Implemantation Lenovo Bios Password non crypte
This commit is contained in:
@@ -0,0 +1,79 @@
|
||||
Setting,Value
|
||||
USBPortAccess,Enabled
|
||||
USBEnumerationDelay,Disabled
|
||||
FrontUSBPorts,Enabled
|
||||
RearUSBPorts,Enabled
|
||||
USBPort1,Enabled
|
||||
USBPort2,Enabled
|
||||
USBPort3,Enabled
|
||||
USBPort5,Enabled
|
||||
USBPort6,Enabled
|
||||
USBPort7,Enabled
|
||||
USBPort8,Enabled
|
||||
SATAController,Enabled
|
||||
SATADrive1,Enabled
|
||||
SATADrive2,Enabled
|
||||
HardDiskPre-delay,Disabled
|
||||
SelectActiveVideo,Auto
|
||||
OnboardAudioController,Enabled
|
||||
InternalSpeaker,Enabled
|
||||
OnboardEthernetController,Enabled
|
||||
PXEIPV4NetworkStack,Enabled
|
||||
ASPMSupport,Auto
|
||||
PCIe16xSlotSpeed,Auto
|
||||
PCIe1xSlotSpeed,Auto
|
||||
SpeedShiftTechnology,Enabled
|
||||
HyperThreadingTechnology,Enabled
|
||||
CoreMultiProcessing,Enabled
|
||||
VirtualizationTechnology,Enabled
|
||||
VTdFeature,Enabled
|
||||
C1ESupport,Enabled
|
||||
CStateSupport,C1C3C6C7C8C10
|
||||
IntelDPTFSupport,Enabled
|
||||
AfterPowerLoss,Last State
|
||||
EnhancedPowerSavingMode,Disabled
|
||||
SmartPowerOn,Enabled
|
||||
IntelligentCoolingPerformanceMode,Performance mode
|
||||
WakeUponAlarm,Disabled
|
||||
AlarmTime,[00:00:00]
|
||||
AlarmDayofWeek,Sunday
|
||||
UserDefinedAlarmSunday,Disabled
|
||||
UserDefinedAlarmMonday,Disabled
|
||||
UserDefinedAlarmTuesday,Disabled
|
||||
UserDefinedAlarmWednesday,Disabled
|
||||
UserDefinedAlarmThursday,Disabled
|
||||
UserDefinedAlarmFriday,Disabled
|
||||
UserDefinedAlarmSaturday,Disabled
|
||||
UserDefinedAlarmTime,[00:00:00]
|
||||
AccessSecuritySettings,Disabled
|
||||
RemoteSetSMP,Disabled
|
||||
RequireHDPonSystemBoot,Auto
|
||||
BlockSIDAuthentication,Enabled
|
||||
SetMinimumLength,Disabled
|
||||
SetStrongPassword,Disabled
|
||||
KeyboardLayout,English
|
||||
BIOSPasswordAtSystemBoot,Yes
|
||||
BIOSPasswordAtReboot,No
|
||||
BIOSPasswordAtBootDeviceList,No
|
||||
RequireSVPwhenFlashing,No
|
||||
AllowJumperClearSVP,Yes
|
||||
PasswordCountExceededError,Enabled
|
||||
SecureRollBackPrevention,Yes
|
||||
WindowsUEFIFirmwareUpdate,Enabled
|
||||
SmartUSBProtection,Disabled
|
||||
securewipe,Disabled
|
||||
SecurityChip,Enabled
|
||||
PhysicalPresenceforClear,Enabled
|
||||
SecureBoot,Enabled
|
||||
AbsolutePersistenceModule,Enabled
|
||||
CoverTamperDetected,Disabled
|
||||
ConfigurationChangeDetection,Disabled
|
||||
Firstbootdevice,Boot Order
|
||||
BootUpNumLockStatus,On
|
||||
UsbBootSupport,Enabled
|
||||
PXEIPV6NetworkStack,Disabled
|
||||
TurboMode,Enabled
|
||||
OptionKeysDisplay,Disabled
|
||||
WakeonLAN,Enabled
|
||||
FastBoot,Enabled
|
||||
BootOrder,PCIE SLOT 1:Network 1:USB HDD 1
|
||||
|
@@ -0,0 +1,85 @@
|
||||
Setting,Value
|
||||
USBPortAccess,Enabled
|
||||
USBEnumerationDelay,Disabled
|
||||
FrontUSBPorts,Enabled
|
||||
RearUSBPorts,Enabled
|
||||
USBPort1,Enabled
|
||||
USBPort2,Enabled
|
||||
USBPort3,Enabled
|
||||
USBPort5,Enabled
|
||||
USBPort6,Enabled
|
||||
USBPort7,Enabled
|
||||
USBPort8,Enabled
|
||||
SATAController,Enabled
|
||||
SATADrive1,Enabled
|
||||
SATADrive2,Enabled
|
||||
HardDiskPre-delay,Disabled
|
||||
SelectActiveVideo,Auto
|
||||
OnboardAudioController,Enabled
|
||||
InternalSpeaker,Enabled
|
||||
OnboardEthernetController,Enabled
|
||||
PXEIPV4NetworkStack,Enabled
|
||||
ASPMSupport,Auto
|
||||
PCIe16xSlotSpeed,Auto
|
||||
PCIe1xSlotSpeed,Auto
|
||||
SpeedShiftTechnology,Enabled
|
||||
HyperThreadingTechnology,Enabled
|
||||
CoreMultiProcessing,Enabled
|
||||
VirtualizationTechnology,Enabled
|
||||
VTdFeature,Enabled
|
||||
C1ESupport,Enabled
|
||||
CStateSupport,C1C3C6C7C8C10
|
||||
IntelDPTFSupport,Enabled
|
||||
AfterPowerLoss,Last State
|
||||
EnhancedPowerSavingMode,Disabled
|
||||
SmartPowerOn,Enabled
|
||||
IntelligentCoolingPerformanceMode,Performance mode
|
||||
WakeUponAlarm,Disabled
|
||||
AlarmTime,[00:00:00]
|
||||
AlarmDayofWeek,Sunday
|
||||
UserDefinedAlarmSunday,Disabled
|
||||
UserDefinedAlarmMonday,Disabled
|
||||
UserDefinedAlarmTuesday,Disabled
|
