Ajout dela structure MDT dans Infra-LAB

This commit is contained in:
2026-05-24 16:21:20 +02:00
parent fed8d42171
commit 049b03b4d4
522 changed files with 105109 additions and 0 deletions
Binary file not shown.
Binary file not shown.
Binary file not shown.
@@ -0,0 +1,87 @@
#TYPE Selected.System.Management.Automation.PSCustomObject
"Setting","Value"
"Serial Port1 Address","3F8/IRQ4"
"USB Support","Enabled"
"USB Legacy Support","Enabled"
"USB Enumeration Delay","Disabled"
"Front USB Ports","Enabled"
"Rear USB Ports","Enabled"
"USB Port 1","Enabled"
"USB Port 2","Enabled"
"USB Port 3","Enabled"
"USB Port 4","Enabled"
"USB Port 5","Enabled"
"USB Port 6","Enabled"
"USB Port 7","Enabled"
"USB Port 8","Enabled"
"USB Port 9","Enabled"
"SATA Controller","Enabled"
"SATA Drive 1","Enabled"
"SATA Drive 2","Enabled"
"SATA Drive 3","Enabled"
"Configure SATA as","AHCI"
"Hard Disk Pre-delay","Disabled"
"Select Active Video","Auto"
"Onboard Audio Controller","Enabled"
"Internal Speaker","Enabled"
"Onboard Ethernet Controller","Enabled"
"PXE Option ROM","Enabled"
"PXE IPV4 Network Stack","Enabled"
"PXE IPV6 Network Stack","Disabled"
"ASPM Support","Auto"
"PCIe 16x Slot Speed","Auto"
"PCIe 1x Slot 1 Speed","Auto"
"PCIe 1x Slot 2 Speed","Auto"
"EIST Support","Enabled"
"Core Multi-Processing","Enabled"
"Intel(R) Virtualization Technology","Enabled"
"VT-d","Enabled"
"C1E Support","Enabled"
"C State Support","C1C3C6C7C8"
"Intel(R) SGX Control","Software Controlled"
"Intel(R) SIPP Support","Enabled"
"Dust Shield Alert","Disabled"
"After Power Loss","Last State"
"Enhanced Power Saving Mode","Disabled"
"Smart Power On","Enabled"
"ICE Performance Modes","Better Acoustic Performance"
"ICE Thermal Alert","Enabled"
"Wake on LAN","Automatic"
"Wake from Serial Port Ring","Primary"
"Wake Up on Alarm","Disabled"
"Startup Sequence","Primary"
"Alarm Time(HH:MM:SS)",""
"Alarm Date(MM/DD/YYYY)",""
"Alarm Day of Week","Sunday"
"Sunday","Disabled"
"Monday","Disabled"
"Tuesday","Disabled"
"Wednesday","Disabled"
"Thursday","Disabled"
"Friday","Disabled"
"Saturday","Disabled"
"User Defined Alarm Time",""
"Allow Flashing BIOS to a Previous Version","Yes"
"Require Admin. Pass. when Flashing","No"
"Windows UEFI Firmware Update","Enabled"
"Require POP on System Boot","Yes"
"Require POP on Restart","No"
"Require Admin. Pass. For F12 Boot","No"
"Smart USB Protection","Disabled"
"Require HDP on System Boot","Auto"
"TCG Security Device","Discrete TPM"
"Security Chip 2.0","Enabled"
"Secure Boot","Disabled"
"Network Offline Locker","Disabled"
"Computrace Module Activation Setting","Enabled"
"Device Guard","Disabled"
"Chassis Intrusion Detection","Disabled"
"Configuration Change Detection","Disabled"
"Password Count Exceeded Error","Enabled"
"CSM","Enabled"
"Boot Mode","Legacy Only"
"Boot Up Num-Lock Status","On"
"OS Optimized Defaults","Enabled"
"Primary Boot Sequence","SATA 1:SATA 2:SATA 3:Network 1"
"Error Boot Sequence","Network 1:M.2 Drive 1:PCIe4X_1 Drive:PCIe16X_1 Drive:SATA 1:SATA 2:SATA 3:Other Device"
"Automatic Boot Sequence","M.2 Drive 1:PCIe4X_1 Drive:PCIe16X_1 Drive:SATA 1:Network 1:SATA 2:SATA 3:Other Device"
1 #TYPE Selected.System.Management.Automation.PSCustomObject
2 Setting Value
3 Serial Port1 Address 3F8/IRQ4
4 USB Support Enabled
5 USB Legacy Support Enabled
6 USB Enumeration Delay Disabled
7 Front USB Ports Enabled
8 Rear USB Ports Enabled
9 USB Port 1 Enabled
10 USB Port 2 Enabled
11 USB Port 3 Enabled
12 USB Port 4 Enabled
13 USB Port 5 Enabled
14 USB Port 6 Enabled
15 USB Port 7 Enabled
16 USB Port 8 Enabled
17 USB Port 9 Enabled
18 SATA Controller Enabled
19 SATA Drive 1 Enabled
20 SATA Drive 2 Enabled
21 SATA Drive 3 Enabled
22 Configure SATA as AHCI
23 Hard Disk Pre-delay Disabled
24 Select Active Video Auto
25 Onboard Audio Controller Enabled
26 Internal Speaker Enabled
27 Onboard Ethernet Controller Enabled
28 PXE Option ROM Enabled
29 PXE IPV4 Network Stack Enabled
30 PXE IPV6 Network Stack Disabled
31 ASPM Support Auto
32 PCIe 16x Slot Speed Auto
33 PCIe 1x Slot 1 Speed Auto
34 PCIe 1x Slot 2 Speed Auto
35 EIST Support Enabled
36 Core Multi-Processing Enabled
37 Intel(R) Virtualization Technology Enabled
38 VT-d Enabled
39 C1E Support Enabled
40 C State Support C1C3C6C7C8
41 Intel(R) SGX Control Software Controlled
42 Intel(R) SIPP Support Enabled
43 Dust Shield Alert Disabled
44 After Power Loss Last State
45 Enhanced Power Saving Mode Disabled
46 Smart Power On Enabled
47 ICE Performance Modes Better Acoustic Performance
48 ICE Thermal Alert Enabled
49 Wake on LAN Automatic
50 Wake from Serial Port Ring Primary
51 Wake Up on Alarm Disabled
52 Startup Sequence Primary
53 Alarm Time(HH:MM:SS)
54 Alarm Date(MM/DD/YYYY)
55 Alarm Day of Week Sunday
56 Sunday Disabled
57 Monday Disabled
58 Tuesday Disabled
59 Wednesday Disabled
60 Thursday Disabled
61 Friday Disabled
62 Saturday Disabled
63 User Defined Alarm Time
64 Allow Flashing BIOS to a Previous Version Yes
65 Require Admin. Pass. when Flashing No
66 Windows UEFI Firmware Update Enabled
67 Require POP on System Boot Yes
68 Require POP on Restart No
69 Require Admin. Pass. For F12 Boot No
70 Smart USB Protection Disabled
71 Require HDP on System Boot Auto
72 TCG Security Device Discrete TPM
73 Security Chip 2.0 Enabled
74 Secure Boot Disabled
75 Network Offline Locker Disabled
76 Computrace Module Activation Setting Enabled
77 Device Guard Disabled
78 Chassis Intrusion Detection Disabled
79 Configuration Change Detection Disabled
80 Password Count Exceeded Error Enabled
81 CSM Enabled
82 Boot Mode Legacy Only
83 Boot Up Num-Lock Status On
84 OS Optimized Defaults Enabled
85 Primary Boot Sequence SATA 1:SATA 2:SATA 3:Network 1
86 Error Boot Sequence Network 1:M.2 Drive 1:PCIe4X_1 Drive:PCIe16X_1 Drive:SATA 1:SATA 2:SATA 3:Other Device
87 Automatic Boot Sequence M.2 Drive 1:PCIe4X_1 Drive:PCIe16X_1 Drive:SATA 1:Network 1:SATA 2:SATA 3:Other Device
@@ -0,0 +1,94 @@
qQd8bbzDvJ2n7mc1dSZC2utCpdw=
KEy Encryption 4pzwCVD6gNj5mtut
Serial Port1 Address,3F8/IRQ4
USB Support,Enabled
USB Legacy Support,Enabled
USB Enumeration Delay,Enabled
Front USB Ports,Enabled
Rear USB Ports,Enabled
USB Port 1,Enabled
USB Port 2,Enabled
USB Port 3,Enabled
USB Port 4,Enabled
USB Port 5,Enabled
USB Port 6,Enabled
USB Port 7,Enabled
USB Port 8,Enabled
USB Port 9,Enabled
Card Reader,Enabled
SATA Controller,Enabled
SATA Drive 1,Enabled
SATA Drive 2,Enabled
SATA Drive 3,Enabled
Configure SATA as,AHCI
Hard Disk Pre-delay,Disabled
Select Active Video,Auto
Onboard Audio Controller,Enabled
Internal Speaker,Enabled
Onboard Ethernet Controller,Enabled
PXE Option ROM,Enabled
PXE IPV4 Network Stack,Enabled
PXE IPV6 Network Stack,Enabled
ASPM Support,Auto
PCIe 16x Slot Speed,Auto
PCIe 1x Slot 1 Speed,Auto
