Table 4. Security menu items (continued)

Menu item

Submenu item

Selection

Comments

 

 

 

 

 

Anti-Theft

Intel AT Module Activation

Disabled

Enable or disable the UEFI BIOS

 

 

Enabled

interface to activate the Intel AT

 

 

module, which is an optional

 

 

Permanently

 

 

anti-theft service from Intel.

 

 

 

Disabled

 

 

 

 

 

Note: If you set the Intel AT

 

 

 

 

module activation to Permanently

 

 

 

 

Disabled, you will be unable to

 

 

 

 

enable this setting again.

 

 

 

 

 

 

Computrace

Disabled

Enable or disable the UEFI BIOS

 

 

Enabled

interface to activate the computrace

 

 

module. Computrace is an optional

 

 

Permanently

 

 

monitoring service from Absolute

 

 

 

Disabled

Software.

 

 

 

 

Note: If you set the computrace

 

 

 

 

module activation to Permanently

 

 

 

 

Disabled, you will be unable to

 

 

 

 

enable this setting again.

 

 

 

 

 

Secure Boot

Secure Boot

Disabled (if

Enable or disable the Secure Boot

 

 

 

OS Optimized

feature. Select Enable to prevent

 

 

 

Defaults is

unauthorized operating systems

 

 

 

Disabled)

from running at boot time. Select

 

 

Enabled (if

Disabled to allow any operating

 

 

systems to run at boot time.

 

 

 

OS Optimized

 

 

 

 

 

 

 

Defaults is

 

 

 

 

Enabled)

 

 

 

 

 

 

 

Platform Mode

User Mode

Specify the system operating mode.

 

 

Setup Mode

 

 

 

 

 

 

 

Secure Boot Mode

Standard Mode

Specify the Secure Boot mode.

 

 

Custom Mode

 

 

 

 

 

 

 

Reset to Setup Mode

Yes

This option is used to clear the

 

 

No

current platform key and put the

 

 

system into setup mode. You

 

 

 

 

 

 

 

 

can install your own platform key

 

 

 

 

and customize the Secure Boot

 

 

 

 

signature databases in setup mode.

 

 

 

 

Secure Boot mode will be set to

 

 

 

 

custom mode.

 

 

 

 

 

 

Restore Factory keys

Yes

This option is used to restore all

 

 

No

keys and certificates in Secure Boot

 

 

databases to factory defaults. Any

 

 

 

 

 

 

 

 

customized Secure Boot settings

 

 

 

 

will be erased, and the default

 

 

 

 

platform key will be re-established

 

 

 

 

along with the original signature

 

 

 

 

databases including certificate for

 

 

 

 

Windows 8.1 operating system.

 

 

 

 

 

Startup menu

To change the startup settings of your computer, select the Startup tab from the ThinkPad Setup menu.

Chapter 7. Advanced configuration 71

Page 85
Image 85
Lenovo 20CD0033US Startup menu, Menu item Submenu item Selection Comments Anti-Theft, Secure Boot, Defaults is Enabled