
UNSOLVED
XPS 13 9310 (BIOS 3.36.0): admin password can be changed but never cleared - empty value validated as a new password
On an XPS 13 9310 running the current BIOS, the admin password cannot be removed. It can be changed without any problem - it simply cannot be cleared. The machine is in a default BIOS configuration and I have not found any setting that explains this.
I have observed the same behaviour on three Latitude models as well; details on those are at the end of this post.
PRIMARY CASE: XPS 13 9310, BIOS 3.36.0
Steps to reproduce:
(1) Enter BIOS Setup and authenticate with the current admin password.
(2) Open the admin password dialog, enter the current password, press Enter.
(3) Leave New Password blank and press Enter. Leave Confirm Password blank and press Enter.
(4) Confirm the prompt, click APPLY CHANGES, exit with ESC.
(5) Reboot and re-enter BIOS Setup.
Expected: no password is requested; the settings are unlocked.
Actual: the previous password is still required. No error or warning is shown at any point - the operation appears to succeed and silently does nothing.
Control test: identical procedure, but typing 12345 twice instead of leaving the fields blank. This is accepted and 12345 becomes the new password. The dialog, the authentication and the write path all work correctly - only the empty value fails.
BIOS configuration on this machine:
Password Configuration, minimum length: 4 (adjustable 04-32)
Admin Setup Lockout: Disabled
Enable Non-Admin Password Changes: Enabled
Absolute: Disabled
Asset Tag / Ownership Tag: Empty
There is also no storage device installed in this machine. There is no operating system, no Dell Command agent and no Intune or SCCM policy that could re-apply a BIOS password. Nothing outside the firmware is able to restore it.
WHAT THIS LOOKS LIKE
I assume the minimum length of 4 is standard and that clearing works on most systems, which would mean the empty value is normally exempt from the length check. Here that exemption does not appear to apply: the empty value seems to be validated as if it were a new password, fails the four-character minimum, and is discarded - leaving the previous password in place, silently.
Two observations elsewhere are consistent with this reading:
Dell Command PowerShell Provider 2.10.0 fails to clear BIOS passwords with "Admin Password must contain minimum 4, and maximum 32 characters", with Strong Password disabled. The reporter notes it happens unpredictably rather than always. That thread has had no reply.
Dell Command | Configure defines error 60, "Password not changed, new password does not meet criteria" - the same class of failure.
The Dell Command | Intel vPro Out of Band documentation lists these as separate operations: Clear ("clear either the Admin or System password"), Set, and Length ("specify the minimum and maximum length"). In Dell's own model, clearing is not a special case of setting a password, so the new-password length policy should not govern it.
KB 000131024 states that a known BIOS password can be removed by the user in BIOS Setup. KB 000190038 documents the key sequence required by the newer Dell-branded BIOS, and that sequence is exactly what I perform. The password is not cleared.
ALSO OBSERVED ON
I have personally attempted the same removal, with the same result, on:
Latitude 5440, BIOS 1.20.1
Latitude 5430, BIOS 1.39.1
Latitude 3510, BIOS 1.31.0
I do not have these machines available at the moment, so I have not audited their Security settings the way I did on the XPS, and I cannot confirm whether their BIOS versions are current. I mention them only to show that the behaviour is not specific to one model or one BIOS branch.
QUESTIONS
(1) Is the empty value supposed to be exempt from the minimum-length check when clearing the admin password? If so, under what conditions does that exemption fail?
(2) Is there a supported way to clear the admin password on BIOS 3.36.0 that I have missed?
(3) If this is a defect, which BIOS releases are affected and is a fix planned?
Given that the failure is silent, I would also suggest that a rejected clear operation should report an error rather than returning to the menu as if it had succeeded.
Responses (0)
Solutions (0)