PCIe 1x Slot 2 Speed,Auto
EIST Support,Enabled
Intel(R) Hyper-Threading Technology,Enabled
Core Multi-Processing,Enabled
Intel(R) Virtualization Technology,Enabled
VT-d,Enabled
TxT,Disabled
C1E Support,Enabled
C State Support,C1C3C6C7C8
Turbo Mode,Enabled
Intel(R) SGX Control,Software Controlled
Intel(R) SIPP Support,Enabled
Dust Shield Alert,Disabled
After Power Loss,Last State
Enhanced Power Saving Mode,Disabled
Smart Power On,Enabled
ICE Performance Modes,Better Acoustic Performance
ICE Thermal Alert,Enabled
Wake on LAN,Automatic
Wake from Serial Port Ring,Primary
Wake Up on Alarm,Disabled
Startup Sequence,Primary
Alarm Time(HH:MM:SS),[00:00:00][Status:ShowOnly]
Alarm Date(MM/DD/YYYY),[01/01/2017][Status:ShowOnly]
Alarm Day of Week,Sunday
Sunday,Disabled
Monday,Disabled
Tuesday,Disabled
Wednesday,Disabled
Thursday,Disabled
Friday,Disabled
Saturday,Disabled
User Defined Alarm Time,[00:00:00][Status:ShowOnly]
Allow Flashing BIOS to a Previous Version,Yes
Require Admin. Pass. when Flashing,No
Windows UEFI Firmware Update,Enabled
Require POP on System Boot,Yes
Require POP on Restart,No
POP Changeable by User,Yes
Require Admin. Pass. For F12 Boot,No
Smart USB Protection,Disabled
Require HDP on System Boot,Auto
TCG Security Device,Discrete TPM
Security Chip 2.0,Enabled
Secure Boot,Disabled
Network Offline Locker,Disabled
Computrace Module Activation Setting,Enabled
Device Guard,Disabled
Chassis Intrusion Detection,Disabled
Configuration Change Detection,Disabled
Password Count Exceeded Error,Enabled
Block SID Authentication,Enabled
CSM,Enabled
Boot Mode,Auto
Boot Priority,Legacy First
Boot Up Num-Lock Status,On
OS Optimized Defaults,Enabled
Primary Boot Sequence,USB HDD:SATA 1:SATA 2:SATA 3:Network 1
Error Boot Sequence,USB HDD:USB CDROM:Network 1:M.2 Drive 1:PCIe4X_1 Drive:PCIe16X_1 Drive:SATA 1:SATA 2:SATA 3:Other Device
Automatic Boot Sequence,USB HDD:USB CDROM:Other Device:Network 1:M.2 Drive 1:PCIe4X_1 Drive:PCIe16X_1 Drive:SATA 1:SATA 2:SATA 3
@@ -0,0 +1,85 @@
SerialPort1Address,3F8/IRQ4
USBPortAccess,Enabled
USBEnumerationDelay,Disabled
FrontUSBPorts,Enabled
USBPort1,Enabled
USBPort2,Enabled
USBPort3,Enabled
USBPort4,Enabled
USBPort5,Enabled
RearUSBPorts,Enabled
USBPort7,Enabled
USBPort8,Enabled
USBPort9,Enabled
USBPort10,Enabled
SATAController,Enabled
SATADrive1,Enabled
SATADrive2,Enabled
SATADrive3,Enabled
ConfigureSATAas,AHCI
HardDiskPre-delay,Disabled
UMAFrameBufferSize,Auto
PrimaryVideoController,Auto
OnboardAudioController,Enabled
InternalSpeaker,Enabled
OnboardEthernetController,Enabled
WirelessLANAccess,Enabled
PXEIPV4NetworkStack,Enabled
PXEIPV6NetworkStack,Disabled
ASPMSupport,Disabled
PCIe16xSlotSpeed,Auto
CardReader,Enabled
Bluetooth,Enabled
AMDSecureVirtualMachine,Enabled
IOMMU,Enabled
CPBMode,Enabled
CStateSupport,Enabled
DASHSupport,Disabled
ConsoleRedirectionTerminalType,VT100+
DustShieldAlert,Disabled
AfterPowerLoss,Last State
EnhancedPowerSavingMode,Disabled
SmartPowerOn,Enabled
IntelligentCoolingPerformanceMode,Best Performance
WakeonLAN,Automatic
WakeUponAlarm,Disabled
StartupSequence,Primary
AlarmTime(HH:MM:SS),[00:00:00][Status:ShowOnly]
AlarmDate(MM/DD/YYYY),[01/01/2021][Status:ShowOnly]
AlarmDayofWeek,Sunday
UserDefinedAlarmSunday,Disabled
UserDefinedAlarmMonday,Disabled
UserDefinedAlarmTuesday,Disabled
UserDefinedAlarmWednesday,Disabled
UserDefinedAlarmThursday,Disabled
UserDefinedAlarmFriday,Disabled
UserDefinedAlarmSaturday,Disabled
UserDefinedAlarmTime,[00:00:00][Status:ShowOnly]
AccessSecuritySettings,Disabled
RemoteSetSMP,Disabled
SetMinimumLength,Disabled
SetStrongPassword,Disabled
KeyboardLayout,English
AllowJumperClearSVP,Yes
SecureRollBackPrevention,Yes
RequireSVPwhenFlashing,No
WindowsUEFIFirmwareUpdate,Enabled
BIOSPasswordAtSystemBoot,Yes
BIOSPasswordAtReboot,No
BIOSPasswordAtBootDeviceList,No
SmartUSBProtection,Disabled
PhysicalPresenceforClear,Enabled
RequireHDPonSystemBoot,Auto
SecureBoot,Enabled
AbsolutePersistenceModule,Enabled
DeviceGuard,Disabled
ElectronicLock,Unlock
CoverTamperDetected,Disabled
ConfigurationChangeDetection,Disabled
PasswordCountExceededError,Enabled
BootUpNumLockStatus,On
OptionKeysDisplay,Disabled
FastBoot,Enabled
PrimaryBootSequence,M.2 Drive 1:SATA 1:SATA 2:SATA 3:Network 1:USB HDD:USB CDROM:Other Device
ErrorBootSequence,Network 1:M.2 Drive 1:SATA 1:SATA 2:SATA 3:Other Device
AutomaticBootSequence,Network 1:M.2 Drive 1:SATA 1:SATA 2:SATA 3:Other Device
@@ -0,0 +1,706 @@
<#
.DESCRIPTION
Automatically configure Lenovo BIOS passwords and prompt the user if manual intervention is required.
PASSWORD STATUS CODES
0 - No password set
1 - Power on password set
2 - Supervisor password set
3 - Power on and supervisor passwords set
4 - Hard drive password set
5 - Power on and hard drive passwords set
6 - Supervisor and hard drive passwords set
7 - Supervisor, power on, and hard drive passwords set
.PARAMETER SupervisorSet
Specify this switch to change an existing supervisor password. Must also specify the SupervisorPassword and OldSupervisorPassword parameters.
.PARAMETER SupervisorClear
Specify this swtich to clear an existing supervisor password. Must also specify the OldSupervisorPassword parameter.
.PARAMETER PowerOnSet
Specify this switch to change an existing power on password. Must also specify the PowerOnPassword and OldPowerOnPassword parameters.
.PARAMETER PowerOnClear
Specify this switch to clear an existing power on password. Must also specify the OldPowerOnPassword parameter.
.PARAMETER HDDPasswordClear
Specify this swtich to clear an existing master and/or user hard drive password. Must also specify the HDDMasterPassword and/or HDDUserPassword parameters.
.PARAMETER SupervisorPassword
Specify the new supervisor password to set.
.PARAMETER OldSupervisorPassword
Specify the old supervisor password(s) to be changed. Multiple passwords can be specified as a comma seperated list.
.PARAMETER PowerOnPassword
Specify the new power on password to set.
.PARAMETER OldPowerOnPassword
Specify the old power on password(s) to be changed. Multiple passwords can be specified as a comma seperated list.
.PARAMETER HDDUserPassword
Specify the current user hard drive password to clear.
.PARAMETER HDDMasterPassword
Specify the current master hard drive password to clear.
.PARAMETER NoUserPrompt
The script will run silently and will not prompt the user with a message box.
.PARAMETER ContinueOnError
The script will ignore any errors caused by changing or clearing the passwords. This will not suppress errors caused by parameter validation.
.PARAMETER SMSTSPasswordRetry
For use in a task sequence. If specified, the script will assume the script needs to run at least one more time. This will ignore password errors and suppress user prompts.
