Windows BIOS Configuration

Administrators can set Windows BIOS settings on Lenovo devices. At least one Lenovo device that supports BIOS settings must be enrolled to set this configuration.

To configure:

  1. Go to Configuration> +Add.

  2. Select Windows BIOS configuration.

  3. Enter a name for the configuration.

  4. Enter a description.

  5. In the Choose device model section, select the device model from the drop down list.
  6. In the Configuration Setup section, configure the following options:

    The list of settings vary depending on what is available for the specific device model that is enrolled.

    Setting

    What to do

    AMT Control

    Select any of the following options:

    • Disable
    • Enable
    Adaptive Thermal Management AC

    Select any of the following options:

    • Balanced
    • Maximized Performance

    Adaptive Thermal Management Battery

    Select any of the following options:

    • Balanced
    • Maximized Performance

    Always On USB

    Select any of the following options:

    • Disable
    • Enable
    BIOSPasswordAtBootDeviceList

    Select any of the following options:

    • Disable
    • Enable
    BIOS Password At Reboot

    Select any of the following options:

    • Disable
    • Enable
    BIOS Password At Unattended Boot

    Select any of the following options:

    • Disable
    • Enable
    BIOS Update By End Users

    Select any of the following options:

    • Disable
    • Enable
    Bluetooth Access

    Select any of the following options:

    • Disable
    • Enable
    Boot Device List F12 Option

    Select any of the following options:

    • Disable
    • Enable
    Boot DisplayDevice

    Select any of the following options:

    • DisplayPort
    • Dock Display
    • HDMI
    • LCD
    BootMode

    Select any of the following options:

    • Diagnostics
    • Quick
    Boot Order Lock

    Select any of the following options:

    • Disable
    • Enable
    BootTimeExtension

    Select any of the following options:

    • 1
    • 10
    • 2
    • 3
    • 5
    • Disable
    BottomCover Tamper Detected

    Select any of the following options:

    • Disable
    • Enable
    CPU Power Management

    Select any of the following options:

    • Automatic
    • Disable
    Computrace Module Activation

    Select any of the following options:

    • Disable
    • Enable
    Data Execution Prevention

    Select any of the following options:

    • Disable
    • Enable
    Ethernet LAN Access

    Select any of the following options:

    • Disable
    • Enable
    Ethernet LAN Option ROM

    Select any of the following options:

    • Disable
    • Enable
    Fingerprint Password Authentication

    Select any of the following options:

    • Disable
    • Enable
    Fingerprint Pre-desktop Authentication

    Select any of the following options:

    • Disable
    • Enable
    Fingerprint Reader Access

    Select any of the following options:

    • Disable
    • Enable
    Fingerprint Reader Priority

    Select any of the following options:

    • External
    • Internal Only
    Fingerprint Security Mode

    Select any of the following options:

    • High
    • Normal
    Fn Ctrl Key Swap

    Select any of the following options:

    • Disable
    • Enable
    FnKeyAsPrimary

    Select any of the following options:

    • Disable
    • Enable
    FnSticky

    Select any of the following options:

    • Disable
    • Enable
    IPv4 Network Stack

    Select any of the following options:

    • Disable
    • Enable
    IPv6 Network Stack

    Select any of the following options:

    • Disable
    • Enable
    Integrated Camera Access

    Select any of the following options:

    • Disable
    • Enable
    InternalStorageTamper

    Select any of the following options:

    • Disable
    • Enable
    Keyboard Beep

    Select any of the following options:

    • Disable
    • Enable
    Lock BIOS Setting

    Select any of the following options:

    • Disable
    • Enable
    Memory Card Slot Access

    Select any of the following options:

    • Disable
    • Enable
    Microphone Access

    Select any of the following options:

    • Disable
    • Enable
    Minimum Password Length

    Select any of the following options:

    • 4
    • 5
    • 6
    • 7
    • 8
    • 9
    • 10
    • 11
    • 12
    • Disable
    NFFControl

    Select any of the following options:

    • Disable
    • Enable
    Nfc Access

    Select any of the following options:

    • Disable
    • Enable
    On By Ac Attach

    Select any of the following options:

    • Disable
    • Enable
    PasswordBeep

    Select any of the following options:

    • Disable
    • Enable
    PasswordCountExceededError

    Select any of the following options:

    • Disable
    • Enable
    Physical Presence For Tpm Clear

    Select any of the following options:

    • Disable
    • Enable
    Physical Presence For Tpm Provision

    Select any of the following options:

    • Disable
    • Enable
    Rapid Start Technology

    Select any of the following options:

    • Disable
    • Enable
    SecureBoot Select Enable
    Secure Roll Back Prevention

    Select any of the following options:

    • Disable
    • Enable
    Security Chip

    Select any of the following options:

    • Active
    • Disable
    • Enable
    • Inactive
    Smart Card Slot Access

    Select any of the following options:

    • Disable
    • Enable
    SpeedStep

    Select any of the following options:

    • Disable
    • Enable
    Startup Option Keys

    Select any of the following options:

    • Disable
    • Enable
    TXT Feature

    Select any of the following options:

    • Disable
    • Enable
    Total Graphics Memory

    Select any of the following options:

    • 256 MB
    • 512 MB
    TouchPad

    Select any of the following options:

    • Automatic
    • Disable
    TrackPoint

    Select any of the following options:

    • Automatic
    • Disable
    USB30 Mode

    Select any of the following options:

    • Automatic
    • Disable
    • Enable
    USB BIOS Support

    Select any of the following options:

    • Disable
    • Enable
    USB Port Access

    Select any of the following options:

    • Disable
    • Enable
    Uefi Pxe Boot Priority

    Select any of the following options:

    • IPv4 First
    • IPv6 First
    VTd Feature

    Select any of the following options:

    • Disable
    • Enable
    Virtualization Technology

    Select any of the following options:

    • Disable
    • Enable
    Wake On LAN

    Select any of the following options:

    • AC Only
    • AC and battery
    • Disable
    • Enable
    Wireless LAN Access

    Select any of the following options:

    • Disable
    • Enable
    Wireless WAN Access

    Select any of the following options:

    • Disable
    • Enable
  7. Click Next.

  8. Select one of the following distribution options:

    • All Devices
    • No Devices(default)
    • Custom

  9. Click Done.