Temporary Pre-boot Bypass with a Script
If you run scripts to do unattended maintenance or installations (for example, SCCM) you
might want the script to reboot the system and let the script continue after reboot. This requires
the script to turn off Pre-boot when the computer is rebooted. Enable this feature in the
Temporary Pre-boot Bypass Settings windows. The Temporary Pre-boot Bypass script can
only run during the timeframe configured in Temporary Pre-boot Bypass Settings.
Running a Temporary Pre-boot Bypass script
In a script you execute the FdeControl.exe utility to enable or disable Pre-boot at the next
restart:
n
Run: FDEControl.exe set-wol-on to enable Temporary Pre-boot Bypass.
Run: FDEControl.exe set-wol-off to disable Temporary Pre-boot Bypass.
n
The above commands will fail with code 13 ( UNAUTHORIZED ) if executed outside the
timeframe specified in the policy.
Temporarily Require Pre-boot
If you do not require Pre-boot, users go straight to the Windows login. Because this makes the
computer less secure, we recommend that you require Pre-boot authentication in some
scenarios.
To temporarily require Pre-boot:
1. In a Full Disk Encryption rule in the Policy, right-click the Do not authenticate before
OS loads Pre-boot Action and select Edit Properties.
2. Configure these options to Require Pre-boot authentication if one or more of these
conditions are met:
n
More than X failed logon attempts were made - If a user's failed logon attempts
exceed the number of tries specified, Pre-boot is required. The computer
automatically reboots and the user must authenticate in Pre-boot.
n
The hard disk is not used by the original computer (hardware Hash) -If selected,
the client generates a hardware hash from identification data found in the BIOS
and on the CPU. If the hard drive is stolen and put in a different computer, the hash
will be incorrect and Pre-boot is required. The computer reboots automatically, and
the user must authenticate in Pre-boot.
Warning - Clear this option before you upgrade BIOS firmware or replace
hardware. After the upgrade, the hardware hash is automatically updated to match
the new configuration.
Authentication before the Operating System Loads (Pre-boot)
R81 Harmony Endpoint Server Administration Guide | 194
Need help?
Do you have a question about the HARMONY R81 and is the answer not in the manual?