||||
UserDefinedAlarmWednesday,Disabled
|
||||
UserDefinedAlarmThursday,Disabled
|
||||
UserDefinedAlarmFriday,Disabled
|
||||
UserDefinedAlarmSaturday,Disabled
|
||||
UserDefinedAlarmTime,[00:00:00]
|
||||
AccessSecuritySettings,Disabled
|
||||
RemoteSetSMP,Disabled
|
||||
RequireHDPonSystemBoot,Auto
|
||||
BlockSIDAuthentication,Enabled
|
||||
SetMinimumLength,Disabled
|
||||
SetStrongPassword,Disabled
|
||||
KeyboardLayout,English
|
||||
BIOSPasswordAtSystemBoot,Yes
|
||||
BIOSPasswordAtReboot,No
|
||||
BIOSPasswordAtBootDeviceList,No
|
||||
RequireSVPwhenFlashing,No
|
||||
AllowJumperClearSVP,Yes
|
||||
PasswordCountExceededError,Enabled
|
||||
SecureRollBackPrevention,Yes
|
||||
WindowsUEFIFirmwareUpdate,Enabled
|
||||
SmartUSBProtection,Disabled
|
||||
securewipe,Disabled
|
||||
SecurityChip,Enabled
|
||||
PhysicalPresenceforClear,Enabled
|
||||
SecureBoot,Enabled
|
||||
AbsolutePersistenceModule,Enabled
|
||||
CoverTamperDetected,Disabled
|
||||
ConfigurationChangeDetection,Disabled
|
||||
Firstbootdevice,Boot Order
|
||||
BootUpNumLockStatus,On
|
||||
UsbBootSupport,Enabled
|
||||
Language,French
|
||||
M.2Drive1,Enabled
|
||||
PXEIPV6NetworkStack,Disabled
|
||||
TurboMode,Enabled
|
||||
OptionKeysDisplay,Enabled
|
||||
OptionKeysDisplayStyle,Normal
|
||||
WakeonLAN,Boot Order
|
||||
StartupSequence,Boot Order
|
||||
ThunderBoot,Enabled
|
||||
FastBoot,Enabled
|
||||
BootOrder,M.2 Drive 1:SATA 1:SATA 2:Network 1:USB HDD 1:USB CDROM
|
||||
AlarmDate,[01/01/2024]
|
||||
|
@@ -0,0 +1,86 @@
|
||||
Setting,Value
|
||||
USBPortAccess,Enabled
|
||||
USBEnumerationDelay,Disabled
|
||||
FrontUSBPorts,Enabled
|
||||
RearUSBPorts,Enabled
|
||||
USBPort1,Enabled
|
||||
USBPort2,Enabled
|
||||
USBPort3,Enabled
|
||||
USBPort5,Enabled
|
||||
USBPort6,Enabled
|
||||
USBPort7,Enabled
|
||||
USBPort8,Enabled
|
||||
SATAController,Enabled
|
||||
SATADrive1,Enabled
|
||||
SATADrive2,Enabled
|
||||
HardDiskPre-delay,Disabled
|
||||
SelectActiveVideo,Auto
|
||||
OnboardAudioController,Enabled
|
||||
InternalSpeaker,Enabled
|
||||
OnboardEthernetController,Enabled
|
||||
PXEIPV4NetworkStack,Enabled
|
||||
ASPMSupport,Auto
|
||||
PCIe16xSlotSpeed,Auto
|
||||
PCIe1xSlotSpeed,Auto
|
||||
SpeedShiftTechnology,Enabled
|
||||
HyperThreadingTechnology,Enabled
|
||||
CoreMultiProcessing,Enabled
|
||||
VirtualizationTechnology,Enabled
|
||||
VTdFeature,Enabled
|
||||
C1ESupport,Enabled
|
||||
CStateSupport,C1C3C6C7C8C10
|
||||
IntelDPTFSupport,Enabled
|
||||
AfterPowerLoss,Last State
|
||||
EnhancedPowerSavingMode,Disabled
|
||||
SmartPowerOn,Enabled
|
||||
IntelligentCoolingPerformanceMode,Performance mode
|
||||
WakeUponAlarm,Disabled
|
||||
AlarmTime,[00:00:00]
|
||||
AlarmDayofWeek,Sunday
|
||||
UserDefinedAlarmSunday,Disabled
|
||||
UserDefinedAlarmMonday,Disabled
|
||||
UserDefinedAlarmTuesday,Disabled
|
||||
UserDefinedAlarmWednesday,Disabled
|
||||
UserDefinedAlarmThursday,Disabled
|
||||
UserDefinedAlarmFriday,Disabled
|
||||
UserDefinedAlarmSaturday,Disabled
|
||||
UserDefinedAlarmTime,[00:00:00]
|
||||
AccessSecuritySettings,Disabled
|
||||
RemoteSetSMP,Disabled
|
||||
RequireHDPonSystemBoot,Auto
|
||||
BlockSIDAuthentication,Enabled
|
||||
SetMinimumLength,Disabled
|
||||
SetStrongPassword,Disabled
|
||||
KeyboardLayout,English
|
||||
BIOSPasswordAtSystemBoot,Yes
|
||||
BIOSPasswordAtReboot,No
|
||||
BIOSPasswordAtBootDeviceList,No
|
||||
RequireSVPwhenFlashing,No
|
||||
AllowJumperClearSVP,Yes
|
||||
PasswordCountExceededError,Enabled
|
||||
SecureRollBackPrevention,Yes
|
||||
WindowsUEFIFirmwareUpdate,Enabled
|
||||
SmartUSBProtection,Disabled
|
||||
securewipe,Disabled
|
||||
SecurityChip,Enabled
|
||||
PhysicalPresenceforClear,Enabled
|
||||
SecureBoot,Enabled
|
||||
AbsolutePersistenceModule,Enabled
|
||||
CoverTamperDetected,Disabled
|
||||
ConfigurationChangeDetection,Disabled
|
||||
Firstbootdevice,Boot Order
|
||||
BootUpNumLockStatus,On
|
||||
UsbBootSupport,Enabled
|
||||
Language,French
|
||||
M.2Drive1,Enabled
|
||||
PXEIPV6NetworkStack,Disabled
|
||||
IOMMU,Enabled
|
||||
