From fa9c078ca03cb0b7379f047efcc83eeeeb062423 Mon Sep 17 00:00:00 2001 From: Almeyric Date: Thu, 28 May 2026 20:34:42 +0200 Subject: [PATCH] Implemantation Lenovo Bios Password non crypte --- .../MDT/Scripts/CSV/ConfigBIOSLenovo_Gen3.csv | 79 +++++++ .../MDT/Scripts/CSV/ConfigBIOSLenovo_Gen4.csv | 85 ++++++++ .../MDT/Scripts/CSV/ConfigBIOSLenovo_Gen5.csv | 86 ++++++++ .../CSV/CustomSettings_BIOS_Example.ini | 90 ++++++++ projects/MDT/Scripts/CSV/README.md | 196 ++++++++++++++++++ .../Scripts/Set_BIOSPassword_FromDatabase.vbs | 153 ++++++++++++++ .../ps1/ConfigureBIOSLenovo_TSIntegration.ps1 | 104 ++++++++++ 7 files changed, 793 insertions(+) create mode 100644 projects/MDT/Scripts/CSV/ConfigBIOSLenovo_Gen3.csv create mode 100644 projects/MDT/Scripts/CSV/ConfigBIOSLenovo_Gen4.csv create mode 100644 projects/MDT/Scripts/CSV/ConfigBIOSLenovo_Gen5.csv create mode 100644 projects/MDT/Scripts/CSV/CustomSettings_BIOS_Example.ini create mode 100644 projects/MDT/Scripts/CSV/README.md create mode 100644 projects/MDT/Scripts/Set_BIOSPassword_FromDatabase.vbs create mode 100644 projects/MDT/Scripts/SupportHDF/ps1/ConfigureBIOSLenovo_TSIntegration.ps1 diff --git a/projects/MDT/Scripts/CSV/ConfigBIOSLenovo_Gen3.csv b/projects/MDT/Scripts/CSV/ConfigBIOSLenovo_Gen3.csv new file mode 100644 index 0000000..1190daf --- /dev/null +++ b/projects/MDT/Scripts/CSV/ConfigBIOSLenovo_Gen3.csv @@ -0,0 +1,79 @@ +Setting,Value +USBPortAccess,Enabled +USBEnumerationDelay,Disabled +FrontUSBPorts,Enabled +RearUSBPorts,Enabled +USBPort1,Enabled +USBPort2,Enabled +USBPort3,Enabled +USBPort5,Enabled +USBPort6,Enabled +USBPort7,Enabled +USBPort8,Enabled +SATAController,Enabled +SATADrive1,Enabled +SATADrive2,Enabled +HardDiskPre-delay,Disabled +SelectActiveVideo,Auto +OnboardAudioController,Enabled +InternalSpeaker,Enabled +OnboardEthernetController,Enabled +PXEIPV4NetworkStack,Enabled +ASPMSupport,Auto +PCIe16xSlotSpeed,Auto +PCIe1xSlotSpeed,Auto +SpeedShiftTechnology,Enabled +HyperThreadingTechnology,Enabled +CoreMultiProcessing,Enabled +VirtualizationTechnology,Enabled +VTdFeature,Enabled +C1ESupport,Enabled +CStateSupport,C1C3C6C7C8C10 +IntelDPTFSupport,Enabled +AfterPowerLoss,Last State +EnhancedPowerSavingMode,Disabled +SmartPowerOn,Enabled +IntelligentCoolingPerformanceMode,Performance mode +WakeUponAlarm,Disabled +AlarmTime,[00:00:00] +AlarmDayofWeek,Sunday +UserDefinedAlarmSunday,Disabled +UserDefinedAlarmMonday,Disabled +UserDefinedAlarmTuesday,Disabled +UserDefinedAlarmWednesday,Disabled +UserDefinedAlarmThursday,Disabled +UserDefinedAlarmFriday,Disabled +UserDefinedAlarmSaturday,Disabled +UserDefinedAlarmTime,[00:00:00] +AccessSecuritySettings,Disabled +RemoteSetSMP,Disabled +RequireHDPonSystemBoot,Auto +BlockSIDAuthentication,Enabled +SetMinimumLength,Disabled +SetStrongPassword,Disabled +KeyboardLayout,English +BIOSPasswordAtSystemBoot,Yes +BIOSPasswordAtReboot,No +BIOSPasswordAtBootDeviceList,No +RequireSVPwhenFlashing,No +AllowJumperClearSVP,Yes +PasswordCountExceededError,Enabled +SecureRollBackPrevention,Yes +WindowsUEFIFirmwareUpdate,Enabled +SmartUSBProtection,Disabled +securewipe,Disabled +SecurityChip,Enabled +PhysicalPresenceforClear,Enabled +SecureBoot,Enabled +AbsolutePersistenceModule,Enabled +CoverTamperDetected,Disabled +ConfigurationChangeDetection,Disabled +Firstbootdevice,Boot Order +BootUpNumLockStatus,On +UsbBootSupport,Enabled +PXEIPV6NetworkStack,Disabled +TurboMode,Enabled +OptionKeysDisplay,Disabled +WakeonLAN,Enabled +FastBoot,Enabled +BootOrder,PCIE SLOT 1:Network 1:USB HDD 1 diff --git a/projects/MDT/Scripts/CSV/ConfigBIOSLenovo_Gen4.csv b/projects/MDT/Scripts/CSV/ConfigBIOSLenovo_Gen4.csv new file mode 100644 index 0000000..559e23a --- /dev/null +++ b/projects/MDT/Scripts/CSV/ConfigBIOSLenovo_Gen4.csv @@ -0,0 +1,85 @@ +Setting,Value +USBPortAccess,Enabled +USBEnumerationDelay,Disabled +FrontUSBPorts,Enabled +RearUSBPorts,Enabled +USBPort1,Enabled +USBPort2,Enabled +USBPort3,Enabled +USBPort5,Enabled +USBPort6,Enabled +USBPort7,Enabled +USBPort8,Enabled +SATAController,Enabled +SATADrive1,Enabled +SATADrive2,Enabled +HardDiskPre-delay,Disabled +SelectActiveVideo,Auto +OnboardAudioController,Enabled +InternalSpeaker,Enabled +OnboardEthernetController,Enabled +PXEIPV4NetworkStack,Enabled +ASPMSupport,Auto +PCIe16xSlotSpeed,Auto +PCIe1xSlotSpeed,Auto +SpeedShiftTechnology,Enabled +HyperThreadingTechnology,Enabled +CoreMultiProcessing,Enabled +VirtualizationTechnology,Enabled +VTdFeature,Enabled +C1ESupport,Enabled +CStateSupport,C1C3C6C7C8C10 +IntelDPTFSupport,Enabled +AfterPowerLoss,Last State +EnhancedPowerSavingMode,Disabled +SmartPowerOn,Enabled +IntelligentCoolingPerformanceMode,Performance mode +WakeUponAlarm,Disabled +AlarmTime,[00:00:00] +AlarmDayofWeek,Sunday +UserDefinedAlarmSunday,Disabled +UserDefinedAlarmMonday,Disabled +UserDefinedAlarmTuesday,Disabled +UserDefinedAlarmWednesday,Disabled +UserDefinedAlarmThursday,Disabled +UserDefinedAlarmFriday,Disabled +UserDefinedAlarmSaturday,Disabled +UserDefinedAlarmTime,[00:00:00] +AccessSecuritySettings,Disabled +RemoteSetSMP,Disabled +RequireHDPonSystemBoot,Auto +BlockSIDAuthentication,Enabled +SetMinimumLength,Disabled +SetStrongPassword,Disabled +KeyboardLayout,English +BIOSPasswordAtSystemBoot,Yes +BIOSPasswordAtReboot,No +BIOSPasswordAtBootDeviceList,No +RequireSVPwhenFlashing,No +AllowJumperClearSVP,Yes +PasswordCountExceededError,Enabled +SecureRollBackPrevention,Yes +WindowsUEFIFirmwareUpdate,Enabled +SmartUSBProtection,Disabled +securewipe,Disabled +SecurityChip,Enabled +PhysicalPresenceforClear,Enabled +SecureBoot,Enabled +AbsolutePersistenceModule,Enabled +CoverTamperDetected,Disabled +ConfigurationChangeDetection,Disabled +Firstbootdevice,Boot Order +BootUpNumLockStatus,On +UsbBootSupport,Enabled +Language,French +M.2Drive1,Enabled +PXEIPV6NetworkStack,Disabled +TurboMode,Enabled +OptionKeysDisplay,Enabled +OptionKeysDisplayStyle,Normal +WakeonLAN,Boot Order +StartupSequence,Boot Order +ThunderBoot,Enabled +FastBoot,Enabled +BootOrder,M.2 Drive 1:SATA 1:SATA 2:Network 1:USB HDD 1:USB CDROM +AlarmDate,[01/01/2024] diff --git a/projects/MDT/Scripts/CSV/ConfigBIOSLenovo_Gen5.csv b/projects/MDT/Scripts/CSV/ConfigBIOSLenovo_Gen5.csv new file mode 100644 index 0000000..43badb0 --- /dev/null +++ b/projects/MDT/Scripts/CSV/ConfigBIOSLenovo_Gen5.csv @@ -0,0 +1,86 @@ +Setting,Value +USBPortAccess,Enabled +USBEnumerationDelay,Disabled +FrontUSBPorts,Enabled +RearUSBPorts,Enabled +USBPort1,Enabled +USBPort2,Enabled +USBPort3,Enabled +USBPort5,Enabled +USBPort6,Enabled +USBPort7,Enabled +USBPort8,Enabled +SATAController,Enabled +SATADrive1,Enabled +SATADrive2,Enabled +HardDiskPre-delay,Disabled +SelectActiveVideo,Auto +OnboardAudioController,Enabled +InternalSpeaker,Enabled +OnboardEthernetController,Enabled +PXEIPV4NetworkStack,Enabled +ASPMSupport,Auto +PCIe16xSlotSpeed,Auto +PCIe1xSlotSpeed,Auto +SpeedShiftTechnology,Enabled +HyperThreadingTechnology,Enabled +CoreMultiProcessing,Enabled +VirtualizationTechnology,Enabled +VTdFeature,Enabled +C1ESupport,Enabled +CStateSupport,C1C3C6C7C8C10 +IntelDPTFSupport,Enabled +AfterPowerLoss,Last State +EnhancedPowerSavingMode,Disabled +SmartPowerOn,Enabled +IntelligentCoolingPerformanceMode,Performance mode +WakeUponAlarm,Disabled +AlarmTime,[00:00:00] +AlarmDayofWeek,Sunday +UserDefinedAlarmSunday,Disabled +UserDefinedAlarmMonday,Disabled +UserDefinedAlarmTuesday,Disabled +UserDefinedAlarmWednesday,Disabled +UserDefinedAlarmThursday,Disabled +UserDefinedAlarmFriday,Disabled +UserDefinedAlarmSaturday,Disabled +UserDefinedAlarmTime,[00:00:00] +AccessSecuritySettings,Disabled +RemoteSetSMP,Disabled +RequireHDPonSystemBoot,Auto +BlockSIDAuthentication,Enabled +SetMinimumLength,Disabled +SetStrongPassword,Disabled +KeyboardLayout,English +BIOSPasswordAtSystemBoot,Yes +BIOSPasswordAtReboot,No +BIOSPasswordAtBootDeviceList,No +RequireSVPwhenFlashing,No +AllowJumperClearSVP,Yes +PasswordCountExceededError,Enabled +SecureRollBackPrevention,Yes +WindowsUEFIFirmwareUpdate,Enabled +SmartUSBProtection,Disabled +securewipe,Disabled +SecurityChip,Enabled +PhysicalPresenceforClear,Enabled +SecureBoot,Enabled +AbsolutePersistenceModule,Enabled +CoverTamperDetected,Disabled +ConfigurationChangeDetection,Disabled +Firstbootdevice,Boot Order +BootUpNumLockStatus,On +UsbBootSupport,Enabled +Language,French +M.2Drive1,Enabled +PXEIPV6NetworkStack,Disabled +IOMMU,Enabled +TurboMode,Enabled +OptionKeysDisplay,Enabled +OptionKeysDisplayStyle,Normal +WakeonLAN,Boot Order +StartupSequence,Boot Order +ThunderBoot,Disabled +FastBoot,Enabled +BootOrder,M.2 Drive 1:SATA 1:SATA 2:Network 1:USB CDROM:USB HDD 1 +AlarmDate,[01/01/2024] diff --git a/projects/MDT/Scripts/CSV/CustomSettings_BIOS_Example.ini b/projects/MDT/Scripts/CSV/CustomSettings_BIOS_Example.ini new file mode 100644 index 0000000..0dd4c58 --- /dev/null +++ b/projects/MDT/Scripts/CSV/CustomSettings_BIOS_Example.ini @@ -0,0 +1,90 @@ +; ========================================================= +; EXEMPLE CONFIGURATION BIOS LENOVO ZÉRO TOUCH +; ========================================================= +; Ajouter la variable BIOSPassword dans votre CustomSettings.ini +; pour passer le mot de passe BIOS automatiquement +; ========================================================= + +; EXEMPLE 1 - Configuration globale (tous les déploiements) +; Utiliser plutôt un script VBS sécurisé pour définir la variable BIOSPassword +; Exemple: cscript.exe "%SCRIPTROOT%\SupportHDF\Set_BIOSPassword_FromDatabase.vbs" + +[Default] +; Aucune valeur de mot de passe BIOS ne doit être stockée en clair ici. +; BIOSPassword=MonMotDePasseBIOS + +; EXEMPLE 2 - Configuration par site +; Les sections suivantes montrent l'emplacement mais ne doivent pas contenir de clair. +[S2080] +; BIOSPassword=MotDePasseS2080 + +[S2073] +; BIOSPassword=MotDePasseS2073 + +; EXEMPLE 3 - Configuration par rôle/département +[Role_Admin] +; BIOSPassword=MotDePasseAdmin + +[Role_User] +; BIOSPassword=MotDePasseUser + +; ========================================================= +; SÉCURITÉ - RECOMMANDATIONS IMPORTANTES +; ========================================================= +; +; ⚠️ NE PAS STOCKER LES MOTS DE PASSE EN CLAIR +; +; Alternatives recommandées: +; +; 1. Script VBS de prédeploiement (DeployWiz_Initialization.vbs) +; → Récupère le mot de passe depuis une base de données sécurisée +; → Établit la variable MDT BIOSPassword +; → Utilisable avec LDAP, Active Directory, ou base de données locale +; +; 2. Chiffrement MDT avec DataBASE.xml +; → Utiliser la fonction MDT natif de chiffrement +; +; 3. Configuration par groupe Active Directory +; → Créer des groupes ordinateurs spécifiques +; → Affecter les mots de passe par groupe +; +; 4. Service d'identité/Coffre-fort d'entreprise +; → Intégration avec Azure Key Vault ou similaire +; → Récupération sécurisée lors du déploiement +; +; ========================================================= +; FORMAT VARIABLES MDT DISPONIBLES +; ========================================================= +; +; Les variables suivantes sont automatiquement détectées: +; +; %LenovoModel% - Modèle Lenovo