Implemantation Lenovo Bios Password non crypte

This commit is contained in:
2026-05-28 20:34:42 +02:00
parent 8812221954
commit fa9c078ca0
7 changed files with 793 additions and 0 deletions
@@ -0,0 +1,79 @@
Setting,Value
USBPortAccess,Enabled
USBEnumerationDelay,Disabled
FrontUSBPorts,Enabled
RearUSBPorts,Enabled
USBPort1,Enabled
USBPort2,Enabled
USBPort3,Enabled
USBPort5,Enabled
USBPort6,Enabled
USBPort7,Enabled
USBPort8,Enabled
SATAController,Enabled
SATADrive1,Enabled
SATADrive2,Enabled
HardDiskPre-delay,Disabled
SelectActiveVideo,Auto
OnboardAudioController,Enabled
InternalSpeaker,Enabled
OnboardEthernetController,Enabled
PXEIPV4NetworkStack,Enabled
ASPMSupport,Auto
PCIe16xSlotSpeed,Auto
PCIe1xSlotSpeed,Auto
SpeedShiftTechnology,Enabled
HyperThreadingTechnology,Enabled
CoreMultiProcessing,Enabled
VirtualizationTechnology,Enabled
VTdFeature,Enabled
C1ESupport,Enabled
CStateSupport,C1C3C6C7C8C10
IntelDPTFSupport,Enabled
AfterPowerLoss,Last State
EnhancedPowerSavingMode,Disabled
SmartPowerOn,Enabled
IntelligentCoolingPerformanceMode,Performance mode
WakeUponAlarm,Disabled
AlarmTime,[00:00:00]
AlarmDayofWeek,Sunday
UserDefinedAlarmSunday,Disabled
UserDefinedAlarmMonday,Disabled
UserDefinedAlarmTuesday,Disabled
UserDefinedAlarmWednesday,Disabled
UserDefinedAlarmThursday,Disabled
UserDefinedAlarmFriday,Disabled
UserDefinedAlarmSaturday,Disabled
UserDefinedAlarmTime,[00:00:00]
AccessSecuritySettings,Disabled
RemoteSetSMP,Disabled
RequireHDPonSystemBoot,Auto
BlockSIDAuthentication,Enabled
SetMinimumLength,Disabled
SetStrongPassword,Disabled
KeyboardLayout,English
BIOSPasswordAtSystemBoot,Yes
BIOSPasswordAtReboot,No
BIOSPasswordAtBootDeviceList,No
RequireSVPwhenFlashing,No
AllowJumperClearSVP,Yes
PasswordCountExceededError,Enabled
SecureRollBackPrevention,Yes
WindowsUEFIFirmwareUpdate,Enabled
SmartUSBProtection,Disabled
securewipe,Disabled
SecurityChip,Enabled
PhysicalPresenceforClear,Enabled
SecureBoot,Enabled
AbsolutePersistenceModule,Enabled
CoverTamperDetected,Disabled
ConfigurationChangeDetection,Disabled
Firstbootdevice,Boot Order
BootUpNumLockStatus,On
UsbBootSupport,Enabled
PXEIPV6NetworkStack,Disabled
TurboMode,Enabled
OptionKeysDisplay,Disabled
WakeonLAN,Enabled
FastBoot,Enabled
BootOrder,PCIE SLOT 1:Network 1:USB HDD 1
1 Setting Value
2 USBPortAccess Enabled
3 USBEnumerationDelay Disabled
4 FrontUSBPorts Enabled
5 RearUSBPorts Enabled
6 USBPort1 Enabled
7 USBPort2 Enabled
8 USBPort3 Enabled
9 USBPort5 Enabled
10 USBPort6 Enabled
11 USBPort7 Enabled
12 USBPort8 Enabled
13 SATAController Enabled
14 SATADrive1 Enabled
15 SATADrive2 Enabled
16 HardDiskPre-delay Disabled
17 SelectActiveVideo Auto
18 OnboardAudioController Enabled
19 InternalSpeaker Enabled
20 OnboardEthernetController Enabled
21 PXEIPV4NetworkStack Enabled
22 ASPMSupport Auto
23 PCIe16xSlotSpeed Auto
24 PCIe1xSlotSpeed Auto
25 SpeedShiftTechnology Enabled
26 HyperThreadingTechnology Enabled
27 CoreMultiProcessing Enabled
28 VirtualizationTechnology Enabled
29 VTdFeature Enabled
30 C1ESupport Enabled
31 CStateSupport C1C3C6C7C8C10
32 IntelDPTFSupport Enabled
33 AfterPowerLoss Last State
34 EnhancedPowerSavingMode Disabled
35 SmartPowerOn Enabled
36 IntelligentCoolingPerformanceMode Performance mode
37 WakeUponAlarm Disabled
38 AlarmTime [00:00:00]
39 AlarmDayofWeek Sunday
40 UserDefinedAlarmSunday Disabled
41 UserDefinedAlarmMonday Disabled
42 UserDefinedAlarmTuesday Disabled
43 UserDefinedAlarmWednesday Disabled
44 UserDefinedAlarmThursday Disabled
45 UserDefinedAlarmFriday Disabled
46 UserDefinedAlarmSaturday Disabled
47 UserDefinedAlarmTime [00:00:00]
48 AccessSecuritySettings Disabled
49 RemoteSetSMP Disabled
50 RequireHDPonSystemBoot Auto
51 BlockSIDAuthentication Enabled
