System firmware UEFI Admin Password


  1. Posts : 812
    Win10
       #1

    System firmware UEFI Admin Password


    I am thinking about setting an Admin password for the UEFI firmware settings.
    Is this really required?

    BitLocker full drive encryption is enabled.


    I have Secure Boot enabled, but what if my laptop gets stolen and someone can change the UEFI settings?


    .So can I create the UEFI Admin password to be the same as my OS Admin password?
    Would this pose an issue? My passwords are very complex.

    Its very surprising to me that in most of security related forums out there, setting a UEFI Admin password is off the radar and not talked about so much...
      My Computer


  2. Posts : 15,485
    Windows10
       #2

    win10freak said:
    I am thinking about setting an Admin password for the UEFI firmware settings.
    Is this really required?

    BitLocker full drive encryption is enabled.


    I have Secure Boot enabled, but what if my laptop gets stolen and someone can change the UEFI settings?


    .So can I create the UEFI Admin password to be the same as my OS Admin password?
    Would this pose an issue? My passwords are very complex.

    Its very surprising to me that in most of security related forums out there, setting a UEFI Admin password is off the radar and not talked about so much...
    Problem is if you set a password and forget it, you are screwed and may have to resort to elaborate physical methods to reset bios.

    There is no real need to use a bios password unless you want to prevent users with PHYSICAL access to pc to change anything.

    Remote users/hackers cannot modify the bios.

    I guess it helps if laptop is stolen but even then most thieves would wipe drives anyway. You should not keep confidential details on a laptop if risk of theft is high where you take it.
      My Computer


  3. Posts : 812
    Win10
    Thread Starter
       #3

    Forgot to mention that I am the only one using my laptop and nobody else.

    So will it be fine not to set an Admin UEFI password?
      My Computer


  4. Posts : 809
    Win10
       #4

    There's no real benefit of a UEFI admin password, which just prevents people from modifying your UEFI settings, if you are concerned about physical theft.

    Secure Boot protects against attackers from modifying your OS boot files and surreptitiously installing malware or disabling OS protections. It's not even required for BitLocker, which uses a separate mechanism to validate the bootloader.

    If someone steals your laptop then BitLocker (preferably with a PIN) is sufficient to protect your data.
      My Computer


  5. Posts : 79
    Windows 10 Pro
       #5

    Proper assessment of your security requirements is necessary before implementing a security solution. Always remember that there is a trade-off between the security you apply and the ease of use of your system.
      My Computer


  6. Posts : 79
    Windows 10 Pro
       #6

    win10freak said:
    Forgot to mention that I am the only one using my laptop and nobody else.

    So will it be fine not to set an Admin UEFI password?
    If you believe that no one has any reason to access your laptop when you are not around it, then, there is no need for one.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 00:43.
Find Us




Windows 10 Forums