Managing supervisor credentials

Depending on the Absolute product licenses associated with your account, the Remote Supervisor Credentials feature may not be available.

Supervisor credentials—also known as administrator or firmware passwords—are a firmware-level security control that restricts access to UEFI/BIOS settings. They help prevent unauthorized changes to critical device configuration, such as boot order, Secure Boot settings, and hardware options, reducing the risk of device tampering. Setting or changing supervisor credentials locally requires physical access to the device and entry into UEFI/BIOS setup during startup.

Using the Remote Supervisor Credentials (RSVC) feature, you can remotely and securely create, update, or remove supervisor credentials on supported Lenovo devices. Credentials can be in the following forms:

  • Certificate

    A trusted digital certificate that is stored in a device's firmware and lets administrators access UEFI/BIOS settings

    For more information about certificate authentication, see Certificate-based BIOS Authentication in Lenovo documentation.

  • Password

    A text password that lets administrators access UEFI/BIOS settings

You can submit a Manage Supervisor Credentials request from the Device Details page of a device. You can also select devices in a device group, device group folder, or device report to submit a request for all selected devices. Alternatively, you can upload a file of device identifiers and submit a request.

  • The RSVC feature does not store your devices' supervisor credentials. You are responsible for maintaining them in a secure, centralized secret management system with appropriate access controls.
  • To set, update, or remove supervisor credentials in a device's firmware, a device restart by a device user or another application is required. The Secure Endpoint Agent does not force a restart.
  • You can't cancel a Manage Supervisor Credentials request after it's submitted.