Ajout dela structure MDT dans Infra-LAB
This commit is contained in:
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
@@ -0,0 +1,87 @@
|
||||
#TYPE Selected.System.Management.Automation.PSCustomObject
|
||||
"Setting","Value"
|
||||
"Serial Port1 Address","3F8/IRQ4"
|
||||
"USB Support","Enabled"
|
||||
"USB Legacy Support","Enabled"
|
||||
"USB Enumeration Delay","Disabled"
|
||||
"Front USB Ports","Enabled"
|
||||
"Rear USB Ports","Enabled"
|
||||
"USB Port 1","Enabled"
|
||||
"USB Port 2","Enabled"
|
||||
"USB Port 3","Enabled"
|
||||
"USB Port 4","Enabled"
|
||||
"USB Port 5","Enabled"
|
||||
"USB Port 6","Enabled"
|
||||
"USB Port 7","Enabled"
|
||||
"USB Port 8","Enabled"
|
||||
"USB Port 9","Enabled"
|
||||
"SATA Controller","Enabled"
|
||||
"SATA Drive 1","Enabled"
|
||||
"SATA Drive 2","Enabled"
|
||||
"SATA Drive 3","Enabled"
|
||||
"Configure SATA as","AHCI"
|
||||
"Hard Disk Pre-delay","Disabled"
|
||||
"Select Active Video","Auto"
|
||||
"Onboard Audio Controller","Enabled"
|
||||
"Internal Speaker","Enabled"
|
||||
"Onboard Ethernet Controller","Enabled"
|
||||
"PXE Option ROM","Enabled"
|
||||
"PXE IPV4 Network Stack","Enabled"
|
||||
"PXE IPV6 Network Stack","Disabled"
|
||||
"ASPM Support","Auto"
|
||||
"PCIe 16x Slot Speed","Auto"
|
||||
"PCIe 1x Slot 1 Speed","Auto"
|
||||
"PCIe 1x Slot 2 Speed","Auto"
|
||||
"EIST Support","Enabled"
|
||||
"Core Multi-Processing","Enabled"
|
||||
"Intel(R) Virtualization Technology","Enabled"
|
||||
"VT-d","Enabled"
|
||||
"C1E Support","Enabled"
|
||||
"C State Support","C1C3C6C7C8"
|
||||
"Intel(R) SGX Control","Software Controlled"
|
||||
"Intel(R) SIPP Support","Enabled"
|
||||
"Dust Shield Alert","Disabled"
|
||||
"After Power Loss","Last State"
|
||||
"Enhanced Power Saving Mode","Disabled"
|
||||
"Smart Power On","Enabled"
|
||||
"ICE Performance Modes","Better Acoustic Performance"
|
||||
"ICE Thermal Alert","Enabled"
|
||||
"Wake on LAN","Automatic"
|
||||
"Wake from Serial Port Ring","Primary"
|
||||
"Wake Up on Alarm","Disabled"
|
||||
"Startup Sequence","Primary"
|
||||
"Alarm Time(HH:MM:SS)",""
|
||||
"Alarm Date(MM/DD/YYYY)",""
|
||||
"Alarm Day of Week","Sunday"
|
||||
"Sunday","Disabled"
|
||||
"Monday","Disabled"
|
||||
"Tuesday","Disabled"
|
||||
"Wednesday","Disabled"
|
||||
"Thursday","Disabled"
|
||||
"Friday","Disabled"
|
||||
"Saturday","Disabled"
|
||||
"User Defined Alarm Time",""
|
||||
"Allow Flashing BIOS to a Previous Version","Yes"
|
||||
"Require Admin. Pass. when Flashing","No"
|
||||
"Windows UEFI Firmware Update","Enabled"
|
||||
"Require POP on System Boot","Yes"
|
||||
"Require POP on Restart","No"
|
||||
"Require Admin. Pass. For F12 Boot","No"
|
||||
"Smart USB Protection","Disabled"
|
||||
"Require HDP on System Boot","Auto"
|
||||
"TCG Security Device","Discrete TPM"
|
||||
"Security Chip 2.0","Enabled"
|
||||
"Secure Boot","Disabled"
|
||||
"Network Offline Locker","Disabled"
|
||||
"Computrace Module Activation Setting","Enabled"
|
||||
"Device Guard","Disabled"
|
||||
"Chassis Intrusion Detection","Disabled"
|
||||
"Configuration Change Detection","Disabled"
|
||||
"Password Count Exceeded Error","Enabled"
|
||||
"CSM","Enabled"
|
||||
"Boot Mode","Legacy Only"
|
||||
"Boot Up Num-Lock Status","On"
|
||||
"OS Optimized Defaults","Enabled"
|
||||
"Primary Boot Sequence","SATA 1:SATA 2:SATA 3:Network 1"
|
||||
"Error Boot Sequence","Network 1:M.2 Drive 1:PCIe4X_1 Drive:PCIe16X_1 Drive:SATA 1:SATA 2:SATA 3:Other Device"
|
||||
"Automatic Boot Sequence","M.2 Drive 1:PCIe4X_1 Drive:PCIe16X_1 Drive:SATA 1:Network 1:SATA 2:SATA 3:Other Device"
|
||||
|
@@ -0,0 +1,94 @@
|
||||
qQd8bbzDvJ2n7mc1dSZC2utCpdw=
|
||||
KEy Encryption 4pzwCVD6gNj5mtut
|
||||
Serial Port1 Address,3F8/IRQ4
|
||||
USB Support,Enabled
|
||||
USB Legacy Support,Enabled
|
||||
USB Enumeration Delay,Enabled
|
||||
Front USB Ports,Enabled
|
||||
Rear USB Ports,Enabled
|
||||
USB Port 1,Enabled
|
||||
USB Port 2,Enabled
|
||||
USB Port 3,Enabled
|
||||
USB Port 4,Enabled
|
||||
USB Port 5,Enabled
|
||||
USB Port 6,Enabled
|
||||
USB Port 7,Enabled
|
||||
USB Port 8,Enabled
|
||||
USB Port 9,Enabled
|
||||
Card Reader,Enabled
|
||||
SATA Controller,Enabled
|
||||
SATA Drive 1,Enabled
|
||||
SATA Drive 2,Enabled
|
||||
SATA Drive 3,Enabled
|
||||
Configure SATA as,AHCI
|
||||
Hard Disk Pre-delay,Disabled
|
||||
Select Active Video,Auto
|
||||
Onboard Audio Controller,Enabled
|
||||
Internal Speaker,Enabled
|
||||
Onboard Ethernet Controller,Enabled
|
||||
PXE Option ROM,Enabled
|
||||
PXE IPV4 Network Stack,Enabled
|
||||
PXE IPV6 Network Stack,Enabled
|
||||
ASPM Support,Auto
|
||||
PCIe 16x Slot Speed,Auto
|
||||
PCIe 1x Slot 1 Speed,Auto
|
||||
PCIe 1x Slot 2 Speed,Auto
|
||||
EIST Support,Enabled
|
||||
Intel(R) Hyper-Threading Technology,Enabled
|
||||
Core Multi-Processing,Enabled
|
||||
Intel(R) Virtualization Technology,Enabled
|
||||
VT-d,Enabled
|
||||
TxT,Disabled
|
||||
C1E Support,Enabled
|
||||
C State Support,C1C3C6C7C8
|
||||
Turbo Mode,Enabled
|
||||
Intel(R) SGX Control,Software Controlled
|
||||
Intel(R) SIPP Support,Enabled
|
||||
Dust Shield Alert,Disabled
|
||||
After Power Loss,Last State
|
||||
Enhanced Power Saving Mode,Disabled
|
||||
Smart Power On,Enabled
|
||||
ICE Performance Modes,Better Acoustic Performance
|
||||
ICE Thermal Alert,Enabled
|
||||
Wake on LAN,Automatic
|
||||
Wake from Serial Port Ring,Primary
|
||||
Wake Up on Alarm,Disabled
|
||||
Startup Sequence,Primary
|
||||
Alarm Time(HH:MM:SS),[00:00:00][Status:ShowOnly]
|
||||
Alarm Date(MM/DD/YYYY),[01/01/2017][Status:ShowOnly]
|
||||
Alarm Day of Week,Sunday
|
||||
Sunday,Disabled
|
||||
Monday,Disabled
|
||||
Tuesday,Disabled
|
||||
Wednesday,Disabled
|
||||
Thursday,Disabled
|
||||
Friday,Disabled
|
||||
Saturday,Disabled
|
||||
User Defined Alarm Time,[00:00:00][Status:ShowOnly]
|
||||
Allow Flashing BIOS to a Previous Version,Yes
|
||||
Require Admin. Pass. when Flashing,No
|
||||
Windows UEFI Firmware Update,Enabled
|
||||
Require POP on System Boot,Yes
|
||||
Require POP on Restart,No
|
||||
POP Changeable by User,Yes
|
||||
Require Admin. Pass. For F12 Boot,No
|
||||
Smart USB Protection,Disabled
|
||||
Require HDP on System Boot,Auto
|
||||
TCG Security Device,Discrete TPM
|
||||
Security Chip 2.0,Enabled
|
||||
Secure Boot,Disabled
|
||||
Network Offline Locker,Disabled
|
||||
Computrace Module Activation Setting,Enabled
|
||||
Device Guard,Disabled
|
||||
Chassis Intrusion Detection,Disabled
|
||||
Configuration Change Detection,Disabled
|
||||
Password Count Exceeded Error,Enabled
|
||||
Block SID Authentication,Enabled
|
||||
CSM,Enabled
|
||||
Boot Mode,Auto
|
||||
Boot Priority,Legacy First
|
||||
Boot Up Num-Lock Status,On
|
||||
OS Optimized Defaults,Enabled
|
||||
Primary Boot Sequence,USB HDD:SATA 1:SATA 2:SATA 3:Network 1
|
||||
Error Boot Sequence,USB HDD:USB CDROM:Network 1:M.2 Drive 1:PCIe4X_1 Drive:PCIe16X_1 Drive:SATA 1:SATA 2:SATA 3:Other Device
|
||||
Automatic Boot Sequence,USB HDD:USB CDROM:Other Device:Network 1:M.2 Drive 1:PCIe4X_1 Drive:PCIe16X_1 Drive:SATA 1:SATA 2:SATA 3
|
||||
@@ -0,0 +1,85 @@
|
||||
SerialPort1Address,3F8/IRQ4
|
||||
USBPortAccess,Enabled
|
||||
USBEnumerationDelay,Disabled
|
||||
FrontUSBPorts,Enabled
|
||||
USBPort1,Enabled
|
||||
USBPort2,Enabled
|
||||
USBPort3,Enabled
|
||||
USBPort4,Enabled
|
||||
USBPort5,Enabled
|
||||
RearUSBPorts,Enabled
|
||||
USBPort7,Enabled
|
||||
USBPort8,Enabled
|
||||
USBPort9,Enabled
|
||||
USBPort10,Enabled
|
||||
SATAController,Enabled
|
||||
SATADrive1,Enabled
|
||||
SATADrive2,Enabled
|
||||
SATADrive3,Enabled
|
||||
ConfigureSATAas,AHCI
|
||||
HardDiskPre-delay,Disabled
|
||||
UMAFrameBufferSize,Auto