détecté (Gen 3, 4, ou 5) +; %DEPLOYROOT% - Racine du partage MDT +; %ComputerName% - Nom de l'ordinateur +; %BIOSPassword% - Mot de passe BIOS (défini ici) +; +; ========================================================= +; COMPORTEMENT DU SCRIPT +; ========================================================= +; +; Le script ConfigureBIOSLenovo_TSIntegration.ps1: +; +; 1. Détecte le modèle Lenovo (Gen 3/4/5) +; 2. Charge le fichier CSV approprié +; 3. Vérifie l'état du mot de passe BIOS (WMI) +; 4. Si mot de passe détecté ET BIOSPassword vide → ERREUR +; 5. Applique les paramètres (avec ou sans mot de passe) +; 6. Mode ZÉRO TOUCH - Pas d'interaction utilisateur +; +; ========================================================= +; LOGS DE DIAGNOSTIC +; ========================================================= +; +; Vérifier les logs de la séquence de tâches: +; C:\MININT\SMSTS.log +; +; Chercher les lignes [INFO], [WARN], [ERROR]: +; [INFO] Application des paramètres avec authentification BIOS... +; [INFO] Paramètres BIOS appliqués avec succès (Zéro Touch) +; +; ========================================================= diff --git a/projects/MDT/Scripts/CSV/README.md b/projects/MDT/Scripts/CSV/README.md new file mode 100644 index 0000000..002ec4e --- /dev/null +++ b/projects/MDT/Scripts/CSV/README.md @@ -0,0 +1,196 @@ +# Configuration BIOS Lenovo - Intégration MDT avec SetBIOS Module +## Résumé des changements effectués + +### 1. Fichiers CSV créés +Trois fichiers CSV ont été créés dans le dossier `c:\MDT\Scripts\SupportHDF\CSV\`: + +- **ConfigBIOSLenovo_Gen3.csv** - Paramètres pour ThinkCentre neo 50s Gen 3 +- **ConfigBIOSLenovo_Gen4.csv** - Paramètres pour ThinkCentre neo 50s Gen 4 +- **ConfigBIOSLenovo_Gen5.csv** - Paramètres pour ThinkCentre neo 50s Gen 5 + +Chaque fichier contient: +- Les paramètres **CommonSettings** (communes à toutes les générations) +- Les paramètres **GenX Settings** (spécifiques à chaque génération) +- Format CSV: "Setting,Value" compatible avec le module SetBIOS.psm1 + +#### Contenu des fichiers CSV: +- **Gen3**: 79 paramètres +- **Gen4**: 84 paramètres +- **Gen5**: 85 paramètres + +### 2. Script PowerShell créé +**Chemin**: `c:\MDT\Scripts\SupportHDF\ps1\ConfigureBIOSLenovo_TSIntegration.ps1` + +**Fonction**: Script d'intégration à la séquence de tâches qui: +1. Détecte le modèle Lenovo (Gen3, Gen4, ou Gen5) +2. Charge le fichier CSV approprié +3. Importe le module SetBIOS.psm1 +4. Vérifie si un mot de passe BIOS est configuré (via WMI) +5. Exécute Set-Bios avec le fichier CSV +6. Utilise la variable MDT `BIOSPassword` pour éviter toute interaction + +**Variables d'environnement utilisées**: +- `%DEPLOYROOT%` - Racine du déploiement MDT +- `$env:LenovoModel` - Modèle détecté automatiquement via WMI + +**Gestion du mot de passe**: +- Détection automatique via classe WMI: `Lenovo_BiosPasswordSettings` +- Le script appelle `Set-Bios -Password` si un mot de passe est détecté +- L'utilisateur sera invité à entrer le mot de passe lors de l'exécution + +### 3. Tâche ajoutée au fichier ts.xml +**Chemin du fichier**: `c:\MDT\Control\DEPL-W11-25H2-00\ts.xml` + +**Emplacement**: Dans le groupe "Postinstall", après le groupe "Settings Only Bios Change Lenovo" + +**Groupe créé**: "Configure BIOS Lenovo Full Settings" +- **Conditions**: S'exécute pour tous les ordinateurs Lenovo ThinkCentre (détection WMI) +- **Tâche**: Exécute le script ConfigureBIOSLenovo_TSIntegration.ps1 +- **Mode**: WinPEandFullOS +- **Gestion d'erreur**: continueOnError=true (ne bloque pas la séquence si erreur) + +**Condition WMI**: +```sql +SELECT * FROM Win32_ComputerSystemProduct WHERE Name LIKE '%ThinkCentre%' OR Name LIKE '%neo 50s%' +``` + +### 