52 SetMinimumLength Disabled
53 SetStrongPassword Disabled
54 KeyboardLayout English
55 BIOSPasswordAtSystemBoot Yes
56 BIOSPasswordAtReboot No
57 BIOSPasswordAtBootDeviceList No
58 RequireSVPwhenFlashing No
59 AllowJumperClearSVP Yes
60 PasswordCountExceededError Enabled
61 SecureRollBackPrevention Yes
62 WindowsUEFIFirmwareUpdate Enabled
63 SmartUSBProtection Disabled
64 securewipe Disabled
65 SecurityChip Enabled
66 PhysicalPresenceforClear Enabled
67 SecureBoot Enabled
68 AbsolutePersistenceModule Enabled
69 CoverTamperDetected Disabled
70 ConfigurationChangeDetection Disabled
71 Firstbootdevice Boot Order
72 BootUpNumLockStatus On
73 UsbBootSupport Enabled
74 PXEIPV6NetworkStack Disabled
75 TurboMode Enabled
76 OptionKeysDisplay Disabled
77 WakeonLAN Enabled
78 FastBoot Enabled
79 BootOrder PCIE SLOT 1:Network 1:USB HDD 1
@@ -0,0 +1,85 @@
Setting,Value
USBPortAccess,Enabled
USBEnumerationDelay,Disabled
FrontUSBPorts,Enabled
RearUSBPorts,Enabled
USBPort1,Enabled
USBPort2,Enabled
USBPort3,Enabled
USBPort5,Enabled
USBPort6,Enabled
USBPort7,Enabled
USBPort8,Enabled
SATAController,Enabled
SATADrive1,Enabled
SATADrive2,Enabled
HardDiskPre-delay,Disabled
SelectActiveVideo,Auto
OnboardAudioController,Enabled
InternalSpeaker,Enabled
OnboardEthernetController,Enabled
PXEIPV4NetworkStack,Enabled
ASPMSupport,Auto
PCIe16xSlotSpeed,Auto
PCIe1xSlotSpeed,Auto
SpeedShiftTechnology,Enabled
HyperThreadingTechnology,Enabled
CoreMultiProcessing,Enabled
VirtualizationTechnology,Enabled
VTdFeature,Enabled
C1ESupport,Enabled
CStateSupport,C1C3C6C7C8C10
IntelDPTFSupport,Enabled
AfterPowerLoss,Last State
EnhancedPowerSavingMode,Disabled
SmartPowerOn,Enabled
IntelligentCoolingPerformanceMode,Performance mode
WakeUponAlarm,Disabled
AlarmTime,[00:00:00]
AlarmDayofWeek,Sunday
UserDefinedAlarmSunday,Disabled
UserDefinedAlarmMonday,Disabled
UserDefinedAlarmTuesday,Disabled
UserDefinedAlarmWednesday,Disabled
UserDefinedAlarmThursday,Disabled
UserDefinedAlarmFriday,Disabled
UserDefinedAlarmSaturday,Disabled
UserDefinedAlarmTime,[00:00:00]
AccessSecuritySettings,Disabled
RemoteSetSMP,Disabled
RequireHDPonSystemBoot,Auto
BlockSIDAuthentication,Enabled
SetMinimumLength,Disabled
SetStrongPassword,Disabled
KeyboardLayout,English
BIOSPasswordAtSystemBoot,Yes
BIOSPasswordAtReboot,No
BIOSPasswordAtBootDeviceList,No
RequireSVPwhenFlashing,No
AllowJumperClearSVP,Yes
PasswordCountExceededError,Enabled
SecureRollBackPrevention,Yes
WindowsUEFIFirmwareUpdate,Enabled
SmartUSBProtection,Disabled
securewipe,Disabled
SecurityChip,Enabled
PhysicalPresenceforClear,Enabled
SecureBoot,Enabled
AbsolutePersistenceModule,Enabled
CoverTamperDetected,Disabled
ConfigurationChangeDetection,Disabled
Firstbootdevice,Boot Order
BootUpNumLockStatus,On
UsbBootSupport,Enabled
Language,French
M.2Drive1,Enabled
PXEIPV6NetworkStack,Disabled
TurboMode,Enabled
OptionKeysDisplay,Enabled
OptionKeysDisplayStyle,Normal
WakeonLAN,Boot Order
StartupSequence,Boot Order
ThunderBoot,Enabled
FastBoot,Enabled
BootOrder,M.2 Drive 1:SATA 1:SATA 2:Network 1:USB HDD 1:USB CDROM
AlarmDate,[01/01/2024]
1 Setting Value
2 USBPortAccess Enabled
3 USBEnumerationDelay Disabled
4 FrontUSBPorts Enabled
5 RearUSBPorts Enabled
6 USBPort1 Enabled
7 USBPort2 Enabled
8 USBPort3 Enabled
9 USBPort5 Enabled
10 USBPort6 Enabled
11 USBPort7 Enabled
12 USBPort8 Enabled
13 SATAController Enabled
14 SATADrive1 Enabled
15 SATADrive2 Enabled
16 HardDiskPre-delay Disabled
17 SelectActiveVideo Auto
18 OnboardAudioController Enabled
19 InternalSpeaker Enabled
20 OnboardEthernetController Enabled
21 PXEIPV4NetworkStack Enabled
22 ASPMSupport Auto
23 PCIe16xSlotSpeed Auto
24 PCIe1xSlotSpeed Auto
25 SpeedShiftTechnology Enabled