|
||||
PrimaryVideoController,Auto
|
||||
OnboardAudioController,Enabled
|
||||
InternalSpeaker,Enabled
|
||||
OnboardEthernetController,Enabled
|
||||
WirelessLANAccess,Enabled
|
||||
PXEIPV4NetworkStack,Enabled
|
||||
PXEIPV6NetworkStack,Disabled
|
||||
ASPMSupport,Disabled
|
||||
PCIe16xSlotSpeed,Auto
|
||||
CardReader,Enabled
|
||||
Bluetooth,Enabled
|
||||
AMDSecureVirtualMachine,Enabled
|
||||
IOMMU,Enabled
|
||||
CPBMode,Enabled
|
||||
CStateSupport,Enabled
|
||||
DASHSupport,Disabled
|
||||
ConsoleRedirectionTerminalType,VT100+
|
||||
DustShieldAlert,Disabled
|
||||
AfterPowerLoss,Last State
|
||||
EnhancedPowerSavingMode,Disabled
|
||||
SmartPowerOn,Enabled
|
||||
IntelligentCoolingPerformanceMode,Best Performance
|
||||
WakeonLAN,Automatic
|
||||
WakeUponAlarm,Disabled
|
||||
StartupSequence,Primary
|
||||
AlarmTime(HH:MM:SS),[00:00:00][Status:ShowOnly]
|
||||
AlarmDate(MM/DD/YYYY),[01/01/2021][Status:ShowOnly]
|
||||
AlarmDayofWeek,Sunday
|
||||
UserDefinedAlarmSunday,Disabled
|
||||
UserDefinedAlarmMonday,Disabled
|
||||
UserDefinedAlarmTuesday,Disabled
|
||||
UserDefinedAlarmWednesday,Disabled
|
||||
UserDefinedAlarmThursday,Disabled
|
||||
UserDefinedAlarmFriday,Disabled
|
||||
UserDefinedAlarmSaturday,Disabled
|
||||
UserDefinedAlarmTime,[00:00:00][Status:ShowOnly]
|
||||
AccessSecuritySettings,Disabled
|
||||
RemoteSetSMP,Disabled
|
||||
SetMinimumLength,Disabled
|
||||
SetStrongPassword,Disabled
|
||||
KeyboardLayout,English
|
||||
AllowJumperClearSVP,Yes
|
||||
SecureRollBackPrevention,Yes
|
||||
RequireSVPwhenFlashing,No
|
||||
WindowsUEFIFirmwareUpdate,Enabled
|
||||
BIOSPasswordAtSystemBoot,Yes
|
||||
BIOSPasswordAtReboot,No
|
||||
BIOSPasswordAtBootDeviceList,No
|
||||
SmartUSBProtection,Disabled
|
||||
PhysicalPresenceforClear,Enabled
|
||||
RequireHDPonSystemBoot,Auto
|
||||
SecureBoot,Enabled
|
||||
AbsolutePersistenceModule,Enabled
|
||||
DeviceGuard,Disabled
|
||||
ElectronicLock,Unlock
|
||||
CoverTamperDetected,Disabled
|
||||
ConfigurationChangeDetection,Disabled
|
||||
PasswordCountExceededError,Enabled
|
||||
BootUpNumLockStatus,On
|
||||
OptionKeysDisplay,Disabled
|
||||
FastBoot,Enabled
|
||||
PrimaryBootSequence,M.2 Drive 1:SATA 1:SATA 2:SATA 3:Network 1:USB HDD:USB CDROM:Other Device
|
||||
ErrorBootSequence,Network 1:M.2 Drive 1:SATA 1:SATA 2:SATA 3:Other Device
|
||||
AutomaticBootSequence,Network 1:M.2 Drive 1:SATA 1:SATA 2:SATA 3:Other Device
|
||||
@@ -0,0 +1,706 @@
|
||||
<#
|
||||
.DESCRIPTION
|
||||
Automatically configure Lenovo BIOS passwords and prompt the user if manual intervention is required.
|
||||
|
||||
PASSWORD STATUS CODES
|
||||
0 - No password set
|
||||
1 - Power on password set
|
||||
2 - Supervisor password set
|
||||
3 - Power on and supervisor passwords set
|
||||
4 - Hard drive password set
|
||||
5 - Power on and hard drive passwords set
|
||||
6 - Supervisor and hard drive passwords set
|
||||
7 - Supervisor, power on, and hard drive passwords set
|
||||
|
||||
.PARAMETER SupervisorSet
|
||||
Specify this switch to change an existing supervisor password. Must also specify the SupervisorPassword and OldSupervisorPassword parameters.
|
||||
|
||||
.PARAMETER SupervisorClear
|
||||
Specify this swtich to clear an existing supervisor password. Must also specify the OldSupervisorPassword parameter.
|
||||
|
||||
.PARAMETER PowerOnSet
|
||||
Specify this switch to change an existing power on password. Must also specify the PowerOnPassword and OldPowerOnPassword parameters.
|
||||
|
||||
.PARAMETER PowerOnClear
|
||||
Specify this switch to clear an existing power on password. Must also specify the OldPowerOnPassword parameter.
|
||||
|
||||
.PARAMETER HDDPasswordClear
|
||||
Specify this swtich to clear an existing master and/or user hard drive password. Must also specify the HDDMasterPassword and/or HDDUserPassword parameters.
|
||||
|
||||
.PARAMETER SupervisorPassword
|
||||
Specify the new supervisor password to set.
|
||||
|
||||
.PARAMETER OldSupervisorPassword
|
||||
Specify the old supervisor password(s) to be changed. Multiple passwords can be specified as a comma seperated list.
|
||||
|
||||
.PARAMETER PowerOnPassword
|
||||
Specify the new power on password to set.
|
||||
|
||||
.PARAMETER OldPowerOnPassword
|
||||
Specify the old power on password(s) to be changed. Multiple passwords can be specified as a comma seperated list.
|
||||
|
||||
.PARAMETER HDDUserPassword
|
||||
Specify the current user hard drive password to clear.
|
||||
|
||||
.PARAMETER HDDMasterPassword
|
||||
Specify the current master hard drive password to clear.
|
||||
|
||||
.PARAMETER NoUserPrompt
|
||||
The script will run silently and will not prompt the user with a message box.
|
||||
|
||||
.PARAMETER ContinueOnError
|
||||
The script will ignore any errors caused by changing or clearing the passwords. This will not suppress errors caused by parameter validation.
|
||||
|
||||
.PARAMETER SMSTSPasswordRetry
|
||||
For use in a task sequence. If specified, the script will assume the script needs to run at least one more time. This will ignore password errors and suppress user prompts.
|
||||
|
||||
.EXAMPLE
|
||||
Change an existing supervisor password
|
||||
Manage-LenovoBiosPasswords.ps1 -SupervisorSet -SupervisorPassword <String> -OldSupervisorPassword <String1>,<String2>
|
||||
|
||||
Change an existing supervisor password and clear a power on password
|
||||
Manage-LenovoBiosPasswords.ps1 -SupervisorSet -SupervisorPassword <String> -OldSupervisorPassword <String1>,<String2> -PowerOnClear -OldPowerOnPassword <String1>,<String2>
|
||||
|
||||
Clear existing supervisor and power on passwords
|
||||
Manage-LenovoBiosPasswords.ps1 -SupervisorClear -OldSupervisorPassword <String1>,<String2> -PowerOnClear -OldPowerOnPassword <String1>,<String2>
|
||||
|
||||
Clear existing user and master hard drive passwords
|
||||
Manage-LenovoBiosPasswords.ps1 -HDDPasswordClear -HDDUserPassword <String> -HDDMasterPassword <String>
|
||||
|
||||
Clear an existing power on password, suppress any user prompts, and continue on error
|
||||
Manage-LenovoBiosPasswords.ps1 -PowerOnClear -OldPowerOnPassword <String1>,<String2> -NoUserPrompt -ContinueOnError
|
||||
|
||||
.NOTES
|
||||
Created by: Jon Anderson (@ConfigJon)
|
||||
Reference: https://www.configjon.com/lenovo-bios-password-management
|
||||
Modifed: 02/10/2020
|
||||
|
||||
.CHANGELOG
|
||||
07/17/2019 - Updated the script name to Manage-LenovoBiosPasswords. Updated the log directory name to LenovoBiosScripts. Updated the log file name to Manage-LenovoBiosPasswords
|
||||
07/27/2019 - Formatting changes. Changed the NewSupervisorPassword parameter to SupervisorPassword. Changed the NewPowerOnPassword parameter to PowerOnPassword.
|
||||
Changed the SMSTSPasswordRetry parameter to be a switch instead of an integer value. Changed the SMSTSChangeSup TS variable to LenovoChangeSupervisor.
|
||||
Changed the SMSTSClearSup TS variable to LenovoClearSupervisor. Changed the SMSTSChangePo TS variable to LenovoChangePowerOn. Changed the SMSTSClearPo TS variable to LenovoClearPowerOn
|
||||
11/04/2019 - Added additional logging. Changed the default log path to $ENV:ProgramData\BiosScripts\Lenovo. Modifed the parameter validation logic.
|
||||
01/30/2020 - Changed the SupervisorChange and PowerOnChange parameters to SupervisorSet and PowerOnSet. Changed the LenovoChangeSupervisor task sequence variable to LenovoSetSupervisor.
|
||||
Changed the LenovoChangePowerOn task sequence variable to LenovoSetPowerOn. Updated the parameter validation checks.
|
||||
02/10/2020 - Added better logic for error handling when no Supervisor or Power On Passwords are set.
