Guide for IT administrators on using HP Sure Admin to manage BIOS settings with certificate‑based authentication.
About this manual
HP Sure Admin lets IT administrators securely manage BIOS settings on remote or local computers using certificate and public‑key encryption, eliminating the need for passwords. The tool consists of the Manageability Integration Kit (MIK), the HP Sure Admin Local Access Authenticator mobile app, and the target computer with enhanced BIOS verification mode.
The manual covers quick start steps, key creation and export methods (manual, Azure AD revocation, and OneDrive), mobile app configuration for Android and iOS, BIOS unlocking procedures, and a comprehensive list of error codes for troubleshooting. This manual is written in Chinese.
What's inside
- Quick Start
- Using HP Sure Admin
- Disabling HP Sure Admin
- Creating and Managing Keys
- Mobile Settings
- Error Codes
Frequently asked questions
How can I disable HP Sure Admin?
In the BIOS F10 settings select “Restore security settings to factory defaults,” or use the BCU command to remotely call the WMI that restores defaults, or cancel provisioning on the MIK security provisioning page.
What is required for the mobile app to obtain a one‑time PIN?
The HP Sure Admin mobile app must have network access to contact the server and retrieve the one‑time PIN.
What does error code 100 indicate?
Error code 100 (QRCodeUnknownError) is a general error when scanning a QR code.
How can I export a key using Azure AD revocation?
Select Azure AD login, choose the appropriate Azure AD group, and follow the prompts to create and export the key; the mobile app will require network access to obtain the one‑time PIN.