26 HyperThreadingTechnology Enabled
27 CoreMultiProcessing Enabled
28 VirtualizationTechnology Enabled
29 VTdFeature Enabled
30 C1ESupport Enabled
31 CStateSupport C1C3C6C7C8C10
32 IntelDPTFSupport Enabled
33 AfterPowerLoss Last State
34 EnhancedPowerSavingMode Disabled
35 SmartPowerOn Enabled
36 IntelligentCoolingPerformanceMode Performance mode
37 WakeUponAlarm Disabled
38 AlarmTime [00:00:00]
39 AlarmDayofWeek Sunday
40 UserDefinedAlarmSunday Disabled
41 UserDefinedAlarmMonday Disabled
42 UserDefinedAlarmTuesday Disabled
43 UserDefinedAlarmWednesday Disabled
44 UserDefinedAlarmThursday Disabled
45 UserDefinedAlarmFriday Disabled
46 UserDefinedAlarmSaturday Disabled
47 UserDefinedAlarmTime [00:00:00]
48 AccessSecuritySettings Disabled
49 RemoteSetSMP Disabled
50 RequireHDPonSystemBoot Auto
51 BlockSIDAuthentication Enabled
52 SetMinimumLength Disabled
53 SetStrongPassword Disabled
54 KeyboardLayout English
55 BIOSPasswordAtSystemBoot Yes
56 BIOSPasswordAtReboot No
57 BIOSPasswordAtBootDeviceList No
58 RequireSVPwhenFlashing No
59 AllowJumperClearSVP Yes
60 PasswordCountExceededError Enabled
61 SecureRollBackPrevention Yes
62 WindowsUEFIFirmwareUpdate Enabled
63 SmartUSBProtection Disabled
64 securewipe Disabled
65 SecurityChip Enabled
66 PhysicalPresenceforClear Enabled
67 SecureBoot Enabled
68 AbsolutePersistenceModule Enabled
69 CoverTamperDetected Disabled
70 ConfigurationChangeDetection Disabled
71 Firstbootdevice Boot Order
72 BootUpNumLockStatus On
73 UsbBootSupport Enabled
74 Language French
75 M.2Drive1 Enabled
76 PXEIPV6NetworkStack Disabled
77 TurboMode Enabled
78 OptionKeysDisplay Enabled
79 OptionKeysDisplayStyle Normal
80 WakeonLAN Boot Order
81 StartupSequence Boot Order
82 ThunderBoot Enabled
83 FastBoot Enabled
84 BootOrder M.2 Drive 1:SATA 1:SATA 2:Network 1:USB HDD 1:USB CDROM
85 AlarmDate [01/01/2024]
@@ -0,0 +1,86 @@
Setting,Value
USBPortAccess,Enabled
USBEnumerationDelay,Disabled
FrontUSBPorts,Enabled
RearUSBPorts,Enabled
USBPort1,Enabled
USBPort2,Enabled
USBPort3,Enabled
USBPort5,Enabled
USBPort6,Enabled
USBPort7,Enabled
USBPort8,Enabled
SATAController,Enabled
SATADrive1,Enabled
SATADrive2,Enabled
HardDiskPre-delay,Disabled
SelectActiveVideo,Auto
OnboardAudioController,Enabled
InternalSpeaker,Enabled
OnboardEthernetController,Enabled
PXEIPV4NetworkStack,Enabled
ASPMSupport,Auto
PCIe16xSlotSpeed,Auto
PCIe1xSlotSpeed,Auto
SpeedShiftTechnology,Enabled
HyperThreadingTechnology,Enabled
CoreMultiProcessing,Enabled
VirtualizationTechnology,Enabled
VTdFeature,Enabled
C1ESupport,Enabled
CStateSupport,C1C3C6C7C8C10
IntelDPTFSupport,Enabled
AfterPowerLoss,Last State
EnhancedPowerSavingMode,Disabled
SmartPowerOn,Enabled
IntelligentCoolingPerformanceMode,Performance mode
WakeUponAlarm,Disabled
AlarmTime,[00:00:00]
AlarmDayofWeek,Sunday
UserDefinedAlarmSunday,Disabled
UserDefinedAlarmMonday,Disabled
UserDefinedAlarmTuesday,Disabled
UserDefinedAlarmWednesday,Disabled
UserDefinedAlarmThursday,Disabled
UserDefinedAlarmFriday,Disabled
UserDefinedAlarmSaturday,Disabled
UserDefinedAlarmTime,[00:00:00]
AccessSecuritySettings,Disabled
RemoteSetSMP,Disabled
RequireHDPonSystemBoot,Auto
BlockSIDAuthentication,Enabled
SetMinimumLength,Disabled
SetStrongPassword,Disabled
KeyboardLayout,English
BIOSPasswordAtSystemBoot,Yes
BIOSPasswordAtReboot,No
BIOSPasswordAtBootDeviceList,No
RequireSVPwhenFlashing,No
AllowJumperClearSVP,Yes
PasswordCountExceededError,Enabled
SecureRollBackPrevention,Yes
WindowsUEFIFirmwareUpdate,Enabled
SmartUSBProtection,Disabled
securewipe,Disabled
SecurityChip,Enabled
PhysicalPresenceforClear,Enabled
SecureBoot,Enabled
AbsolutePersistenceModule,Enabled
CoverTamperDetected,Disabled
ConfigurationChangeDetection,Disabled