|
||||
06/09/2020 - Updated some Write-LogEntry lines to include missing -Severity parameters
|
||||
#>
|
||||
|
||||
#Parameters ===================================================================================================================
|
||||
|
||||
param (
|
||||
[Parameter(Mandatory=$false)][Switch]$SupervisorSet,
|
||||
[Parameter(Mandatory=$false)][Switch]$SupervisorClear,
|
||||
[Parameter(Mandatory=$false)][Switch]$PowerOnSet,
|
||||
[Parameter(Mandatory=$false)][Switch]$PowerOnClear,
|
||||
[Parameter(Mandatory=$false)][Switch]$HDDPasswordClear,
|
||||
[Parameter(Mandatory=$false)][ValidateNotNullOrEmpty()][String]$SupervisorPassword,
|
||||
[Parameter(Mandatory=$false)][ValidateNotNullOrEmpty()][String[]]$OldSupervisorPassword,
|
||||
[Parameter(Mandatory=$false)][ValidateNotNullOrEmpty()][String]$PowerOnPassword,
|
||||
[Parameter(Mandatory=$false)][ValidateNotNullOrEmpty()][String[]]$OldPowerOnPassword,
|
||||
[Parameter(Mandatory=$false)][ValidateNotNullOrEmpty()][String]$HDDUserPassword,
|
||||
[Parameter(Mandatory=$false)][ValidateNotNullOrEmpty()][String]$HDDMasterPassword,
|
||||
[Parameter(Mandatory=$false)][Switch]$NoUserPrompt,
|
||||
[Parameter(Mandatory=$false)][Switch]$ContinueOnError,
|
||||
[Parameter(Mandatory=$false)][Switch]$SMSTSPasswordRetry
|
||||
)
|
||||
|
||||
#Functions ====================================================================================================================
|
||||
|
||||
#Determine if a task sequence is currently running
|
||||
Function Get-TaskSequenceStatus
|
||||
{
|
||||
try
|
||||
{
|
||||
$TSEnv = New-Object -ComObject Microsoft.SMS.TSEnvironment
|
||||
}
|
||||
catch{}
|
||||
|
||||
if ($NULL -eq $TSEnv)
|
||||
{
|
||||
return $False
|
||||
}
|
||||
else
|
||||
{
|
||||
try
|
||||
{
|
||||
$SMSTSType = $TSEnv.Value("_SMSTSType")
|
||||
}
|
||||
catch{}
|
||||
|
||||
if ($NULL -eq $SMSTSType)
|
||||
{
|
||||
return $False
|
||||
}
|
||||
else
|
||||
{
|
||||
return $True
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#Create a user prompt with custom body and title text if the NoUserPrompt variable is not set
|
||||
Function Start-UserPrompt
|
||||
{
|
||||
[CmdletBinding()]
|
||||
param (
|
||||
[Parameter(Mandatory=$True)][ValidateNotNullOrEmpty()][String[]]$BodyText,
|
||||
[Parameter(Mandatory=$True)][ValidateNotNullOrEmpty()][String[]]$TitleText
|
||||
)
|
||||
|
||||
if (!($NoUserPrompt))
|
||||
{
|
||||
(New-Object -ComObject Wscript.Shell).Popup("$BodyText",0,"$TitleText",0x0 + 0x30) | Out-Null
|
||||
}
|
||||
}
|
||||
|
||||
#Write data to a CMTrace compatible log file. (Credit to SCConfigMgr - https://www.scconfigmgr.com/)
|
||||
Function Write-LogEntry
|
||||
{
|
||||
param (
|
||||
[parameter(Mandatory = $true, HelpMessage = "Value added to the log file.")]
|
||||
[ValidateNotNullOrEmpty()]
|
||||
[string]$Value,
|
||||
[parameter(Mandatory = $true, HelpMessage = "Severity for the log entry. 1 for Informational, 2 for Warning and 3 for Error.")]
|
||||
[ValidateNotNullOrEmpty()]
|
||||
[ValidateSet("1", "2", "3")]
|
||||
[string]$Severity,
|
||||
[parameter(Mandatory = $false, HelpMessage = "Name of the log file that the entry will written to.")]
|
||||
[ValidateNotNullOrEmpty()]
|
||||
[string]$FileName = "Manage-LenovoBiosPasswords.log"
|
||||
)
|
||||
# Determine log file location
|
||||
$LogFilePath = Join-Path -Path $LogsDirectory -ChildPath $FileName
|
||||
|
||||
# Construct time stamp for log entry
|
||||
if (-not(Test-Path -Path 'variable:global:TimezoneBias'))
|
||||
{
|
||||
[string]$global:TimezoneBias = [System.TimeZoneInfo]::Local.GetUtcOffset((Get-Date)).TotalMinutes
|
||||
if ($TimezoneBias -match "^-")
|
||||
{
|
||||
$TimezoneBias = $TimezoneBias.Replace('-', '+')
|
||||
}
|
||||
else
|
||||
{
|
||||
$TimezoneBias = '-' + $TimezoneBias
|
||||
}
|
||||
}
|
||||
$Time = -join @((Get-Date -Format "HH:mm:ss.fff"), $TimezoneBias)
|
||||
|
||||
# Construct date for log entry
|
||||
$Date = (Get-Date -Format "MM-dd-yyyy")
|
||||
|
||||
# Construct context for log entry
|
||||
$Context = $([System.Security.Principal.WindowsIdentity]::GetCurrent().Name)
|
||||
|
||||
# Construct final log entry
|
||||
$LogText = "<![LOG[$($Value)]LOG]!><time=""$($Time)"" date=""$($Date)"" component=""Manage-LenovoBiosPasswords"" context=""$($Context)"" type=""$($Severity)"" thread=""$($PID)"" file="""">"
|
||||
|
||||
# Add value to log file
|
||||
try
|
||||
{
|
||||
Out-File -InputObject $LogText -Append -NoClobber -Encoding Default -FilePath $LogFilePath -ErrorAction Stop
|
||||
}
|
||||
catch [System.Exception]
|
||||
{
|
||||
Write-Warning -Message "Unable to append log entry to $FileName file. Error message at line $($_.InvocationInfo.ScriptLineNumber): $($_.Exception.Message)"
|
||||
}
|
||||
}
|
||||
|
||||
#Main program =================================================================================================================
|
||||
|
||||
#Configure Logging and task sequence variables
|
||||
if (Get-TaskSequenceStatus)
|
||||
{
|
||||
$TSEnv = New-Object -COMObject Microsoft.SMS.TSEnvironment
|
||||
$TSProgress = New-Object -ComObject Microsoft.SMS.TsProgressUI
|
||||
$LogsDirectory = $TSEnv.Value("_SMSTSLogPath")
|
||||
}
|
||||
else
|
||||
{
|
||||
$LogsDirectory = "$ENV:ProgramData\BiosScripts\Lenovo"
|
||||
if (!(Test-Path -PathType Container $LogsDirectory))
|
||||
{
|
||||
New-Item -Path $LogsDirectory -ItemType "Directory" -Force | Out-Null
|
||||
}
|
||||
}
|
||||
Write-Output "Log path set to $LogsDirectory\Manage-LenovoBiosPasswords.log"
|
||||
Write-LogEntry -Value "START - Lenovo BIOS password management script" -Severity 1
|
||||
|
||||
#Connect to the Lenovo_BiosPasswordSettings WMI class
|
||||
$Error.Clear()
|
||||
try
|
||||
{
|
||||
Write-LogEntry -Value "Connect to the Lenovo_BiosPasswordSettings WMI class" -Severity 1
|
||||
$PasswordSettings = Get-WmiObject -Namespace root\wmi -Class Lenovo_BiosPasswordSettings
|
||||
}
|
||||
catch
|
||||
{
|
||||
Write-LogEntry -Value "Unable to connect to the Lenovo_BiosPasswordSettings WMI class" -Severity 3
|
||||
throw "Unable to connect to the Lenovo_BiosPasswordSettings WMI class"
|
||||
}
|
||||
if (!($Error))
|
||||
{
|
||||
Write-LogEntry -Value "Successfully connected to the Lenovo_BiosPasswordSettings WMI class" -Severity 1
|
||||
}
|
||||
|
||||
#Connect to the Lenovo_SetBiosPassword WMI class
|
||||
$Error.Clear()
|
||||
try
|
||||
{
|
||||
Write-LogEntry -Value "Connect to the Lenovo_SetBiosPassword WMI class" -Severity 1
|
||||
$PasswordSet = Get-WmiObject -Namespace root\wmi -Class Lenovo_SetBiosPassword
|
||||
}
|
||||
catch
|
||||
{
|
||||
Write-LogEntry -Value "Unable to connect to the Lenovo_SetBiosPassword WMI class" -Severity 3
|
||||
throw "Unable to connect to the Lenovo_BiosPasswordSettings WMI class"
|
||||
}
|
||||
if (!($Error))
|
||||
{
|
||||
Write-LogEntry -Value "Successfully connected to the Lenovo_SetBiosPassword WMI class" -Severity 1
|
||||
}
|
||||
|
||||
#Get the current password status
|
||||
Write-LogEntry -Value "Get the current password state and validate the specified password is not blank" -Severity 1
|
||||
$PasswordStatus = $PasswordSettings.PasswordState
|
||||
if ((($PasswordStatus -eq 0) -or ($PasswordStatus -eq 1) -or ($PasswordStatus -eq 4) -or ($PasswordStatus -eq 5)))
|
||||
{
|
||||
Write-LogEntry -Value "The supervisor password is not currently set" -Severity 1
|
||||
}
|
||||
else
|
||||
{
|
||||
Write-LogEntry -Value "The supervisor password is currently set" -Severity 1
|
||||
}
|
||||
if ((($PasswordStatus -eq 0) -or ($PasswordStatus -eq 2) -or ($PasswordStatus -eq 4) -or ($PasswordStatus -eq 6)))
|
||||
{
|
||||
Write-LogEntry -Value "The power on password is not currently set" -Severity 1
|
||||
}
|
||||
else
|
||||
{
|
||||
Write-LogEntry -Value "The power on password is currently set" -Severity 1
|
||||
}
|
||||
|
||||
#Parameter validation
|
||||
Write-LogEntry -Value "Begin parameter validation" -Severity 1
|
