mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-23 06:13:41 +00:00
fixing more warnings and conflicts
This commit is contained in:
Binary file not shown.
Before Width: | Height: | Size: 169 KiB After Width: | Height: | Size: 134 KiB |
Binary file not shown.
Before Width: | Height: | Size: 54 KiB After Width: | Height: | Size: 69 KiB |
BIN
devices/surface/images/manage-surface-uefi-fig5-a.png
Normal file
BIN
devices/surface/images/manage-surface-uefi-fig5-a.png
Normal file
Binary file not shown.
After Width: | Height: | Size: 90 KiB |
@ -1,5 +1,5 @@
|
||||
---
|
||||
title: Manage Surface UEFI settings (Surface)
|
||||
title: Manage Surface UEFI settings
|
||||
description: Use Surface UEFI settings to enable or disable devices or components, configure security settings, and adjust Surface device boot settings.
|
||||
keywords: firmware, security, features, configure, hardware
|
||||
ms.localizationpriority: medium
|
||||
@ -10,7 +10,7 @@ ms.pagetype: devices, surface
|
||||
author: dansimp
|
||||
ms.author: dansimp
|
||||
ms.topic: article
|
||||
ms.date: 07/27/2017
|
||||
ms.date: 02/26/2020
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
---
|
||||
@ -61,7 +61,11 @@ You can find up-to-date information about the latest firmware version for your S
|
||||
|
||||
## UEFI Security page
|
||||
|
||||
The Security page allows you to set a password to protect UEFI settings. This password must be entered when you boot the Surface device to UEFI. The password can contain the following characters (as shown in Figure 2):
|
||||

|
||||
|
||||
*Figure 2. Configure Surface UEFI security settings*
|
||||
|
||||
The Security page allows you to set a password to protect UEFI settings. This password must be entered when you boot the Surface device to UEFI. The password can contain the following characters (as shown in Figure 3):
|
||||
|
||||
- Uppercase letters: A-Z
|
||||
|
||||
@ -75,19 +79,20 @@ The password must be at least 6 characters and is case sensitive.
|
||||
|
||||

|
||||
|
||||
*Figure 2. Add a password to protect Surface UEFI settings*
|
||||
*Figure 3. Add a password to protect Surface UEFI settings*
|
||||
|
||||
On the Security page you can also change the configuration of Secure Boot on your Surface device. Secure Boot technology prevents unauthorized boot code from booting on your Surface device, which protects against bootkit and rootkit-type malware infections. You can disable Secure Boot to allow your Surface device to boot third-party operating systems or bootable media. You can also configure Secure Boot to work with third-party certificates, as shown in Figure 3. Read more about [Secure Boot](https://msdn.microsoft.com/windows/hardware/commercialize/manufacture/desktop/secure-boot-overview) in the TechNet Library.
|
||||
On the Security page you can also change the configuration of Secure Boot on your Surface device. Secure Boot technology prevents unauthorized boot code from booting on your Surface device, which protects against bootkit and rootkit-type malware infections. You can disable Secure Boot to allow your Surface device to boot third-party operating systems or bootable media. You can also configure Secure Boot to work with third-party certificates, as shown in Figure 4. Read more about [Secure Boot](https://msdn.microsoft.com/windows/hardware/commercialize/manufacture/desktop/secure-boot-overview) in the TechNet Library.
|
||||
|
||||

|
||||
|
||||
*Figure 3. Configure Secure Boot*
|
||||
*Figure 4. Configure Secure Boot*
|
||||
|
||||
You can also enable or disable the Trusted Platform Module (TPM) device on the Security page, as shown in Figure 4. The TPM is used to authenticate encryption for your device’s data with BitLocker. Read more about [BitLocker](https://technet.microsoft.com/itpro/windows/keep-secure/bitlocker-overview) in the TechNet Library.
|
||||
Depending on your device, you may also be able to see if your TPM is enabled or disabled. If you do not see the **Enable TPM** setting, open tpm.msc in Windows to check the status, as shown in Figure 5. The TPM is used to authenticate encryption for your device’s data with BitLocker. To learn more, see [BitLocker overview](https://docs.microsoft.com/windows/security/information-protection/bitlocker/bitlocker-overview).
|
||||
|
||||