Firstbootdevice,Boot Order
BootUpNumLockStatus,On
UsbBootSupport,Enabled
Language,French
M.2Drive1,Enabled
PXEIPV6NetworkStack,Disabled
IOMMU,Enabled
TurboMode,Enabled
OptionKeysDisplay,Enabled
OptionKeysDisplayStyle,Normal
WakeonLAN,Boot Order
StartupSequence,Boot Order
ThunderBoot,Disabled
FastBoot,Enabled
BootOrder,M.2 Drive 1:SATA 1:SATA 2:Network 1:USB CDROM:USB HDD 1
AlarmDate,[01/01/2024]
1 Setting Value
2 USBPortAccess Enabled
3 USBEnumerationDelay Disabled
4 FrontUSBPorts Enabled
5 RearUSBPorts Enabled
6 USBPort1 Enabled
7 USBPort2 Enabled
8 USBPort3 Enabled
9 USBPort5 Enabled
10 USBPort6 Enabled
11 USBPort7 Enabled
12 USBPort8 Enabled
13 SATAController Enabled
14 SATADrive1 Enabled
15 SATADrive2 Enabled
16 HardDiskPre-delay Disabled
17 SelectActiveVideo Auto
18 OnboardAudioController Enabled
19 InternalSpeaker Enabled
20 OnboardEthernetController Enabled
21 PXEIPV4NetworkStack Enabled
22 ASPMSupport Auto
23 PCIe16xSlotSpeed Auto
24 PCIe1xSlotSpeed Auto
25 SpeedShiftTechnology Enabled
26 HyperThreadingTechnology Enabled
27 CoreMultiProcessing Enabled
28 VirtualizationTechnology Enabled
29 VTdFeature Enabled
30 C1ESupport Enabled
31 CStateSupport C1C3C6C7C8C10
32 IntelDPTFSupport Enabled
33 AfterPowerLoss Last State
34 EnhancedPowerSavingMode Disabled
35 SmartPowerOn Enabled
36 IntelligentCoolingPerformanceMode Performance mode
37 WakeUponAlarm Disabled
38 AlarmTime [00:00:00]
39 AlarmDayofWeek Sunday
40 UserDefinedAlarmSunday Disabled
41 UserDefinedAlarmMonday Disabled
42 UserDefinedAlarmTuesday Disabled
43 UserDefinedAlarmWednesday Disabled
44 UserDefinedAlarmThursday Disabled
45 UserDefinedAlarmFriday Disabled
46 UserDefinedAlarmSaturday Disabled
47 UserDefinedAlarmTime [00:00:00]
48 AccessSecuritySettings Disabled
49 RemoteSetSMP Disabled
50 RequireHDPonSystemBoot Auto
51 BlockSIDAuthentication Enabled
52 SetMinimumLength Disabled
53 SetStrongPassword Disabled
54 KeyboardLayout English
55 BIOSPasswordAtSystemBoot Yes
56 BIOSPasswordAtReboot No
57 BIOSPasswordAtBootDeviceList No
58 RequireSVPwhenFlashing No
59 AllowJumperClearSVP Yes
60 PasswordCountExceededError Enabled
61 SecureRollBackPrevention Yes
62 WindowsUEFIFirmwareUpdate Enabled
63 SmartUSBProtection Disabled
64 securewipe Disabled
65 SecurityChip Enabled
66 PhysicalPresenceforClear Enabled
67 SecureBoot Enabled
68 AbsolutePersistenceModule Enabled
69 CoverTamperDetected Disabled
70 ConfigurationChangeDetection Disabled
71 Firstbootdevice Boot Order
72 BootUpNumLockStatus On
73 UsbBootSupport Enabled
74 Language French
75 M.2Drive1 Enabled
76 PXEIPV6NetworkStack Disabled
77 IOMMU Enabled
78 TurboMode Enabled
79 OptionKeysDisplay Enabled
80 OptionKeysDisplayStyle Normal
81 WakeonLAN Boot Order
82 StartupSequence Boot Order
83 ThunderBoot Disabled
84 FastBoot Enabled
85 BootOrder M.2 Drive 1:SATA 1:SATA 2:Network 1:USB CDROM:USB HDD 1
86 AlarmDate [01/01/2024]
@@ -0,0 +1,90 @@
; =========================================================
; EXEMPLE CONFIGURATION BIOS LENOVO ZÉRO TOUCH
; =========================================================
; Ajouter la variable BIOSPassword dans votre CustomSettings.ini
; pour passer le mot de passe BIOS automatiquement
; =========================================================
; EXEMPLE 1 - Configuration globale (tous les déploiements)
; Utiliser plutôt un script VBS sécurisé pour définir la variable BIOSPassword
; Exemple: cscript.exe "%SCRIPTROOT%\SupportHDF\Set_BIOSPassword_FromDatabase.vbs"
[Default]
; Aucune valeur de mot de passe BIOS ne doit être stockée en clair ici.
; BIOSPassword=MonMotDePasseBIOS
; EXEMPLE 2 - Configuration par site
; Les sections suivantes montrent l'emplacement mais ne doivent pas contenir de clair.