||||
|
||||
if (($SupervisorSet) -and !($SupervisorPassword -and $OldSupervisorPassword))
|
||||
{
|
||||
$ErrorMsg = "When using the SupervisorSet switch, the SupervisorPassword and OldSupervisorPassword parameters must also be specified"
|
||||
Write-LogEntry -Value $ErrorMsg -Severity 3
|
||||
throw $ErrorMsg
|
||||
}
|
||||
if (($SupervisorClear) -and !($OldSupervisorPassword))
|
||||
{
|
||||
$ErrorMsg = "When using the SupervisorClear switch, the OldSupervisorPassword parameter must also be specified"
|
||||
Write-LogEntry -Value $ErrorMsg -Severity 3
|
||||
throw $ErrorMsg
|
||||
}
|
||||
if (($PowerOnSet) -and !($PowerOnPassword -and $OldPowerOnPassword))
|
||||
{
|
||||
$ErrorMsg = "When using the PowerOnSet switch, the PowerOnPassword and OldPowerOnPassword parameters must also be specified"
|
||||
Write-LogEntry -Value $ErrorMsg -Severity 3
|
||||
throw $ErrorMsg
|
||||
}
|
||||
if (($PowerOnClear) -and !($OldPowerOnPassword))
|
||||
{
|
||||
$ErrorMsg = "When using the PowerOnClear switch, the OldPowerOnPassword parameter must also be specified"
|
||||
Write-LogEntry -Value $ErrorMsg -Severity 3
|
||||
throw $ErrorMsg
|
||||
}
|
||||
if (($SupervisorSet) -and ($SupervisorClear))
|
||||
{
|
||||
$ErrorMsg = "Cannot specify the SupervisorSet and SupervisorClear parameters simultaneously"
|
||||
Write-LogEntry -Value $ErrorMsg -Severity 3
|
||||
throw $ErrorMsg
|
||||
}
|
||||
if (($PowerOnSet) -and ($PowerOnClear))
|
||||
{
|
||||
$ErrorMsg = "Cannot specify the PowerOnSet and PowerOnClear parameters simultaneously"
|
||||
Write-LogEntry -Value $ErrorMsg -Severity 3
|
||||
throw $ErrorMsg
|
||||
}
|
||||
if (($HDDPasswordClear) -and !($HDDUserPassword))
|
||||
{
|
||||
$ErrorMsg = "When using the HDDPasswordClear switch, the HDDUserPassword parameter must also be specified"
|
||||
Write-LogEntry -Value $ErrorMsg -Severity 3
|
||||
throw $ErrorMsg
|
||||
}
|
||||
if (($HDDMasterPassword) -and !($HDDUserPassword))
|
||||
{
|
||||
$ErrorMsg = "When specifying a master hard drive password, a user hard drive password must also be specified"
|
||||
Write-LogEntry -Value $ErrorMsg -Severity 3
|
||||
throw $ErrorMsg
|
||||
}
|
||||
if (($HDDMasterPassword -or $HDDUserPassword) -and !($HDDPasswordClear))
|
||||
{
|
||||
$ErrorMsg = "When using the HDDMasterPassword or HDDUserPassword parameters, the HDDPasswordClear parameter must also be specified"
|
||||
Write-LogEntry -Value $ErrorMsg -Severity 3
|
||||
throw $ErrorMsg
|
||||
}
|
||||
if (($OldSupervisorPassword -or $SupervisorPassword) -and !($SupervisorSet -or $SupervisorClear))
|
||||
{
|
||||
$ErrorMsg = "When using the OldSupervisorPassword or SupervisorPassword parameters, one of the SupervisorSet or SupervisorClear parameters must also be specified"
|
||||
Write-LogEntry -Value $ErrorMsg -Severity 3
|
||||
throw $ErrorMsg
|
||||
}
|
||||
if (($OldPowerOnPassword -or $PowerOnPassword) -and !($PowerOnSet -or $PowerOnClear))
|
||||
{
|
||||
$ErrorMsg = "When using the OldPowerOnPassword or PowerOnPassword parameters, one of the PowerOnSet or PowerOnClear parameters must also be specified"
|
||||
Write-LogEntry -Value $ErrorMsg -Severity 3
|
||||
throw $ErrorMsg
|
||||
}
|
||||
if ($OldSupervisorPassword.Count -gt 2) #Prevents entering more than 2 old supervisor passwords
|
||||
{
|
||||
$ErrorMsg = "Please specify 2 or fewer old supervisor passwords"
|
||||
Write-LogEntry -Value $ErrorMsg -Severity 3
|
||||
throw $ErrorMsg
|
||||
}
|
||||
if ($OldPowerOnPassword.Count -gt 2) #Prevents entering more than 2 old power on passwords
|
||||
{
|
||||
$ErrorMsg = "Please specify 2 or fewer old power on passwords"
|
||||
Write-LogEntry -Value $ErrorMsg -Severity 3
|
||||
throw $ErrorMsg
|
||||
}
|
||||
if (($SMSTSPasswordRetry) -and !(Get-TaskSequenceStatus))
|
||||
{
|
||||
Write-LogEntry -Value "The SMSTSPasswordRetry parameter was specifed while not running in a task sequence. Setting SMSTSPasswordRetry to false." -Severity 2
|
||||
$SMSTSPasswordRetry = 0
|
||||
}
|
||||
Write-LogEntry -Value "Parameter validation completed" -Severity 1
|
||||
|
||||
#Set variables from a previous script session
|
||||
if (Get-TaskSequenceStatus)
|
||||
{
|
||||
Write-LogEntry -Value "Check for existing task sequence variables" -Severity 1
|
||||
$LenovoSetSupervisor = $TSEnv.Value("LenovoSetSupervisor")
|
||||
if ($LenovoSetSupervisor -eq "Failed")
|
||||
{
|
||||
Write-LogEntry -Value "Previous unsuccessful supervisor password set attempt detected" -Severity 1
|
||||
}
|
||||
$LenovoClearSupervisor = $TSEnv.Value("LenovoClearSupervisor")
|
||||
if ($LenovoClearSupervisor -eq "Failed")
|
||||
{
|
||||
Write-LogEntry -Value "Previous unsuccessful supervisor password clear attempt detected" -Severity 1
|
||||
}
|
||||
$LenovoSetPowerOn = $TSEnv.Value("LenovoSetPowerOn")
|
||||
if ($LenovoSetPowerOn -eq "Failed")
|
||||
{
|
||||
Write-LogEntry -Value "Previous unsuccessful power on password set attempt detected" -Severity 1
|
||||
}
|
||||
$LenovoClearPowerOn = $TSEnv.Value("LenovoClearPowerOn")
|
||||
if ($LenovoClearPowerOn -eq "Failed")
|
||||
{
|
||||
Write-LogEntry -Value "Previous unsuccessful power on password clear attempt detected" -Severity 1
|
||||
}
|
||||
}
|
||||
|
||||
#Attempting to set or clear a supervisor password when no supervisor password currently exists
|
||||
if ((($PasswordStatus -eq 0) -or ($PasswordStatus -eq 1) -or ($PasswordStatus -eq 4) -or ($PasswordStatus -eq 5)))
|
||||
{
|
||||
if ($SupervisorSet)
|
||||
{
|
||||
$SupervisorPWExists = "Failed"
|
||||
Write-LogEntry -Value "No supervisor password currently set. Unable to set the supervisor password" -Severity 3
|
||||
}
|
||||
if ($SupervisorClear)
|
||||
{
|
||||
Write-LogEntry -Value "No supervisor password currently set. No need to clear the supervisor password" -Severity 2
|
||||
Clear-Variable SupervisorClear
|
||||
}
|
||||
}
|
||||
|
||||
#Attempting to set or clear a power on password when no power on password currently exists
|
||||
if ((($PasswordStatus -eq 0) -or ($PasswordStatus -eq 2) -or ($PasswordStatus -eq 4) -or ($PasswordStatus -eq 6)))
|
||||
{
|
||||
if ($PowerOnSet)
|
||||
{
|
||||
$PowerOnPWExists = "Failed"
|
||||
Write-LogEntry -Value "No power on password currently set. Unable to set the power on password" -Severity 3
|
||||
}
|
||||
if ($PowerOnClear)
|
||||
{
|
||||
Write-LogEntry -Value "No power on password currently set. No need to clear the power on password" -Severity 2
|
||||
Clear-Variable PowerOnClear
|
||||
}
|
||||
}
|
||||
|
||||
#If a supervisor password is set, attempt to clear or change it
|
||||
if (($PasswordStatus -eq 2) -or ($PasswordStatus -eq 3) -or($PasswordStatus -eq 6) -or($PasswordStatus -eq 7))
|
||||
{
|
||||
#Change the existing supervisor password
|
||||
if (($SupervisorSet) -and ($LenovoSetSupervisor -ne "Success"))
|
||||
{
|
||||
Write-LogEntry -Value "Attempt to change the existing supervisor password" -Severity 1
|
||||
$SupervisorPWSet = "Failed"
|
||||
if (Get-TaskSequenceStatus)
|
||||
{
|
||||
$TSEnv.Value("LenovoSetSupervisor") = "Failed"
|
||||
}
|
||||
|
||||
if ($PasswordSet.SetBiosPassword("pap,$SupervisorPassword,$SupervisorPassword,ascii,us").Return -eq "Success")
|
||||
{
|
||||
#Password already correct
|
||||
$SupervisorPWSet = "Success"
|
||||
if (Get-TaskSequenceStatus)
|
||||
{
|
||||
$TSEnv.Value("LenovoSetSupervisor") = "Success"
|
||||
}
|
||||
Write-LogEntry -Value "The supervisor password is already set correctly" -Severity 1
|
||||
}
|
||||
else
|
||||
{
|
||||
$Counter = 0
|
||||
While($Counter -lt $OldSupervisorPassword.Count){
|
||||
if ($PasswordSet.SetBiosPassword("pap,$($OldSupervisorPassword[$Counter]),$SupervisorPassword,ascii,us").Return -eq "Success")
|
||||
{
|
||||
#Successfully changed the password
|
||||
$SupervisorPWSet = "Success"
|
||||
if (Get-TaskSequenceStatus)
|
||||
{
|
||||
$TSEnv.Value("LenovoSetSupervisor") = "Success"
|
||||
}
|
||||
Write-LogEntry -Value "The supervisor password has been successfully changed" -Severity 1