.EXAMPLE
Change an existing supervisor password
Manage-LenovoBiosPasswords.ps1 -SupervisorSet -SupervisorPassword <String> -OldSupervisorPassword <String1>,<String2>
Change an existing supervisor password and clear a power on password
Manage-LenovoBiosPasswords.ps1 -SupervisorSet -SupervisorPassword <String> -OldSupervisorPassword <String1>,<String2> -PowerOnClear -OldPowerOnPassword <String1>,<String2>
Clear existing supervisor and power on passwords
Manage-LenovoBiosPasswords.ps1 -SupervisorClear -OldSupervisorPassword <String1>,<String2> -PowerOnClear -OldPowerOnPassword <String1>,<String2>
Clear existing user and master hard drive passwords
Manage-LenovoBiosPasswords.ps1 -HDDPasswordClear -HDDUserPassword <String> -HDDMasterPassword <String>
Clear an existing power on password, suppress any user prompts, and continue on error
Manage-LenovoBiosPasswords.ps1 -PowerOnClear -OldPowerOnPassword <String1>,<String2> -NoUserPrompt -ContinueOnError
.NOTES
Created by: Jon Anderson (@ConfigJon)
Reference: https://www.configjon.com/lenovo-bios-password-management
Modifed: 02/10/2020
.CHANGELOG
07/17/2019 - Updated the script name to Manage-LenovoBiosPasswords. Updated the log directory name to LenovoBiosScripts. Updated the log file name to Manage-LenovoBiosPasswords
07/27/2019 - Formatting changes. Changed the NewSupervisorPassword parameter to SupervisorPassword. Changed the NewPowerOnPassword parameter to PowerOnPassword.
Changed the SMSTSPasswordRetry parameter to be a switch instead of an integer value. Changed the SMSTSChangeSup TS variable to LenovoChangeSupervisor.
Changed the SMSTSClearSup TS variable to LenovoClearSupervisor. Changed the SMSTSChangePo TS variable to LenovoChangePowerOn. Changed the SMSTSClearPo TS variable to LenovoClearPowerOn
11/04/2019 - Added additional logging. Changed the default log path to $ENV:ProgramData\BiosScripts\Lenovo. Modifed the parameter validation logic.
01/30/2020 - Changed the SupervisorChange and PowerOnChange parameters to SupervisorSet and PowerOnSet. Changed the LenovoChangeSupervisor task sequence variable to LenovoSetSupervisor.
Changed the LenovoChangePowerOn task sequence variable to LenovoSetPowerOn. Updated the parameter validation checks.
02/10/2020 - Added better logic for error handling when no Supervisor or Power On Passwords are set.
06/09/2020 - Updated some Write-LogEntry lines to include missing -Severity parameters
#>
#Parameters ===================================================================================================================
param (
[Parameter(Mandatory=$false)][Switch]$SupervisorSet,
[Parameter(Mandatory=$false)][Switch]$SupervisorClear,
[Parameter(Mandatory=$false)][Switch]$PowerOnSet,
[Parameter(Mandatory=$false)][Switch]$PowerOnClear,
[Parameter(Mandatory=$false)][Switch]$HDDPasswordClear,
[Parameter(Mandatory=$false)][ValidateNotNullOrEmpty()][String]$SupervisorPassword,
[Parameter(Mandatory=$false)][ValidateNotNullOrEmpty()][String[]]$OldSupervisorPassword,
[Parameter(Mandatory=$false)][ValidateNotNullOrEmpty()][String]$PowerOnPassword,
[Parameter(Mandatory=$false)][ValidateNotNullOrEmpty()][String[]]$OldPowerOnPassword,
[Parameter(Mandatory=$false)][ValidateNotNullOrEmpty()][String]$HDDUserPassword,
[Parameter(Mandatory=$false)][ValidateNotNullOrEmpty()][String]$HDDMasterPassword,
[Parameter(Mandatory=$false)][Switch]$NoUserPrompt,
[Parameter(Mandatory=$false)][Switch]$ContinueOnError,
[Parameter(Mandatory=$false)][Switch]$SMSTSPasswordRetry
)
#Functions ====================================================================================================================
#Determine if a task sequence is currently running
Function Get-TaskSequenceStatus
{
try
{
$TSEnv = New-Object -ComObject Microsoft.SMS.TSEnvironment
}
catch{}
if ($NULL -eq $TSEnv)
{
return $False
}
else
{
try
{
$SMSTSType = $TSEnv.Value("_SMSTSType")
}
catch{}
if ($NULL -eq $SMSTSType)
{
return $False
}
else
{
return $True
}
}
}
#Create a user prompt with custom body and title text if the NoUserPrompt variable is not set
Function Start-UserPrompt
{
[CmdletBinding()]
param (
[Parameter(Mandatory=$True)][ValidateNotNullOrEmpty()][String[]]$BodyText,
[Parameter(Mandatory=$True)][ValidateNotNullOrEmpty()][String[]]$TitleText
)
if (!($NoUserPrompt))
{
(New-Object -ComObject Wscript.Shell).Popup("$BodyText",0,"$TitleText",0x0 + 0x30) | Out-Null
}
}
#Write data to a CMTrace compatible log file. (Credit to SCConfigMgr - https://www.scconfigmgr.com/)
Function Write-LogEntry
{
param (
[parameter(Mandatory = $true, HelpMessage = "Value added to the log file.")]
[ValidateNotNullOrEmpty()]
[string]$Value,
[parameter(Mandatory = $true, HelpMessage = "Severity for the log entry. 1 for Informational, 2 for Warning and 3 for Error.")]
[ValidateNotNullOrEmpty()]
[ValidateSet("1", "2", "3")]
[string]$Severity,
[parameter(Mandatory = $false, HelpMessage = "Name of the log file that the entry will written to.")]
[ValidateNotNullOrEmpty()]
[string]$FileName = "Manage-LenovoBiosPasswords.log"
)
# Determine log file location
$LogFilePath = Join-Path -Path $LogsDirectory -ChildPath $FileName
# Construct time stamp for log entry
if (-not(Test-Path -Path 'variable:global:TimezoneBias'))
{
[string]$global:TimezoneBias = [System.TimeZoneInfo]::Local.GetUtcOffset((Get-Date)).TotalMinutes
if ($TimezoneBias -match "^-")
{
$TimezoneBias = $TimezoneBias.Replace('-', '+')
}
else
{
$TimezoneBias = '-' + $TimezoneBias
}
}
$Time = -join @((Get-Date -Format "HH:mm:ss.fff"), $TimezoneBias)
# Construct date for log entry
$Date = (Get-Date -Format "MM-dd-yyyy")
# Construct context for log entry
$Context = $([System.Security.Principal.WindowsIdentity]::GetCurrent().Name)
# Construct final log entry
$LogText = "<![LOG[$($Value)]LOG]!><time=""$($Time)"" date=""$($Date)"" component=""Manage-LenovoBiosPasswords"" context=""$($Context)"" type=""$($Severity)"" thread=""$($PID)"" file="""">"
# Add value to log file
try
{
Out-File -InputObject $LogText -Append -NoClobber -Encoding Default -FilePath $LogFilePath -ErrorAction Stop
}
catch [System.Exception]
{
Write-Warning -Message "Unable to append log entry to $FileName file. Error message at line $($_.InvocationInfo.ScriptLineNumber): $($_.Exception.Message)"
}
}
#Main program =================================================================================================================
#Configure Logging and task sequence variables
if (Get-TaskSequenceStatus)
{
$TSEnv = New-Object -COMObject Microsoft.SMS.TSEnvironment
$TSProgress = New-Object -ComObject Microsoft.SMS.TsProgressUI
$LogsDirectory = $TSEnv.Value("_SMSTSLogPath")
}
else
{
$LogsDirectory = "$ENV:ProgramData\BiosScripts\Lenovo"
if (!(Test-Path -PathType Container $LogsDirectory))
{
New-Item -Path $LogsDirectory -ItemType "Directory" -Force | Out-Null
}
}
Write-Output "Log path set to $LogsDirectory\Manage-LenovoBiosPasswords.log"
Write-LogEntry -Value "START - Lenovo BIOS password management script" -Severity 1
#Connect to the Lenovo_BiosPasswordSettings WMI class
$Error.Clear()
try
{
Write-LogEntry -Value "Connect to the Lenovo_BiosPasswordSettings WMI class" -Severity 1
$PasswordSettings = Get-WmiObject -Namespace root\wmi -Class Lenovo_BiosPasswordSettings