[S2080]
; BIOSPassword=MotDePasseS2080
[S2073]
; BIOSPassword=MotDePasseS2073
; EXEMPLE 3 - Configuration par rôle/département
[Role_Admin]
; BIOSPassword=MotDePasseAdmin
[Role_User]
; BIOSPassword=MotDePasseUser
; =========================================================
; SÉCURITÉ - RECOMMANDATIONS IMPORTANTES
; =========================================================
;
; ⚠️ NE PAS STOCKER LES MOTS DE PASSE EN CLAIR
;
; Alternatives recommandées:
;
; 1. Script VBS de prédeploiement (DeployWiz_Initialization.vbs)
; → Récupère le mot de passe depuis une base de données sécurisée
; → Établit la variable MDT BIOSPassword
; → Utilisable avec LDAP, Active Directory, ou base de données locale
;
; 2. Chiffrement MDT avec DataBASE.xml
; → Utiliser la fonction MDT natif de chiffrement
;
; 3. Configuration par groupe Active Directory
; → Créer des groupes ordinateurs spécifiques
; → Affecter les mots de passe par groupe
;
; 4. Service d'identité/Coffre-fort d'entreprise
; → Intégration avec Azure Key Vault ou similaire
; → Récupération sécurisée lors du déploiement
;
; =========================================================
; FORMAT VARIABLES MDT DISPONIBLES
; =========================================================
;
; Les variables suivantes sont automatiquement détectées:
;
; %LenovoModel% - Modèle Lenovo détecté (Gen 3, 4, ou 5)
; %DEPLOYROOT% - Racine du partage MDT
; %ComputerName% - Nom de l'ordinateur
; %BIOSPassword% - Mot de passe BIOS (défini ici)
;
; =========================================================
; COMPORTEMENT DU SCRIPT
; =========================================================
;
; Le script ConfigureBIOSLenovo_TSIntegration.ps1:
;
; 1. Détecte le modèle Lenovo (Gen 3/4/5)
; 2. Charge le fichier CSV approprié
; 3. Vérifie l'état du mot de passe BIOS (WMI)
; 4. Si mot de passe détecté ET BIOSPassword vide → ERREUR
; 5. Applique les paramètres (avec ou sans mot de passe)
; 6. Mode ZÉRO TOUCH - Pas d'interaction utilisateur
;
; =========================================================
; LOGS DE DIAGNOSTIC
; =========================================================
;
; Vérifier les logs de la séquence de tâches:
; C:\MININT\SMSTS.log
;
; Chercher les lignes [INFO], [WARN], [ERROR]:
; [INFO] Application des paramètres avec authentification BIOS...
; [INFO] Paramètres BIOS appliqués avec succès (Zéro Touch)
;
; =========================================================
+196
View File
@@ -0,0 +1,196 @@
# Configuration BIOS Lenovo - Intégration MDT avec SetBIOS Module
## Résumé des changements effectués
### 1. Fichiers CSV créés
Trois fichiers CSV ont été créés dans le dossier `c:\MDT\Scripts\SupportHDF\CSV\`:
- **ConfigBIOSLenovo_Gen3.csv** - Paramètres pour ThinkCentre neo 50s Gen 3
- **ConfigBIOSLenovo_Gen4.csv** - Paramètres pour ThinkCentre neo 50s Gen 4
- **ConfigBIOSLenovo_Gen5.csv** - Paramètres pour ThinkCentre neo 50s Gen 5
Chaque fichier contient:
- Les paramètres **CommonSettings** (communes à toutes les générations)
- Les paramètres **GenX Settings** (spécifiques à chaque génération)
- Format CSV: "Setting,Value" compatible avec le module SetBIOS.psm1
#### Contenu des fichiers CSV:
- **Gen3**: 79 paramètres
- **Gen4**: 84 paramètres
- **Gen5**: 85 paramètres
### 2. Script PowerShell créé
**Chemin**: `c:\MDT\Scripts\SupportHDF\ps1\ConfigureBIOSLenovo_TSIntegration.ps1`
**Fonction**: Script d'intégration à la séquence de tâches qui:
1. Détecte le modèle Lenovo (Gen3, Gen4, ou Gen5)
2. Charge le fichier CSV approprié
3. Importe le module SetBIOS.psm1
4. Vérifie si un mot de passe BIOS est configuré (via WMI)
5. Exécute Set-Bios avec le fichier CSV
6. Utilise la variable MDT `BIOSPassword` pour éviter toute interaction
**Variables d'environnement utilisées**:
- `%DEPLOYROOT%` - Racine du déploiement MDT
- `$env:LenovoModel` - Modèle détecté automatiquement via WMI
**Gestion du mot de passe**:
- Détection automatique via classe WMI: `Lenovo_BiosPasswordSettings`
- Le script appelle `Set-Bios -Password` si un mot de passe est détecté
- L'utilisateur sera invité à entrer le mot de passe lors de l'exécution
### 3. Tâche ajoutée au fichier ts.xml
**Chemin du fichier**: `c:\MDT\Control\DEPL-W11-25H2-00\ts.xml`
**Emplacement**: Dans le groupe "Postinstall", après le groupe "Settings Only Bios Change Lenovo"
**Groupe créé**: "Configure BIOS Lenovo Full Settings"
- **Conditions**: S'exécute pour tous les ordinateurs Lenovo ThinkCentre (détection WMI)
- **Tâche**: Exécute le script ConfigureBIOSLenovo_TSIntegration.ps1
- **Mode**: WinPEandFullOS
- **Gestion d'erreur**: continueOnError=true (ne bloque pas la séquence si erreur)
**Condition WMI**:
```sql
SELECT * FROM Win32_ComputerSystemProduct WHERE Name LIKE '%ThinkCentre%' OR Name LIKE '%neo 50s%'
```
### 4. Fonctionnement du mot de passe BIOS (MODE ZÉRO TOUCH)
La tâche fonctionne **sans intervention utilisateur**:
**Sans mot de passe BIOS**:
- Le script s'exécute normalement
- Les paramètres sont appliqués directement
**Avec mot de passe BIOS actif** (Zéro Touch):
- Le script détecte l'état du mot de passe via WMI (`Lenovo_BiosPasswordSettings`)
- Le mot de passe doit être fourni via la variable MDT `BIOSPassword`
- Le mot de passe est utilisé directement - **AUCUNE demande interactive**
- Les paramètres sont appliqués avec authentification automatique
#### Configuration du mot de passe BIOS (MODE SÉCURISÉ)
Ne pas stocker le mot de passe en clair dans CustomSettings.ini.