4. Fonctionnement du mot de passe BIOS (MODE ZÉRO TOUCH) + +La tâche fonctionne **sans intervention utilisateur**: + +**Sans mot de passe BIOS**: +- Le script s'exécute normalement +- Les paramètres sont appliqués directement + +**Avec mot de passe BIOS actif** (Zéro Touch): +- Le script détecte l'état du mot de passe via WMI (`Lenovo_BiosPasswordSettings`) +- Le mot de passe doit être fourni via la variable MDT `BIOSPassword` +- Le mot de passe est utilisé directement - **AUCUNE demande interactive** +- Les paramètres sont appliqués avec authentification automatique + +#### Configuration du mot de passe BIOS (MODE SÉCURISÉ) + +Ne pas stocker le mot de passe en clair dans CustomSettings.ini. +Le mot de passe doit être récupéré via un script sécurisé avant l'étape BIOS. + +Utilisez le script VBS suivant: +```ini +cscript.exe "%SCRIPTROOT%\SupportHDF\Set_BIOSPassword_FromDatabase.vbs" +``` + +Ce script doit définir la variable MDT `BIOSPassword` en mémoire au moment de l'exécution. + +#### Conditions obligatoires: +- Si un mot de passe BIOS est détecté sur le système +- ET la variable `BIOSPassword` est vide +- → **Le script échoue avec erreur** (pas d'authentification possible) + +#### Recommandations sécurité: +1. Ne pas mettre le mot de passe en clair dans CustomSettings.ini +2. Utiliser un script VBS de prédeploiement qui: + - Récupère le mot de passe depuis une source chiffrée ou sécurisée + - Le définit dans la variable MDT `BIOSPassword` +3. Ne conserver aucun mot de passe BIOS en clair dans les fichiers de configuration + + +### 5. Détection du modèle Lenovo + +Le script détecte automatiquement la génération selon les critères suivants: +- **Gen 5**: Si le modèle contient "Gen 5", "Gen5", "gen 5", ou "gen5" +- **Gen 4**: Si le modèle contient "Gen 4", "Gen4", "gen 4", ou "gen4" +- **Gen 3 (par défaut)**: Tous les autres cas + +Priorité de détection: +1. Variable d'environnement `$env:LenovoModel` (si définie) +2. WMI `Win32_ComputerSystemProduct.Name` (détection locale) +3. Défaut: Gen 3 + +### 6. Points importants + +✓ **La tâche existante n'est pas modifiée** - Le groupe "Settings Only Bios Change Lenovo" reste inchangé (disabled=true) + +✓ **Gestion différenciée** - Chaque génération (Gen3, Gen4, Gen5) a son propre fichier CSV + +✓ **Détection du mot de passe** - Automatique via WMI, pas besoin de variable manuelle + +✓ **Sécurité** - Le script affiche les détails de la configuration dans les logs MDT + +### 7. Tests recommandés + +Pour tester correctement: +1. **Commencer par Gen5** (comme demandé) +2. Vérifier les logs de la séquence de tâches: `C:\MININT\SMSTS.log` +3. Tester avec et sans mot de passe BIOS configuré +4. Vérifier que les paramètres BIOS sont bien appliqués après le redémarrage + +### 8. Variables d'environnement MDT (optionnel) + +Pour forcer un modèle spécifique, vous pouvez définir dans CustomSettings.ini: +```ini +[Default] +LenovoModel=ThinkCentre neo 50s Gen 5 +BIOSPassword=MonMotDePasse ; ZÉRO TOUCH - Mode automatique sans interaction +``` + +### 9. Configuration des tests + +#### Mode ZÉRO TOUCH (Recommandé): +1. Ajouter la variable `BIOSPassword` dans CustomSettings.ini +2. Ou utiliser un script VBS pour la définir depuis une source sécurisée +3. Le déploiement fonctionnera sans demande de mot de passe + +#### Mode sans mot de passe: +1. Laisser `BIOSPassword` vide +2. S'assurer que le BIOS Lenovo n'a pas de mot de passe configuré +3. Le déploiement s'exécutera directement + +### 10. Architecture sécurisée recommandée + +**Approche SANS clair en production**: + +``` +Fichier CustomSettings.ini + ↓ + (appelle) + ↓ +Set_BIOSPassword_FromDatabase.vbs + ↓ +(récupère de): +- Base de données chiffrée +- Active Directory (attribut personnalisé) +- API HTTPS (coffre-fort d'entreprise) +- Fichier sécurisé (permissions AD) + ↓ +Variable MDT: BIOSPassword + ↓ +ConfigureBIOSLenovo_TSIntegration.ps1 + ↓ +Module SetBIOS (applique les paramètres) +``` + +### 11. Fichiers de support + +Fichiers d'exemple fournis: +- **CustomSettings_BIOS_Example.ini** - Exemples de configuration +- **Set_BIOSPassword_FromDatabase.vbs** - Script pour récupérer le mot de passe sécurisement + +### 9. Fichiers modifiés/créés + +``` +c:\MDT\ +├── Scripts\ +│ └── SupportHDF\ +│ ├── CSV\ +│ │ ├── ConfigBIOSLenovo_Gen3.csv [CRÉÉ] +│ │ ├── ConfigBIOSLenovo_Gen4.csv [CRÉÉ] +│ │ └── ConfigBIOSLenovo_Gen5.csv [CRÉÉ] +│ └── ps1\ +│ └── ConfigureBIOSLenovo_TSIntegration.ps1 [CRÉÉ] +└── Control\ + └── DEPL-W11-25H2-00\ + └── ts.xml [MODIFIÉ - Groupe "Configure BIOS Lenovo Full Settings" ajouté] +``` + +--- +**Date de création**: 28/05/2026 +**Module SetBIOS utilisé**: 1.0 (c:\MDT\Tools\Modules\SetBIOS\1.0\SetBIOS.psm1) diff --git a/projects/MDT/Scripts/Set_BIOSPassword_FromDatabase.vbs b/projects/MDT/Scripts/Set_BIOSPassword_FromDatabase.vbs new file mode 100644 index 0000000..3312f04 --- /dev/null +++ b/projects/MDT/Scripts/Set_BIOSPassword_FromDatabase.vbs @@ -0,0 +1,153 @@ +' ========================================================= +' EXEMPLE: Set_BIOSPassword_FromDatabase.vbs +' ========================================================= +' Script VBS pour récupérer le mot de passe BIOS de manière sécurisée +' À intégrer dans la séquence de tâches MDT ou DeployWiz_Initialization.vbs +' +' UTILISATION: +' 1. Adapter ce script pour votre source (BD, LDAP, fichier sécurisé, etc.) +' 2. L'ajouter en étape de prédeploiement +' 3. Le script définira la variable MDT BIOSPassword +' 4. ConfigureBIOSLenovo_TSIntegration.ps1 la récupérera automatiquement +' +' ========================================================= + +' Charger les objets MDT +Set objMDT = CreateObject("Microsoft.SMS.TSEnvironment") +Set objShell = CreateObject("WScript.Shell") + +' Variables de diagnostic +Dim strComputer, strModel, strPassword, strSource +strComputer = objMDT("ComputerName") +strModel = "" + +' ========================================================= +' EXEMPLE 1: Récupérer le mot de passe depuis un fichier sécurisé +' ========================================================= +Function GetPasswordFromFile() + Dim objFSO, objFile, strLine + Dim strPasswordFile + + ' Fichier sécurisé en lecture seule (permissions AD) + strPasswordFile = "\\serveur\partage_admin\bios_passwords.txt" + + On Error Resume Next + Set objFSO = CreateObject("Scripting.FileSystemObject") + + If objFSO.FileExists(strPasswordFile) Then + Set objFile = objFSO.OpenTextFile(strPasswordFile, 1) ' Lecture seule + Do While Not objFile.AtEndOfStream + strLine = objFile.ReadLine() + ' Format du fichier: NOM_ORDINATEUR=MOTDEPASSE + If InStr(strLine, strComputer & "=") > 0 Then + GetPasswordFromFile = Split(strLine, "=")(1) + Exit Function + End If + Loop + objFile.Close() + End If + + GetPasswordFromFile = "" +End Function + +' ========================================================= +' EXEMPLE 2: Récupérer le mot de passe depuis Active Directory +' ========================================================= +Function GetPasswordFromAD() + Dim objAD, objComputer, strPassword + + On Error Resume Next + Set objAD = CreateObject("ADSystemInfo") + Set objComputer = GetObject("LDAP://") + + ' Attribut personnalisé AD (ex: "biosPassword") + If objComputer.Get("biosPassword") <> "" Then + GetPasswordFromAD = objComputer.Get("biosPassword") + Else + GetPasswordFromAD = "" + End If +End Function + +' ========================================================= +' EXEMPLE 