Everything you want to know about

Slides:



Advertisements
Similar presentations
Microsoft ® Official Course First Look Clinic Overview of Windows 8 By Ragowo Riantory, S.Kom, MCP.
Advertisements

Mark O’Shea | MVP Windows Expert – IT Professional.
Windows 8: Windows To Go Overview Zvezdan PavkovicTanya Koval Senior ConsultantArchitect WCL333.
MCITP: Microsoft Windows Vista Desktop Support - Enterprise Section 1: Prepare to Deploy.
Automating Microsoft Azure with PowerShell MMS Minnesota 2014 Trevor Sullivan and David O’Brien – #MMSMinnesota.
Windows Deployment - Now and Into the Future
Implementering af Windows 8 in real life Windows 8 OS Deployment Windows 8 OS Deployment features of ConfigMgr 2012 SP1 Take a look at what’s coming.
Windows 7 Deployment Tools and Technologies
Managing Your Datacenter with Microsoft System Center Configuration Manager Kent Agerlund, ECM MVP, Coretech.
Session Agenda Designed to address BIOS Limitations Needed for the larger server platforms (Intel-HP Itanium) First called Intel Boot Initiative.
Troubleshooting OS Deployment MMS Minnesota 2014 Johan Michael #MMSOSD.
Scott Drucker, Systems Engineer Migrating to Microsoft Vista with WinINSTALL.
TechEd /25/2017 5:34 AM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
End to End Automation with MDT Managing your reference images. Fred om Daniel
Windows 10 Setup InternalsWindows 10 Setup Internals Johan
Are you Ready for Configuration Manager vNext?
PowerShell Package Management for the Enterprise Kirk Aleksandar
Windows 10 Feature & Servicing Updates Options and Demystifying Steven Rachui
RAID Mode With 2.2TB HDD on AMD with EFI
Define, bundle, deployDefine, bundle, deploy Working with Windows Server Containers and Docker James David O’Brien.
with Configuration Manager, MDT, and Intune
ConfigMgr! Intune! Azure!ConfigMgr! Intune! Azure! Understanding Cloud Based Management Options Steven Rachui
Monitoring and Managing the Hybrid Cloud with System Center
Managing Third Party Updates with Microsoft’s System Center Configuration Manager Secunia Integration, MMS 2015 Kent AgerlundSherry Kissinger.
Infrastructure & Operational Maturity And Why You Should Care Kerrie Meyler, MVP networkworld.com/author/kerrie- meyler/ John Joyner, MVP opsmgrunleashed.wordpress.com/
Nano ServerNano Server The Future of Window Server Mikael Johan
House of tails dogs charity All donations go 100% to the charity #MMSGIVEBACK.
Managing iOS Device Using ConfigMgr and Intune Hybrid MDM John Presenter #2 Twitter Handle Blog or address.
Critical Security Controls & Effective Cyber Defense Hasain “The Wolf”
Automating Reference ImagesAutomating Reference Images Henrik Blog.coretech.dk/hra Kent Blog.coretech.dk/kea.
How to Model an Application for Monitoring Nathan Jonathan
Introduction to Administering a SQL Server Matthew Steve Thompson, stevethompsonmvp.wordpress.com.
The Art of deploying Windows 10 With ConfigMgr 2012 R2 Johan Mikael
XPlatform ManagementxPlatform Management Windows Provisioning from *nix David James.
Midwest Management Summit MMSSQL – What are Your SQL Reporting Questions? #MMSMinnesot a #MMSSQL.
ConfigMgr 2012 SQL Refresher MMS Minnesota 2014 Matthew Teegarden/Steve Thompson.
Introduction to T-SQL – Part Deux Matthew Sherry Kissinger kissinger.
OS Deployment - LEVEL 500OS Deployment - LEVEL 500 Johan
App-V: An Overview MMS Minnesota 2014 Fred #MMSMinnesota #MMSAppV.
Restricted Admin & Credential Exposure MMS Minnesota 2014 Hasain Alshakarti – TrueSec Enterprise Security #MMSMinnesota #MMSConfigMgr #MMSLove.
Server OS Deployment Deep Dive with two crazy guys and ConfigMgr 2012 R2 MMS Minnesota 2014 Greg Nash.
Sweet SUITE Imaging MMS Minnesota 2014 #MMSMinnesota #MMSConfigMgr #MMSLove Steven Rachui Premier Field Engineer Microsoft Corporation
Secure Boot.
Automating Installations by Using the Microsoft Windows 2000 Setup Manager Create setup scripts simply and easily. Create and modify answer files and UDFs.
WELCOME. Skills and Techniques - Session 2 Skills and Techniques Booting from Windows 8.1 and Windows 10 devices.
SQL Tips & Tricks Best practices from the field John Nelson Apps Systems Engineer Steve Thompson Senior Consultant,
Long Live Azure Automation!Long Live Azure Automation! Cloud-first Configuration Management and Automation Beth Cooper Program Manager.
Configuration Manager Deploying Surface Pro 3 with Configuration Manager Niall Brady ECM MVP
Updating yourUpdating your Enterprise Environment Ronnie Jakobsen Senior Architect Coretech Kent Agerlund Chief Technical Architect.
What's up with all these Windows 10 options?
Prepare for Windows 10 and UEFI
Moving to Windows 10 Vishal Ladwa – PowerONPlatforms Consultant
Extended Operating System Support
Leveraging Vendor Tools for Client Management Productivity
Exploring the wealth of Configmgr Community tools
System Center 2012 Configuration Manager
How To Implement and Stay Out of the News
Manage Microsoft devices like a Pro
If You Simply Deploy Windows 10, You Failed
Migrating Infrastructure to Microsoft Azure
Shielded VM and Guarded Fabric
Modernize ConfigMgr OSD with Community Tools
11/8/2018 5:04 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Hardware Security: Keeping Drivers and Firmware Updated Jason Ross
11/23/2018 3:03 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Option ROM Designs for UEFI
The bios.
Deploying and Managing Windows To Go
Microsoft 365 Business Technical Fundamentals Series
SCCM in hybrid world Predrag Jelesijević Microsoft 7/6/ :17 AM
Presentation transcript:

Everything you want to know about BIOS-UEFI Settings Niall C. Brady niall@windows-noob.com Windows-noob Ronnie Jakobsen rja@coretech.dk Coretech Mike Terrill mike.terrill@1e.com 1E

Everything you want to know about BIOS-UEFI Settings Niall C. Brady niall@windows-noob.com Windows-noob Ronnie Jakobsen rja@coretech.dk Coretech Mike Terrill mike.terrill@1e.com 1E

Mike Terrill Ronnie Jakobsen Niall C. Brady @ncbrady AZSMUG 9+ Years 6 year ECM MVP Deploying Windows since Windows NT 4.0/ConfigMgr since SMS1.2 Working in IT since NT was hot, started programming in 1981 on a TI-99 Working with SCCM since SMS 2003, started programming in 1985 in ZX80 Assembly $$$ Tequila Whisky Preferably Scottish Whiskey

Agenda Why UEFI? Upgrade methodologies: Refreshing an UEFI BitLocker’ed device Bare minimum BIOS settings for UEFI OEM specific settings Configuring settings programmatically Inventory vendor specific settings

Why UEFI?

Upgrade Methodologies Could do Wait for hardware replacement to do the switch Deploy Windows 10 to BIOS machines Should do Switch over UEFI if at all possible Automate the switch to save you a lot of time Should not do Convert to UEFI for performance benefits Convert to UEFI and disable Secure Boot Manually switch your hardware to UEFI Not move to UEFI at all

Refreshing (not upgrading) an UEFI BitLocker’ed device

Bare minimum BIOS settings for UEFI Boot mode (or BIOS mode) Boot list order Secure Boot PXE UEFI Network Boot Upgrade to the latest BIOS-UEFI version!!! (For more info, see Updating your Enterprise Environment)

Settings of Interest BIOS Settings: Boot Mode (i.e. Legacy, UEFI Hybrid, UEFI Native) Secure Boot (not just enabled or disabled, but capable) UEFI PXE Virtualization Settings (DEP, VTd, VTx) TPM (OS mgmt, Activation Policy, Device) WOL Device Boot Order: Legacy, UEFI, Network

Client Architecture Types (Option 93) UEFI PXE Booting Client Architecture Types (Option 93) Boot Image Type Architecture Name x86 x64 Intel x86PC ● ○ 1 NEC/PC98 2 EFI Itanium 3 DEC Alpha 4 Arc x86 5 Intel Lean Client 6 EFI IA32 7 EFI BC 8 EFI Xscale 9 EFI x86-64

Booting with ConfigMgr BIOS Configuration Boot List Option Legacy Option ROMs (CSM) _SMSTSBootUEFI Client Architecture PC BIOS Legacy Enabled FALSE Intel x86PC UEFI Hybrid (with Legacy ROMs) UEFI FALSE* TRUE* Intel x86PC* EFI BC* Disabled TRUE EFI BC

Vendor specific settings – Dell, HP and Lenovo

Configure Settings Programmatically Vendor tools - Dell Dell Command | Configure (aka CCTK) Get BIOS mode: Cctk bootorder --activebootlist Enable UEFI: Cctk bootorder --activebootlist=uefi Get Legacy ROM setting (aka CSM): Cctk --legacyorom Disable Legacy ROMs: Cctk --legacyorom=disable Enable Secure Boot: Cctk --secureboot=enable

Configure Settings Programmatically Vendor tools - HP HP BIOS Configuration Utility Get BIOS mode: BiosConfigUtility(64).exe Enable UEFI: BiosConfigUtility(64).exe /setvalue:"Boot Mode","UEFI Native (Without CSM)" Enable Secure Boot: BiosConfigUtility(64).exe /setvalue:"SecureBoot","Enable"

Configure Settings Programmatically Vendor tools - Lenovo One method – VBScript Get current settings: Cscript ListAll.vbs Enable UEFI & Secure Boot: Cscript SetConfig.vbs SecureBoot Enable

And Then … Discuss: Evaluations: Ask your questions-real world answers! Plenty of time to engage, share knowledge. Discuss: Evaluations: Please provide session feedback by clicking the EVAL button in the scheduler app (also download slides). One lucky winner will receive a free ticket to the next MMS!

And Then …

Q & A / Discussion

Windows 10 Servicing with Configuration Manager Other Sessions: Niall Windows 10 Servicing with Configuration Manager Tuesday at 11:00 AM & Wednesday at 2:00 PM

Other Sessions: Mike & Ronnie Everything you want to know about BIOS/UEFI Settings Tuesday at 2:00 PM Updating your Enterprise Environment Wednesday at 11:00 AM Configuration Manager meet Power BI Thursday at 2:00 PM