Le mot de passe doit être récupéré via un script sécurisé avant l'étape BIOS.
Utilisez le script VBS suivant:
```ini
cscript.exe "%SCRIPTROOT%\SupportHDF\Set_BIOSPassword_FromDatabase.vbs"
```
Ce script doit définir la variable MDT `BIOSPassword` en mémoire au moment de l'exécution.
#### Conditions obligatoires:
- Si un mot de passe BIOS est détecté sur le système
- ET la variable `BIOSPassword` est vide
-**Le script échoue avec erreur** (pas d'authentification possible)
#### Recommandations sécurité:
1. Ne pas mettre le mot de passe en clair dans CustomSettings.ini
2. Utiliser un script VBS de prédeploiement qui:
- Récupère le mot de passe depuis une source chiffrée ou sécurisée
- Le définit dans la variable MDT `BIOSPassword`
3. Ne conserver aucun mot de passe BIOS en clair dans les fichiers de configuration
### 5. Détection du modèle Lenovo
Le script détecte automatiquement la génération selon les critères suivants:
- **Gen 5**: Si le modèle contient "Gen 5", "Gen5", "gen 5", ou "gen5"
- **Gen 4**: Si le modèle contient "Gen 4", "Gen4", "gen 4", ou "gen4"
- **Gen 3 (par défaut)**: Tous les autres cas
Priorité de détection:
1. Variable d'environnement `$env:LenovoModel` (si définie)
2. WMI `Win32_ComputerSystemProduct.Name` (détection locale)
3. Défaut: Gen 3
### 6. Points importants
**La tâche existante n'est pas modifiée** - Le groupe "Settings Only Bios Change Lenovo" reste inchangé (disabled=true)
**Gestion différenciée** - Chaque génération (Gen3, Gen4, Gen5) a son propre fichier CSV
**Détection du mot de passe** - Automatique via WMI, pas besoin de variable manuelle
**Sécurité** - Le script affiche les détails de la configuration dans les logs MDT
### 7. Tests recommandés
Pour tester correctement:
1. **Commencer par Gen5** (comme demandé)
2. Vérifier les logs de la séquence de tâches: `C:\MININT\SMSTS.log`
3. Tester avec et sans mot de passe BIOS configuré
4. Vérifier que les paramètres BIOS sont bien appliqués après le redémarrage
### 8. Variables d'environnement MDT (optionnel)
Pour forcer un modèle spécifique, vous pouvez définir dans CustomSettings.ini:
```ini
[Default]
LenovoModel=ThinkCentre neo 50s Gen 5
BIOSPassword=MonMotDePasse ; ZÉRO TOUCH - Mode automatique sans interaction
```
### 9. Configuration des tests
#### Mode ZÉRO TOUCH (Recommandé):
1. Ajouter la variable `BIOSPassword` dans CustomSettings.ini
2. Ou utiliser un script VBS pour la définir depuis une source sécurisée
3. Le déploiement fonctionnera sans demande de mot de passe
#### Mode sans mot de passe:
1. Laisser `BIOSPassword` vide
2. S'assurer que le BIOS Lenovo n'a pas de mot de passe configuré
3. Le déploiement s'exécutera directement
### 10. Architecture sécurisée recommandée
**Approche SANS clair en production**:
```
Fichier CustomSettings.ini
(appelle)
Set_BIOSPassword_FromDatabase.vbs
(récupère de):
- Base de données chiffrée
- Active Directory (attribut personnalisé)
- API HTTPS (coffre-fort d'entreprise)
- Fichier sécurisé (permissions AD)
Variable MDT: BIOSPassword
ConfigureBIOSLenovo_TSIntegration.ps1
Module SetBIOS (applique les paramètres)
```
### 11. Fichiers de support
Fichiers d'exemple fournis:
- **CustomSettings_BIOS_Example.ini** - Exemples de configuration
- **Set_BIOSPassword_FromDatabase.vbs** - Script pour récupérer le mot de passe sécurisement
### 9. Fichiers modifiés/créés
```
c:\MDT\
├── Scripts\
│ └── SupportHDF\
│ ├── CSV\
│ │ ├── ConfigBIOSLenovo_Gen3.csv [CRÉÉ]
│ │ ├── ConfigBIOSLenovo_Gen4.csv [CRÉÉ]
│ │ └── ConfigBIOSLenovo_Gen5.csv [CRÉÉ]
│ └── ps1\
│ └── ConfigureBIOSLenovo_TSIntegration.ps1 [CRÉÉ]
└── Control\
└── DEPL-W11-25H2-00\
└── ts.xml [MODIFIÉ - Groupe "Configure BIOS Lenovo Full Settings" ajouté]
```
---
**Date de création**: 28/05/2026
**Module SetBIOS utilisé**: 1.0 (c:\MDT\Tools\Modules\SetBIOS\1.0\SetBIOS.psm1)
@@ -0,0 +1,153 @@
' =========================================================
' EXEMPLE: Set_BIOSPassword_FromDatabase.vbs
' =========================================================
' Script VBS pour récupérer le mot de passe BIOS de manière sécurisée
' À intégrer dans la séquence de tâches MDT ou DeployWiz_Initialization.vbs
'
' UTILISATION:
' 1. Adapter ce script pour votre source (BD, LDAP, fichier sécurisé, etc.)
