Security Menu

Security Menu Option Description

HDD Security Configuration

Specify the HDD security configuration options.

Secure Boot

Specify the secure boot options.

System Mode

Secure Boot is activated when Platform Key (PK) is enrolled, System mode is User (default) or Deployed, and the Compatibility Support Module (CSM) function is disabled.

Attempt Secure Boot

When enabled (default), Secure Boot is activated when Platform Key (PK) is enrolled, System mode is User or Deployed, and the Compatibility Support Module (CSM) function is disabled.

Secure Boot Mode

Specifies Standard or Custom (default) Secure Boot mode.

Restore Factory Keys

Forces system to User mode. Installs factory default Secure Boot key databases.

Reset to Setup Mode

Removes platform key and resets system to Setup mode.

Enter Audit Mode

Resets the system to Audit Mode and erases the PK variable.

Key Management

Specify the key management options.

Factory Key Provision

Disables (default) provisioning factory default Secure Boot keys when the system is in Setup Mode.

Restore Factory Keys

Forces system to User mode. Installs factory default Secure Boot key databases.

Export Secure Boot variables

Select a file system to copy the NVRAM content of Secure Boot variables to files in a root folder on a file system device.

Enroll EFI Images

Enrolls an EFI image to run in Secure Boot mode.

Secure Boot Variable | Size | Keys | Key Source

Displays the size, platform keys, key exchange keys, and signatures.

Image Execution Policy

Specify the image execution policies.

Option ROM

Deny Execute (default), Query User

Removable Media

Deny Execute (default), Query User

Fixed Media

Deny Execute (default), Query User