Table 9. System setup options—Power menu (continued)
Power
Enabled Lid Switch Enable or disable the lid switch.
By default, the Enable Lid Switch option is enabled.
Power On Lid Open When enabled, allows the system to power up from the off state whenever the
lid is opened.
By default, the Power On Lid Open option is enabled.
Intel Speed Shift Technology Enable or disable the Intel speed shift technology support.
By default, the Intel Speed Shift Technology option is enabled.
Table 10. System setup options—Security menu
Security
TPM 2.0 Security
TPM 2.0 Security On Allows you to enable or disable TPM visibility to operating system.
By default, the TPM 2.0 Security On option is enabled.
Attestation Enable Enables to control whether the Trusted Platform Module (TPM) Endorsement
Hierarchy is available to the operating system.
By default, the Attestation Enable option is enabled.
Key Storage Enable Enables to control whether the Trusted Platform Module (TPM) Storage
Hierarchy is available to the operating system.
By default, the Key Storage Enable option is enabled.
SHA-256 When enabled, the BIOS and TPM will use the SHA-256 hash algorithm to
extend measurements into the TPM PCRs during BIOS boot.
By default, the SHA-256 option is enabled.
Clear Enables to clear the TPM owner information and returns the TPM to the
default state.
By default, the Clear option is disabled.
PPI Bypass for Clear Commands Controls the TPM Physical Presence Interface (PPI).
By default, the PPI ByPass for clear Commands option is disabled.
Intel Total Memory Encryption
Multi-Key Total Memory Encryption (Up
to 16 keys)
Enable or disable you to protect memory from physical attacks including freeze
spray, probing DDR to read the cycles, and others.
By default, the Total Memory Encryption option is disabled.
Chassis intrusion Controls the chassis intrusion feature.
By default, the On-Silent option is enabled.
Block Boot Until Cleared Booting is disabled until the option Block Boot Until Cleared is cleared.
SMM Security Mitigation Enable or disable additional UEFI SMM Security Mitigation protections.
By default, the option is enabled.
Data Wipe on Next Boot
Start Data Wipe Enable or disable the data wipe on next boot.
By default, the Start Data Wipe option is disabled.
Absolute Enable or disable or permanently disable the BIOS module interface of the
optional Absolute Persistence Module service from Absolute software.
72 BIOS setup