Table 5. System setup optionsāSecurity menu (continued)
Security
Password Bypass Bypass the System (Boot) Password and the internal HDD password prompts
during a system restart.
Password Change Enable or disable changes to the System and Hard Disk passwords when an
administrator password is set.
Non-Admin Setup Changes Enable or disable changes to the setup options when an administrator
password is set.
UEFI Capsule Firmware Updates Enable or disable BIOS updates through UEFI capsule update packages.
TPM 2.0 Security Enables you to control whether the Trusted platform Module (TPM) must be
visible to the operating system.
Absolute Enable or disable the BIOS module interface of the optional Absolute
Persistence Module service from
Admin Setup Lockout Enable to prevent users from entering Setup when an Admin Password is set.
Master Password Lockout Enable to disable master password support.
NOTE: Hard Disk passwords need to be cleared before the setting can be
changed.
SMM Security Mitigation Enables or disables additional UEFI SMM Security Mitigation protections.
Table 6. System setup optionsāSecure Boot menu
Secure Boot
Secure Boot Enable Enables or disables the computer to boot using only validated boot software.
Default: OFF.
NOTE: For Secure Boot to be enabled, the computer needs to be in UEFI
boot mode and the Enable Legacy Option ROMs option needs to be turned
off.
Secure Boot Mode Selects the Secure Boot operation mode.
Default: Deployed Mode.
NOTE: Deployed Mode should be selected for normal operation of Secure
Boot.
Expert Key Management
Expert Key Management Enable or disable Expert Key Management.
Custom Mode Key Management Select the custom values for Expert Key Management.
Table 7. System setup optionsāIntel Software Guard Extensions menu
Intel Software Guard Extensions
Intel SGX Enable Enable or disable Intel Software Guard Extensions.
Enclave Memory Size Set the Intel Software Guard Extensions Enclave Reserve Memory Size.
Table 8. System setup optionsāPerformance menu
Performance
Multi-Core Support Changes the number of CPU cores available to the operating system. The
default value is set to the maximum number of cores.
Default: All Cores.
Intel SpeedStep Enables or disables the Intel SpeedStep Technology to dynamically adjust
processor voltage and core frequency, decreasing average power consumption
and heat production.
System setup 71