Welcome to our peer-to-peer forums, where owners help owners. Need help now? Visit eSupport here.

English Community

Software and Operating SystemEnterprise Client Management
All Forum Topics
Options

4 Posts

08-08-2017

United States of America

4 Signins

62 Page Views

  • Posts: 4
  • Registered: ‎08-08-2017
  • Location: United States of America
  • Views: 62
  • Message 1 of 8

M93z - ThinkBios Config Tool - Secure Boot

2017-08-10, 13:25 PM

I am trying to use the ThinkBios Config tool to enable Secure Boot as part of an OSD refresh via MDT.  It doesn't appear to be a supported option on the M93z, but works fine on most other models including the older M92z.  The BIOS version I am using is the newest available from support.lenovo.com (FEKT9BA).

 

Secure boot doesnt show as a configurable option in the tool's GUI and obvioulsy isnt configurable via the command line tool either.

 

Any ideas as to why this function isnt supported on the M93z?

Reply
Options

2001 Posts

03-03-2016

United States of America

4004 Signins

48065 Page Views

  • Posts: 2001
  • Registered: ‎03-03-2016
  • Location: United States of America
  • Views: 48065
  • Message 2 of 8

Re: M93z - ThinkBios Config Tool - Secure Boot

2017-08-10, 14:05 PM

steven121,

 

I have confirmed with our ThinkCentre Engineer that this is currently not working, but it is known and they are actively working to resolve it in a future BIOS release.

 

I dont know if this will help you, but if you can set OS Optimized Defaults to Enabled in the ThinkBIOS Config Tool, this may work around that issue.  If you have customizations in the BIOS, (ie Front USB Ports Disabled or something like that), then you may want to capture the entire set of settings generated by ThinkBIOS Config Tool.  *** Remember this will only effect non-Security settings.***  If you apply with OS Optimized Defaults set to enabled, and have all your other customizations in the output file, it should keep all the settings.

 

HTH,

 

Tlawson

Reply
Options

4 Posts

08-08-2017

United States of America

4 Signins

62 Page Views

  • Posts: 4
  • Registered: ‎08-08-2017
  • Location: United States of America
  • Views: 62
  • Message 3 of 8

Re: M93z - ThinkBios Config Tool - Secure Boot

2017-08-10, 17:55 PM

Alas, no luck.  On the M93z, "OS Optimized Defaults" is not a configurable option with the tool.  I ran the tool on an M900z and it is an option alongside Secure Boot.  

 

Is there an ETA on the updated BIOS for the M93z?

 

 

Reply
Options

2001 Posts

03-03-2016

United States of America

4004 Signins

48065 Page Views

  • Posts: 2001
  • Registered: ‎03-03-2016
  • Location: United States of America
  • Views: 48065
  • Message 4 of 8

Re: M93z - ThinkBios Config Tool - Secure Boot

2017-08-10, 18:02 PM

steven121,

 

No word as of yet, but fingers crossed it will be soon.  

 

Thanks for testing that scenario, I was hoping for a work around for the time being, but it appears as though the WMI interface for Secure Boot and OS Optimized Defaults will be rolling out together.

 

Thx,

 

Tlawson

Reply
Options

4 Posts

08-08-2017

United States of America

4 Signins

62 Page Views

  • Posts: 4
  • Registered: ‎08-08-2017
  • Location: United States of America
  • Views: 62
  • Message 5 of 8

Re: M93z - ThinkBios Config Tool - Secure Boot

2017-08-10, 18:09 PM

Yeah, thanks, it was worth a try.  An option that does exist as a partial workaround is setting the "Boot mode" to "UEFI Only".  That option does at least exist on the M93z today and it gets us part of the way to our goal of implementing an OS refresh with GPT/UEFI/Secureboot enabled.

 

Is there a mechanism by which I can get a notification when the updated BIOS is available?

 

Thanks for your help.

Reply
Options

2001 Posts

03-03-2016

United States of America

4004 Signins

48065 Page Views

  • Posts: 2001
  • Registered: ‎03-03-2016
  • Location: United States of America
  • Views: 48065
  • Message 6 of 8

Re: M93z - ThinkBios Config Tool - Secure Boot

2017-08-10, 18:15 PM

steven121,

 

Yes, you can get notifications... on all your products.  Head over to http://support.lenovo.com and in the upper corner click the sign-in button.  I think your forum account will log you in, if not, create a login.  Once logged in, hover over your email address/sign in name in the corner and when the popup menu appears, select 'My Products.'  In there you can add your products (M93z or M900z).  As you are adding them to your list, setup notifications for different types of alerts.  Drivers and Downloads is what you will need.  Security notifications are good too.

 

 

HTH,

 

Tlawson

Reply
Options

1 Posts

08-09-2019

Norway

1 Signins

16 Page Views

  • Posts: 1
  • Registered: ‎08-09-2019
  • Location: Norway
  • Views: 16
  • Message 7 of 8

Re: M93z - ThinkBios Config Tool - Secure Boot

2019-08-09, 13:29 PM

Hi.

 

I had similar issues with Lenovo M900. Solved this with powershell :

 

Create a powershell script with theese two lines :

(gwmi -class Lenovo_SetBiosSetting –namespace root\wmi).SetBiosSetting("OS Optimized Defaults,Enabled")

(gwmi -class Lenovo_SaveBiosSettings -namespace root\wmi).SaveBiosSettings()

 

Create a package with your script
Create a step early in your task secuence : Run PowerShell Script
Enter your powershell scriptname
Set PowerShell execution policy to Bypass

 

See attached picture.

 

Hope this works for you as well.

 

Regards.

 

Thomas.

Reply
Options

914 Posts

06-09-2015

United States of America

5515 Signins

52226 Page Views

  • Posts: 914
  • Registered: ‎06-09-2015
  • Location: United States of America
  • Views: 52226
  • Message 8 of 8

Re: M93z - ThinkBios Config Tool - Secure Boot

2019-08-09, 13:37 PM
You can also save a few steps by entering it directly into the task sequence in the same step. thanks for posting your solution.
Reply
Forum Home

Community Guidelines

Please review our Guidelines before posting.

Learn More

Check out current deals!

Go Shop
X

Save

X

Delete

X

No, I don’t want to share ideas Yes, I agree to these terms