}
catch
{
Write-LogEntry -Value "Unable to connect to the Lenovo_BiosPasswordSettings WMI class" -Severity 3
throw "Unable to connect to the Lenovo_BiosPasswordSettings WMI class"
}
if (!($Error))
{
Write-LogEntry -Value "Successfully connected to the Lenovo_BiosPasswordSettings WMI class" -Severity 1
}
#Connect to the Lenovo_SetBiosPassword WMI class
$Error.Clear()
try
{
Write-LogEntry -Value "Connect to the Lenovo_SetBiosPassword WMI class" -Severity 1
$PasswordSet = Get-WmiObject -Namespace root\wmi -Class Lenovo_SetBiosPassword
}
catch
{
Write-LogEntry -Value "Unable to connect to the Lenovo_SetBiosPassword WMI class" -Severity 3
throw "Unable to connect to the Lenovo_BiosPasswordSettings WMI class"
}
if (!($Error))
{
Write-LogEntry -Value "Successfully connected to the Lenovo_SetBiosPassword WMI class" -Severity 1
}
#Get the current password status
Write-LogEntry -Value "Get the current password state and validate the specified password is not blank" -Severity 1
$PasswordStatus = $PasswordSettings.PasswordState
if ((($PasswordStatus -eq 0) -or ($PasswordStatus -eq 1) -or ($PasswordStatus -eq 4) -or ($PasswordStatus -eq 5)))
{
Write-LogEntry -Value "The supervisor password is not currently set" -Severity 1
}
else
{
Write-LogEntry -Value "The supervisor password is currently set" -Severity 1
}
if ((($PasswordStatus -eq 0) -or ($PasswordStatus -eq 2) -or ($PasswordStatus -eq 4) -or ($PasswordStatus -eq 6)))
{
Write-LogEntry -Value "The power on password is not currently set" -Severity 1
}
else
{
Write-LogEntry -Value "The power on password is currently set" -Severity 1
}
#Parameter validation
Write-LogEntry -Value "Begin parameter validation" -Severity 1
if (($SupervisorSet) -and !($SupervisorPassword -and $OldSupervisorPassword))
{
$ErrorMsg = "When using the SupervisorSet switch, the SupervisorPassword and OldSupervisorPassword parameters must also be specified"
Write-LogEntry -Value $ErrorMsg -Severity 3
throw $ErrorMsg
}
if (($SupervisorClear) -and !($OldSupervisorPassword))
{
$ErrorMsg = "When using the SupervisorClear switch, the OldSupervisorPassword parameter must also be specified"
Write-LogEntry -Value $ErrorMsg -Severity 3
throw $ErrorMsg
}
if (($PowerOnSet) -and !($PowerOnPassword -and $OldPowerOnPassword))
{
$ErrorMsg = "When using the PowerOnSet switch, the PowerOnPassword and OldPowerOnPassword parameters must also be specified"
Write-LogEntry -Value $ErrorMsg -Severity 3
throw $ErrorMsg
}
if (($PowerOnClear) -and !($OldPowerOnPassword))
{
$ErrorMsg = "When using the PowerOnClear switch, the OldPowerOnPassword parameter must also be specified"
Write-LogEntry -Value $ErrorMsg -Severity 3
throw $ErrorMsg
}
if (($SupervisorSet) -and ($SupervisorClear))
{
$ErrorMsg = "Cannot specify the SupervisorSet and SupervisorClear parameters simultaneously"
Write-LogEntry -Value $ErrorMsg -Severity 3
throw $ErrorMsg
}
if (($PowerOnSet) -and ($PowerOnClear))
{
$ErrorMsg = "Cannot specify the PowerOnSet and PowerOnClear parameters simultaneously"
Write-LogEntry -Value $ErrorMsg -Severity 3
throw $ErrorMsg
}
if (($HDDPasswordClear) -and !($HDDUserPassword))
{
$ErrorMsg = "When using the HDDPasswordClear switch, the HDDUserPassword parameter must also be specified"
Write-LogEntry -Value $ErrorMsg -Severity 3
throw $ErrorMsg
}
if (($HDDMasterPassword) -and !($HDDUserPassword))
{
$ErrorMsg = "When specifying a master hard drive password, a user hard drive password must also be specified"
Write-LogEntry -Value $ErrorMsg -Severity 3
throw $ErrorMsg
}
if (($HDDMasterPassword -or $HDDUserPassword) -and !($HDDPasswordClear))
{
$ErrorMsg = "When using the HDDMasterPassword or HDDUserPassword parameters, the HDDPasswordClear parameter must also be specified"
Write-LogEntry -Value $ErrorMsg -Severity 3
throw $ErrorMsg
}
if (($OldSupervisorPassword -or $SupervisorPassword) -and !($SupervisorSet -or $SupervisorClear))
{
$ErrorMsg = "When using the OldSupervisorPassword or SupervisorPassword parameters, one of the SupervisorSet or SupervisorClear parameters must also be specified"
Write-LogEntry -Value $ErrorMsg -Severity 3
throw $ErrorMsg
}
if (($OldPowerOnPassword -or $PowerOnPassword) -and !($PowerOnSet -or $PowerOnClear))
{
$ErrorMsg = "When using the OldPowerOnPassword or PowerOnPassword parameters, one of the PowerOnSet or PowerOnClear parameters must also be specified"
Write-LogEntry -Value $ErrorMsg -Severity 3
throw $ErrorMsg
}
if ($OldSupervisorPassword.Count -gt 2) #Prevents entering more than 2 old supervisor passwords
{
$ErrorMsg = "Please specify 2 or fewer old supervisor passwords"
Write-LogEntry -Value $ErrorMsg -Severity 3
throw $ErrorMsg
}
if ($OldPowerOnPassword.Count -gt 2) #Prevents entering more than 2 old power on passwords
{
$ErrorMsg = "Please specify 2 or fewer old power on passwords"
Write-LogEntry -Value $ErrorMsg -Severity 3
throw $ErrorMsg
}
if (($SMSTSPasswordRetry) -and !(Get-TaskSequenceStatus))
{
Write-LogEntry -Value "The SMSTSPasswordRetry parameter was specifed while not running in a task sequence. Setting SMSTSPasswordRetry to false." -Severity 2
$SMSTSPasswordRetry = 0
}
Write-LogEntry -Value "Parameter validation completed" -Severity 1
#Set variables from a previous script session
if (Get-TaskSequenceStatus)
{
Write-LogEntry -Value "Check for existing task sequence variables" -Severity 1
$LenovoSetSupervisor = $TSEnv.Value("LenovoSetSupervisor")
if ($LenovoSetSupervisor -eq "Failed")
{
Write-LogEntry -Value "Previous unsuccessful supervisor password set attempt detected" -Severity 1
}
$LenovoClearSupervisor = $TSEnv.Value("LenovoClearSupervisor")
if ($LenovoClearSupervisor -eq "Failed")
{
Write-LogEntry -Value "Previous unsuccessful supervisor password clear attempt detected" -Severity 1
}
$LenovoSetPowerOn = $TSEnv.Value("LenovoSetPowerOn")
if ($LenovoSetPowerOn -eq "Failed")
{
Write-LogEntry -Value "Previous unsuccessful power on password set attempt detected" -Severity 1
}
$LenovoClearPowerOn = $TSEnv.Value("LenovoClearPowerOn")
if ($LenovoClearPowerOn -eq "Failed")
{
Write-LogEntry -Value "Previous unsuccessful power on password clear attempt detected" -Severity 1
}
}
#Attempting to set or clear a supervisor password when no supervisor password currently exists
if ((($PasswordStatus -eq 0) -or ($PasswordStatus -eq 1) -or ($PasswordStatus -eq 4) -or ($PasswordStatus -eq 5)))
{
if ($SupervisorSet)
{
$SupervisorPWExists = "Failed"
Write-LogEntry -Value "No supervisor password currently set. Unable to set the supervisor password" -Severity 3
}
if ($SupervisorClear)
{
Write-LogEntry -Value "No supervisor password currently set. No need to clear the supervisor password" -Severity 2
Clear-Variable SupervisorClear
}
}
#Attempting to set or clear a power on password when no power on password currently exists
if ((($PasswordStatus -eq 0) -or ($PasswordStatus -eq 2) -or ($PasswordStatus -eq 4) -or ($PasswordStatus -eq 6)))
{
if ($PowerOnSet)
{
$PowerOnPWExists = "Failed"
Write-LogEntry -Value "No power on password currently set. Unable to set the power on password" -Severity 3
}
if ($PowerOnClear)
{
Write-LogEntry -Value "No power on password currently set. No need to clear the power on password" -Severity 2