|
||||

|
||||
|
||||
*Figure 5. TPM console*
|
||||
|
||||
*Figure 4. Configure Surface UEFI security settings*
|
||||
|
||||
## UEFI menu: Devices
|
||||
|
||||
@ -107,11 +112,11 @@ The Devices page allows you to enable or disable specific devices and component
|
||||
|
||||
- Onboard Audio (Speakers and Microphone)
|
||||
|
||||
Each device is listed with a slider button that you can move to **On** (enabled) or **Off** (disabled) position, as shown in Figure 5.
|
||||
Each device is listed with a slider button that you can move to **On** (enabled) or **Off** (disabled) position, as shown in Figure 6.
|
||||
|
||||

|
||||
|
||||
*Figure 5. Enable and disable specific devices*
|
||||
*Figure 6. Enable and disable specific devices*
|
||||
|
||||
## UEFI menu: Boot configuration
|
||||
|
||||
@ -127,11 +132,11 @@ The Boot Configuration page allows you to change the order of your boot devices
|
||||
|
||||
You can boot from a specific device immediately, or you can swipe left on that device’s entry in the list using the touchscreen. You can also boot immediately to a USB device or USB Ethernet adapter when the Surface device is powered off by pressing the **Volume Down** button and the **Power** button simultaneously.
|
||||
|
||||
For the specified boot order to take effect, you must set the **Enable Alternate Boot Sequence** option to **On**, as shown in Figure 6.
|
||||
For the specified boot order to take effect, you must set the **Enable Alternate Boot Sequence** option to **On**, as shown in Figure 7.
|
||||
|
||||

|
||||
|
||||
*Figure 6. Configure the boot order for your Surface device*
|
||||
*Figure 7. Configure the boot order for your Surface device*
|
||||
|
||||
You can also turn on and off IPv6 support for PXE with the **Enable IPv6 for PXE Network Boot** option, for example when performing a Windows deployment using PXE where the PXE server is configured for IPv4 only.
|
||||
|
||||
@ -139,7 +144,7 @@ You can also turn on and off IPv6 support for PXE with the **Enable IPv6 for PXE
|
||||
The Management page allows you to manage use of Zero Touch UEFI Management and other features on eligible devices including Surface Pro 7, Surface Pro X, and Surface Laptop 3.
|
||||
|
||||

|
||||
*Figure 7. Manage access to Zero Touch UEFI Management and other features*
|
||||
*Figure 8. Manage access to Zero Touch UEFI Management and other features*
|
||||
|
||||
|
||||
Zero Touch UEFI Management lets you remotely manage UEFI settings by using a device profile within Intune called Device Firmware Configuration Interface (DFCI). If you do not configure this setting, the ability to manage eligible devices with DFCI is set to **Ready**. To prevent DFCI, select **Opt-Out**.
|
||||
@ -151,11 +156,11 @@ For more information, refer to [Intune management of Surface UEFI settings](surf
|
||||
|
||||
## UEFI menu: Exit
|
||||
|
||||
Use the **Restart Now** button on the **Exit** page to exit UEFI settings, as shown in Figure 8.
|
||||
Use the **Restart Now** button on the **Exit** page to exit UEFI settings, as shown in Figure 9.
|
||||
|
||||

|
||||
|
||||
*Figure 8. Click Restart Now to exit Surface UEFI and restart the device*
|
||||
*Figure 9. Click Restart Now to exit Surface UEFI and restart the device*
|
||||
|
||||
## Surface UEFI boot screens
|
||||
|
||||
@ -163,44 +168,44 @@ When you update Surface device firmware, by using either Windows Update or manua
|
||||
|
||||

|
||||
|
||||
*Figure 9. The Surface UEFI firmware update displays a blue progress bar*
|
||||
*Figure 10. The Surface UEFI firmware update displays a blue progress bar*
|
||||
|
||||

|
||||
|
||||
*Figure 10. The System Embedded Controller firmware update displays a green progress bar*
|
||||
*Figure 11. The System Embedded Controller firmware update displays a green progress bar*
|
||||
|
||||

