Table3.Securitymenuitems(continued)
Menuitem
Submenuitem
Value
Comments
SecureBoot
•Disabled
•Enabled
EnableordisabletheUEFISecureBootfeature.
SelectEnabletopreventunauthorizedoperating
systemsfromrunningatboottime.Select
Disabledtoallowanyoperatingsystemstorun
atboottime.
PlatformMode
•SetupMode
•UserMode
Specifythesystemoperatingmode.
SecureBootMode•StandardMode
•CustomMode
SpecifytheSecureBootmode.
ResettoSetupMode
Thisoptionisusedtoclearthecurrentplatform
keyandputthesystemintoSetupMode.You
caninstallyourownplatformkeyandcustomize
theSecureBootsignaturedatabasesinSetup
Mode.
SecureBootmodewillbesettoCustomMode.
RestoreFactory
Keys
Thisoptionisusedtorestoreallkeysand
certificatesinSecureBootdatabasestofactory
defaults.AnycustomizedSecureBootsettings
willbeerased,andthedefaultplatformkey
willbere-establishedalongwiththeoriginal
signaturedatabasesincludingcertificateforthe
Windows8andWindows10operatingsystems.
SecureBoot
ClearAllSecure
BootKeys
Thisoptionisusedtoclearallkeysand
certificatesinSecureBootdatabases.You
caninstallyourownkeysandcertificatesafter
selectingthisoption.
IntelSGXControlIntelSGXControl
•Disabled
•Enabled
•Software
Controlled
ThisoptionenablesordisablesIntelSoftware
GuardExtensions(SGX)function.
Disabled:DisablesSGX.
Enabled:EnablesSGX.
SoftwareControlled:SoftwareGuard
Extensionswillbecontrolledbytheoperating
system.
Startupmenu
Tochangethestartupsettingsofyourcomputer,selecttheStartuptabfromtheThinkPadSetupmenu.
Attention:
•Afteryouchangethestartupsequence,ensurethatyouselectacorrectdeviceduringacopy,asave,ora
formatoperation.Otherwiseyourdatamightbeerasedoroverwritten.
•IfyouareusingtheBitLockerdriveencryption,donotchangethestartupsequence.BitLockerdrive
encryptionlocksthecomputerfromstartingoncedetectsthechangeofstartupsequence.
Tochangethestartupsequencetemporarilysothatthecomputerstartsfromadesireddrive,dothefollowing:
1.Turnoffthecomputer.
2.Turnonthecomputer.WhentheLenovologoisdisplayed,pressF12.
Chapter6.Advancedconfiguration87