TurboMode,Enabled
|
||||
OptionKeysDisplay,Enabled
|
||||
OptionKeysDisplayStyle,Normal
|
||||
WakeonLAN,Boot Order
|
||||
StartupSequence,Boot Order
|
||||
ThunderBoot,Disabled
|
||||
FastBoot,Enabled
|
||||
BootOrder,M.2 Drive 1:SATA 1:SATA 2:Network 1:USB CDROM:USB HDD 1
|
||||
AlarmDate,[01/01/2024]
|
||||
|
@@ -0,0 +1,90 @@
|
||||
; =========================================================
|
||||
; EXEMPLE CONFIGURATION BIOS LENOVO ZÉRO TOUCH
|
||||
; =========================================================
|
||||
; Ajouter la variable BIOSPassword dans votre CustomSettings.ini
|
||||
; pour passer le mot de passe BIOS automatiquement
|
||||
; =========================================================
|
||||
|
||||
; EXEMPLE 1 - Configuration globale (tous les déploiements)
|
||||
; Utiliser plutôt un script VBS sécurisé pour définir la variable BIOSPassword
|
||||
; Exemple: cscript.exe "%SCRIPTROOT%\SupportHDF\Set_BIOSPassword_FromDatabase.vbs"
|
||||
|
||||
[Default]
|
||||
; Aucune valeur de mot de passe BIOS ne doit être stockée en clair ici.
|
||||
; BIOSPassword=MonMotDePasseBIOS
|
||||
|
||||
; EXEMPLE 2 - Configuration par site
|
||||
; Les sections suivantes montrent l'emplacement mais ne doivent pas contenir de clair.
|
||||
[S2080]
|
||||
; BIOSPassword=MotDePasseS2080
|
||||
|
||||
[S2073]
|
||||
; BIOSPassword=MotDePasseS2073
|
||||
|
||||
; EXEMPLE 3 - Configuration par rôle/département
|
||||
[Role_Admin]
|
||||
; BIOSPassword=MotDePasseAdmin
|
||||
|
||||
[Role_User]
|
||||
; BIOSPassword=MotDePasseUser
|
||||
|
||||
; =========================================================
|
||||
; SÉCURITÉ - RECOMMANDATIONS IMPORTANTES
|
||||
; =========================================================
|
||||
;
|
||||
; ⚠️ NE PAS STOCKER LES MOTS DE PASSE EN CLAIR
|
||||
;
|
||||
; Alternatives recommandées:
|
||||
;
|
||||
; 1. Script VBS de prédeploiement (DeployWiz_Initialization.vbs)
|
||||
; → Récupère le mot de passe depuis une base de données sécurisée
|
||||
; → Établit la variable MDT BIOSPassword
|
||||
; → Utilisable avec LDAP, Active Directory, ou base de données locale
|
||||
;
|
||||
; 2. Chiffrement MDT avec DataBASE.xml
|
||||
; → Utiliser la fonction MDT natif de chiffrement
|
||||
;
|
||||
; 3. Configuration par groupe Active Directory
|
||||
; → Créer des groupes ordinateurs spécifiques
|
||||
; → Affecter les mots de passe par groupe
|
||||
;
|
||||
; 4. Service d'identité/Coffre-fort d'entreprise
|
||||
; → Intégration avec Azure Key Vault ou similaire
|
||||
; → Récupération sécurisée lors du déploiement
|
||||
;
|
||||
; =========================================================
|
||||
; FORMAT VARIABLES MDT DISPONIBLES
|
||||
; =========================================================
|
||||
;
|
||||
; Les variables suivantes sont automatiquement détectées:
|
||||
;
|
||||
; %LenovoModel% - Modèle Lenovo détecté (Gen 3, 4, ou 5)
|
||||
; %DEPLOYROOT% - Racine du partage MDT
|
||||
; %ComputerName% - Nom de l'ordinateur
|
||||
; %BIOSPassword% - Mot de passe BIOS (défini ici)
|
||||
;
|
||||
; =========================================================
|
||||
; COMPORTEMENT DU SCRIPT
|
||||
; =========================================================
|
||||
;
|
||||
; Le script ConfigureBIOSLenovo_TSIntegration.ps1:
|
||||
;
|
||||
; 1. Détecte le modèle Lenovo (Gen 3/4/5)
|
||||
; 2. Charge le fichier CSV approprié
|
||||
; 3. Vérifie l'état du mot de passe BIOS (WMI)
|
||||
; 4. Si mot de passe détecté ET BIOSPassword vide → ERREUR
|
||||
; 5. Applique les paramètres (avec ou sans mot de passe)
|
||||
; 6. Mode ZÉRO TOUCH - Pas d'interaction utilisateur
|
||||
;
|
||||
; =========================================================
|
||||
; LOGS DE DIAGNOSTIC
|
||||
; =========================================================
|
||||
;
|
||||
; Vérifier les logs de la séquence de tâches:
|
||||
; C:\MININT\SMSTS.log
|
||||
;
|
||||
; Chercher les lignes [INFO], [WARN], [ERROR]:
|
||||
; [INFO] Application des paramètres avec authentification BIOS...
