Certificate Based Bios Management - Lenovo ThinkPad Z13 Gen 2 User Manual

Hide thumbs Also See for ThinkPad Z13 Gen 2:
Table of Contents

Advertisement

2. Press F12 during the power-on process.
3. If you set a power-on password, you are prompted to enter the correct password.
4. Select App Menu ➙ ThinkShield Passwordless Power-On Device Manager and press Enter.
5. Insert the FIDO2 USB device to register the device by following steps:
a. Select the available FIDO2 USB device that you want to register in the Discovered Devices field.
b. Click Yes in the displayed window to confirm the device you selected.
c. If you set a power-on password, you are prompted to enter the correct password.
d. The User operation request window is displayed. You are prompted to press the button on the
connected FIDO2 USB device, and then follow the on-screen instruction to close the window.
e. Press Esc to exit and restart your computer.
Notes:
• If you want to unregister your devices, click the available FIDO2 USB device that you want to unregister in
the My Device field and enter the correct power-on password for verification.
• If you use more than one FIDO2 USB device with a common identifier for registration, only one device is
available.
Log in to the System with Passwordless Power-On Authentication
1. Restart the computer.
2. ThinkShield Passwordless Power-On Authentication window is displayed.
3. Insert your registered FIDO2 USB device for detection.
4. Then follow the on-screen instruction to press the button on your FIDO2 USB device for verification.
5. After your device is verified, the power-on process continues.
Note: You should insert the FIDO2 USB device or enter the power-on password within 60 seconds.
Otherwise, your computer will shut down automatically.

Certificate based BIOS management

Certificate-based BIOS authentication (also called the password-less management mode) provides more
secure UEFI BIOS management with password-free solution. It is used to replace the supervisor password /
system management password for authentication if you have set one.
Note: Supervisor password / system management password are disabled automatically when certificate
mode is enabled. But the power-on password / hard disk password / NVMe password still can be used
normally in certificate mode if you have set one.
For certificate enrollment, see Certificate Enrollment Guide at:
enrollment_guide
Enter the BIOS menu with certificate
Once you have enrolled the certificate, you can enter the BIOS menu with the certificate.
1. Restart the computer. When the logo screen is displayed, press F1 to enter the UEFI BIOS menu.
2. The QR code is displayed. Scan the QR code to save the request data and send the request data to IT
admin by e-mail or phone.
Note: If you choose to authenticate without the QR code, save the request data in a USB key and send
the request data to IT admin by e-mail or phone.
3. Enter the unlock code provided by IT admin and click OK.
https://support.lenovo.com/docs/certificate_
.
Chapter 4
Secure your computer and information
31

Advertisement

Table of Contents
loading

This manual is also suitable for:

Thinkpad z16 gen 2

Table of Contents