|
||||
break
|
||||
}
|
||||
else
|
||||
{
|
||||
#Failed to change the password
|
||||
$Counter++
|
||||
}
|
||||
}
|
||||
if ($SupervisorPWSet -eq "Failed")
|
||||
{
|
||||
Write-LogEntry -Value "Failed to change the supervisor password" -Severity 3
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#Clear the existing supervisor password
|
||||
if (($SupervisorClear) -and ($LenovoClearSupervisor -ne "Success"))
|
||||
{
|
||||
Write-LogEntry -Value "Attempt to clear the existing supervisor password" -Severity 1
|
||||
$SupervisorPWClear = "Failed"
|
||||
if (Get-TaskSequenceStatus)
|
||||
{
|
||||
$TSEnv.Value("LenovoClearSupervisor") = "Failed"
|
||||
}
|
||||
|
||||
$Counter = 0
|
||||
While($Counter -lt $OldSupervisorPassword.Count){
|
||||
if ($PasswordSet.SetBiosPassword("pap,$($OldSupervisorPassword[$Counter]),,ascii,us").Return -eq "Success")
|
||||
{
|
||||
#Successfully cleared the password
|
||||
$SupervisorPWClear = "Success"
|
||||
if (Get-TaskSequenceStatus)
|
||||
{
|
||||
$TSEnv.Value("LenovoClearSupervisor") = "Success"
|
||||
}
|
||||
Write-LogEntry -Value "The supervisor password has been successfully cleared" -Severity 1
|
||||
break
|
||||
}
|
||||
else
|
||||
{
|
||||
#Failed to clear the password
|
||||
$Counter++
|
||||
}
|
||||
}
|
||||
if ($SupervisorPWClear -eq "Failed")
|
||||
{
|
||||
Write-LogEntry -Value "Failed to clear the supervisor password" -Severity 3
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#If a power on password is set, attempt to clear or change it
|
||||
if (($PasswordStatus -eq 1) -or ($PasswordStatus -eq 3) -or($PasswordStatus -eq 5) -or($PasswordStatus -eq 7))
|
||||
{
|
||||
#Change the existing supervisor password
|
||||
if (($PowerOnSet) -and ($LenovoSetPowerOn -ne "Success"))
|
||||
{
|
||||
Write-LogEntry -Value "Attempt to change the existing power on password" -Severity 1
|
||||
$PowerOnPWSet = "Failed"
|
||||
if (Get-TaskSequenceStatus)
|
||||
{
|
||||
$TSEnv.Value("LenovoSetPowerOn") = "Failed"
|
||||
}
|
||||
|
||||
if ($PasswordSet.SetBiosPassword("pop,$PowerOnPassword,$PowerOnPassword,ascii,us").Return -eq "Success")
|
||||
{
|
||||
#Password already correct
|
||||
$PowerOnPWSet = "Success"
|
||||
if (Get-TaskSequenceStatus)
|
||||
{
|
||||
$TSEnv.Value("LenovoSetPowerOn") = "Success"
|
||||
}
|
||||
Write-LogEntry -Value "The power on password is already set correctly" -Severity 1
|
||||
}
|
||||
else
|
||||
{
|
||||
$Counter = 0
|
||||
While($Counter -lt $OldPowerOnPassword.Count){
|
||||
if ($PasswordSet.SetBiosPassword("pop,$($OldPowerOnPassword[$Counter]),$PowerOnPassword,ascii,us").Return -eq "Success")
|
||||
{
|
||||
#Successfully changed the password
|
||||
$PowerOnPWSet = "Success"
|
||||
if (Get-TaskSequenceStatus)
|
||||
{
|
||||
$TSEnv.Value("LenovoSetPowerOn") = "Success"
|
||||
}
|
||||
Write-LogEntry -Value "The power on password has been successfully changed" -Severity 1
|
||||
break
|
||||
}
|
||||
else
|
||||
{
|
||||
#Failed to change the password
|
||||
$Counter++
|
||||
}
|
||||
}
|
||||
if ($PowerOnPWSet -eq "Failed")
|
||||
{
|
||||
Write-LogEntry -Value "Failed to change the power on password" -Severity 3
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#Clear the existing power on password
|
||||
if (($PowerOnClear) -and ($LenovoClearPowerOn -ne "Success"))
|
||||
{
|
||||
Write-LogEntry -Value "Attempt to clear the existing power on password" -Severity 1
|
||||
$PowerOnPWClear = "Failed"
|
||||
if (Get-TaskSequenceStatus)
|
||||
{
|
||||
$TSEnv.Value("LenovoClearPowerOn") = "Failed"
|
||||
}
|
||||
|
||||
$Counter = 0
|
||||
While($Counter -lt $OldPowerOnPassword.Count){
|
||||
if ($PasswordSet.SetBiosPassword("pop,$($OldPowerOnPassword[$Counter]),,ascii,us").Return -eq "Success")
|
||||
{
|
||||
#Successfully cleared the password
|
||||
$PowerOnPWClear = "Success"
|
||||
if (Get-TaskSequenceStatus)
|
||||
{
|
||||
$TSEnv.Value("LenovoClearPowerOn") = "Success"
|
||||
}
|
||||
Write-LogEntry -Value "The power on password has been successfully cleared" -Severity 1
|
||||
break
|
||||
}
|
||||
else
|
||||
{
|
||||
#Failed to clear the password
|
||||
$Counter++
|
||||
}
|
||||
}
|
||||
if ($PowerOnPWClear -eq "Failed")
|
||||
{
|
||||
Write-LogEntry -Value "Failed to clear the power on password" -Severity 3
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#Attempt to clear the hard drive password(s)
|
||||
if ($HDDPasswordClear)
|
||||
{
|
||||
if (($HDDUserPassword) -and ($HDDMasterPassword))
|
||||
{
|
||||
Write-LogEntry -Value "Attempt to clear the existing user and master hard drive passwords" -Severity 1
|
||||
$PasswordSet.SetBiosPassword("mhdp1,$HDDMasterPassword,,ascii,us")
|
||||
$PasswordSet.SetBiosPassword("uhdp1,$HDDUserPassword,,ascii,us")
|
||||
}
|
||||
elseif (($HDDUserPassword) -and !($HDDMasterPassword))
|
||||
{
|
||||
Write-LogEntry -Value "Attempt to clear the existing user hard drive password" -Severity 1
|
||||
$PasswordSet.SetBiosPassword("uhdp1,$HDDUserPassword,,ascii,us")
|
||||
}
|
||||
}
|
||||
|
||||
#Prompt the user about any password set failures
|
||||
if (($SupervisorPWExists -eq "Failed") -or ($PowerOnPWExists -eq "Failed"))
|
||||
{
|
||||
if (!($NoUserPrompt))
|
||||
{
|
||||
Write-LogEntry -Value "Failures detected, display on-screen prompts for any required manual actions" -Severity 2
|
||||
#Close the task sequence progress dialog
|
||||
if (Get-TaskSequenceStatus)
|
||||
{
|
||||
$TSProgress.CloseProgressDialog()
|
||||
}
|
||||
#Display prompts
|
||||
if ($SupervisorPWExists -eq "Failed")
|
||||
{
|
||||
Start-UserPrompt -BodyText "No supervisor password is set. Please reboot the computer and manually set a supervisor password" -TitleText "Lenovo Password Management Script"
|
||||
}
|
||||
if ($PowerOnPWExists -eq "Failed")
|
||||
{
|
||||
Start-UserPrompt -BodyText "No power on password is set. Please reboot the computer and manually set a power on password." -TitleText "Lenovo Password Management Script"
|
||||
}
|
||||
}
|
||||
#Exit the script with an error
|
||||
if (!($ContinueOnError))
|
||||
{
|
||||
Write-LogEntry -Value "Failures detected, exiting the script" -Severity 3
|
||||
Write-Output "Password management tasks failed. Check the log file for more information"
|
||||
Write-LogEntry -Value "END - Lenovo BIOS password management script" -Severity 1
|
||||
Exit 1
|
||||
}
|
||||
else
|
||||
{
|
||||
Write-LogEntry -Value "Failures detected, but the ContinueOnError parameter was set. Script execution will continue" -Severity 3
|
||||
Write-Output "Failures detected, but the ContinueOnError parameter was set. Script execution will continue"
|
||||
}
|
||||
}
|
||||
|
||||
#Prompt the user about any password change or clear failures
|
||||
if ((($SupervisorPWSet -eq "Failed") -or ($SupervisorPWClear -eq "Failed") -or ($PowerOnPWSet -eq "Failed") -or ($PowerOnPWClear -eq "Failed")) -and (!($SMSTSPasswordRetry)))
|
||||
{
|
||||
if (!($NoUserPrompt))
|
||||
{
|
||||
Write-LogEntry -Value "Failures detected, display on-screen prompts for any required manual actions" -Severity 2
|
||||
#Close the task sequence progress dialog
|
||||
if (Get-TaskSequenceStatus)
|
||||
{
|
||||
$TSProgress.CloseProgressDialog()
|
||||
}
|
||||
if ($SupervisorPWSet -eq "Failed")
|
||||
{
|
||||
Start-UserPrompt -BodyText "The supervisor password is set, but cannot be automatically changed. Please reboot the computer and manually change the supervisor password." -TitleText "Lenovo Password Management Script"
|
||||
}
|
||||
if ($SupervisorPWClear -eq "Failed")
|
||||
{
|
||||
Start-UserPrompt -BodyText "The supervisor password is set, but cannot be automatically cleared. Please reboot the computer and manually clear the supervisor password." -TitleText "Lenovo Password Management Script"
|
||||
}
|
||||
if ($PowerOnPWSet -eq "Failed")
|
||||
{
|
||||
Start-UserPrompt -BodyText "The power on password is set, but cannot be automatically changed. Please reboot the computer and manually change the power on password." -TitleText "Lenovo Password Management Script"
