Table 30. System setup options — Security menu (continued)
Security
Password Change Allows the user to permit or deny system password or hard
disk drive password changes.
By default, the Permitted option is selected.
Absolute Allows the user to track the computer
By default, the Absolute is disabled.
Absolute Status Allows the user to activate or deactivate the Absolute
feature Displays if the system password is clear or set.
By default, the Absolute Status is deactivate.
WINDOWS SMM SECURITY MITIGATIONS TABLE
(WSMT)
Enables or disables configuration of platform features on
Dell Client Systems with WSMT-enabled BIOS.
By default, the option is enabled.
Firmware TPM Enables or disables the firmware TPM.
By default, the option is enabled.
PPI Bypass for Clear Command Allows the user to control the TPM Physical Presence
Interface (PPI). When enabled, this setting allows the
operating system to skip BIOS PPI user prompts when
issuing the Clear command. Changes to this setting take
effect immediately.
By default, the option is disabled.
Enable Pre-Boot DMA Support Enables or disables the pre-boot DMA protection for the
internal and external ports.
By default, the option is enabled.
Enable OS Kernel DMA Support Enables or disables the Kernel DMA protection for the
internal and external ports.
By default, the option is enabled.
UEFI Firmware Capsule Updates Enables or disables BIOS updates through UEFI capsule
update packages.
By default, the option is enabled.
Secure Boot
Secure Boot Enables or disables the computer to boot using only
validated boot software.
By default, the option is enabled.
Select Secure Boot Allows the user to select the Secure Boot operation mode.
By default, the Deployed Mode option is selected.
Expert Key Management Enables or disables Expert Key Management feature.
By default, the option is enabled.
Custom Mode Enables or disables the keys in the PK, KEK, db, and dbx
security key databases to be modified.
By default, the option is disabled.
Enable Microsoft UEFI CA Allows the user to add the Microsoft UEFI CA to the BIOS
UEFI Secure Boot database.
When enabled, the Microsoft UEFI CA is added to the BIOS
UEFI Secure Boot database.
90 BIOS setup