<# .SYNOPSIS Sets the Dell BIOS Password Bypass option so reboots and resumes skip the power-on and drive password prompts. .DESCRIPTION Password Bypass lets a Dell PC that has a system (power-on) or internal drive password come back from a restart or resume without stopping at the password prompt. A cold boot still asks. This script reads the current value, checks the model supports the mode you asked for, and changes it. If a BIOS admin password is set, the change needs it; pass it as a SecureString or let the script read it from a Configuration Manager task sequence variable at runtime. Exit codes: 0 = changed, already set, or not a Dell; 1 = the BIOS refused the change; 2 = provider missing or setting not supported; 3 = admin password needed but not supplied. .PARAMETER Mode Disabled, RebootBypass, ResumeBypass, or RebootAndResumeBypass. .PARAMETER AdminPassword The BIOS admin password, if one is set. .PARAMETER PasswordVariable Task sequence variable to read the admin password from when -AdminPassword isn't given. .EXAMPLE .\Set-DellPasswordBypass.ps1 -Mode RebootBypass -AdminPassword (Read-Host -AsSecureString 'BIOS admin password') .EXAMPLE .\Set-DellPasswordBypass.ps1 -Mode Disabled #> [CmdletBinding(SupportsShouldProcess)] param( [Parameter(Mandatory)] [ValidateSet('Disabled', 'RebootBypass', 'ResumeBypass', 'RebootAndResumeBypass')] [string]$Mode, [securestring]$AdminPassword, [ValidateNotNullOrEmpty()][string]$PasswordVariable = 'BIOSAdminPassword' ) function Get-TSSecret { param([string]$Name) try { $ts = New-Object -ComObject Microsoft.SMS.TSEnvironment -ErrorAction Stop } catch { return $null } $value = $ts.Value($Name) if ([string]::IsNullOrEmpty($value)) { return $null } ConvertTo-SecureString -String $value -AsPlainText -Force } function Import-DellProvider { if (Get-Module -ListAvailable -Name DellBIOSProvider) { Import-Module DellBIOSProvider -ErrorAction Stop; return } # Fall back to a copy shipped in the package (Save-Module puts it in a version subfolder). $bundled = Get-ChildItem -Path (Join-Path $PSScriptRoot 'DellBIOSProvider') -Filter 'DellBIOSProvider.psd1' -Recurse -ErrorAction SilentlyContinue | Select-Object -First 1 if ($bundled) { Import-Module $bundled.FullName -ErrorAction Stop; return } throw 'DellBIOSProvider not found. Install it, or copy the module folder into the package next to this script.' } $result = [ordered]@{ ComputerName = $env:COMPUTERNAME; Setting = 'PasswordBypass'; Before = ''; After = ''; Status = ''; Detail = '' } $manufacturer = (Get-CimInstance -ClassName Win32_ComputerSystem).Manufacturer if ($manufacturer -notlike 'Dell*') { $result.Status = 'NotApplicable'; $result.Detail = "Manufacturer is '$manufacturer'." [pscustomobject]$result; exit 0 } try { Import-DellProvider } catch { $result.Status = 'Failed'; $result.Detail = $_.Exception.Message; [pscustomobject]$result; exit 2 } $item = Get-Item -Path 'DellSmbios:\Security\PasswordBypass' -ErrorAction SilentlyContinue if (-not $item) { $result.Status = 'NotSupported'; $result.Detail = 'This model does not expose PasswordBypass.' [pscustomobject]$result; exit 2 } if ($item.PossibleValues -and ($item.PossibleValues -notcontains $Mode)) { $result.Status = 'NotSupported'; $result.Detail = "Model accepts: $($item.PossibleValues -join ', ')" [pscustomobject]$result; exit 2 } $result.Before = "$($item.CurrentValue)" if ($result.Before -eq $Mode) { $result.Status = 'NoChange'; $result.After = $result.Before [pscustomobject]$result; exit 0 } # Changing any setting needs the admin password when one is set. $adminSet = "$((Get-Item -Path 'DellSmbios:\Security\IsAdminPasswordSet' -ErrorAction SilentlyContinue).CurrentValue)" -ne 'False' if ($adminSet -and -not $AdminPassword) { $AdminPassword = Get-TSSecret -Name $PasswordVariable } if ($adminSet -and -not $AdminPassword) { $result.Status = 'Failed'; $result.Detail = 'A BIOS admin password is set, but none was supplied.' [pscustomobject]$result; exit 3 } $exitCode = 0 if ($PSCmdlet.ShouldProcess($env:COMPUTERNAME, "Set PasswordBypass from '$($result.Before)' to '$Mode'")) { $setArgs = @{ Path = 'DellSmbios:\Security\PasswordBypass'; Value = $Mode; ErrorAction = 'Stop' } if ($adminSet) { $setArgs.Password = [System.Net.NetworkCredential]::new('', $AdminPassword).Password } try { Set-Item @setArgs $result.Status = 'Changed' } catch { $result.Status = 'Failed'; $result.Detail = $_.Exception.Message; $exitCode = 1 } finally { $setArgs.Remove('Password') } } else { $result.Status = 'WhatIf' } $result.After = "$((Get-Item -Path 'DellSmbios:\Security\PasswordBypass' -ErrorAction SilentlyContinue).CurrentValue)" [pscustomobject]$result exit $exitCode