|
||||
; [INFO] Paramètres BIOS appliqués avec succès (Zéro Touch)
|
||||
;
|
||||
; =========================================================
|
||||
@@ -0,0 +1,196 @@
|
||||
# Configuration BIOS Lenovo - Intégration MDT avec SetBIOS Module
|
||||
## Résumé des changements effectués
|
||||
|
||||
### 1. Fichiers CSV créés
|
||||
Trois fichiers CSV ont été créés dans le dossier `c:\MDT\Scripts\SupportHDF\CSV\`:
|
||||
|
||||
- **ConfigBIOSLenovo_Gen3.csv** - Paramètres pour ThinkCentre neo 50s Gen 3
|
||||
- **ConfigBIOSLenovo_Gen4.csv** - Paramètres pour ThinkCentre neo 50s Gen 4
|
||||
- **ConfigBIOSLenovo_Gen5.csv** - Paramètres pour ThinkCentre neo 50s Gen 5
|
||||
|
||||
Chaque fichier contient:
|
||||
- Les paramètres **CommonSettings** (communes à toutes les générations)
|
||||
- Les paramètres **GenX Settings** (spécifiques à chaque génération)
|
||||
- Format CSV: "Setting,Value" compatible avec le module SetBIOS.psm1
|
||||
|
||||
#### Contenu des fichiers CSV:
|
||||
- **Gen3**: 79 paramètres
|
||||
- **Gen4**: 84 paramètres
|
||||
- **Gen5**: 85 paramètres
|
||||
|
||||
### 2. Script PowerShell créé
|
||||
**Chemin**: `c:\MDT\Scripts\SupportHDF\ps1\ConfigureBIOSLenovo_TSIntegration.ps1`
|
||||
|
||||
**Fonction**: Script d'intégration à la séquence de tâches qui:
|
||||
1. Détecte le modèle Lenovo (Gen3, Gen4, ou Gen5)
|
||||
2. Charge le fichier CSV approprié
|
||||
3. Importe le module SetBIOS.psm1
|
||||
4. Vérifie si un mot de passe BIOS est configuré (via WMI)
|
||||
5. Exécute Set-Bios avec le fichier CSV
|
||||
6. Utilise la variable MDT `BIOSPassword` pour éviter toute interaction
|
||||
|
||||
**Variables d'environnement utilisées**:
|
||||
- `%DEPLOYROOT%` - Racine du déploiement MDT
|
||||
- `$env:LenovoModel` - Modèle détecté automatiquement via WMI
|
||||
|
||||
**Gestion du mot de passe**:
|
||||
- Détection automatique via classe WMI: `Lenovo_BiosPasswordSettings`
|
||||
- Le script appelle `Set-Bios -Password` si un mot de passe est détecté
|
||||
- L'utilisateur sera invité à entrer le mot de passe lors de l'exécution
|
||||
|
||||
### 3. Tâche ajoutée au fichier ts.xml
|
||||
**Chemin du fichier**: `c:\MDT\Control\DEPL-W11-25H2-00\ts.xml`
|
||||
|
||||
**Emplacement**: Dans le groupe "Postinstall", après le groupe "Settings Only Bios Change Lenovo"
|
||||
|
||||
**Groupe créé**: "Configure BIOS Lenovo Full Settings"
|
||||
- **Conditions**: S'exécute pour tous les ordinateurs Lenovo ThinkCentre (détection WMI)
|
||||
- **Tâche**: Exécute le script ConfigureBIOSLenovo_TSIntegration.ps1
|
||||
- **Mode**: WinPEandFullOS
|
||||
- **Gestion d'erreur**: continueOnError=true (ne bloque pas la séquence si erreur)
|
||||
|
||||
**Condition WMI**:
|
||||
```sql
|
||||
SELECT * FROM Win32_ComputerSystemProduct WHERE Name LIKE '%ThinkCentre%' OR Name LIKE '%neo 50s%'
|
||||
```
|
||||
|
||||
### 4. Fonctionnement du mot de passe BIOS (MODE ZÉRO TOUCH)
|
||||
|
||||
La tâche fonctionne **sans intervention utilisateur**:
|
||||
|
||||
**Sans mot de passe BIOS**:
|
||||
- Le script s'exécute normalement
|
||||
- Les paramètres sont appliqués directement
|
||||
|
||||
**Avec mot de passe BIOS actif** (Zéro Touch):
|
||||
- Le script détecte l'état du mot de passe via WMI (`Lenovo_BiosPasswordSettings`)
|
||||
- Le mot de passe doit être fourni via la variable MDT `BIOSPassword`
|
||||
- Le mot de passe est utilisé directement - **AUCUNE demande interactive**
|
||||
- Les paramètres sont appliqués avec authentification automatique
|
||||
|
||||
#### Configuration du mot de passe BIOS (MODE SÉCURISÉ)
|
||||
|
||||
Ne pas stocker le mot de passe en clair dans CustomSettings.ini.