Clear-Variable PowerOnClear
}
}
#If a supervisor password is set, attempt to clear or change it
if (($PasswordStatus -eq 2) -or ($PasswordStatus -eq 3) -or($PasswordStatus -eq 6) -or($PasswordStatus -eq 7))
{
#Change the existing supervisor password
if (($SupervisorSet) -and ($LenovoSetSupervisor -ne "Success"))
{
Write-LogEntry -Value "Attempt to change the existing supervisor password" -Severity 1
$SupervisorPWSet = "Failed"
if (Get-TaskSequenceStatus)
{
$TSEnv.Value("LenovoSetSupervisor") = "Failed"
}
if ($PasswordSet.SetBiosPassword("pap,$SupervisorPassword,$SupervisorPassword,ascii,us").Return -eq "Success")
{
#Password already correct
$SupervisorPWSet = "Success"
if (Get-TaskSequenceStatus)
{
$TSEnv.Value("LenovoSetSupervisor") = "Success"
}
Write-LogEntry -Value "The supervisor password is already set correctly" -Severity 1
}
else
{
$Counter = 0
While($Counter -lt $OldSupervisorPassword.Count){
if ($PasswordSet.SetBiosPassword("pap,$($OldSupervisorPassword[$Counter]),$SupervisorPassword,ascii,us").Return -eq "Success")
{
#Successfully changed the password
$SupervisorPWSet = "Success"
if (Get-TaskSequenceStatus)
{
$TSEnv.Value("LenovoSetSupervisor") = "Success"
}
Write-LogEntry -Value "The supervisor password has been successfully changed" -Severity 1
break
}
else
{
#Failed to change the password
$Counter++
}
}
if ($SupervisorPWSet -eq "Failed")
{
Write-LogEntry -Value "Failed to change the supervisor password" -Severity 3
}
}
}
#Clear the existing supervisor password
if (($SupervisorClear) -and ($LenovoClearSupervisor -ne "Success"))
{
Write-LogEntry -Value "Attempt to clear the existing supervisor password" -Severity 1
$SupervisorPWClear = "Failed"
if (Get-TaskSequenceStatus)
{
$TSEnv.Value("LenovoClearSupervisor") = "Failed"
}
$Counter = 0
While($Counter -lt $OldSupervisorPassword.Count){
if ($PasswordSet.SetBiosPassword("pap,$($OldSupervisorPassword[$Counter]),,ascii,us").Return -eq "Success")
{
#Successfully cleared the password
$SupervisorPWClear = "Success"
if (Get-TaskSequenceStatus)
{
$TSEnv.Value("LenovoClearSupervisor") = "Success"
}
Write-LogEntry -Value "The supervisor password has been successfully cleared" -Severity 1
break
}
else
{
#Failed to clear the password
$Counter++
}
}
if ($SupervisorPWClear -eq "Failed")
{
Write-LogEntry -Value "Failed to clear the supervisor password" -Severity 3
}
}
}
#If a power on password is set, attempt to clear or change it
if (($PasswordStatus -eq 1) -or ($PasswordStatus -eq 3) -or($PasswordStatus -eq 5) -or($PasswordStatus -eq 7))
{
#Change the existing supervisor password
if (($PowerOnSet) -and ($LenovoSetPowerOn -ne "Success"))
{
Write-LogEntry -Value "Attempt to change the existing power on password" -Severity 1
$PowerOnPWSet = "Failed"
if (Get-TaskSequenceStatus)
{
$TSEnv.Value("LenovoSetPowerOn") = "Failed"
}
if ($PasswordSet.SetBiosPassword("pop,$PowerOnPassword,$PowerOnPassword,ascii,us").Return -eq "Success")
{
#Password already correct
$PowerOnPWSet = "Success"
if (Get-TaskSequenceStatus)
{
$TSEnv.Value("LenovoSetPowerOn") = "Success"
}
Write-LogEntry -Value "The power on password is already set correctly" -Severity 1
}
else
{
$Counter = 0
While($Counter -lt $OldPowerOnPassword.Count){
if ($PasswordSet.SetBiosPassword("pop,$($OldPowerOnPassword[$Counter]),$PowerOnPassword,ascii,us").Return -eq "Success")
{
#Successfully changed the password
$PowerOnPWSet = "Success"
if (Get-TaskSequenceStatus)
{
$TSEnv.Value("LenovoSetPowerOn") = "Success"
}
Write-LogEntry -Value "The power on password has been successfully changed" -Severity 1
break
}
else
{
#Failed to change the password
$Counter++
}
}
if ($PowerOnPWSet -eq "Failed")
{
Write-LogEntry -Value "Failed to change the power on password" -Severity 3
}
}
}
#Clear the existing power on password
if (($PowerOnClear) -and ($LenovoClearPowerOn -ne "Success"))
{
Write-LogEntry -Value "Attempt to clear the existing power on password" -Severity 1
$PowerOnPWClear = "Failed"
if (Get-TaskSequenceStatus)
{
$TSEnv.Value("LenovoClearPowerOn") = "Failed"
}
$Counter = 0
While($Counter -lt $OldPowerOnPassword.Count){
if ($PasswordSet.SetBiosPassword("pop,$($OldPowerOnPassword[$Counter]),,ascii,us").Return -eq "Success")
{
#Successfully cleared the password
$PowerOnPWClear = "Success"
if (Get-TaskSequenceStatus)
{
$TSEnv.Value("LenovoClearPowerOn") = "Success"
}
Write-LogEntry -Value "The power on password has been successfully cleared" -Severity 1
break
}
else
{
#Failed to clear the password
$Counter++
}
}
if ($PowerOnPWClear -eq "Failed")
{
Write-LogEntry -Value "Failed to clear the power on password" -Severity 3
}
}
}
#Attempt to clear the hard drive password(s)
if ($HDDPasswordClear)
{
if (($HDDUserPassword) -and ($HDDMasterPassword))
{
Write-LogEntry -Value "Attempt to clear the existing user and master hard drive passwords" -Severity 1
$PasswordSet.SetBiosPassword("mhdp1,$HDDMasterPassword,,ascii,us")
$PasswordSet.SetBiosPassword("uhdp1,$HDDUserPassword,,ascii,us")
}
elseif (($HDDUserPassword) -and !($HDDMasterPassword))
{
Write-LogEntry -Value "Attempt to clear the existing user hard drive password" -Severity 1
$PasswordSet.SetBiosPassword("uhdp1,$HDDUserPassword,,ascii,us")
}
}
#Prompt the user about any password set failures
if (($SupervisorPWExists -eq "Failed") -or ($PowerOnPWExists -eq "Failed"))
{
if (!($NoUserPrompt))
{
Write-LogEntry -Value "Failures detected, display on-screen prompts for any required manual actions" -Severity 2
#Close the task sequence progress dialog
if (Get-TaskSequenceStatus)
{
$TSProgress.CloseProgressDialog()
}
#Display prompts
if ($SupervisorPWExists -eq "Failed")
{
Start-UserPrompt -BodyText "No supervisor password is set. Please reboot the computer and manually set a supervisor password" -TitleText "Lenovo Password Management Script"
}
if ($PowerOnPWExists -eq "Failed")
{
Start-UserPrompt -BodyText "No power on password is set. Please reboot the computer and manually set a power on password." -TitleText "Lenovo Password Management Script"
}
}
#Exit the script with an error
if (!($ContinueOnError))
{
Write-LogEntry -Value "Failures detected, exiting the script" -Severity 3
Write-Output "Password management tasks failed. Check the log file for more information"
Write-LogEntry -Value "END - Lenovo BIOS password management script" -Severity 1
Exit 1
}
else
{
Write-LogEntry -Value "Failures detected, but the ContinueOnError parameter was set. Script execution will continue" -Severity 3
Write-Output "Failures detected, but the ContinueOnError parameter was set. Script execution will continue"
}
}
#Prompt the user about any password change or clear failures
if ((($SupervisorPWSet -eq "Failed") -or ($SupervisorPWClear -eq "Failed") -or ($PowerOnPWSet -eq "Failed") -or ($PowerOnPWClear -eq "Failed")) -and (!($SMSTSPasswordRetry)))
{
if (!($NoUserPrompt))
{
Write-LogEntry -Value "Failures detected, display on-screen prompts for any required manual actions" -Severity 2
#Close the task sequence progress dialog
if (Get-TaskSequenceStatus)
{
$TSProgress.CloseProgressDialog()
}
if ($SupervisorPWSet -eq "Failed")
{