|
||||
}
|
||||
if ($PowerOnPWClear -eq "Failed")
|
||||
{
|
||||
Start-UserPrompt -BodyText "The power on password is set, but cannot be automatically cleared. Please reboot the computer and manually clear the power on password." -TitleText "Lenovo Password Management Script"
|
||||
}
|
||||
}
|
||||
#Exit the script with an error
|
||||
if (!($ContinueOnError))
|
||||
{
|
||||
Write-LogEntry -Value "Failures detected, exiting the script" -Severity 3
|
||||
Write-Output "Password management tasks failed. Check the log file for more information"
|
||||
Write-LogEntry -Value "END - Lenovo BIOS password management script" -Severity 1
|
||||
Exit 1
|
||||
}
|
||||
else
|
||||
{
|
||||
Write-LogEntry -Value "Failures detected, but the ContinueOnError parameter was set. Script execution will continue" -Severity 3
|
||||
Write-Output "Failures detected, but the ContinueOnError parameter was set. Script execution will continue"
|
||||
}
|
||||
}
|
||||
elseif ((($SupervisorPWExists -eq "Failed") -or ($SupervisorPWSet -eq "Failed") -or ($SupervisorPWClear -eq "Failed") -or ($PowerOnPWExists -eq "Failed") -or ($PowerOnPWSet -eq "Failed") -or ($PowerOnPWClear -eq "Failed")) -and ($SMSTSPasswordRetry))
|
||||
{
|
||||
Write-LogEntry -Value "Failures detected, but the SMSTSPasswordRetry parameter was set. No user prompts will be displayed" -Severity 3
|
||||
Write-Output "Failures detected, but the SMSTSPasswordRetry parameter was set. No user prompts will be displayed"
|
||||
}
|
||||
else
|
||||
{
|
||||
Write-Output "Password management tasks succeeded. Check the log file for more information"
|
||||
}
|
||||
Write-LogEntry -Value "END - Lenovo BIOS password management script" -Severity 1
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,87 @@
|
||||
Serial Port1 Address,3F8/IRQ4
|
||||
USB Support,Enabled
|
||||
USB Legacy Support,Enabled
|
||||
USB Debug Support,Disabled
|
||||
USB Enumeration Delay,Disabled
|
||||
USB Virtual KBC Support,Disabled
|
||||
Front USB Ports,Enabled
|
||||
USB Port 1,Enabled
|
||||
USB Port 2,Enabled
|
||||
USB Port 3,Enabled
|
||||
USB Port 4,Enabled
|
||||
Rear USB Ports,Enabled
|
||||
USB Port 5,Enabled
|
||||
USB Port 6,Enabled
|
||||
USB Port 7,Enabled
|
||||
USB Port 8,Enabled
|
||||
SATA Controller,Enabled
|
||||
SATA Drive 1,Enabled
|
||||
SATA Drive 2,Enabled
|
||||
SATA Drive 3,Enabled
|
||||
Configure SATA as,AHCI
|
||||
Hard Disk Pre-delay,Disabled
|
||||
Select Active Video,Auto
|
||||
Pre-Allocated Memory Size,32MB
|
||||
Total Graphics Memory,Maximum
|
||||
Onboard Audio Controller,Enabled
|
||||
Internal Speaker,Enabled
|
||||
Onboard Ethernet Controller,Enabled
|
||||
Boot Agent,PXE
|
||||
PXE IPV4 network stack,Enabled
|
||||
PXE IPV6 network stack,Disabled
|
||||
PCIe 16x Slot Speed,Auto
|
||||
PCIe 1x Slot 1 Speed,Auto
|
||||
PCIe 1x Slot 2 Speed,Auto
|
||||
EIST Support,Enabled
|
||||
Intel(R) Hyper-Threading Technology,Enabled
|
||||
Core Multi-Processing,Enabled
|
||||
Intel(R) Virtualization Technology,Enabled
|
||||
VT-d,Enabled
|
||||
C1E Support,Enabled
|
||||
C State Support,C1C3C6C7C8
|
||||
Turbo Mode,Enabled
|
||||
Intel(R) SGX Control,Software Controlled
|
||||
Current State,Disabled
|
||||
Dust Shield Alert,Disabled
|
||||
After Power Loss,Last State
|
||||
Enhanced Power Saving Mode,Disabled
|
||||
Wake on LAN,Automatic
|
||||
Wake from PCI Device,Primary
|
||||
Wake from Serial Port Ring,Primary
|
||||
Wake Up on Alarm,Disabled
|
||||
Startup Sequence,Primary
|
||||
Alarm Time(HH:MM:SS),00:00:00][Status:ShowOnly
|
||||
Alarm Date(MM/DD/YYYY),01/01/2016][Status:ShowOnly
|
||||
Alarm Day of Week,Sunday
|
||||
Sunday,Disabled
|
||||
Monday,Disabled
|
||||
Tuesday,Disabled
|
||||
Wednesday,Disabled
|
||||
Thursday,Disabled
|
||||
Friday,Disabled
|
||||
Saturday,Disabled
|
||||
User Defined Alarm Time,00:00:00][Status:ShowOnly
|
||||
Allow Flashing BIOS to a Previous Version,Yes
|
||||
Require Admin. Pass. when Flashing,No
|
||||
Windows UEFI Firmware Update,Enabled
|
||||
Require POP on System Boot,Yes
|
||||
Require POP on Restart,No
|
||||
Require Admin. Pass. For F12 Boot,No
|
||||
Smart USB Protection,Disabled
|
||||
Require HDP on System Boot,Auto
|
||||
TCG Security Device,Discrete TPM
|
||||
Security Chip 2.0,Enabled
|
||||
Secure Boot,Disabled
|
||||
Network Offline Locker Setup,Disabled
|
||||
Credential Guard,Disabled
|
||||
Chassis Intrusion Detection,Disabled
|
||||
Configuration Change Detection,Disabled
|
||||
Password Count Exceeded Error,Enabled
|
||||
CSM,Enabled
|
||||
Boot Mode,Legacy Only
|
||||
Boot Up Num-Lock Status,On
|
||||
Startup Device Menu Prompt,Enabled
|
||||
OS Optimized Defaults,Enabled
|
||||
Primary Boot Sequence,USB FDD:USB KEY:M.2 Drive:SATA 1:SATA 2:SATA 3:Network 1:USB HDD:USB CDROM:Other Device;[Excluded from boot order:Network 2:Network 3:Network 4]
|
||||
Error Boot Sequence,Network 1:M.2 Drive:SATA 1:SATA 2:SATA 3:Other Device;[Excluded from boot order:Network 2:Network 3:Network 4:USB FDD:USB HDD:USB CDROM:USB KEY]
|
||||
Automatic Boot Sequence,SATA 1:M.2 Drive:Network 1:SATA 2:SATA 3:Other Device;[Excluded from boot order:Network 2:Network 3:Network 4:USB FDD:USB HDD:USB CDROM:USB KEY]
|
||||
@@ -0,0 +1,3 @@
|
||||
Wake on LAN,Automatic
|
||||
Primary Boot Sequence,SATA 1:SATA 2:SATA 3:Network 1
|
||||
Automatic Boot Sequence,Network1:SATA 1:M.2 Drive:SATA 3:Other device
|
||||
@@ -0,0 +1,4 @@
|
||||
qQd8bbzDvJ2n7mc1dSZC2utCpdw=
|
||||
Wake on LAN,Automatic
|
||||
Primary Boot Sequence,SATA 1:SATA 2:SATA 3:Network 1
|
||||
Automatic Boot Sequence,Network1:SATA 1:M.2 Drive:SATA 3:Other device
|
||||
@@ -0,0 +1 @@
|
||||
Primary Boot Sequence,SATA 1:SATA 2:SATA 3:Network 1
|
||||
@@ -0,0 +1,6 @@
|
||||
Boot Agent,PXE
|
||||
PXE IPV4 network stack,Enabled
|
||||
PXE IPV6 network stack,Disabled
|
||||
Secure Boot,Enabled
|
||||
Secure boot,Enabled
|
||||
Primary Boot Sequence,Network 1:SATA 1:SATA 2:SATA 3
|
||||
@@ -0,0 +1,3 @@
|
||||
BootOrder,NVMe0:NVMe1:HDD0:HDD1:HDD2:HDD3:PCILAN
|
||||
IPv4NetworkStack,Enable
|
||||
IPv6NetworkStack,Disable
|
||||
@@ -0,0 +1,4 @@
|
||||
Wake on LAN,Automatic
|
||||
BootOrder,NVMe0:NVMe1:HDD0:HDD1:HDD2:HDD3:PCILAN
|
||||
IPv4NetworkStack,Enable
|
||||
IPv6NetworkStack,Disable
|
||||
@@ -0,0 +1 @@
|
||||
BootOrder,NVMe0:NVMe1:HDD0:HDD1:HDD2:HDD3:PCILAN
|
||||
@@ -0,0 +1,5 @@
|
||||
IPv4NetworkStack,Enable
|
||||
IPv6NetworkStack,Disable
|
||||
UefiPxeBootPriority,IPv4First
|
||||
SecureBoot,Enable
|
||||
BootOrder,PCILAN:NVMe0:NVMe1:HDD0:HDD1:HDD2:HDD3
|
||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
@@ -0,0 +1,37 @@
|
||||
|
||||
BIOS Changes History
|
||||
|
||||
|
||||
General Information:
|
||||
|
||||
M46J9xxUSA is Flash CD ROM image.
|
||||
M46JTxxUSA is Flash in DOS zip package.
|
||||
M46JYxxUSA is Flash in Windows utility.
|
||||
M46KTxxA is the binary image. (BIOS)
|
||||
NOTE: All changes carry forward. That is, if a change is added in 01,it is also in 02, 03 etc.
|
||||
|
||||
This file will be updated from the beginning with first Production BIOS release
|
||||
|
||||
CHANGES for M46KT15A/M46JT15A
|
||||
1.Initial BIOS release
|
||||
|
||||
CHANGES for M46KT1AA/M46JT1AA
|
||||
1.Optimize BIOS item function and Software WMI function.
|
||||
|
||||
CHANGES for M46KT1BA/M46JT1BA
|
||||
1.Fix Error 0164:Memory Size Decreased" will not occur if Memory slots are changed or Memory of the same brand Size is replaced
|
||||
|
||||
CHANGES for M46KT1DA/M46JT1DA
|
||||
1.ThinkCentre support Infineon TPM chip
|
||||
2.Modify Setup items
|
||||
|
||||
CHANGES for M46KT1EA/M46JT1EA
|
||||
1.Optimize WIFI card compatibility function.
|
||||
|
||||
CHANGES for M46KT1FA/M46JT1FA
|
||||
1.Optimize WMI/BIOS item/audio function.
|
||||
2.Update Secure wipe and Lenovo Diagnostic firmware.
|
||||
|
||||
CHANGES for M46KT20A/M46JT20A
|
||||
1.Optimize BIOS item function and string.
|
||||
2.Optimize system sleep function.
