Table 44. System setup options—Passwords menu(continued)
Passwords
Minimum Characters Set the minimum characters allowed for password.
Password Changes
Allow Non-Admin Password Changes The Allow Non-Admin Password Changes option in BIOS setup allows an
end user to set or change the system or hard drive passwords without entering
the administrator password. This gives an administrator control over the BIOS
settings but enables an end user to provide their own password.
By default, the Allow Non-Admin Password Changes option is disabled.
For additional security, Dell Technologies recommends keeping the Allow Non-
Admin Password Changes option disabled.
Admin Setup Lockout
Enable Admin Setup Lockout The Admin Setup Lockout option prevents an end user from even viewing the
BIOS setup configuration without first entering the administrator password (if
set).
By default, the Admin Setup Lockout option is disabled.
For additional security, Dell Technologies recommends keeping the Admin
Setup Lockout option disabled.
Master Password Lockout
Enable Master Password Lockout The Master Password Lockout setting allows you to disable the Recovery
Password feature. If the system, administrator, or hard drive password is
forgotten, the system becomes unusable.
NOTE: When the owner password is set, the Master Password Lockout
option is not available.
NOTE: When an internal hard drive password is set, it must first be cleared
before Master Password Lockout can be changed.
By default, the Enable Master Password Lockout option is disabled.
Dell Technologies does not recommend enabling the Master Password
Lockout unless you have implemented your own password recovery system.
Allow Non-Admin PSID Revert
Enable Allow Non-Admin PSID Revert Controls access to the Physical Security ID (PSID) revert of NVMe hard-drives
from the Dell Security Manager prompt.
By default, the option is disabled.
Table 45. System setup options—Update, Recovery menu
Update, Recovery
UEFI Capsule Firmware Updates Enable or disable BIOS updates through UEFI capsule update packages.
NOTE: Disabling this option will block BIOS updates from services such as
Microsoft Windows Update and Linux Vendor Firmware Service (LVFS).
By default, the option is enabled.
BIOS Recovery from Hard Drive Enables the user to recover from certain corrupted BIOS conditions from a
recovery file on the user primary hard drive or an external USB key.
By default, the option is enabled.
NOTE: BIOS Recovery from Hard Drive is not available for Self-Encrypting
Drives (SED).
BIOS Downgrade
Allow BIOS Downgrade This field controls the flashing of the system firmware to previous revisions.
168 BIOS Setup