|
||||
|
||||
*Figure 11. The SAM Controller firmware update displays an orange progress bar*
|
||||
*Figure 12. The SAM Controller firmware update displays an orange progress bar*
|
||||
|
||||

|
||||
|
||||
*Figure 12. The Intel Management Engine firmware update displays a red progress bar*
|
||||
*Figure 13. The Intel Management Engine firmware update displays a red progress bar*
|
||||
|
||||

|
||||
|
||||
*Figure 13. The Surface touch firmware update displays a gray progress bar*
|
||||
*Figure 14. The Surface touch firmware update displays a gray progress bar*
|
||||
|
||||

|
||||
|
||||
*Figure 14. The Surface KIP firmware update displays a light green progress bar*
|
||||
*Figure 15. The Surface KIP firmware update displays a light green progress bar*
|
||||
|
||||

|
||||
|
||||
*Figure 15. The Surface ISH firmware update displays a light pink progress bar*
|
||||
*Figure 16 The Surface ISH firmware update displays a light pink progress bar*
|
||||
|
||||

|
||||
|
||||
*Figure 16. The Surface Trackpad firmware update displays a pink progress bar*
|
||||
*Figure 17. The Surface Trackpad firmware update displays a pink progress bar*
|
||||
|
||||

|
||||
|
||||
*Figure 17. The Surface TCON firmware update displays a light gray progress bar*
|
||||
*Figure 18. The Surface TCON firmware update displays a light gray progress bar*
|
||||
|
||||
|
||||

|
||||
|
||||
*Figure 18. The Surface TPM firmware update displays a purple progress bar*
|
||||
*Figure 19. The Surface TPM firmware update displays a purple progress bar*
|
||||
|
||||
|
||||
>[!NOTE]
|
||||
@ -208,7 +213,7 @@ When you update Surface device firmware, by using either Windows Update or manua
|
||||
|
||||