|
||||
@@ -0,0 +1,472 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<title>readme</title>
|
||||
</head>
|
||||
<body class='bodyStyle'>
|
||||
<pre>
|
||||
--CONTENTS--<br>
|
||||
1 - SRWIN Usage
|
||||
2 - CFGWIN Usage
|
||||
3 - Compiler Information
|
||||
|
||||
*************************************************************************************
|
||||
* 1. SRWIN Usage *
|
||||
* *
|
||||
* SRWIN/SRWINx64 is a tool to manage the system BIOS settings. With this *
|
||||
* tool it is possible to save/restore BIOS settings. SRWIN is for the *
|
||||
* Windows operating system. *
|
||||
* *
|
||||
* NOTE 1: SRWIN.exe/SRWINx64.exe, BIOS level, and Configuration Settings *
|
||||
* all need to be from the same BIOS level. The BIOS level on the donor *
|
||||
* system must be the same level as the systems that will be receiving *
|
||||
* the Configuration Settings. *
|
||||
* *
|
||||
* NOTE 2: The following commands require an Administrator Password to be set *
|
||||
* prior to usage. Without an Administrator Password set, this program will *
|
||||
* generate an error message when attempting to change the setting: *
|
||||
* dtpm *
|
||||
* dtpm2 *
|
||||
* ftpm *
|
||||
* cfgsata *
|
||||
* cfgssata *
|
||||
* *
|
||||
* *
|
||||
* The following commands are provided for the operation. Note, for SRWIN *
|
||||
* you need to run it from Command Prompt box with Administrator privileges *
|
||||
* under Windows. Some commands may not be applicable on some systems. *
|
||||
* *
|
||||
* Usage: srwin [arg1] [option1] [arg2] [option2]... *
|
||||
* *
|
||||
* where [Arguments]: *
|
||||
* /b [filename] Backup all BIOS settings to the file *
|
||||
* /r [filename] Restore BIOS settings from input file *
|
||||
* /pass [password] Input current system BIOS password *
|
||||
* /newadp [password] Set new Administrator password *
|
||||
* /newpop [password] Set new Power-on password *
|
||||
* /clradp Clear current system Administrator password *
|
||||
* /clrpop Clear current system Power-on password *
|
||||
* /nor Don't reboot after restore *
|
||||
* /ign Ignore BIOS level check *
|
||||
* /f9 Load BIOS Setup default *
|
||||
* /kbdless [option] Change item "Keboardless Operation" *
|
||||
* [option] *
|
||||
* enable -- Set the item to "Enabled" *
|
||||
* disable -- Set the item to "Disabled" *
|
||||
* /fdd [option] Change item "Floppy A" *
|
||||
* [option] *
|
||||
* enable -- Set the item to "Enabled" *
|
||||
* disable -- Set the item to "Disabled" *
|
||||
* /pbs [option] Change first device of primary boot sequence *
|
||||
* /ebs [option] Change first device of error boot sequence *
|
||||
* /abs [option] Change first device of automatic boot sequence *
|
||||
* [option] *
|
||||
* fdd -- Floppy disk drive *
|
||||
* sata1 -- SATA drive 1 *
|
||||
* sata2 -- SATA drive 2 *
|
||||
* sata3 -- SATA drive 3 *
|
||||
* sata4 -- SATA drive 4 *
|
||||
* sata5 -- SATA drive 5 *
|
||||
* sata6 -- SATA drive 6 *
|
||||
* sata7 -- SATA drive 7 *
|
||||
* sata8 -- SATA drive 8 *
|
||||
* sata9 -- SATA drive 9 *
|
||||
* sata10 -- SATA drive 10 *
|
||||
* ufdd_group -- USB FDD group *
|
||||
* ufdd1 -- USB FDD 1 *
|
||||
* ufdd2 -- USB FDD 2 *
|
||||
* ukey_group -- USB key group *
|
||||
* ukey1 -- USB key 1 *
|
||||
* ukey2 -- USB key 2 *
|
||||
* uhdd_group -- USB HDD group *
|
||||
* uhdd1 -- USB HDD 1 *
|
||||
* uhdd2 -- USB HDD 2 *
|
||||
* uodd_group -- USB ODD group *
|
||||
* uodd1 -- USB ODD 1 *
|
||||
* uodd2 -- USB ODD 2 *
|
||||
* lan1 -- LAN 1 *
|
||||
* lan2 -- LAN 2 *
|
||||
* scu_hdd1 -- SCU Hard disk drive 1 *
|
||||
* scu_hdd2 -- SCU Hard disk drive 2 *
|
||||
* scu_hdd3 -- SCU Hard disk drive 3 *
|
||||
* scu_hdd4 -- SCU Hard disk drive 4 *
|
||||
* Mezz_SATA -- Mezz-SATA *
|
||||
* eSATA -- eSATA *
|
||||
* device1 -- Device 1 *
|
||||
* device2 -- Device 2 *
|
||||
* device3 -- Device 3 *
|
||||
* device4 -- Device 4 *
|
||||
* device5 -- Device 5 *
|
||||
* device6 -- Device 6 *
|
||||
* Mezz1_PCIe_P1 -- Mezz1-PCIe-P1 *
|
||||
* Mezz1_PCIe_P2 -- Mezz1-PCIe-P2 *
|
||||
* Mezz2_PCIe_P1 -- Mezz2-PCIe-P1 *
|
||||
* Mezz2_PCIe_P2 -- Mezz2-PCIe-P2 *
|
||||
* PCIE_SLOT_1 -- PCIe slot 1 *
|
||||
* PCIE_SLOT_2 -- PCIe slot 2 *
|
||||
* PCIE_SLOT_3 -- PCIe slot 3 *
|
||||
* PCIE_SLOT_x -- PCIe slot # *
|
||||
* PCIE_SLOT_9 -- PCIe slot 9 *
|
||||
* M2_DRIVER_1 -- M.2 Driver 1 *
|
||||
* M2_DRIVER_2 -- M.2 Driver 2 *
|
||||
* M2_DRIVER_3 -- M.2 Driver 3 *
|
||||
* M2_DRIVER_4 -- M.2 Driver # *
|
||||
* VMD1 -- VMD/VROC Device 1 *
|
||||
* VMD2 -- VMD/VROC Device 2 *
|
||||
* VMD3 -- VMD/VROC Device 3 *
|
||||
* /dtpm [option] Change discrete TPM 1.2 status *
|
||||
* (requires Administrator Password - see NOTE 2 above) *
|
||||
* [option] *
|
||||
* disable -- Disable discrete TPM 1.2 *
|
||||
* inactive -- Set discrete TPM 1.2 inactive *
|
||||
* active -- Set discrete TPM 1.2 active *
|
||||
* /ftpm [option] Change firmware TPM status *
|
||||
* (requires Administrator Password - see NOTE 2 above) *
|
||||
* [option] *
|
||||
* disable -- Disable firmware TPM *
|
||||
* enable -- Set firmware TPM enable *
|
||||
* /dtpm2 [option] Change discrete TPM 2.0 status *
|
||||
* (requires Administrator Password - see NOTE 2 above) *
|
||||
* [option] *
|
||||
* disable -- Disable discrete TPM 2.0 *
|
||||
* enable -- Set discrete TPM 2.0 enable *
|
||||
* /vga [option] Change vga pre-allocated memory size *
|
||||
* [option] *
|
||||
* 32mb -- Set the size to 32mb *
|
||||
* 64mb -- Set the size to 64mb *
|
||||
* 128mb -- Set the size to 128mb *
|
||||
* 256mb -- Set the size to 256mb *
|
||||
* 512mb -- Set the size to 512mb *
|
||||
* 1024mb -- Set the size to 1024mb *
|
||||
* /cfgsata [option] Change SATA setting *
|
||||
* (requires Administrator Password - see NOTE 2 above) *
|
||||
* [option] *
|
||||
* ide -- Config SATA as IDE *
|
||||
* ahci -- Config SATA as AHCI *
|
||||
* raid -- Config SATA as RAID *
|
||||
* optane -- Config SATA as Intel(R) RST with Intel(R) Opta*
|
||||
* /above4GB [option] Change Above 4GB Decoding *
|
||||
* [option] *
|
||||
* enable -- Set the item to "Enabled" *
|
||||
* disable -- Set the item to "Disabled" *
|
||||
* /cfgssata [option] Change sSATA setting *
|
||||
* (requires Administrator Password - see NOTE 2 above) *
|
||||
* [option] *
|
||||
* ide -- Config sSATA as IDE *
|
||||
* ahci -- Config sSATA as AHCI *
|
||||
* raid -- Config sSATA as RAID *
|
||||
* /EHCIHandOff [option] Change EHCIHandOff setting *
|
||||
* [option] *
|
||||
* enable -- Set the item to "Enabled" *
|
||||
* disable -- Set the item to "Disabled" *
|
||||
* /PowerLoss [option] Change AfterPowerLoss setting *
|
||||
* [option] *
|
||||
* on -- set the item to "Power On" *
|
||||
* off -- set the item to "Power Off" *
|
||||
* last -- set the item to "Last State" *
|
||||
* /CardReader [option] Change CardReader setting *
|
||||
* [option] *
|
||||
* enable -- Set the item to "Enabled" *
|
||||
* disable -- Set the item to "Disabled" *
|
||||
* /strom [option] Change Storage Oprom Launch mode *
|
||||
* [option] *
|
||||
* disable -- Do not launch *
|
||||
* uefi -- UEFI Only *
|
||||
* legacy -- Legacy Only *
|
||||
* /satahotplug [option] Change SATA Port Hotplug *
|
||||
* [option] *
|
||||
* disable -- Disable All SATA Port Hotplug *
|
||||
* enable -- Enable All SATA Port 1 Hotplug *
|
||||
* 00~3ff -- ECX of HDD-hotplug *
|
||||
* -- Bit[0] for SATA Port 1 = 0 -Disable 1-Enable *
|
||||
* -- Bit[1] for SATA Port 2 = 0 -Disable 1-Enable *
|
||||
* -- Bit[2] for SATA Port 3 = 0 -Disable 1-Enable *
|
||||
* -- Bit[3] for SATA Port 4 = 0 -Disable 1-Enable *
|
||||
* -- Bit[4] for SATA Port 5 = 0 -Disable 1-Enable *
|
||||
* -- Bit[5] for SATA Port 6 = 0 -Disable 1-Enable *
|
||||
* -- Bit[6] for SATA Port 7 = 0 -Disable 1-Enable *
|
||||
* -- Bit[7] for SATA Port 8 = 0 -Disable 1-Enable *
|
||||
* -- Bit[8] for SATA Port 9 = 0 -Disable 1-Enable *
|
||||
* -- Bit[9] for SATA Port 10 = 0 -Disable 1-Enable *
|
||||
* /sata1hotplug Enable SATA Port 1 Hotplug Only *
|
||||
* /sata2hotplug Enable SATA Port 2 Hotplug Only *
|
||||
* /sata3hotplug Enable SATA Port 3 Hotplug Only *
|
||||
* /sata4hotplug Enable SATA Port 4 Hotplug Only *
|
||||
* /sata5hotplug Enable SATA Port 5 Hotplug Only *
|
||||
* /sata6hotplug Enable SATA Port 6 Hotplug Only *
|
||||
* /sata7hotplug Enable SATA Port 7 Hotplug Only *
|
||||
* /sata8hotplug Enable SATA Port 8 Hotplug Only *
|
||||
* /sata9hotplug Enable SATA Port 9 Hotplug Only *
|
||||
* /sata10hotplug Enable SATA Port 10 Hotplug Only *
|
||||
* /winguard [option] Change Device Guard and Credential Guard setting *
|
||||
* [option] *
|
||||
* disable -- Disable Device Guard and Credential Guard *
|
||||
* enable -- Enable Device Guard and Credential Guard *
|
||||
* /pxe [option] Change Boot Agent setting *
|
||||
* [option] *
|
||||
* disable -- Disable Boot Agent *
|
||||
* enable -- Enable PXE boot *
|
||||
* smc -- Enable SMC boot *
|
||||
* /tbt [option] Change ThunderBolt card location *
|
||||
* [option] *
|
||||
* slot1 -- ThunderBolt plug into slot 1 *
|
||||
* slot2 -- ThunderBolt plug into slot 2 *
|
||||
* slotx -- ThunderBolt plug into slot # *
|
||||
* slot9 -- ThunderBolt plug into slot 9 *
|
||||
* /xhci [option] Change USB xHCI controller mode setting *
|
||||
* [option] *
|
||||
* sauto -- set controller to Smart auto *
|
||||
* auto -- set controller to auto *
|
||||
* enable -- set controller to enable *
|
||||
* disable -- set controller to disable *
|
||||
* manual -- set controller to manual *
|
||||
* /mmioh [option] Change MMIOHBase setting *
|
||||
* [option] *
|
||||
* 1t -- set the MMIOH base to 1T *
|
||||
* 4t -- set the MMIOH base to 4T *
|
||||
* 16t -- set the MMIOH base to 16T *
|
||||
* 24t -- set the MMIOH base to 24T *
|
||||
* 40t -- set the MMIOH base to 40T *
|
||||
* 56t -- set the MMIOH base to 56T *
|
||||
* /msb [option] Change Windows Modern Standby setting *
|
||||
* [option] *
|
||||
* disable -- Disabled *
|
||||
