Windows BIOS Configuration

Administrators can set Windows BIOS settings on Lenovo devices. At least one Lenovo device that supports BIOS settings must be enrolled to set this configuration.

To configure:

  1. Go to Configuration> +Add.

  2. Select Windows BIOS configuration.

  3. Enter a name for the configuration.

  4. Enter a description.

  5. In the Choose device model section, select the device model from the drop down list.
  6. In the Configuration Setup section, configure the following options:

    The list of settings vary depending on what is available for the specific device model that is enrolled. Please refer to the respective device website for more information.

    Setting

    What to do

    AMT Control

    Select any of the following options:

    • Disable
    • Enable
    Adaptive Thermal Management AC

    Select any of the following options:

    • Balanced
    • Maximized Performance

    Adaptive Thermal Management Battery

    Select any of the following options:

    • Balanced
    • Maximized Performance

    Always On USB

    Select any of the following options:

    • Disable
    • Enable
    BIOSPasswordAtBootDeviceList

    Select any of the following options:

    • Disable
    • Enable
    BIOS Password At Reboot

    Select any of the following options:

    • Disable
    • Enable
    BIOS Password At Unattended Boot

    Select any of the following options:

    • Disable
    • Enable
    BIOS Update By End Users

    Select any of the following options:

    • Disable
    • Enable
    Bluetooth Access

    Select any of the following options:

    • Disable
    • Enable
    Boot Device List F12 Option

    Select any of the following options:

    • Disable
    • Enable
    Boot DisplayDevice

    Select any of the following options:

    • DisplayPort
    • Dock Display
    • HDMI
    • LCD
    BootMode

    Select any of the following options:

    • Diagnostics
    • Quick
    Boot Order Lock

    Select any of the following options:

    • Disable
    • Enable
    BootTimeExtension

    Select any of the following options:

    • 1
    • 10
    • 2
    • 3
    • 5
    • Disable
    BottomCover Tamper Detected

    Select any of the following options:

    • Disable
    • Enable
    CPU Power Management

    Select any of the following options:

    • Automatic
    • Disable
    Computrace Module Activation

    Select any of the following options:

    • Disable
    • Enable
    Data Execution Prevention

    Select any of the following options:

    • Disable
    • Enable
    Ethernet LAN Access

    Select any of the following options:

    • Disable
    • Enable
    Ethernet LAN Option ROM

    Select any of the following options:

    • Disable
    • Enable
    Fingerprint Password Authentication

    Select any of the following options:

    • Disable
    • Enable
    Fingerprint Pre-desktop Authentication

    Select any of the following options:

    • Disable
    • Enable
    Fingerprint Reader Access

    Select any of the following options:

    • Disable
    • Enable
    Fingerprint Reader Priority

    Select any of the following options:

    • External
    • Internal Only
    Fingerprint Security Mode

    Select any of the following options:

    • High
    • Normal
    Fn Ctrl Key Swap

    Select any of the following options:

    • Disable
    • Enable
    FnKeyAsPrimary

    Select any of the following options:

    • Disable
    • Enable
    FnSticky

    Select any of the following options:

    • Disable
    • Enable
    IPv4 Network Stack

    Select any of the following options:

    • Disable
    • Enable
    IPv6 Network Stack

    Select any of the following options:

    • Disable
    • Enable
    Integrated Camera Access

    Select any of the following options:

    • Disable
    • Enable
    InternalStorageTamper

    Select any of the following options:

    • Disable
    • Enable
    Keyboard Beep

    Select any of the following options:

    • Disable
    • Enable
    Lock BIOS Setting

    Select any of the following options:

    • Disable
    • Enable
    Memory Card Slot Access

    Select any of the following options:

    • Disable
    • Enable
    Microphone Access

    Select any of the following options:

    • Disable
    • Enable
    Minimum Password Length

    Select any of the following options:

    • 4
    • 5
    • 6
    • 7
    • 8
    • 9
    • 10
    • 11
    • 12
    • Disable
    NFFControl

    Select any of the following options:

    • Disable
    • Enable
    Nfc Access

    Select any of the following options:

    • Disable
    • Enable
    On By Ac Attach

    Select any of the following options:

    • Disable
    • Enable
    PasswordBeep

    Select any of the following options:

    • Disable
    • Enable
    PasswordCountExceededError

    Select any of the following options:

    • Disable
    • Enable
    Physical Presence For Tpm Clear

    Select any of the following options:

    • Disable
    • Enable
    Physical Presence For Tpm Provision

    Select any of the following options:

    • Disable
    • Enable
    Rapid Start Technology

    Select any of the following options:

    • Disable
    • Enable
    SecureBoot Select Enable
    Secure Roll Back Prevention

    Select any of the following options:

    • Disable
    • Enable
    Security Chip

    Select any of the following options:

    • Active
    • Disable
    • Enable
    • Inactive
    Smart Card Slot Access

    Select any of the following options:

    • Disable
    • Enable
    SpeedStep

    Select any of the following options:

    • Disable
    • Enable
    Startup Option Keys

    Select any of the following options:

    • Disable
    • Enable
    TXT Feature

    Select any of the following options:

    • Disable
    • Enable
    Total Graphics Memory

    Select any of the following options:

    • 256 MB
    • 512 MB
    TouchPad

    Select any of the following options:

    • Automatic
    • Disable
    TrackPoint

    Select any of the following options:

    • Automatic
    • Disable
    USB30 Mode

    Select any of the following options:

    • Automatic
    • Disable
    • Enable
    USB BIOS Support

    Select any of the following options:

    • Disable
    • Enable
    USB Port Access

    Select any of the following options:

    • Disable
    • Enable
    Uefi Pxe Boot Priority

    Select any of the following options:

    • IPv4 First
    • IPv6 First
    VTd Feature

    Select any of the following options:

    • Disable
    • Enable
    Virtualization Technology

    Select any of the following options:

    • Disable
    • Enable
    Wake On LAN

    Select any of the following options:

    • AC Only
    • AC and battery
    • Disable
    • Enable
    Wireless LAN Access

    Select any of the following options:

    • Disable
    • Enable
    Wireless WAN Access

    Select any of the following options:

    • Disable
    • Enable
  7. Click Next.

  8. Select one of the following distribution options:

    • All Devices
    • No Devices(default)
    • Custom

  9. Click Done.