|
||||
Le mot de passe doit être récupéré via un script sécurisé avant l'étape BIOS.
|
||||
|
||||
Utilisez le script VBS suivant:
|
||||
```ini
|
||||
cscript.exe "%SCRIPTROOT%\SupportHDF\Set_BIOSPassword_FromDatabase.vbs"
|
||||
```
|
||||
|
||||
Ce script doit définir la variable MDT `BIOSPassword` en mémoire au moment de l'exécution.
|
||||
|
||||
#### Conditions obligatoires:
|
||||
- Si un mot de passe BIOS est détecté sur le système
|
||||
- ET la variable `BIOSPassword` est vide
|
||||
- → **Le script échoue avec erreur** (pas d'authentification possible)
|
||||
|
||||
#### Recommandations sécurité:
|
||||
1. Ne pas mettre le mot de passe en clair dans CustomSettings.ini
|
||||
2. Utiliser un script VBS de prédeploiement qui:
|
||||
- Récupère le mot de passe depuis une source chiffrée ou sécurisée
|
||||
- Le définit dans la variable MDT `BIOSPassword`
|
||||
3. Ne conserver aucun mot de passe BIOS en clair dans les fichiers de configuration
|
||||
|
||||
|
||||
### 5. Détection du modèle Lenovo
|
||||
|
||||
Le script détecte automatiquement la génération selon les critères suivants:
|
||||
- **Gen 5**: Si le modèle contient "Gen 5", "Gen5", "gen 5", ou "gen5"
|
||||
- **Gen 4**: Si le modèle contient "Gen 4", "Gen4", "gen 4", ou "gen4"
|
||||
- **Gen 3 (par défaut)**: Tous les autres cas
|
||||
|
||||
Priorité de détection:
|
||||
1. Variable d'environnement `$env:LenovoModel` (si définie)
|
||||
2. WMI `Win32_ComputerSystemProduct.Name` (détection locale)
|
||||
3. Défaut: Gen 3
|
||||
|
||||
### 6. Points importants
|
||||
|
||||
✓ **La tâche existante n'est pas modifiée** - Le groupe "Settings Only Bios Change Lenovo" reste inchangé (disabled=true)
|
||||
|
||||
✓ **Gestion différenciée** - Chaque génération (Gen3, Gen4, Gen5) a son propre fichier CSV
|
||||
|
||||
✓ **Détection du mot de passe** - Automatique via WMI, pas besoin de variable manuelle
|
||||
|
||||
✓ **Sécurité** - Le script affiche les détails de la configuration dans les logs MDT
|
||||
|
||||
### 7. Tests recommandés
|
||||
|
||||
Pour tester correctement:
|
||||
1. **Commencer par Gen5** (comme demandé)
|
||||
2. Vérifier les logs de la séquence de tâches: `C:\MININT\SMSTS.log`
|
||||
3. Tester avec et sans mot de passe BIOS configuré
|
||||
4. Vérifier que les paramètres BIOS sont bien appliqués après le redémarrage
|
||||
|
||||
### 8. Variables d'environnement MDT (optionnel)
|
||||
|
||||
Pour forcer un modèle spécifique, vous pouvez définir dans CustomSettings.ini:
|
||||
```ini
|
||||
[Default]
|
||||
LenovoModel=ThinkCentre neo 50s Gen 5
|
||||
BIOSPassword=MonMotDePasse ; ZÉRO TOUCH - Mode automatique sans interaction
|
||||
```
|
||||
|
||||
### 9. Configuration des tests
|
||||
|
||||
#### Mode ZÉRO TOUCH (Recommandé):
|
||||
1. Ajouter la variable `BIOSPassword` dans CustomSettings.ini
|
||||
2. Ou utiliser un script VBS pour la définir depuis une source sécurisée
|
||||
3. Le déploiement fonctionnera sans demande de mot de passe
|
||||
|
||||
#### Mode sans mot de passe:
|
||||
1. Laisser `BIOSPassword` vide
|
||||
2. S'assurer que le BIOS Lenovo n'a pas de mot de passe configuré
|
||||
3. Le déploiement s'exécutera directement
|
||||
|
||||
### 10. Architecture sécurisée recommandée
|
||||
|
||||
**Approche SANS clair en production**:
|
||||
|
||||
```
|
||||
Fichier CustomSettings.ini
|
||||
↓
|
||||
(appelle)
|
||||
↓
|
||||
Set_BIOSPassword_FromDatabase.vbs
|
||||
↓
|
||||
(récupère de):
|
||||
- Base de données chiffrée
|
||||
- Active Directory (attribut personnalisé)
|
||||
- API HTTPS (coffre-fort d'entreprise)
|
||||
- Fichier sécurisé (permissions AD)
|
||||
↓
|
||||
Variable MDT: BIOSPassword
|
||||
↓
|
||||
ConfigureBIOSLenovo_TSIntegration.ps1
|
||||
↓
|
||||
Module SetBIOS (applique les paramètres)
|
||||
```
|
||||
|
||||
### 11. Fichiers de support
|
||||
|
||||
Fichiers d'exemple fournis:
|
||||
- **CustomSettings_BIOS_Example.ini** - Exemples de configuration