3: Récupérer depuis un appel HTTPS/JSON (API) +' ========================================================= +Function GetPasswordFromAPI() + Dim objHTTP, strURL, strResponse, objJSON + + ' URL sécurisée HTTPS avec authentification + ' Exemple: https://api.interne.com/bios/password?computer=PC001 + strURL = "https://api.interne.com/bios/password?computer=" & strComputer + + On Error Resume Next + Set objHTTP = CreateObject("MSXML2.XMLHTTP.6.0") + + With objHTTP + .Open "GET", strURL, False + .setRequestHeader "Authorization", "Bearer TOKEN_AUTHENTICATION" + .Send + + If .Status = 200 Then + ' Parser la réponse JSON (exemple simplifié) + strResponse = .ResponseText + ' Implémenter le parsing JSON selon votre API + GetPasswordFromAPI = strResponse + End If + End With +End Function + +' ========================================================= +' RÉCUPÉRER LE MOT DE PASSE (ordre de priorité) +' ========================================================= +Dim strBIOSPassword +strBIOSPassword = "" + +' 1. Essayer le fichier sécurisé +strBIOSPassword = GetPasswordFromFile() +If strBIOSPassword = "" Then + WScript.Echo "[INFO] Mot de passe non trouvé dans fichier sécurisé" +End If + +' 2. Essayer Active Directory +If strBIOSPassword = "" Then + strBIOSPassword = GetPasswordFromAD() + If strBIOSPassword = "" Then + WScript.Echo "[INFO] Mot de passe non trouvé dans Active Directory" + End If +End If + +' 3. Essayer l'API HTTPS +If strBIOSPassword = "" Then + strBIOSPassword = GetPasswordFromAPI() + If strBIOSPassword = "" Then + WScript.Echo "[INFO] Mot de passe non trouvé via API" + End If +End If + +' ========================================================= +' DÉFINIR LA VARIABLE MDT +' ========================================================= +If strBIOSPassword <> "" Then + objMDT("BIOSPassword") = strBIOSPassword + WScript.Echo "[INFO] Variable BIOSPassword définie avec succès" + WScript.Echo "[INFO] Ordinateur: " & strComputer + WScript.Echo "[INFO] Longueur mot de passe: " & Len(strBIOSPassword) & " caractères" +Else + WScript.Echo "[WARN] Impossible de récupérer le mot de passe BIOS" + WScript.Echo "[WARN] Déploiement sans authentification BIOS" + objMDT("BIOSPassword") = "" +End If + +' ========================================================= +' INTÉGRATION DANS LA SÉQUENCE MDT +' ========================================================= +' +' Pour utiliser ce script: +' +' 1. Sauvegarder en tant que: %DEPLOYROOT%\Scripts\Set_BIOSPassword.vbs +' 2. Ajouter une étape "Exécuter un script" AVANT la tâche BIOS +' 3. Commande: cscript.exe "%SCRIPTROOT%\Set_BIOSPassword.vbs" +' 4. La variable MDT BIOSPassword sera disponible pour le script PowerShell +' +' ========================================================= + +WScript.Quit(0) diff --git a/projects/MDT/Scripts/SupportHDF/ps1/ConfigureBIOSLenovo_TSIntegration.ps1 b/projects/MDT/Scripts/SupportHDF/ps1/ConfigureBIOSLenovo_TSIntegration.ps1 new file mode 100644 index 0000000..aafed5f --- /dev/null +++ b/projects/MDT/Scripts/SupportHDF/ps1/ConfigureBIOSLenovo_TSIntegration.ps1 @@ -0,0 +1,104 @@ +# ConfigureBIOSLenovo_TSIntegration.ps1 +# Applique les paramètres BIOS Lenovo via le module SetBIOS +# Mode ZÉRO TOUCH - Pas d'interaction utilisateur +# Utilise une variable MDT BIOSPassword pour authentification automatique + +Write-Output "[INFO] ========== Démarrage de la configuration BIOS Lenovo (Zéro Touch) ==========" + +# Déterminer le modèle Lenovo et sélectionner le fichier CSV approprié +$LenovoModel = $env:LenovoModel + +if ([string]::IsNullOrEmpty($LenovoModel)) { + try { + $LenovoModel = (Get-WmiObject Win32_ComputerSystemProduct -ErrorAction Stop).Name + Write-Output "[INFO] LenovoModel