|
||||
|
||||
*Figure 19. Surface boot screen that indicates Secure Boot has been disabled in Surface UEFI settings*
|
||||
*Figure 20. Surface boot screen that indicates Secure Boot has been disabled in Surface UEFI settings*
|
||||
|
||||
## Related topics
|
||||
|
||||
|
@ -1,6 +1,6 @@
|
||||
---
|
||||
title: Microsoft Surface Dock Firmware Update
|
||||
description: This article explains how to use Microsoft Surface Dock Firmware Update, newly redesigned to update Surface Dock firmware while running in the background on your Surface device.
|
||||
description: This article explains how to use Microsoft Surface Dock Firmware Update to update Surface Dock firmware. When installed on your Surface device, it will update any Surface Dock attached to your Surface device.
|
||||
ms.localizationpriority: medium
|
||||
ms.prod: w10
|
||||
ms.mktglfcycl: manage
|
||||
@ -11,6 +11,7 @@ ms.topic: article
|
||||
ms.reviewer: scottmca
|
||||
manager: dansimp
|
||||
ms.audience: itpro
|
||||
ms.date: 02/07/2020
|
||||
---
|
||||
# Microsoft Surface Dock Firmware Update
|
||||
|
||||
@ -32,17 +33,19 @@ This section is optional and provides an overview of how to monitor installation
|
||||
To monitor the update:
|
||||
|
||||
1. Open Event Viewer, browse to **Windows Logs > Application**, and then under **Actions** in the right-hand pane click **Filter Current Log**, enter **SurfaceDockFwUpdate** next to **Event sources**, and then click **OK**.
|
||||
|
||||
2. Type the following command at an elevated command prompt:
|
||||
|
||||
```cmd
|
||||
Reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\Services\SurfaceDockFwUpdate\Parameters"
|
||||
```
|
||||
```cmd
|
||||
Reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\Services\SurfaceDockFwUpdate\Parameters"
|
||||
```
|
||||
3. Install the update as described in the [next section](#install-the-surface-dock-firmware-update) of this article.
|
||||
|
||||
4. Event 2007 with the following text indicates a successful update: **Firmware update finished. hr=0 DriverTelementry EventCode = 2007**.
|
||||
- If the update is not successful, then event ID 2007 will be displayed as an **Error** event rather than **Information**. Additionally, the version reported in the Windows Registry will not be current.
|
||||
- If the update is not successful, then event ID 2007 will be displayed as an **Error** event rather than **Information**. Additionally, the version reported in the Windows Registry will not be current.
|
||||
5. When the update is complete, updated DWORD values will be displayed in the Windows Registry, corresponding to the current version of the tool. See the [Versions reference](#versions-reference) section in this article for details. For example:
|
||||
- Component10CurrentFwVersion 0x04ac3970 (78395760)
|
||||
- Component20CurrentFwVersion 0x04915a70 (76634736)
|
||||
- Component10CurrentFwVersion 0x04ac3970 (78395760)
|
||||
- Component20CurrentFwVersion 0x04915a70 (76634736)
|
||||
|
||||
>[!TIP]
|
||||
>If you see "The description for Event ID xxxx from source SurfaceDockFwUpdate cannot be found" in event text, this is expected and can be ignored.
|
||||
@ -52,8 +55,8 @@ To monitor the update:
|
||||
This section describes how to install the firmware update.
|
||||
|
||||
1. Download and install [Microsoft Surface Dock Firmware Update](https://www.microsoft.com/download/details.aspx?id=46703).
|
||||
- The update requires a Surface device running Windows 10, version 1803 or later.
|
||||
- Installing the MSI file might prompt you to restart Surface. However, restarting is not required to perform the update.
|
||||
- The update requires a Surface device running Windows 10, version 1803 or later.
|
||||
- Installing the MSI file might prompt you to restart Surface. However, restarting is not required to perform the update.
|
||||
|
||||
2. Disconnect your Surface device from the Surface Dock (using the power adapter), wait ~5 seconds, and then reconnect. The Surface Dock Firmware Update will update the dock silently in background. The process can take a few minutes to complete and will continue even if interrupted.
|
||||
|
||||
@ -68,10 +71,10 @@ You can use Windows Installer commands (Msiexec.exe) to deploy Surface Dock Firm
|
||||
msiexec /i "\\share\folder\Surface_Dock_FwUpdate_1.42.139_Win10_17134_19.084.31680_0.msi" /quiet /norestart
|
||||
```
|
||||
|
||||
> [!NOTE]
|
||||
> A log file is not created by default. In order to create a log file, you will need to append "/l*v [path]". For example: Msiexec.exe /i \<path to msi file\> /l*v %windir%\logs\ SurfaceDockFWI.log"
|
||||
> [!NOTE]
|
||||
> A log file is not created by default. In order to create a log file, you will need to append "/l*v [path]". For example: Msiexec.exe /i \<path to msi file\> /l*v %windir%\logs\ SurfaceDockFWI.log"
|
||||
|
||||
For more information, refer to [Command line options](https://docs.microsoft.com/windows/win32/msi/command-line-options) documentation.
|
||||
For more information, refer to [Command line options](https://docs.microsoft.com/windows/win32/msi/command-line-options) documentation.
|
||||
|
||||
> [!IMPORTANT]
|
||||
> If you want to keep your Surface Dock updated using any other method, refer to [Update your Surface Dock](https://support.microsoft.com/help/4023478/surface-update-your-surface-dock) for details.
|
||||
@ -96,11 +99,11 @@ Successful completion of Surface Dock Firmware Update results in new registry ke
|
||||
|
||||
1. Open Regedit and navigate to the following registry path:
|
||||
|
||||
- **HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\Services\SurfaceDockFwUpdate\Parameters**
|
||||
- **HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\Services\SurfaceDockFwUpdate\Parameters**
|
||||
|
||||
2. Look for the registry keys: **Component10CurrentFwVersion and Component20CurrentFwVersion**, which refer to the firmware that is currently on the device.
|
||||
|
||||

|
||||

|
||||
|
||||
3. Verify the new registry key values match the updated registry key values listed in the Versions reference at the end of this document. If the values match, the firmware was updated successfully.
|
||||
|
||||
|
Reference in New Issue
Block a user