Transcription of Integration Kit - HP
1 Technical whitepaper HP manageability Integration Kit HP Client Management Solutions July 2019 925167-005 Technical whitepaper Table of contents Contents Table of contents .. 2 List of figures .. 7 List of tables .. 9 1 Overview .. 10 2 system requirements .. 11 Supported Microsoft system center configuration manager versions .. 11 Supported client operating systems .. 11 3 Downloading HP manageability Integration Kit .. 12 4 Installing HP manageability Integration Kit into configuration manager .. 13 Distributing HP Client Support Packages .. 13 5 HP MIK plugins .. 15 Compliance settings .. 15 configuration Baselines .. 16 6 HP BIOS Password manager .. 17 Supported client platforms .. 17 Supported client operating systems.
2 17 Prerequisites .. 17 User interface .. 17 Creating a policy .. 17 Change BIOS Password .. 19 Remove the BIOS Password .. 23 Set new BIOS Password .. 25 7 HP BIOS configuration .. 28 Technical whitepaper Supported client platforms .. 28 Supported client operating systems .. 28 Prerequisites .. 28 User interface .. 28 Category View button .. 28 List View button .. 29 Select All Settings .. 31 Show Selected Settings Only .. 31 Expand All/Collapse All button .. 32 Filter to settings containing .. 33 Creating a policy .. 33 Editing a policy .. 34 8 HP Client Security with Intel Authenticate Support .. 36 Supported client platforms .. 36 Supported client operating systems .. 36 Other client system prerequisites.
3 36 User interface .. 36 Client Security manager .. 37 Intel Authenticate .. 38 Windows Logon Policy .. 38 Windows Session and VPN Policy .. 40 Advanced Options .. 40 Device Access 41 Removable Media .. 42 Creating a policy .. 42 Editing a policy .. 43 Additional information .. 43 Security Provisioning .. 44 Initial Provisioning or Update Provisioning .. 44 Deprovision .. 46 Additional information .. 46 HP Sure Run .. 48 Overview .. 48 configuration .. 48 Technical whitepaper HP Sure Run Gen 2 S/W Introductions .. 52 Supported client platforms .. 53 Supported client operating systems .. 53 Other client system prerequisites .. 53 Pre-Requisite .. 53 Creating a policy.
4 53 Additional information .. 55 HP Sure 56 configuration .. 56 Supported client platforms .. 59 Supported client operating systems and system prerequisites .. 59 Creating a policy .. 60 Steps to create and sign an image manifest .. 61 The following methods can be used to create sha256 hashes in Windows: .. 61 Note: .. 61 Steps to create and sign a recovery agent manifest .. 61 The following methods can be used to create sha256 hashes in Windows: .. 62 Note: .. 63 Interaction between HP Sure Run and HP Sure Recover .. 63 9 Device Guard (Windows 10 only) .. 57 Supported client platforms .. 57 Supported client operating systems .. 57 Other client system prerequisites .. 57 Creating a policy.
5 57 Editing policy .. 59 Additional information .. 59 10 HP Sure Start .. 61 Supported client platforms .. 61 Supported client operating systems .. 61 Other client system prerequisites .. 61 User interface .. 62 Events and Recovery Settings tab .. 62 Audit Log tab .. 64 Technical whitepaper Creating a policy .. 64 Editing a policy .. 65 Additional information .. 65 Audit logs .. 66 11 HP Sure View .. 67 Overview .. 67 Supported Client Platforms .. 67 Supported client operating systems .. 67 Creating a policy .. 67 Editing a policy .. 69 12 TPM Firmware Update .. 71 Supported client platforms .. 71 Notebook computers: .. 71 Supported client operating systems .. 72 Other client system prerequisites.
6 72 Creating a policy .. 72 Editing a policy .. 73 Additional information .. 74 13 HP WorkWise (Windows 10 only) .. 75 Supported client platforms .. 75 Client system prerequisites .. 75 User interface .. 75 Creating a policy .. 76 Editing a policy .. 76 14 HP Client Driver Packs .. 78 Creating and importing an HP driver pack .. 78 Downloading and importing HP driver packs .. 82 Obtaining HP driver packs .. 84 Creating driver packs using HP SDM .. 85 Importing HP driver packs .. 86 15 HP Client Boot Images .. 88 Technical whitepaper Obtaining a WinPE driver pack .. 88 Importing a WinPE driver pack and creating boot images .. 88 16 HP Client Task Sequences .. 90 Creating a deployment task sequence.
7 90 Configuring task sequences .. 91 Assigning a boot image .. 93 Allowing access to deployment content .. 93 Configuring the Set BIOS configuration task step .. 93 Adding and editing configuration files .. 94 Refreshing task sequence references .. 95 Using the Configure RAID Example template .. 95 Preparing the packages used by the task sequence .. 95 Configuring task sequence steps .. 96 Assigning a boot image .. 97 Allowing access to deployment content .. 98 Understanding the task sequence execution flow .. 98 17 HP BIOS configuration Utility (BCU) .. 100 18 HP Sure Click .. 101 19 HP Sure Sense .. 102 20 HP Password Utility .. 104 21 HP Collaboration Keyboard .. 105 22 HP Recipes .. 106 23 HP Reports.
8 104 24 Uninstalling HP MIK .. 105 25 Appendix A Device collection query examples .. 105 All HP Systems including older models .. 105 HP systems with a specific model name .. 106 Technical whitepaper Windows 10 Enterprise systems .. 106 Determining whether Device Guard can be enabled .. 107 23 Systems with HP Sure Start support .. 108 TPM 109 Systems with TPM Version .. 109 Systems with TPM Version .. 109 Systems with a specified application installed .. 109 Systems with Intel Authenticate or a valid Intel Authenticate policy enforced for HP Client Security .. 110 24 Appendix B Troubleshooting .. 113 HP MIK installation 113 Driver pack issues .. 113 WinPE image creation issues .. 113 Before troubleshooting a task sequence.
9 113 Common task sequence problems .. 114 Task sequence creation and management issues .. 115 Task sequence execution issues .. 116 Diagnosing driver pack or task sequence errors .. 118 25 Appendix C Sure Run & Sure Recover Key Generation for MIK .. 120 Creating the Key Endorsement Certificate: .. 120 Create the Signing Key Certificate: .. 120 26 For more information .. 122 Technical whitepaper List of figures Figure 1 HP manageability Integration Kit Navigation Index .. 13 Figure 2 Software Library of configuration manager .. 14 Figure 3 configuration Items .. 16 Figure 4 Create Policy .. 18 Figure 5 Creating a baseline name .. 18 Figure 6 Completing the Create Baseline task .. 19 Figure 7 Changing the BIOS password.
10 20 Figure 8 BIOS Password change summary .. 21 Figure 9 Compliance settings .. 22 Figure 10 Deploy compliance settings .. 22 Figure 11 Select Device Collection .. 23 Figure 12 Removing the BIOS password .. 24 Figure 13 Confirming BIOS password removal .. 25 Figure 14 Set new BIOS password .. 26 Figure 15 Confirming new BIOS password .. 27 Figure 16 HP BIOS configuration (List view) .. 30 Figure 17 HP BIOS configuration (Select All Settings) .. 31 Figure 18 HP BIOS configuration (Show Selected Settings Only) .. 31 Figure 19 Expand/Collapse 32 Figure 20 HP BIOS configuration (Filter to settings containing) .. 33 Figure 21 configuration baseline list .. 35 Figure 22 Configure high-level features of HP Client Security manager .