|
||||
- **Set_BIOSPassword_FromDatabase.vbs** - Script pour récupérer le mot de passe sécurisement
|
||||
|
||||
### 9. Fichiers modifiés/créés
|
||||
|
||||
```
|
||||
c:\MDT\
|
||||
├── Scripts\
|
||||
│ └── SupportHDF\
|
||||
│ ├── CSV\
|
||||
│ │ ├── ConfigBIOSLenovo_Gen3.csv [CRÉÉ]
|
||||
│ │ ├── ConfigBIOSLenovo_Gen4.csv [CRÉÉ]
|
||||
│ │ └── ConfigBIOSLenovo_Gen5.csv [CRÉÉ]
|
||||
│ └── ps1\
|
||||
│ └── ConfigureBIOSLenovo_TSIntegration.ps1 [CRÉÉ]
|
||||
└── Control\
|
||||
└── DEPL-W11-25H2-00\
|
||||
└── ts.xml [MODIFIÉ - Groupe "Configure BIOS Lenovo Full Settings" ajouté]
|
||||
```
|
||||
|
||||
---
|
||||
**Date de création**: 28/05/2026
|
||||
**Module SetBIOS utilisé**: 1.0 (c:\MDT\Tools\Modules\SetBIOS\1.0\SetBIOS.psm1)
|
||||
@@ -0,0 +1,153 @@
|
||||
' =========================================================
|
||||
' EXEMPLE: Set_BIOSPassword_FromDatabase.vbs
|
||||
' =========================================================
|
||||
' Script VBS pour récupérer le mot de passe BIOS de manière sécurisée
|
||||
' À intégrer dans la séquence de tâches MDT ou DeployWiz_Initialization.vbs
|
||||
'
|
||||
' UTILISATION:
|
||||
' 1. Adapter ce script pour votre source (BD, LDAP, fichier sécurisé, etc.)
|
||||
' 2. L'ajouter en étape de prédeploiement
|
||||
' 3. Le script définira la variable MDT BIOSPassword
|
||||
' 4. ConfigureBIOSLenovo_TSIntegration.ps1 la récupérera automatiquement
|
||||
'
|
||||
' =========================================================
|
||||
|
||||
' Charger les objets MDT
|
||||
Set objMDT = CreateObject("Microsoft.SMS.TSEnvironment")
|
||||
Set objShell = CreateObject("WScript.Shell")
|
||||
|
||||
' Variables de diagnostic
|
||||
Dim strComputer, strModel, strPassword, strSource
|
||||
strComputer = objMDT("ComputerName")
|
||||
strModel = ""
|
||||
|
||||
' =========================================================
|
||||
' EXEMPLE 1: Récupérer le mot de passe depuis un fichier sécurisé
|
||||
' =========================================================
|
||||
Function GetPasswordFromFile()
|
||||
Dim objFSO, objFile, strLine
|
||||
Dim strPasswordFile
|
||||
|
||||
' Fichier sécurisé en lecture seule (permissions AD)
|
||||
strPasswordFile = "\\serveur\partage_admin\bios_passwords.txt"
|
||||
|
||||
On Error Resume Next
|
||||
Set objFSO = CreateObject("Scripting.FileSystemObject")
|
||||
|
||||
If objFSO.FileExists(strPasswordFile) Then
|
||||
Set objFile = objFSO.OpenTextFile(strPasswordFile, 1) ' Lecture seule
|
||||
Do While Not objFile.AtEndOfStream
|
||||
strLine = objFile.ReadLine()
|
||||
' Format du fichier: NOM_ORDINATEUR=MOTDEPASSE
|
||||
If InStr(strLine, strComputer & "=") > 0 Then
|
||||
GetPasswordFromFile = Split(strLine, "=")(1)
|
||||
Exit Function
|
||||
End If
|
||||
Loop
|
||||
objFile.Close()
|
||||
End If
|
||||
|
||||
GetPasswordFromFile = ""
|
||||
End Function
|
||||
|
||||
' =========================================================
|
||||
' EXEMPLE 2: Récupérer le mot de passe depuis Active Directory
|
||||
' =========================================================
|
||||
Function GetPasswordFromAD()
|
||||
Dim objAD, objComputer, strPassword
|
||||
|
||||
On Error Resume Next
|
||||
Set objAD = CreateObject("ADSystemInfo")
|
||||
Set objComputer = GetObject("LDAP://<SID=" & objAD.ComputerSID & ">")
|
||||
|
||||
' Attribut personnalisé AD (ex: "biosPassword")
|
||||
If objComputer.Get("biosPassword") <> "" Then
|
||||
GetPasswordFromAD = objComputer.Get("biosPassword")
|
||||
Else
|
||||
GetPasswordFromAD = ""
|
||||
End If
|
||||
End Function
|
||||
|
||||
' =========================================================
|
||||
' EXEMPLE 3: Récupérer depuis un appel HTTPS/JSON (API)
|
||||
' =========================================================
|
||||
Function GetPasswordFromAPI()
|
||||
Dim objHTTP, strURL, strResponse, objJSON
|
||||
|
||||
' URL sécurisée HTTPS avec authentification
|
||||
