Chapter 4: UEFI BIOS
Device Guard Ready
Remove 'UEFI CA' from DB B (available when the system is not in Device
Guard Ready)
Yes
Restore DB defaults
Yes
Platform Key (PK)
Set New Key
Yes
Provision Factory Default Keys
Disabled
Key Exchange Keys
Set New Key
Append Key
Authorized Signatures
Set New Key
Append Key
Forbidden Signatures
Set New Key