Unsolved
2 Posts
0
1773
May 7th, 2021 03:00
Optiplex 3080 how to disable BIOS Flash Update - Remote
Hi Community,
We are a school and recently purchased some Optiplex 3080 MFF's.
We are looking at the BIOS config and have password protected the BIOS setup.
However, during the setup we noticed that even though we have a password for BIOS setup, the F12 (one-time) boot menu still offers a few options that are not password protected.
Our main concern is the "BIOS Flash Update - Remote" option, which is not password protected and can therefore be initiated by anyone using the F12 button. As this has the capacity to brick our computers we would like to remove this option in some way.
So, can we remove this option or password protect it or protect/hide/remove/disable the F12 option.
Can this be done, can we disable or even just nullify it? I am not concerned about how it is achieved.
Our system is currently at Bios V1.3.10
Hope you can help.


speedstep
11 Legend
•
47K Posts
0
May 7th, 2021 09:00
Enabling Secure boot and making all bios changes Admin pass-worded should disable F12 altogether and not allow user to remove battery to try and bypass that.
bra51776
1 Rookie
•
91 Posts
0
May 7th, 2021 10:00
Most BIOS related changes are disabled with the admin password. You tried to go all the way through a BIOS flash from the F12 OTB menu and it allowed you to do it without a confirmation box?
CDSS
2 Posts
0
May 10th, 2021 01:00
Hi All, Thank you for the responses.
The only password not set was the HDD password as we do not want the password set for boot up.
@bra51776 - Yes, despite the password set to protect the BIOS setup menu, it allowed me to go all the way through to update the BIOS remotely. It did ask to confirm the action but that was not prtected by password.
I found the solution. By disabling the UEFI network stack, if removes access to network prior to OS bootup. This disables the F12 boot and disables the ability to contact the internet, which stops access to remote BIOS updates. This is acceptable for me as I can disable this one the builds are complete.
Thank you for your help.