Start-UserPrompt -BodyText "The supervisor password is set, but cannot be automatically changed. Please reboot the computer and manually change the supervisor password." -TitleText "Lenovo Password Management Script"
}
if ($SupervisorPWClear -eq "Failed")
{
Start-UserPrompt -BodyText "The supervisor password is set, but cannot be automatically cleared. Please reboot the computer and manually clear the supervisor password." -TitleText "Lenovo Password Management Script"
}
if ($PowerOnPWSet -eq "Failed")
{
Start-UserPrompt -BodyText "The power on password is set, but cannot be automatically changed. Please reboot the computer and manually change the power on password." -TitleText "Lenovo Password Management Script"
}
if ($PowerOnPWClear -eq "Failed")
{
Start-UserPrompt -BodyText "The power on password is set, but cannot be automatically cleared. Please reboot the computer and manually clear the power on password." -TitleText "Lenovo Password Management Script"
}
}
#Exit the script with an error
if (!($ContinueOnError))
{
Write-LogEntry -Value "Failures detected, exiting the script" -Severity 3
Write-Output "Password management tasks failed. Check the log file for more information"
Write-LogEntry -Value "END - Lenovo BIOS password management script" -Severity 1
Exit 1
}
else
{
Write-LogEntry -Value "Failures detected, but the ContinueOnError parameter was set. Script execution will continue" -Severity 3
Write-Output "Failures detected, but the ContinueOnError parameter was set. Script execution will continue"
}
}
elseif ((($SupervisorPWExists -eq "Failed") -or ($SupervisorPWSet -eq "Failed") -or ($SupervisorPWClear -eq "Failed") -or ($PowerOnPWExists -eq "Failed") -or ($PowerOnPWSet -eq "Failed") -or ($PowerOnPWClear -eq "Failed")) -and ($SMSTSPasswordRetry))
{
Write-LogEntry -Value "Failures detected, but the SMSTSPasswordRetry parameter was set. No user prompts will be displayed" -Severity 3
Write-Output "Failures detected, but the SMSTSPasswordRetry parameter was set. No user prompts will be displayed"
}
else
{
Write-Output "Password management tasks succeeded. Check the log file for more information"
}
Write-LogEntry -Value "END - Lenovo BIOS password management script" -Severity 1
File diff suppressed because it is too large Load Diff
@@ -0,0 +1,87 @@
Serial Port1 Address,3F8/IRQ4
USB Support,Enabled
USB Legacy Support,Enabled
USB Debug Support,Disabled
USB Enumeration Delay,Disabled
USB Virtual KBC Support,Disabled
Front USB Ports,Enabled
USB Port 1,Enabled
USB Port 2,Enabled
USB Port 3,Enabled
USB Port 4,Enabled
Rear USB Ports,Enabled
USB Port 5,Enabled
USB Port 6,Enabled
USB Port 7,Enabled
USB Port 8,Enabled
SATA Controller,Enabled
SATA Drive 1,Enabled
SATA Drive 2,Enabled
SATA Drive 3,Enabled
Configure SATA as,AHCI
Hard Disk Pre-delay,Disabled
Select Active Video,Auto
Pre-Allocated Memory Size,32MB
Total Graphics Memory,Maximum
Onboard Audio Controller,Enabled
Internal Speaker,Enabled
Onboard Ethernet Controller,Enabled
Boot Agent,PXE
PXE IPV4 network stack,Enabled
PXE IPV6 network stack,Disabled
PCIe 16x Slot Speed,Auto
PCIe 1x Slot 1 Speed,Auto
PCIe 1x Slot 2 Speed,Auto
EIST Support,Enabled
Intel(R) Hyper-Threading Technology,Enabled
Core Multi-Processing,Enabled
Intel(R) Virtualization Technology,Enabled
VT-d,Enabled
C1E Support,Enabled
C State Support,C1C3C6C7C8
Turbo Mode,Enabled
Intel(R) SGX Control,Software Controlled
Current State,Disabled
Dust Shield Alert,Disabled
After Power Loss,Last State
Enhanced Power Saving Mode,Disabled
Wake on LAN,Automatic
Wake from PCI Device,Primary
Wake from Serial Port Ring,Primary
Wake Up on Alarm,Disabled
Startup Sequence,Primary
Alarm Time(HH:MM:SS),00:00:00][Status:ShowOnly
Alarm Date(MM/DD/YYYY),01/01/2016][Status:ShowOnly
Alarm Day of Week,Sunday
Sunday,Disabled
Monday,Disabled
Tuesday,Disabled
Wednesday,Disabled
Thursday,Disabled
Friday,Disabled
Saturday,Disabled
User Defined Alarm Time,00:00:00][Status:ShowOnly
Allow Flashing BIOS to a Previous Version,Yes
Require Admin. Pass. when Flashing,No
Windows UEFI Firmware Update,Enabled
Require POP on System Boot,Yes
Require POP on Restart,No
Require Admin. Pass. For F12 Boot,No
Smart USB Protection,Disabled
Require HDP on System Boot,Auto
TCG Security Device,Discrete TPM
Security Chip 2.0,Enabled
Secure Boot,Disabled
Network Offline Locker Setup,Disabled
Credential Guard,Disabled
Chassis Intrusion Detection,Disabled
Configuration Change Detection,Disabled
Password Count Exceeded Error,Enabled
CSM,Enabled
Boot Mode,Legacy Only
Boot Up Num-Lock Status,On
Startup Device Menu Prompt,Enabled
OS Optimized Defaults,Enabled
Primary Boot Sequence,USB FDD:USB KEY:M.2 Drive:SATA 1:SATA 2:SATA 3:Network 1:USB HDD:USB CDROM:Other Device;[Excluded from boot order:Network 2:Network 3:Network 4]
Error Boot Sequence,Network 1:M.2 Drive:SATA 1:SATA 2:SATA 3:Other Device;[Excluded from boot order:Network 2:Network 3:Network 4:USB FDD:USB HDD:USB CDROM:USB KEY]
Automatic Boot Sequence,SATA 1:M.2 Drive:Network 1:SATA 2:SATA 3:Other Device;[Excluded from boot order:Network 2:Network 3:Network 4:USB FDD:USB HDD:USB CDROM:USB KEY]
@@ -0,0 +1,3 @@
Wake on LAN,Automatic
Primary Boot Sequence,SATA 1:SATA 2:SATA 3:Network 1
Automatic Boot Sequence,Network1:SATA 1:M.2 Drive:SATA 3:Other device
@@ -0,0 +1,4 @@
qQd8bbzDvJ2n7mc1dSZC2utCpdw=
Wake on LAN,Automatic
Primary Boot Sequence,SATA 1:SATA 2:SATA 3:Network 1
Automatic Boot Sequence,Network1:SATA 1:M.2 Drive:SATA 3:Other device
@@ -0,0 +1 @@
Primary Boot Sequence,SATA 1:SATA 2:SATA 3:Network 1
@@ -0,0 +1,6 @@
Boot Agent,PXE
PXE IPV4 network stack,Enabled
PXE IPV6 network stack,Disabled
Secure Boot,Enabled
Secure boot,Enabled
Primary Boot Sequence,Network 1:SATA 1:SATA 2:SATA 3
@@ -0,0 +1,3 @@
BootOrder,NVMe0:NVMe1:HDD0:HDD1:HDD2:HDD3:PCILAN
IPv4NetworkStack,Enable
IPv6NetworkStack,Disable
@@ -0,0 +1,4 @@
Wake on LAN,Automatic
BootOrder,NVMe0:NVMe1:HDD0:HDD1:HDD2:HDD3:PCILAN
IPv4NetworkStack,Enable
IPv6NetworkStack,Disable
@@ -0,0 +1 @@
BootOrder,NVMe0:NVMe1:HDD0:HDD1:HDD2:HDD3:PCILAN
@@ -0,0 +1,5 @@
IPv4NetworkStack,Enable
IPv6NetworkStack,Disable
UefiPxeBootPriority,IPv4First
SecureBoot,Enable
BootOrder,PCILAN:NVMe0:NVMe1:HDD0:HDD1:HDD2:HDD3
@@ -0,0 +1,37 @@
BIOS Changes History
General Information:
M46J9xxUSA is Flash CD ROM image.
M46JTxxUSA is Flash in DOS zip package.
M46JYxxUSA is Flash in Windows utility.
M46KTxxA is the binary image. (BIOS)
NOTE: All changes carry forward. That is, if a change is added in 01,it is also in 02, 03 etc.
This file will be updated from the beginning with first Production BIOS release
CHANGES for M46KT15A/M46JT15A
1.Initial BIOS release
CHANGES for M46KT1AA/M46JT1AA
1.Optimize BIOS item function and Software WMI function.
CHANGES for M46KT1BA/M46JT1BA
1.Fix Error 0164:Memory Size Decreased" will not occur if Memory slots are changed or Memory of the same brand Size is replaced
CHANGES for M46KT1DA/M46JT1DA
1.ThinkCentre support Infineon TPM chip
2.Modify Setup items
CHANGES for M46KT1EA/M46JT1EA
1.Optimize WIFI card compatibility function.
CHANGES for M46KT1FA/M46JT1FA
1.Optimize WMI/BIOS item/audio function.
2.Update Secure wipe and Lenovo Diagnostic firmware.
CHANGES for M46KT20A/M46JT20A
1.Optimize BIOS item function and string.
2.Optimize system sleep function.