' Exemple: https://api.interne.com/bios/password?computer=PC001
|
||||
strURL = "https://api.interne.com/bios/password?computer=" & strComputer
|
||||
|
||||
On Error Resume Next
|
||||
Set objHTTP = CreateObject("MSXML2.XMLHTTP.6.0")
|
||||
|
||||
With objHTTP
|
||||
.Open "GET", strURL, False
|
||||
.setRequestHeader "Authorization", "Bearer TOKEN_AUTHENTICATION"
|
||||
.Send
|
||||
|
||||
If .Status = 200 Then
|
||||
' Parser la réponse JSON (exemple simplifié)
|
||||
strResponse = .ResponseText
|
||||
' Implémenter le parsing JSON selon votre API
|
||||
GetPasswordFromAPI = strResponse
|
||||
End If
|
||||
End With
|
||||
End Function
|
||||
|
||||
' =========================================================
|
||||
' RÉCUPÉRER LE MOT DE PASSE (ordre de priorité)
|
||||
' =========================================================
|
||||
Dim strBIOSPassword
|
||||
strBIOSPassword = ""
|
||||
|
||||
' 1. Essayer le fichier sécurisé
|
||||
strBIOSPassword = GetPasswordFromFile()
|
||||
If strBIOSPassword = "" Then
|
||||
WScript.Echo "[INFO] Mot de passe non trouvé dans fichier sécurisé"
|
||||
End If
|
||||
|
||||
' 2. Essayer Active Directory
|
||||
If strBIOSPassword = "" Then
|
||||
strBIOSPassword = GetPasswordFromAD()
|
||||
If strBIOSPassword = "" Then
|
||||
WScript.Echo "[INFO] Mot de passe non trouvé dans Active Directory"
|
||||
End If
|
||||
End If
|
||||
|
||||
' 3. Essayer l'API HTTPS
|
||||
If strBIOSPassword = "" Then
|
||||
strBIOSPassword = GetPasswordFromAPI()
|
||||
If strBIOSPassword = "" Then
|
||||
WScript.Echo "[INFO] Mot de passe non trouvé via API"
|
||||
End If
|
||||
End If
|
||||
|
||||
' =========================================================
|
||||
' DÉFINIR LA VARIABLE MDT
|
||||
' =========================================================
|
||||
If strBIOSPassword <> "" Then
|
||||
objMDT("BIOSPassword") = strBIOSPassword
|
||||
WScript.Echo "[INFO] Variable BIOSPassword définie avec succès"
|
||||
WScript.Echo "[INFO] Ordinateur: " & strComputer
|
||||
WScript.Echo "[INFO] Longueur mot de passe: " & Len(strBIOSPassword) & " caractères"
|
||||
Else
|
||||
WScript.Echo "[WARN] Impossible de récupérer le mot de passe BIOS"
|
||||
WScript.Echo "[WARN] Déploiement sans authentification BIOS"
|
||||
objMDT("BIOSPassword") = ""
|
||||
End If
|
||||
|
||||
' =========================================================
|
||||
' INTÉGRATION DANS LA SÉQUENCE MDT
|
||||
' =========================================================
|
||||
'
|
||||
' Pour utiliser ce script:
|
||||
'
|
||||
' 1. Sauvegarder en tant que: %DEPLOYROOT%\Scripts\Set_BIOSPassword.vbs
|
||||
' 2. Ajouter une étape "Exécuter un script" AVANT la tâche BIOS
|
||||
' 3. Commande: cscript.exe "%SCRIPTROOT%\Set_BIOSPassword.vbs"
|
||||
' 4. La variable MDT BIOSPassword sera disponible pour le script PowerShell
|
||||
'
|
||||
' =========================================================
|
||||
|
||||
WScript.Quit(0)
|
||||
@@ -0,0 +1,104 @@
|
||||
# ConfigureBIOSLenovo_TSIntegration.ps1
|
||||
# Applique les paramètres BIOS Lenovo via le module SetBIOS
|
||||
# Mode ZÉRO TOUCH - Pas d'interaction utilisateur
|
||||
# Utilise une variable MDT BIOSPassword pour authentification automatique
|
||||
|
||||
Write-Output "[INFO] ========== Démarrage de la configuration BIOS Lenovo (Zéro Touch) =========="
|
||||
|
||||
# Déterminer le modèle Lenovo et sélectionner le fichier CSV approprié
|
||||
$LenovoModel = $env:LenovoModel
|
||||
|
||||
if ([string]::IsNullOrEmpty($LenovoModel)) {
|
||||
try {
|
||||
$LenovoModel = (Get-WmiObject Win32_ComputerSystemProduct -ErrorAction Stop).Name
|
||||
Write-Output "[INFO] LenovoModel obtenu via WMI: $LenovoModel"
|
||||
}
|
||||
catch {
|
||||
Write-Output "[WARN] Impossible de déterminer le modèle Lenovo - utilisation de la valeur par défaut Gen 3"
|
||||
$LenovoModel = "Gen 3"
|
||||
}
|
||||
}
|
||||
|
||||
# Déterminer le fichier CSV selon la génération
|
||||
