Category filter
Remote BIOS Password Management with Hexnode
TL;DR: Remotely configure, update, or remove BIOS and pre-boot System passwords on Windows devices directly from Actions > Security. Configured credentials can be securely retrieved in masked format under Device Info > Device Status Info.
Executive Summary
Configuring firmware security traditionally requires manual, desk-side IT visits. Hexnode UEM eliminates this operational overhead by bringing remote hardware-level password management directly to the console. Admins can restrict firmware access or lock endpoints at the pre-boot level before the OS loads.
OEM Compatibility Matrix
| Remote Action | Supported Device Manufacturers |
|---|---|
|
BIOS Password Actions
|
ASUS, HP, Dell, Lenovo |
| Set System Password | Dell |
| Change / Clear System Password | Dell, Lenovo |
How to configure BIOS & System password actions?
- Login to Hexnode UEM portal.
- Navigate to Manage > Devices.
- Select the Windows device you want to Set/Change/Clear BIOS/System password.
- Go to Actions > Security.
How to set BIOS password?
What is Set BIOS Password action?
The Set BIOS Password action configures a new password on the target Windows device to protect and lock the BIOS firmware settings.
Why use this action?
This action prevents users or unauthorized individuals from tampering with low-level hardware configurations—such as altering the boot order to boot from untrusted USB drives, disabling Secure Boot, or bypassing OS security controls. Essential during initial device onboarding or when sending devices to remote/field employees.
How to execute:
- Action: Select Set BIOS Password.
- Required Inputs: Enter the password and click Done.
How to change BIOS password?
What is Change BIOS Password action?
The Change BIOS Password action updates an existing BIOS password on the device to a new credential.
Why use this action?
This action allows admins to routinely update BIOS credentials, respond to IT staff turnover, or update credentials if an active BIOS password has been shared or exposed during physical maintenance.
How to execute:
- Action: Select Change BIOS Password.
- Required Inputs: Enter the Current password and New password, then click Done. Passwords cannot begin or end with spaces.
How to clear BIOS password?
What is Clear BIOS Password action?
The Clear BIOS Password action removes password protection from the device’s BIOS settings completely.
Why use this action?
This action is needed when offboarding endpoints, sending hardware to third-party repair vendors, returning leased equipment, or reassigning devices to teams that require open access to BIOS configurations.
How to execute:
- Action: Select Clear BIOS Password.
- Required Inputs: Enter the Current password and click Clear Password.
How to set system password?
What is Set System Password action?
The Set System Password action configures a pre-boot hardware password that locks the device before the operating system even begins to load.
Why use this action?
This action is ideal when deploying laptops to field employees or remote staff handling sensitive data. It ensures that if a device is physically lost or stolen, no one can boot the machine, access internal storage, or bypass security using external bootable drives.
How to execute:
- Action: Select Set System Password.
- Required Inputs: Enter the password and click Done.
How to change system password?
What is Change System Password action?
The Change System Password action updates the existing pre-boot system password with a new credential.
Why use this action?
This action is useful when rotating pre-boot security keys, reassigning a pre-boot locked device to a new user, or updating credentials after a potential security leak without removing hardware protection entirely.
How to execute:
- Action: Select Change System Password.
- Required Inputs: Enter the Current password and New password, then click Done. Passwords cannot begin or end with spaces.
How to clear system password?
What is Clear System Password action?
The Clear System Password action completely removes the pre-boot hardware password from the device.
Why use this action?
This action is required when transitioning a device back to standard OS-only login, sending devices for OEM vendor hardware repairs, or preparing endpoints for fleet re-imaging.
How to execute:
- Action: Select Clear System Password.
- Required Inputs: Enter the Current password and click Clear Password.
View BIOS & System Password
The configured or updated BIOS and System passwords can be viewed by navigating to: Manage > Devices > select the target device > Device Info tab > Device Status Info section. Click the eye icon toggle to reveal the password.
This provides authorized IT administrators with a secure, centralized location to retrieve active hardware credentials. It serves as a critical safeguard during on-site hardware maintenance, device reassignments, or troubleshooting, allowing admins to instantly recover credentials if local passwords are forgotten or lost to prevent device lockouts.
Frequently Asked Questions
What happens if a space is accidentally included at the beginning or end of a BIOS/System password?
Hexnode UEM automatically trims any leading or trailing spaces from BIOS/System password inputs before applying them to prevent accidental lockouts caused by invisible characters.
How to check if a BIOS or System password action was successfully applied to a device?
Navigate to Action History under the device summary page in the Hexnode UEM console. Once the command reaches and processes on the endpoint, the action status will update to Success.
Will Hexnode display password changes made directly on the physical device?
No. The Device Status Info section only tracks and displays credentials configured or updated directly through the Hexnode UEM console. Password changes made locally on the physical endpoint will not be reflected.