@@ -0,0 +1,472 @@
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8">
<title>readme</title>
</head>
<body class='bodyStyle'>
<pre>
--CONTENTS--<br>
1 - SRWIN Usage
2 - CFGWIN Usage
3 - Compiler Information
*************************************************************************************
* 1. SRWIN Usage *
* *
* SRWIN/SRWINx64 is a tool to manage the system BIOS settings. With this *
* tool it is possible to save/restore BIOS settings. SRWIN is for the *
* Windows operating system. *
* *
* NOTE 1: SRWIN.exe/SRWINx64.exe, BIOS level, and Configuration Settings *
* all need to be from the same BIOS level. The BIOS level on the donor *
* system must be the same level as the systems that will be receiving *
* the Configuration Settings. *
* *
* NOTE 2: The following commands require an Administrator Password to be set *
* prior to usage. Without an Administrator Password set, this program will *
* generate an error message when attempting to change the setting: *
* dtpm *
* dtpm2 *
* ftpm *
* cfgsata *
* cfgssata *
* *
* *
* The following commands are provided for the operation. Note, for SRWIN *
* you need to run it from Command Prompt box with Administrator privileges *
* under Windows. Some commands may not be applicable on some systems. *
* *
* Usage: srwin [arg1] [option1] [arg2] [option2]... *
* *
* where [Arguments]: *
* /b [filename] Backup all BIOS settings to the file *
* /r [filename] Restore BIOS settings from input file *
* /pass [password] Input current system BIOS password *
* /newadp [password] Set new Administrator password *
* /newpop [password] Set new Power-on password *
* /clradp Clear current system Administrator password *
* /clrpop Clear current system Power-on password *
* /nor Don't reboot after restore *
* /ign Ignore BIOS level check *
* /f9 Load BIOS Setup default *
* /kbdless [option] Change item "Keboardless Operation" *
* [option] *
* enable -- Set the item to "Enabled" *
* disable -- Set the item to "Disabled" *
* /fdd [option] Change item "Floppy A" *
* [option] *
* enable -- Set the item to "Enabled" *
* disable -- Set the item to "Disabled" *
* /pbs [option] Change first device of primary boot sequence *
* /ebs [option] Change first device of error boot sequence *
* /abs [option] Change first device of automatic boot sequence *
* [option] *
* fdd -- Floppy disk drive *
* sata1 -- SATA drive 1 *
* sata2 -- SATA drive 2 *
* sata3 -- SATA drive 3 *
* sata4 -- SATA drive 4 *
* sata5 -- SATA drive 5 *
* sata6 -- SATA drive 6 *
* sata7 -- SATA drive 7 *
* sata8 -- SATA drive 8 *
* sata9 -- SATA drive 9 *
* sata10 -- SATA drive 10 *
* ufdd_group -- USB FDD group *
* ufdd1 -- USB FDD 1 *
* ufdd2 -- USB FDD 2 *
* ukey_group -- USB key group *
* ukey1 -- USB key 1 *
* ukey2 -- USB key 2 *
* uhdd_group -- USB HDD group *
* uhdd1 -- USB HDD 1 *
* uhdd2 -- USB HDD 2 *
* uodd_group -- USB ODD group *
* uodd1 -- USB ODD 1 *
* uodd2 -- USB ODD 2 *
* lan1 -- LAN 1 *
* lan2 -- LAN 2 *
* scu_hdd1 -- SCU Hard disk drive 1 *
* scu_hdd2 -- SCU Hard disk drive 2 *
* scu_hdd3 -- SCU Hard disk drive 3 *
* scu_hdd4 -- SCU Hard disk drive 4 *
* Mezz_SATA -- Mezz-SATA *
* eSATA -- eSATA *
* device1 -- Device 1 *
* device2 -- Device 2 *
* device3 -- Device 3 *
* device4 -- Device 4 *
* device5 -- Device 5 *
* device6 -- Device 6 *
* Mezz1_PCIe_P1 -- Mezz1-PCIe-P1 *
* Mezz1_PCIe_P2 -- Mezz1-PCIe-P2 *
* Mezz2_PCIe_P1 -- Mezz2-PCIe-P1 *
* Mezz2_PCIe_P2 -- Mezz2-PCIe-P2 *
* PCIE_SLOT_1 -- PCIe slot 1 *
* PCIE_SLOT_2 -- PCIe slot 2 *
* PCIE_SLOT_3 -- PCIe slot 3 *
* PCIE_SLOT_x -- PCIe slot # *
* PCIE_SLOT_9 -- PCIe slot 9 *
* M2_DRIVER_1 -- M.2 Driver 1 *
* M2_DRIVER_2 -- M.2 Driver 2 *
* M2_DRIVER_3 -- M.2 Driver 3 *
* M2_DRIVER_4 -- M.2 Driver # *
* VMD1 -- VMD/VROC Device 1 *
* VMD2 -- VMD/VROC Device 2 *
* VMD3 -- VMD/VROC Device 3 *
* /dtpm [option] Change discrete TPM 1.2 status *
* (requires Administrator Password - see NOTE 2 above) *
* [option] *
* disable -- Disable discrete TPM 1.2 *
* inactive -- Set discrete TPM 1.2 inactive *
* active -- Set discrete TPM 1.2 active *
* /ftpm [option] Change firmware TPM status *
* (requires Administrator Password - see NOTE 2 above) *
* [option] *
* disable -- Disable firmware TPM *
* enable -- Set firmware TPM enable *
* /dtpm2 [option] Change discrete TPM 2.0 status *
* (requires Administrator Password - see NOTE 2 above) *
* [option] *
* disable -- Disable discrete TPM 2.0 *
* enable -- Set discrete TPM 2.0 enable *
* /vga [option] Change vga pre-allocated memory size *
* [option] *
* 32mb -- Set the size to 32mb *
* 64mb -- Set the size to 64mb *
* 128mb -- Set the size to 128mb *
* 256mb -- Set the size to 256mb *
* 512mb -- Set the size to 512mb *
* 1024mb -- Set the size to 1024mb *
* /cfgsata [option] Change SATA setting *
* (requires Administrator Password - see NOTE 2 above) *
* [option] *
* ide -- Config SATA as IDE *
* ahci -- Config SATA as AHCI *
* raid -- Config SATA as RAID *
* optane -- Config SATA as Intel(R) RST with Intel(R) Opta*
* /above4GB [option] Change Above 4GB Decoding *
* [option] *
* enable -- Set the item to "Enabled" *
* disable -- Set the item to "Disabled" *
* /cfgssata [option] Change sSATA setting *
* (requires Administrator Password - see NOTE 2 above) *
* [option] *
* ide -- Config sSATA as IDE *
* ahci -- Config sSATA as AHCI *
* raid -- Config sSATA as RAID *
* /EHCIHandOff [option] Change EHCIHandOff setting *
* [option] *
* enable -- Set the item to "Enabled" *
* disable -- Set the item to "Disabled" *
* /PowerLoss [option] Change AfterPowerLoss setting *
* [option] *
* on -- set the item to "Power On" *
* off -- set the item to "Power Off" *
* last -- set the item to "Last State" *
* /CardReader [option] Change CardReader setting *
* [option] *
* enable -- Set the item to "Enabled" *
* disable -- Set the item to "Disabled" *
* /strom [option] Change Storage Oprom Launch mode *
* [option] *
* disable -- Do not launch *
* uefi -- UEFI Only *
* legacy -- Legacy Only *
* /satahotplug [option] Change SATA Port Hotplug *
* [option] *
* disable -- Disable All SATA Port Hotplug *
* enable -- Enable All SATA Port 1 Hotplug *
* 00~3ff -- ECX of HDD-hotplug *
* -- Bit[0] for SATA Port 1 = 0 -Disable 1-Enable *
* -- Bit[1] for SATA Port 2 = 0 -Disable 1-Enable *
* -- Bit[2] for SATA Port 3 = 0 -Disable 1-Enable *
* -- Bit[3] for SATA Port 4 = 0 -Disable 1-Enable *
* -- Bit[4] for SATA Port 5 = 0 -Disable 1-Enable *
* -- Bit[5] for SATA Port 6 = 0 -Disable 1-Enable *
* -- Bit[6] for SATA Port 7 = 0 -Disable 1-Enable *
* -- Bit[7] for SATA Port 8 = 0 -Disable 1-Enable *
* -- Bit[8] for SATA Port 9 = 0 -Disable 1-Enable *
* -- Bit[9] for SATA Port 10 = 0 -Disable 1-Enable *
* /sata1hotplug Enable SATA Port 1 Hotplug Only *
* /sata2hotplug Enable SATA Port 2 Hotplug Only *
* /sata3hotplug Enable SATA Port 3 Hotplug Only *
* /sata4hotplug Enable SATA Port 4 Hotplug Only *
* /sata5hotplug Enable SATA Port 5 Hotplug Only *
* /sata6hotplug Enable SATA Port 6 Hotplug Only *
* /sata7hotplug Enable SATA Port 7 Hotplug Only *
* /sata8hotplug Enable SATA Port 8 Hotplug Only *
* /sata9hotplug Enable SATA Port 9 Hotplug Only *
* /sata10hotplug Enable SATA Port 10 Hotplug Only *
* /winguard [option] Change Device Guard and Credential Guard setting *
* [option] *
* disable -- Disable Device Guard and Credential Guard *
* enable -- Enable Device Guard and Credential Guard *
* /pxe [option] Change Boot Agent setting *
* [option] *
* disable -- Disable Boot Agent *
* enable -- Enable PXE boot *
* smc -- Enable SMC boot *
* /tbt [option] Change ThunderBolt card location *
* [option] *
* slot1 -- ThunderBolt plug into slot 1 *
* slot2 -- ThunderBolt plug into slot 2 *
* slotx -- ThunderBolt plug into slot # *
* slot9 -- ThunderBolt plug into slot 9 *
* /xhci [option] Change USB xHCI controller mode setting *
* [option] *
* sauto -- set controller to Smart auto *
* auto -- set controller to auto *
* enable -- set controller to enable *
* disable -- set controller to disable *
* manual -- set controller to manual *
* /mmioh [option] Change MMIOHBase setting *
* [option] *
* 1t -- set the MMIOH base to 1T *
* 4t -- set the MMIOH base to 4T *
* 16t -- set the MMIOH base to 16T *
* 24t -- set the MMIOH base to 24T *
* 40t -- set the MMIOH base to 40T *
* 56t -- set the MMIOH base to 56T *
* /msb [option] Change Windows Modern Standby setting *