if ($LenovoModel -like "*Gen 5*" -or $LenovoModel -like "*Gen5*" -or $LenovoModel -like "*gen 5*" -or $LenovoModel -like "*gen5*") {
|
||||
Write-Output "[INFO] Détection ThinkCentre neo 50s Gen 5 ($LenovoModel)"
|
||||
$CSVFile = "%DEPLOYROOT%\Scripts\SupportHDF\CSV\ConfigBIOSLenovo_Gen5.csv"
|
||||
} elseif ($LenovoModel -like "*Gen 4*" -or $LenovoModel -like "*Gen4*" -or $LenovoModel -like "*gen 4*" -or $LenovoModel -like "*gen4*") {
|
||||
Write-Output "[INFO] Détection ThinkCentre neo 50s Gen 4 ($LenovoModel)"
|
||||
$CSVFile = "%DEPLOYROOT%\Scripts\SupportHDF\CSV\ConfigBIOSLenovo_Gen4.csv"
|
||||
} else {
|
||||
Write-Output "[INFO] Détection ThinkCentre neo 50s Gen 3 ou antérieur ($LenovoModel)"
|
||||
$CSVFile = "%DEPLOYROOT%\Scripts\SupportHDF\CSV\ConfigBIOSLenovo_Gen3.csv"
|
||||
}
|
||||
|
||||
# Remplacer %DEPLOYROOT% par la vraie valeur
|
||||
$CSVFile = $CSVFile -replace "%DEPLOYROOT%", $env:DEPLOYROOT
|
||||
|
||||
# Vérifier que le fichier CSV existe
|
||||
if (!(Test-Path $CSVFile)) {
|
||||
Write-Output "[ERROR] Fichier CSV non trouvé: $CSVFile"
|
||||
exit 1
|
||||
}
|
||||
|
||||
Write-Output "[INFO] Utilisation du fichier CSV: $CSVFile"
|
||||
|
||||
# Charger le module SetBIOS
|
||||
$SetBIOSModule = Join-Path $env:DEPLOYROOT "Tools\Modules\SetBIOS\1.0\SetBIOS.psm1"
|
||||
if (!(Test-Path $SetBIOSModule)) {
|
||||
Write-Output "[ERROR] Module SetBIOS non trouvé: $SetBIOSModule"
|
||||
exit 1
|
||||
}
|
||||
|
||||
try {
|
||||
Import-Module $SetBIOSModule -ErrorAction Stop -Force
|
||||
Write-Output "[INFO] Module SetBIOS importé avec succès"
|
||||
} catch {
|
||||
Write-Output "[ERROR] Impossible d'importer le module SetBIOS: $_"
|
||||
exit 1
|
||||
}
|
||||
|
||||
# Récupérer le mot de passe BIOS depuis les variables MDT
|
||||
$BIOSPassword = $env:BIOSPassword
|
||||
if ([string]::IsNullOrEmpty($BIOSPassword)) {
|
||||
Write-Output "[WARN] Variable MDT BIOSPassword non trouvée"
|
||||
}
|
||||
|
||||
# Vérifier si un mot de passe BIOS est configuré sur le système
|
||||
Write-Output "[INFO] Vérification de l'état du mot de passe BIOS..."
|
||||
try {
|
||||
$BIOSPasswordSettings = Get-WmiObject -Class Lenovo_BiosPasswordSettings -Namespace root\wmi -ErrorAction Stop
|
||||
$PasswordState = $BIOSPasswordSettings.PasswordState
|
||||
Write-Output "[INFO] État du mot de passe BIOS: $PasswordState (0=Pas de mot de passe, 1=Admin, 2=Système, 3=Utilisateur)"
|
||||
|
||||
$IsPasswordSet = ($PasswordState -eq 2 -or $PasswordState -eq 1 -or $PasswordState -eq 3)
|
||||
} catch {
|
||||
Write-Output "[WARN] Impossible de vérifier l'état du mot de passe BIOS via WMI: $_"
|
||||
$IsPasswordSet = $false
|
||||
}
|
||||
|
||||
# Vérifier cohérence mot de passe
|
||||
if ($IsPasswordSet -and [string]::IsNullOrEmpty($BIOSPassword)) {
|
||||
Write-Output "[ERROR] Un mot de passe BIOS est configuré mais la variable MDT BIOSPassword est vide"
|
||||
Write-Output "[ERROR] Ajoutez 'BIOSPassword=VOTRE_MOT_DE_PASSE' dans CustomSettings.ini"
|
||||
exit 1
|
||||
}
|
||||
|
||||
# Exécuter Set-BIOS avec le fichier CSV - Zéro Touch
|
||||
try {
|
||||
Write-Output "[INFO] Application des paramètres BIOS Lenovo..."
|
||||
|
||||
if ($IsPasswordSet -and -not [string]::IsNullOrEmpty($BIOSPassword)) {
|
||||
Write-Output "[INFO] Application des paramètres avec authentification BIOS..."
|
||||
Set-Bios -CSV $CSVFile -PasswordValue $BIOSPassword -ErrorAction Stop
|
||||
} else {
|
||||
Write-Output "[INFO] Application des paramètres BIOS sans authentification..."
|
||||
Set-Bios -CSV $CSVFile -ErrorAction Stop
|
||||
}
|
||||
|
||||
Write-Output "[INFO] ========== Paramètres BIOS appliqués avec succès (Zéro Touch) =========="
|
||||
exit 0
|
||||
} catch {
|
||||
Write-Output "[ERROR] Erreur lors de l'application des paramètres BIOS: $_"
|
||||
Write-Output "[ERROR] ========== Configuration BIOS échouée =========="
|
||||
exit 1
|
||||
}
|
||||
Reference in New Issue
Block a user