' 2. L'ajouter en étape de prédeploiement
' 3. Le script définira la variable MDT BIOSPassword
' 4. ConfigureBIOSLenovo_TSIntegration.ps1 la récupérera automatiquement
'
' =========================================================
' Charger les objets MDT
Set objMDT = CreateObject("Microsoft.SMS.TSEnvironment")
Set objShell = CreateObject("WScript.Shell")
' Variables de diagnostic
Dim strComputer, strModel, strPassword, strSource
strComputer = objMDT("ComputerName")
strModel = ""
' =========================================================
' EXEMPLE 1: Récupérer le mot de passe depuis un fichier sécurisé
' =========================================================
Function GetPasswordFromFile()
Dim objFSO, objFile, strLine
Dim strPasswordFile
' Fichier sécurisé en lecture seule (permissions AD)
strPasswordFile = "\\serveur\partage_admin\bios_passwords.txt"
On Error Resume Next
Set objFSO = CreateObject("Scripting.FileSystemObject")
If objFSO.FileExists(strPasswordFile) Then
Set objFile = objFSO.OpenTextFile(strPasswordFile, 1) ' Lecture seule
Do While Not objFile.AtEndOfStream
strLine = objFile.ReadLine()
' Format du fichier: NOM_ORDINATEUR=MOTDEPASSE
If InStr(strLine, strComputer & "=") > 0 Then
GetPasswordFromFile = Split(strLine, "=")(1)
Exit Function
End If
Loop
objFile.Close()
End If
GetPasswordFromFile = ""
End Function
' =========================================================
' EXEMPLE 2: Récupérer le mot de passe depuis Active Directory
' =========================================================
Function GetPasswordFromAD()
Dim objAD, objComputer, strPassword
On Error Resume Next
Set objAD = CreateObject("ADSystemInfo")
Set objComputer = GetObject("LDAP://<SID=" & objAD.ComputerSID & ">")
' Attribut personnalisé AD (ex: "biosPassword")
If objComputer.Get("biosPassword") <> "" Then
GetPasswordFromAD = objComputer.Get("biosPassword")
Else
GetPasswordFromAD = ""
End If
End Function
' =========================================================
' EXEMPLE 3: Récupérer depuis un appel HTTPS/JSON (API)
' =========================================================
Function GetPasswordFromAPI()
Dim objHTTP, strURL, strResponse, objJSON
' URL sécurisée HTTPS avec authentification
' Exemple: https://api.interne.com/bios/password?computer=PC001
strURL = "https://api.interne.com/bios/password?computer=" & strComputer
On Error Resume Next
Set objHTTP = CreateObject("MSXML2.XMLHTTP.6.0")
With objHTTP
.Open "GET", strURL, False
.setRequestHeader "Authorization", "Bearer TOKEN_AUTHENTICATION"
.Send
If .Status = 200 Then
' Parser la réponse JSON (exemple simplifié)
strResponse = .ResponseText
' Implémenter le parsing JSON selon votre API
GetPasswordFromAPI = strResponse
End If
End With
End Function
' =========================================================
' RÉCUPÉRER LE MOT DE PASSE (ordre de priorité)
' =========================================================
Dim strBIOSPassword
strBIOSPassword = ""
' 1. Essayer le fichier sécurisé
strBIOSPassword = GetPasswordFromFile()
If strBIOSPassword = "" Then
WScript.Echo "[INFO] Mot de passe non trouvé dans fichier sécurisé"
End If
' 2. Essayer Active Directory
If strBIOSPassword = "" Then
strBIOSPassword = GetPasswordFromAD()
If strBIOSPassword = "" Then
WScript.Echo "[INFO] Mot de passe non trouvé dans Active Directory"
End If
End If
' 3. Essayer l'API HTTPS
If strBIOSPassword = "" Then
strBIOSPassword = GetPasswordFromAPI()
If strBIOSPassword = "" Then
WScript.Echo "[INFO] Mot de passe non trouvé via API"
End If
End If
' =========================================================
' DÉFINIR LA VARIABLE MDT
' =========================================================
If strBIOSPassword <> "" Then
objMDT("BIOSPassword") = strBIOSPassword
WScript.Echo "[INFO] Variable BIOSPassword définie avec succès"
WScript.Echo "[INFO] Ordinateur: " & strComputer
WScript.Echo "[INFO] Longueur mot de passe: " & Len(strBIOSPassword) & " caractères"
Else
WScript.Echo "[WARN] Impossible de récupérer le mot de passe BIOS"
WScript.Echo "[WARN] Déploiement sans authentification BIOS"
objMDT("BIOSPassword") = ""
End If
' =========================================================
' INTÉGRATION DANS LA SÉQUENCE MDT
' =========================================================
'
' Pour utiliser ce script:
'
' 1. Sauvegarder en tant que: %DEPLOYROOT%\Scripts\Set_BIOSPassword.vbs
' 2. Ajouter une étape "Exécuter un script" AVANT la tâche BIOS