* enable -- Enabled *
|
||||
* /pass_scan [ScanCode] Input current system BIOS password *
|
||||
* in Scan Code with US keyboard *
|
||||
* /newadp_scan [ScanCode] Set new Administrator password *
|
||||
* in Scan Code with US keyboard *
|
||||
* /newpop_scan [ScanCode] Set new Power-on password *
|
||||
* in Scan Code with US keyboard *
|
||||
* /pass_scan_fr [ScanCode] Input current system BIOS password *
|
||||
* in Scan Code with French keyboard *
|
||||
* /newadp_scan_fr [ScanCode] Set new Administrator password *
|
||||
* in Scan Code with French keyboard *
|
||||
* /newpop_scan_fr [ScanCode] Set new Power-on password *
|
||||
* in Scan Code with French keyboard *
|
||||
* /pass_scan_ge [ScanCode] Input current system BIOS password *
|
||||
* in Scan Code with German keyboard *
|
||||
* /newadp_scan_ge [ScanCode] Set new Administrator password *
|
||||
* in Scan Code with German keyboard *
|
||||
* /newpop_scan_ge [ScanCode] Set new Power-on password *
|
||||
* in Scan Code with German keyboard *
|
||||
* example 1: *
|
||||
* srwin.exe /r settings.dat /pass 123456 /ign *
|
||||
* example 2: *
|
||||
* srwin.exe /pbs sata1 /pass_scan 191e19 *
|
||||
* example 3: *
|
||||
* srwin.exe /newadp 123456 /newpop 123 *
|
||||
* *
|
||||
*************************************************************************************
|
||||
<br> *************************************************************************************
|
||||
* 2. CFGWIN Usage *
|
||||
* *
|
||||
* CFGWIN.exe is a BIOS settings edit tool in Windows supplied by Lenovo. *
|
||||
* With this tool it is possible to modify selected BIOS settings. This *
|
||||
* tool is for Windows operating systems. *
|
||||
* *
|
||||
* The following commands are provided for the operation. Note, for CFGWIN *
|
||||
* you need to run it from Command Prompt box with Administrator privileges *
|
||||
* under Windows. Some commands may not be applicable on some systems. *
|
||||
* *
|
||||
* *
|
||||
* ****** Usage1: capture BIOS settings ****** *
|
||||
* *
|
||||
* CFGWIN /c /path:c:\settings.txt *
|
||||
* /c capture mode *
|
||||
* /path:XX XX -file that will save BIOS settings, if no file *
|
||||
* is specified, all settings will be displayed *
|
||||
* directly to screen. *
|
||||
* *
|
||||
* *** Usage2: Restore BIOS settings when there is no Admin password set *
|
||||
* *
|
||||
* *
|
||||
* CFGWIN /r /path:c:\settings.txt *
|
||||
* /r - restore mode *
|
||||
* /path:XX XX - file that contains settings to be restored *
|
||||
* *
|
||||
* Note:The setting file captured by CFGWIN with "/c" list the supported *
|
||||
* BIOS item that can be restored *
|
||||
* *
|
||||
* *
|
||||
* *
|
||||
* *** Usage3: Restore BIOS settings when there is an Admin password set *
|
||||
* *
|
||||
* *
|
||||
* CFGWIN /r /path:c:\settings.txt /admin:123 *
|
||||
* /r - restore mode *
|
||||
* /path:XX XX -file that contains settings to be restored *
|
||||
* /admin:XX XX -administrator password of target if there is an *
|
||||
* Admin password set on the system, if only a POP *
|
||||
* set, input current POP here *
|
||||
* Note: 1.Please refer to Apendix 1 for password supported *
|
||||
* characters *
|
||||
* *
|
||||
* 2. Recommend using "" to include the password for better *
|
||||
* interpretation *
|
||||
* For example, password is 12 3&, can be written as *
|
||||
* /admin:"12 3&" *
|
||||
* 3. If the password contains " or \ or ', please write as \" *
|
||||
* or \\ or \', which will be interpreted as " or \ or ' *
|
||||
* *
|
||||
* For example, the password is 12"3, please write this as *
|
||||
* /admin:"12\"3" *
|
||||
* *
|
||||
* *
|
||||
* ****** Usage4: Change specific item value ****** *
|
||||
* *
|
||||
* CFGWIN interprets line entries by parsing an item and the new value *
|
||||
* from the settings file. By restoring such a settings file *
|
||||
* with "/r", the specific item can be changed to the expected value. *
|
||||
* *
|
||||
* The format of the settings file is the same as the one generated by *
|
||||
* the CFGWIN capture mode with "/c". There is only one item in each line *
|
||||
* of text file, item name and expected value are separated by comma "," *
|
||||
* as below: *
|
||||
* *
|
||||
* Item name,Expected value; *
|
||||
* *
|
||||
* Example1: Disable USB1 *
|
||||
* Writing a line in setting file as below: *
|
||||
* USB Port 1,Disabled; *
|
||||
* *
|
||||
* Example2: Change primary boot sequence *
|
||||
* Writing a line in setting file as below: *
|
||||
* Primary Boot Sequence,Network Card:Hard Drive:USB Key:CD/DVD Drive: *
|
||||
* USB Hard Disk:USB Floppy:USB CD/DVD:Floppy Drive; *
|
||||
* *
|
||||
* Note: *
|
||||
* All supported items and their selectable value will be listed *
|
||||
* in Lenovo WMI-Desktop Deployment Guide for the machine model you *
|
||||
* are using,please reference it when change item setting. *
|
||||
* *
|
||||
* For security reasons, some settings need the authorization of an *
|
||||
* Administrator Password, please ensure the Administrator Password *
|
||||
* is set before changing these settings: *
|
||||
* OS Optimized Defaults *
|
||||
* CSM *
|
||||
* Secure Boot *
|
||||
* Device Guard *
|
||||
* Discrete TPM FW Switch *
|
||||
* Configure SATA as *
|
||||
* *
|
||||
* When you restore BIOS settings using a file, please make sure that *
|
||||
* all related items are in the correct states, because once an *
|
||||
* item's dependent item is Disabled or in a special setting, this *
|
||||
* item will be hidden and can not be updated through CFGWIN, please *
|
||||
* reference Lenovo WMI-Desktop Deployment Guide for the machine *
|
||||
* model you are using for detail relationship between items. *
|
||||
* *
|
||||
* For example, the two lines below can not be executed in a file *
|
||||
* simultaneously when you are restoring with CFGWIN. This is because *
|
||||
* after the system executes the first line, the USB function has *
|
||||
* been disabled and the second line operation to USB port will not *
|
||||
* be accepted. *
|
||||
* USB Support, Disabled; *
|
||||
* USB Port 1, Enabled; *
|
||||
* *
|
||||
* *
|
||||
* ******** Usage5: Update existing passwords ******* *
|
||||
* *
|
||||
* CFGWIN can update system Administrator password and Power On Password. *
|
||||
* Users can perform this using the format specified below in the settings *
|
||||
* file using "restore mode", please be noticed that password updating *
|
||||
* will only take effect after reboot. Remember that only one password *
|
||||
* can be updated during each reboot cycle. This means that you cannot *
|
||||
* update Admin Password and Power On Password simultaneously in one *
|
||||
* cycle, only one password(either Admin. Password or Power On Password) *
|
||||
* can be updated during each boot cycle. *
|
||||
* *
|
||||
* Note: For the Password region in the .txt file, you need to add ; as *
|
||||
* a terminator. *
|
||||
* *
|
||||
* Example1: Update Admin password from 123 to 321 with ascii,us mode *
|
||||
* Write 3 lines in setting file as below: *
|
||||
* WmiOpcodePasswordType:pap; *
|
||||
* WmiOpcodePasswordCurrent01:123; *
|
||||
* WmiOpcodePasswordNew01:321; *
|
||||
* *
|
||||
* Example2: Update POP from 123 to 321 with ascii,us mode *
|
||||
* Write 3 lines in setting file as below: *
|
||||
* WmiOpcodePasswordType:pop; *
|
||||
* WmiOpcodePasswordCurrent01:123; *
|
||||
* WmiOpcodePasswordNew01:321; *
|
||||
* *
|
||||
* *
|
||||
* *
|
||||
* ******** Usage6: Clear password ******** *
|
||||
* *
|
||||
* Example1: Clear current Admin password with ascii,us mode(assume *
|
||||
* current Admin password is 123) *
|
||||
* Write 3 lines in setting file as below: *
|
||||
* WmiOpcodePasswordType:pap; *
|
||||
* WmiOpcodePasswordCurrent01:123; *
|
||||
* WmiOpcodePasswordNew01:; *
|
||||
* *
|
||||
* Example2: Clear current POP with ascii,us mode(assume current POP is 123) *
|
||||
* Write 3 lines in setting file as below: *
|
||||
* WmiOpcodePasswordType:pop; *
|
||||
* WmiOpcodePasswordCurrent01:123; *
|
||||
* WmiOpcodePasswordNew01:; *
|
||||
* *
|
||||
* *
|
||||
* Appendix 1: Characters that password could use *
|
||||
* 0 - 9 numeral *
|
||||
* a - z letter *
|
||||
* A - Z letter *
|
||||
* Please use quotation marks around passwords that use the *
|
||||
* following characters. See Usage 3 (above) for examples *
|
||||
* ! Exclamation mark *
|
||||
* " Quotation mark *
|
||||
* # Number sign, Hashtag, Octothorpe, Sharp *
|
||||
* $ Dollar sign *
|
||||
* % Percent sign *
|
||||
* & Ampersand *
|
||||
* ' Apostrophe *
|
||||
* ( Left parenthesis *
|
||||
* ) Right parenthesis *
|
||||
* * Asterisk *
|
||||
* + Plus sign *
|
||||
* , Comma *
|
||||
* - Hyphen-minus *
|
||||
* . Full stop *
|
||||
* / Slash (Solidus) *
|
||||
* : Colon *
|
||||
* ; Semicolon *
|
||||
* < Less-than sign *
|
||||
* = Equal sign *
|
||||
* > Greater-than sign *
|
||||
* ? Question mark *
|
||||
* @ At sign *
|
||||
* [ Left Square Bracket *
|
||||
* \ Backslash *
|
||||
* ] Right Square Bracket *
|
||||
* ^ Circumflex accent *
|
||||
* _ Low line *
|
||||
* ` Grave accent *
|
||||
* { Left Curly Bracket *
|
||||
* | Vertical bar *
|
||||
* } Right Curly Bracket *
|
||||
* ~ Tilde, Wave *
|
||||
* Space *
|
||||
* *
|
||||
*************************************************************************************<br>
|
||||
*************************************************************************************
|
||||
* 3. Compiler Information *
|
||||
* *
|
||||
* This Utility is compiled by Inno Setup 5.5.9 (u) *
|
||||
* *
|
||||
*************************************************************************************<br>
|
||||
<pre>
|
||||
</body>
|
||||
<style>
|
||||
.bodyStyle {
|
||||
background: white;
|
||||
color: black;
|
||||
margin-left: 20%;
|
||||
margin-right: 20%;
|
||||
font-size: large;
|
||||
}
|
||||
</style>
|
||||
</html>
|
||||
Binary file not shown.
Binary file not shown.
Reference in New Issue
Block a user