obtenu via WMI: $LenovoModel" + } + catch { + Write-Output "[WARN] Impossible de déterminer le modèle Lenovo - utilisation de la valeur par défaut Gen 3" + $LenovoModel = "Gen 3" + } +} + +# Déterminer le fichier CSV selon la génération +if ($LenovoModel -like "*Gen 5*" -or $LenovoModel -like "*Gen5*" -or $LenovoModel -like "*gen 5*" -or $LenovoModel -like "*gen5*") { + Write-Output "[INFO] Détection ThinkCentre neo 50s Gen 5 ($LenovoModel)" + $CSVFile = "%DEPLOYROOT%\Scripts\SupportHDF\CSV\ConfigBIOSLenovo_Gen5.csv" +} elseif ($LenovoModel -like "*Gen 4*" -or $LenovoModel -like "*Gen4*" -or $LenovoModel -like "*gen 4*" -or $LenovoModel -like "*gen4*") { + Write-Output "[INFO] Détection ThinkCentre neo 50s Gen 4 ($LenovoModel)" + $CSVFile = "%DEPLOYROOT%\Scripts\SupportHDF\CSV\ConfigBIOSLenovo_Gen4.csv" +} else { + Write-Output "[INFO] Détection ThinkCentre neo 50s Gen 3 ou antérieur ($LenovoModel)" + $CSVFile = "%DEPLOYROOT%\Scripts\SupportHDF\CSV\ConfigBIOSLenovo_Gen3.csv" +} + +# Remplacer %DEPLOYROOT% par la vraie valeur +$CSVFile = $CSVFile -replace "%DEPLOYROOT%", $env:DEPLOYROOT + +# Vérifier que le fichier CSV existe +if (!(Test-Path $CSVFile)) { + Write-Output "[ERROR] Fichier CSV non trouvé: $CSVFile" + exit 1 +} + +Write-Output "[INFO] Utilisation du fichier CSV: $CSVFile" + +# Charger le module SetBIOS +$SetBIOSModule = Join-Path $env:DEPLOYROOT "Tools\Modules\SetBIOS\1.0\SetBIOS.psm1" +if (!(Test-Path $SetBIOSModule)) { + Write-Output "[ERROR] Module SetBIOS non trouvé: $SetBIOSModule" + exit 1 +} + +try { + Import-Module $SetBIOSModule -ErrorAction Stop -Force + Write-Output "[INFO] Module SetBIOS importé avec succès" +} catch { + Write-Output "[ERROR] Impossible d'importer le module SetBIOS: $_" + exit 1 +} + +# Récupérer le mot de passe BIOS depuis les variables MDT +$BIOSPassword = $env:BIOSPassword +if ([string]::IsNullOrEmpty($BIOSPassword)) { + Write-Output "[WARN] Variable MDT BIOSPassword non trouvée" +} + +# Vérifier si un mot de passe BIOS est configuré sur le système +Write-Output "[INFO] Vérification de l'état du mot de passe BIOS..." +try { + $BIOSPasswordSettings = Get-WmiObject -Class Lenovo_BiosPasswordSettings -Namespace root\wmi -ErrorAction Stop + $PasswordState = $BIOSPasswordSettings.PasswordState + Write-Output "[INFO] État du mot de passe BIOS: $PasswordState (0=Pas de mot de passe, 1=Admin, 2=Système, 3=Utilisateur)" + + $IsPasswordSet = ($PasswordState -eq 2 -or $PasswordState -eq 1 -or $PasswordState -eq 3) +} catch { + Write-Output "[WARN] Impossible de vérifier l'état du mot de passe BIOS via WMI: $_" + $IsPasswordSet = $false +} + +# Vérifier cohérence mot de passe +if ($IsPasswordSet -and [string]::IsNullOrEmpty($BIOSPassword)) { + Write-Output "[ERROR] Un mot de passe BIOS est configuré mais la variable MDT BIOSPassword est vide" + Write-Output "[ERROR] Ajoutez 'BIOSPassword=VOTRE_MOT_DE_PASSE' dans CustomSettings.ini" + exit 1 +} + +# Exécuter Set-BIOS avec le fichier CSV - Zéro Touch +try { + Write-Output "[INFO] Application des paramètres BIOS Lenovo..." + + if ($IsPasswordSet -and -not [string]::IsNullOrEmpty($BIOSPassword)) { + Write-Output "[INFO] Application des paramètres avec authentification BIOS..." + Set-Bios -CSV $CSVFile -PasswordValue $BIOSPassword -ErrorAction Stop + } else { + Write-Output "[INFO] Application des paramètres BIOS sans authentification..." + Set-Bios -CSV $CSVFile -ErrorAction Stop + } + + Write-Output "[INFO] ========== Paramètres BIOS appliqués avec succès (Zéro Touch) ==========" + exit 0 +} catch { + Write-Output "[ERROR] Erreur lors de l'application des paramètres BIOS: $_" + Write-Output "[ERROR] ========== Configuration BIOS échouée ==========" + exit 1 +}