| TPM 2.0 Security
|
The Trusted Platform Module (TPM) provides various cryptographic services which serve as the cornerstone for many platform security technologies. Trusted Platform Module (TPM) is a security device that stores computer-generated keys for encryption and features such as BitLocker, Virtual Secure Mode, remote Attestation.
|
| TPM 2.0 Security On
|
Allows you to enable or disable TPM.
By default, the
TPM 2.0 Security On option is enabled.
For additional security, Dell Technologies recommends keeping
TPM 2.0 Security On enabled to allow these security technologies to fully function.
NOTE: The options that are listed apply to computers with a discrete
Trusted Platform Module (TPM) chip.
|
| Attestation Enable
|
The
Attestation Enable option controls the endorsement hierarchy of TPM. Disabling the
Attestation Enable option prevents TPM from being used to digitally sign certificates.
By default, the
Attestation Enable option is enabled.
For additional security, Dell Technologies recommends keeping the
Attestation Enable option enabled.
NOTE:When disabled, this feature may cause compatibility issues or loss of functionality in some operating systems.
|
| Key Storage Enable
|
The
Key Storage Enable option controls the storage hierarchy of TPM, which is used to store digital keys. Disabling the
Key Storage Enable option restricts the ability of TPM to store owner's data.
By default, the
Key Storage Enable option is enabled.
For additional security, Dell Technologies recommends keeping the
Key Storage Enable option enabled.
NOTE:When disabled, this feature may cause compatibility issues or loss of functionality in some operating systems.
|
| Clear
|
When enabled, the
Clear option clears information that is stored in the TPM after exiting the computer's BIOS. This option returns to the disabled state when the computer restarts.
By default, the
Clear option is disabled.
Dell Technologies recommends enabling the
Clear option only when TPM data is required to be cleared.
|
| PPI Bypass for Clear Commands
|
The PPI (Physical Presence Interface) Bypass for Clear Commands option allows the operating system to manage certain aspects of PTT. When enabled, you are not prompted to confirm changes to the PTT configuration.
By default, the
PPI Bypass for Clear Commands option is disabled.
For additional security, Dell Technologies recommends keeping the
PPI Bypass for Clear Commands option disabled.
|
| Chassis Intrusion
|
|
| Chassis Intrusion
|
The chassis intrusion detection enables a physical switch that triggers an event when the computer cover is opened.
When set to
Enabled, a notification is displayed on the next boot and the event is logged in the BIOS Events log.
When set to
On-Silent, the event is logged in the BIOS Events log, but no notification is displayed.
When set to
Disabled, no notification is displayed and no event is logged in the BIOS Events log.
By default, the
On-Silent option is enabled.
For additional security, Dell Technologies recommends keeping the
Chassis Intrusion Detection option enabled.
|
| Clear Intrusion Warning
|
The
Clear Intrusion Warning option appears only after chassis intrusion is enabled and is tripped.
By default, the
Clear Intrusion Warning option is disabled.
|
| Block Boot Until Cleared
|
Enables or disables the Block Boot Until Cleared option.
By default, the
Block Boot Until Cleared option is disabled.
NOTE:When enabled, the computer does not boot until the chassis intrusion is cleared. If the administrator password is set, Setup has to be unlocked before the warning can be cleared.
|
| Data Wipe on Next Boot
|
|
| Start Data Wipe
|
Data Wipe is a secure wipe operation that deletes information from a storage device.
CAUTION:The secure Data Wipe operation deletes information in a way that it cannot be reconstructed.
Commands such as delete and format in the operating system may remove files from showing up in the file system. However, they can be reconstructed through forensic means as they are still represented on the physical media. Data Wipe prevents this reconstruction and is not recoverable.
When enabled, the data wipe option will prompt to wipe any storage devices that are connected to the computer on the next boot.
By default, the
Start Data Wipe option is disabled.
|
| UEFI Boot Path Security
|
Enables or disables the computer to prompt the user to enter the Administrator password (if set) when booting to a UEFI boot path device from the F12 boot menu.
By default, the
Always Except Internal HDD option is enabled.
|
| Pluton Security Processor
|
Pluton Security Processor is used by the operating system to provide security services such as Key Storage Provider functionality. When enabled, the Pluton Security Processor services are available to the operating system. Disabling the
Pluton Security Processor might limit some operating system security services and impact functionality. .
By default, the
Pluton Security Processor option is enabled.
For additional security, Dell Technologies recommends keeping the
Pluton Security Processor option enabled.
|