Table3.Securitymenuitems(continued)
Menuitem
Submenuitem
Value
Comments
Anti-Theft
Computrace
•Disabled
•Enabled
•Permanently
Disabled
EnableordisabletheUEFIBIOSinterfaceto
activatethecomputracemodule.Computrace
isanoptionalmonitoringservicefromAbsolute
Software.
Note:Ifyousetthecomputracemodule
activationtoPermanentlyDisabled,youwillbe
unabletoenablethissettingagain.
SecureBoot
•Disabled
•Enabled
EnableordisabletheUEFISecureBootfeature.
SelectEnabletopreventunauthorizedoperating
systemsfromrunningatboottime.Select
Disabledtoallowanyoperatingsystemstorun
atboottime.
PlatformMode
•SetupMode
•UserMode
Specifythesystemoperatingmode.
SecureBootMode•StandardMode
•CustomMode
SpecifytheSecureBootmode.
ResettoSetupMode
Thisoptionisusedtoclearthecurrentplatform
keyandputthesystemintoSetupMode.You
caninstallyourownplatformkeyandcustomize
theSecureBootsignaturedatabasesinSetup
Mode.
SecureBootmodewillbesettoCustomMode.
RestoreFactory
Keys
Thisoptionisusedtorestoreallkeysand
certificatesinSecureBootdatabasestofactory
defaults.AnycustomizedSecureBootsettings
willbeerased,andthedefaultplatformkey
willbere-establishedalongwiththeoriginal
signaturedatabasesincludingcertificateforthe
Windows8andWindows10operatingsystems.
SecureBoot
ClearAllSecure
BootKeys
Thisoptionisusedtoclearallkeysand
certificatesinSecureBootdatabases.You
caninstallyourownkeysandcertificatesafter
selectingthisoption.
Intel(R)SGXControl
•Disabled
•Enabled
•Software
Controlled
ThisoptionenablesordisablesIntel(R)Software
GuardExtension(SGX)function.
IfSoftwareControlledisselected,SGXwillbe
controlledbySGXapplicationforUEFIbootOS.
Intel®SGX
OwnerEPOCH
Change
ChangeOwnerEPOCHtonewrandomvalue.
ThisoptionisusedforclearinguserdataofSGX.
Startupmenu
Tochangethestartupsettingsofyourcomputer,selecttheStartuptabfromtheThinkPadSetupmenu.
Attention:
•Afteryouchangethestartupsequence,ensurethatyouselectacorrectdeviceduringacopy,asave,ora
formatoperation.Otherwiseyourdatamightbeerasedoroverwritten.
Chapter6.Advancedconfiguration65