confirm new password.
Set Power-On Password#
Set, change, or delete the Power-On Password.
Attention
To delete Power-On Password, enter blank fields for each new password line item.
Enter and confirm new password.
Set System Management Password#
Set, change, or delete the System Management Password (SMP).
Attention
To delete System Management Password, enter blank fields for each new password line item.
Enter and confirm new password.
Secure Roll Back Prevention#
Whether flashing BIOS to a previous or current version is prevented (NOT allowed).
Possible options:
- Yes - Flashing NOT allowed. Default.
- No - Flashing BIOS allowed.
| WMI Setting name | Values | Locked by SVP |
|---|---|---|
| SecureRollBackPrevention | No, Yes | Yes |
Windows UEFI Firmware Update#
Possible options:
- Enabled - Default.
- Disabled - BIOS will skip Windows UEFI firmware update.
| WMI Setting name | Values | Locked by SVP |
|---|---|---|
| WindowsUEFIFirmwareUpdate | Disabled, Enabled | Yes |
Smart USB Protection#
Block USB write access (copying data from computer to USB storage device) in Windows.
Possible options:
- Disabled - Default.
- Read Only - The user can copy data from USB to computer, but not from computer to USB.
- No Access - The user cannot use USB storage device in Windows.
| WMI Setting name | Values | Locked by SVP |
|---|---|---|
| SmartUSBProtection | Disabled, Read Only, No Access | Yes |
Secure Wipe#
Hide or display the secure wipe option on the F12 BIOS Startup Menu.
Possible options:
- Disabled - hides
secure wipeoption. Default. - Enabled - shows
secure wipeoption.
| WMI Setting name | Values | Locked by SVP |
|---|---|---|
| securewipe | Disabled, Enabled | Yes |
Device Guard#
Device Guard protects against malware by restricting the device across several technologies.
Possible options:
- Disabled - Ethernet, USB, CD, and other boot methods are enabled. Default.
- Enabled - CPU Virtualization Technology, IOMMU (Intel VT-d, AMD-Vi), Secure boot, and TPM are enabled. Ethernet, USB, CD, and other boot methods are disabled. Only SATA devices are allowed.
| WMI Setting name | Values | Locked by SVP |
|---|---|---|
| DeviceGuard | Disabled, Enabled | Yes |
Secure Core PC Level3#
Whether to support Windows 10/11 Secured-core PCs' Level3.
Possible options:
- Disabled - Default.
- Enabled
More information at Microsoft Docs
Electronic Lock#
Whether to lock the chassis to prevent unauthorized physical access to the system components.
Attention
Effective on the next startup after BIOS setting is saved.
Possible options:
- Disabled - Default.
- Enabled
Cover Tamper Detected#
Chassis Intrusion Detection is a utility that can tell whether someone has opened the case (intruded into the chassis).
Attention
If chassis tamper occurs, you can only clear this error by entering setup.
Possible options:
- Disabled - Default.
- Enabled
| WMI Setting name | Values | Locked by SVP |
|---|---|---|
| CoverTamperDetected | Disabled, Enabled | Yes |
Configuration Change Detection#
Attention
This notice can only be cleared by entering BIOS setup, saving and then exiting.
Possible options:
- Disabled - Default.
- Enabled - When a device is installed or removed, the system will notify the user during POST.
| WMI Setting name | Values | Locked by SVP |
|---|---|---|
| ConfigurationChangeDetection | Disabled, Enabled | Yes |