Table 10. System setup options—Power menu (continued)
Power
Block Sleep Enables to block entering sleep (S3) mode in the operating system.
By default, the Block Sleep option is disabled.
Deep Sleep Control Deep Sleep Control option is disabled in order to enable the Wake from USB
keyboard and mouse feature to work in the shutdown (S5) and Hibernate (S4)
states.
By default, the option is disabled.
Intel Speed Shift Technology Enable or disable the Intel speed shift technology support.
By default, the Intel Speed Shift Technology option is enabled.
Table 11. System setup options—Security menu
Security
TPM 2.0 Security
TPM 2.0 Security On Allows you to enable or disable TPM visibility to operating system.
By default, the TPM 2.0 Security On option is enabled.
Attestation Enable Enables to control whether the Trusted Platform Module (TPM) Endorsement
Hierarchy is available to the operating system.
By default, the Attestation Enable option is enabled.
Key Storage Enable Enables to control whether the Trusted Platform Module (TPM) Storage
Hierarchy is available to the operating system.
By default, the Key Storage Enable option is enabled.
SHA-256 When enabled, the BIOS and TPM will use the SHA-256 hash algorithm to
extend measurements into the TPM PCRs during BIOS boot.
By default, the SHA-256 option is enabled.
Clear Enables to clear the TPM owner information and returns the TPM to the
default state.
By default, the Clear option is disabled.
PPI Bypass for Clear Commands Controls the TPM Physical Presence Interface (PPI).
By default, the PPI ByPass for clear Commands option is disabled.
Intel Total Memory Encryption
Total Memory Encryption Enable or disable to protect memory from physical attacks including freeze
spray, probing DDR to read the cycles, and others.
By default, the option is disabled.
SMM Security Mitigation Enable or disable additional UEFI SMM Security Mitigation protections.
By default, the option is disabled.
Data Wipe on Next Boot
Start Data Wipe Enable or disable the data wipe on next boot.
By default, the Start Data Wipe option is disabled.
Absolute Enable or disable or permanently disable the BIOS module interface of the
optional Absolute Persistence Module service from Absolute software.
By default, the option is enabled.
WARNING: The 'Permanently Disabled' option can only be
selected once. When 'Permanently Disabled' is selected, Absolute
BIOS setup 125