* [option] *
* disable -- Disabled *
* enable -- Enabled *
* /pass_scan [ScanCode] Input current system BIOS password *
* in Scan Code with US keyboard *
* /newadp_scan [ScanCode] Set new Administrator password *
* in Scan Code with US keyboard *
* /newpop_scan [ScanCode] Set new Power-on password *
* in Scan Code with US keyboard *
* /pass_scan_fr [ScanCode] Input current system BIOS password *
* in Scan Code with French keyboard *
* /newadp_scan_fr [ScanCode] Set new Administrator password *
* in Scan Code with French keyboard *
* /newpop_scan_fr [ScanCode] Set new Power-on password *
* in Scan Code with French keyboard *
* /pass_scan_ge [ScanCode] Input current system BIOS password *
* in Scan Code with German keyboard *
* /newadp_scan_ge [ScanCode] Set new Administrator password *
* in Scan Code with German keyboard *
* /newpop_scan_ge [ScanCode] Set new Power-on password *
* in Scan Code with German keyboard *
* example 1: *
* srwin.exe /r settings.dat /pass 123456 /ign *
* example 2: *
* srwin.exe /pbs sata1 /pass_scan 191e19 *
* example 3: *
* srwin.exe /newadp 123456 /newpop 123 *
* *
*************************************************************************************
<br> *************************************************************************************
* 2. CFGWIN Usage *
* *
* CFGWIN.exe is a BIOS settings edit tool in Windows supplied by Lenovo. *
* With this tool it is possible to modify selected BIOS settings. This *
* tool is for Windows operating systems. *
* *
* The following commands are provided for the operation. Note, for CFGWIN *
* you need to run it from Command Prompt box with Administrator privileges *
* under Windows. Some commands may not be applicable on some systems. *
* *
* *
* ****** Usage1: capture BIOS settings ****** *
* *
* CFGWIN /c /path:c:\settings.txt *
* /c capture mode *
* /path:XX XX -file that will save BIOS settings, if no file *
* is specified, all settings will be displayed *
* directly to screen. *
* *
* *** Usage2: Restore BIOS settings when there is no Admin password set *
* *
* *
* CFGWIN /r /path:c:\settings.txt *
* /r - restore mode *
* /path:XX XX - file that contains settings to be restored *
* *
* Note:The setting file captured by CFGWIN with "/c" list the supported *
* BIOS item that can be restored *
* *
* *
* *
* *** Usage3: Restore BIOS settings when there is an Admin password set *
* *
* *
* CFGWIN /r /path:c:\settings.txt /admin:123 *
* /r - restore mode *
* /path:XX XX -file that contains settings to be restored *
* /admin:XX XX -administrator password of target if there is an *
* Admin password set on the system, if only a POP *
* set, input current POP here *
* Note: 1.Please refer to Apendix 1 for password supported *
* characters *
* *
* 2. Recommend using "" to include the password for better *
* interpretation *
* For example, password is 12 3&, can be written as *
* /admin:"12 3&" *
* 3. If the password contains " or \ or ', please write as \" *
* or \\ or \', which will be interpreted as " or \ or ' *
* *
* For example, the password is 12"3, please write this as *
* /admin:"12\"3" *
* *
* *
* ****** Usage4: Change specific item value ****** *
* *
* CFGWIN interprets line entries by parsing an item and the new value *
* from the settings file. By restoring such a settings file *
* with "/r", the specific item can be changed to the expected value. *
* *
* The format of the settings file is the same as the one generated by *
* the CFGWIN capture mode with "/c". There is only one item in each line *
* of text file, item name and expected value are separated by comma "," *
* as below: *
* *
* Item name,Expected value; *
* *
* Example1: Disable USB1 *
* Writing a line in setting file as below: *
* USB Port 1,Disabled; *
* *
* Example2: Change primary boot sequence *
* Writing a line in setting file as below: *
* Primary Boot Sequence,Network Card:Hard Drive:USB Key:CD/DVD Drive: *
* USB Hard Disk:USB Floppy:USB CD/DVD:Floppy Drive; *
* *
* Note: *
* All supported items and their selectable value will be listed *
* in Lenovo WMI-Desktop Deployment Guide for the machine model you *
* are using,please reference it when change item setting. *
* *
* For security reasons, some settings need the authorization of an *
* Administrator Password, please ensure the Administrator Password *
* is set before changing these settings: *
* OS Optimized Defaults *
* CSM *
* Secure Boot *
* Device Guard *
* Discrete TPM FW Switch *
* Configure SATA as *
* *
* When you restore BIOS settings using a file, please make sure that *
* all related items are in the correct states, because once an *
* item's dependent item is Disabled or in a special setting, this *
* item will be hidden and can not be updated through CFGWIN, please *
* reference Lenovo WMI-Desktop Deployment Guide for the machine *
* model you are using for detail relationship between items. *
* *
* For example, the two lines below can not be executed in a file *
* simultaneously when you are restoring with CFGWIN. This is because *
* after the system executes the first line, the USB function has *
* been disabled and the second line operation to USB port will not *
* be accepted. *
* USB Support, Disabled; *
* USB Port 1, Enabled; *
* *
* *
* ******** Usage5: Update existing passwords ******* *
* *
* CFGWIN can update system Administrator password and Power On Password. *
* Users can perform this using the format specified below in the settings *
* file using "restore mode", please be noticed that password updating *
* will only take effect after reboot. Remember that only one password *
* can be updated during each reboot cycle. This means that you cannot *
* update Admin Password and Power On Password simultaneously in one *
* cycle, only one password(either Admin. Password or Power On Password) *
* can be updated during each boot cycle. *
* *
* Note: For the Password region in the .txt file, you need to add ; as *
* a terminator. *
* *
* Example1: Update Admin password from 123 to 321 with ascii,us mode *
* Write 3 lines in setting file as below: *
* WmiOpcodePasswordType:pap; *
* WmiOpcodePasswordCurrent01:123; *
* WmiOpcodePasswordNew01:321; *
* *
* Example2: Update POP from 123 to 321 with ascii,us mode *
* Write 3 lines in setting file as below: *
* WmiOpcodePasswordType:pop; *
* WmiOpcodePasswordCurrent01:123; *
* WmiOpcodePasswordNew01:321; *
* *
* *
* *
* ******** Usage6: Clear password ******** *
* *
* Example1: Clear current Admin password with ascii,us mode(assume *
* current Admin password is 123) *
* Write 3 lines in setting file as below: *
* WmiOpcodePasswordType:pap; *
* WmiOpcodePasswordCurrent01:123; *
* WmiOpcodePasswordNew01:; *
* *
* Example2: Clear current POP with ascii,us mode(assume current POP is 123) *
* Write 3 lines in setting file as below: *
* WmiOpcodePasswordType:pop; *
* WmiOpcodePasswordCurrent01:123; *
* WmiOpcodePasswordNew01:; *
* *
* *
* Appendix 1: Characters that password could use *
* 0 - 9 numeral *
* a - z letter *
* A - Z letter *
* Please use quotation marks around passwords that use the *
* following characters. See Usage 3 (above) for examples *
* ! Exclamation mark *
* " Quotation mark *
* # Number sign, Hashtag, Octothorpe, Sharp *
* $ Dollar sign *
* % Percent sign *
* & Ampersand *
* ' Apostrophe *
* ( Left parenthesis *
* ) Right parenthesis *
* * Asterisk *
* + Plus sign *
* , Comma *
* - Hyphen-minus *
* . Full stop *
* / Slash (Solidus) *
* : Colon *
* ; Semicolon *
* < Less-than sign *
* = Equal sign *
* > Greater-than sign *
* ? Question mark *
* @ At sign *
* [ Left Square Bracket *
* \ Backslash *
* ] Right Square Bracket *
* ^ Circumflex accent *
* _ Low line *
* ` Grave accent *
* { Left Curly Bracket *
* | Vertical bar *
* } Right Curly Bracket *
* ~ Tilde, Wave *
* Space *
* *
*************************************************************************************<br>
*************************************************************************************
* 3. Compiler Information *
* *
* This Utility is compiled by Inno Setup 5.5.9 (u) *
* *
*************************************************************************************<br>
<pre>
</body>
<style>
.bodyStyle {
background: white;
color: black;
margin-left: 20%;
margin-right: 20%;
font-size: large;
}
</style>
</html>
Binary file not shown.
Binary file not shown.