Table 4. Security menu items (continued)

Menu item

Submenu item

Selection

Comments

 

 

 

 

 

Security Chip

Security Chip Selection

Discrete TPM

If you select Discrete TPM, you can

 

 

Intel PTT

use a discrete TPM chip with TPM

 

 

1.2 mode.

 

 

 

 

 

 

 

 

If you select Intel PTT, you can use

 

 

 

 

Intel Platform Trusted Technology

 

 

 

 

with TPM 2.0 mode.

 

 

 

 

Note: The Intel PTT can be used

 

 

 

 

with Mircorosft Windows 8.1

 

 

 

 

operating system.

 

 

 

 

 

 

Security Chip

Active

If you select Active, the security

 

 

Inactive

chip will be functional. If you select

 

 

Inactive, the Security Chip option

 

 

Disabled

 

 

will be visible, but the security chip

 

 

 

 

will not be functional. If you select

 

 

 

 

Disabled, the Security Chip option

 

 

 

 

will be hidden and the security chip

 

 

 

 

will not be functional.

 

 

 

 

 

 

Security Reporting

 

 

Enable or disable the following

 

Options

 

 

Security Reporting Options:

 

 

 

 

BIOS ROM Strings Reporting:

 

 

 

 

 

BIOS text string

 

 

 

 

CMOS Reporting: CMOS data

 

 

 

 

NVRAM Reporting: Security

 

 

 

 

 

data stored in the Asset ID

 

 

 

 

SMBIOS Reporting: SMBIOS

 

 

 

 

 

data

 

 

 

 

 

Clear Security Chip

Enter

This option is used to clear

 

 

 

 

encryption keys. It will

 

 

 

 

not be possible to access

 

 

 

 

already-encrypted data after

 

 

 

 

these keys are cleared.

 

 

 

 

 

 

Physical Presence for

Disabled

This option enables or disables the

 

Provisioning

Enabled

confirmation message when you

 

 

change the settings of the security

 

 

 

 

 

 

 

 

chip.

 

 

 

 

 

 

Physical Presence for

Disabled

This option enables or disables the

 

Clear

Enabled

confirmation message when you

 

 

clear the security chip.

 

 

 

 

 

 

 

 

 

UEFI BIOS Update Option

Flash BIOS Updating by

Disabled

If you select Enabled, all users can

 

End-Users

Enabled

update the UEFI BIOS. If you select

 

 

Disabled, only the person who

 

 

 

 

 

 

 

 

knows the supervisor password can

 

 

 

 

update the UEFI BIOS.

 

 

 

 

 

 

Secure RollBack

Disabled (if

If you select Disabled, you can flash

 

Prevention

 

OS Optimized

the older version of the UEFI BIOS.

 

 

 

Defaults is

 

 

 

 

 

Disabled)

 

 

 

 

Enabled (if

 

 

 

 

 

OS Optimized

 

 

 

 

 

 

 

 

Chapter 7. Advanced configuration 69

Page 83
Image 83
Lenovo 20CD0033US manual Discrete TPM, Inactive, the Security Chip option, Disabled, the Security Chip option, Enter