' 3. Commande: cscript.exe "%SCRIPTROOT%\Set_BIOSPassword.vbs"
' 4. La variable MDT BIOSPassword sera disponible pour le script PowerShell
'
' =========================================================
WScript.Quit(0)
@@ -0,0 +1,104 @@
# ConfigureBIOSLenovo_TSIntegration.ps1
# Applique les paramètres BIOS Lenovo via le module SetBIOS
# Mode ZÉRO TOUCH - Pas d'interaction utilisateur
# Utilise une variable MDT BIOSPassword pour authentification automatique
Write-Output "[INFO] ========== Démarrage de la configuration BIOS Lenovo (Zéro Touch) =========="
# Déterminer le modèle Lenovo et sélectionner le fichier CSV approprié
$LenovoModel = $env:LenovoModel
if ([string]::IsNullOrEmpty($LenovoModel)) {
try {
$LenovoModel = (Get-WmiObject Win32_ComputerSystemProduct -ErrorAction Stop).Name
Write-Output "[INFO] LenovoModel obtenu via WMI: $LenovoModel"
}
catch {
Write-Output "[WARN] Impossible de déterminer le modèle Lenovo - utilisation de la valeur par défaut Gen 3"
$LenovoModel = "Gen 3"
}
}
# Déterminer le fichier CSV selon la génération
if ($LenovoModel -like "*Gen 5*" -or $LenovoModel -like "*Gen5*" -or $LenovoModel -like "*gen 5*" -or $LenovoModel -like "*gen5*") {
Write-Output "[INFO] Détection ThinkCentre neo 50s Gen 5 ($LenovoModel)"
$CSVFile = "%DEPLOYROOT%\Scripts\SupportHDF\CSV\ConfigBIOSLenovo_Gen5.csv"
} elseif ($LenovoModel -like "*Gen 4*" -or $LenovoModel -like "*Gen4*" -or $LenovoModel -like "*gen 4*" -or $LenovoModel -like "*gen4*") {
Write-Output "[INFO] Détection ThinkCentre neo 50s Gen 4 ($LenovoModel)"
$CSVFile = "%DEPLOYROOT%\Scripts\SupportHDF\CSV\ConfigBIOSLenovo_Gen4.csv"
} else {
Write-Output "[INFO] Détection ThinkCentre neo 50s Gen 3 ou antérieur ($LenovoModel)"
$CSVFile = "%DEPLOYROOT%\Scripts\SupportHDF\CSV\ConfigBIOSLenovo_Gen3.csv"
}
# Remplacer %DEPLOYROOT% par la vraie valeur
$CSVFile = $CSVFile -replace "%DEPLOYROOT%", $env:DEPLOYROOT
# Vérifier que le fichier CSV existe
if (!(Test-Path $CSVFile)) {
Write-Output "[ERROR] Fichier CSV non trouvé: $CSVFile"
exit 1
}
Write-Output "[INFO] Utilisation du fichier CSV: $CSVFile"
# Charger le module SetBIOS
$SetBIOSModule = Join-Path $env:DEPLOYROOT "Tools\Modules\SetBIOS\1.0\SetBIOS.psm1"
if (!(Test-Path $SetBIOSModule)) {
Write-Output "[ERROR] Module SetBIOS non trouvé: $SetBIOSModule"
exit 1
}
try {
Import-Module $SetBIOSModule -ErrorAction Stop -Force
Write-Output "[INFO] Module SetBIOS importé avec succès"
} catch {
Write-Output "[ERROR] Impossible d'importer le module SetBIOS: $_"
exit 1
}
# Récupérer le mot de passe BIOS depuis les variables MDT
$BIOSPassword = $env:BIOSPassword
if ([string]::IsNullOrEmpty($BIOSPassword)) {
Write-Output "[WARN] Variable MDT BIOSPassword non trouvée"
}
# Vérifier si un mot de passe BIOS est configuré sur le système
Write-Output "[INFO] Vérification de l'état du mot de passe BIOS..."
try {
$BIOSPasswordSettings = Get-WmiObject -Class Lenovo_BiosPasswordSettings -Namespace root\wmi -ErrorAction Stop
$PasswordState = $BIOSPasswordSettings.PasswordState
Write-Output "[INFO] État du mot de passe BIOS: $PasswordState (0=Pas de mot de passe, 1=Admin, 2=Système, 3=Utilisateur)"
$IsPasswordSet = ($PasswordState -eq 2 -or $PasswordState -eq 1 -or $PasswordState -eq 3)
} catch {
Write-Output "[WARN] Impossible de vérifier l'état du mot de passe BIOS via WMI: $_"
$IsPasswordSet = $false
}
# Vérifier cohérence mot de passe
if ($IsPasswordSet -and [string]::IsNullOrEmpty($BIOSPassword)) {
Write-Output "[ERROR] Un mot de passe BIOS est configuré mais la variable MDT BIOSPassword est vide"
Write-Output "[ERROR] Ajoutez 'BIOSPassword=VOTRE_MOT_DE_PASSE' dans CustomSettings.ini"
exit 1
}
# Exécuter Set-BIOS avec le fichier CSV - Zéro Touch
try {
Write-Output "[INFO] Application des paramètres BIOS Lenovo..."
if ($IsPasswordSet -and -not [string]::IsNullOrEmpty($BIOSPassword)) {
Write-Output "[INFO] Application des paramètres avec authentification BIOS..."
Set-Bios -CSV $CSVFile -PasswordValue $BIOSPassword -ErrorAction Stop
} else {
Write-Output "[INFO] Application des paramètres BIOS sans authentification..."
Set-Bios -CSV $CSVFile -ErrorAction Stop
}
Write-Output "[INFO] ========== Paramètres BIOS appliqués avec succès (Zéro Touch) =========="
exit 0
} catch {
Write-Output "[ERROR] Erreur lors de l'application des paramètres BIOS: $_"
Write-Output "[ERROR] ========== Configuration BIOS échouée =========="
exit 1
}