Use passwords
This section introduces types of passwords in UEFI (Unified Extensible Firmware Interface) BIOS (Basic
Input/Output System) and how to set, change, and remove a password.
Password types
You can set a power-on password, supervisor password, system management password, or NVMe
password in UEFI BIOS to prevent unauthorized access to your computer. However, you are not prompted to
enter any UEFI BIOS password when your computer resumes from sleep mode.
Power-on password
If you set a power-on password, a window is displayed on the screen when you turn on the computer. Enter
the correct password to use the computer.
Supervisor password
The supervisor password protects the system information stored in UEFI BIOS. When entering the UEFI
BIOS menu, enter the correct supervisor password in the window prompted. You also can press Enter to
skip the password prompt. However, you cannot change most of the system configuration options in UEFI
BIOS.
If you have set both the supervisor password and power-on password, you can use the supervisor password
to access your computer when you turn it on. The supervisor password overrides the power-on password.
System management password
The system management password can also protect the system information stored in UEFI BIOS like a
supervisor password, but it has lower authority by default. The system management password can be set
through the UEFI BIOS menu or through the think-lmi firmware-attributes sysfs class.
You can enable the system management password to have the same authority as the supervisor password
to control security-related features. To customize the authority of the system management password through
the UEFI BIOS menu:
1. Restart the computer. When the logo screen is displayed, press F1 to enter the UEFI BIOS menu.
2. Select Security ➙ Password ➙ System Management Password Access Control.
3. Follow the on-screen instructions.
If you have set both the supervisor password and the system management password, the supervisor
password overrides the system management password. If you have set both the system management
password and the power-on password, the system management password overrides the power-on
password.
NVMe passwords
The NVMe password prevents unauthorized access to the data on the storage drive. When an NVMe
password is set, you are prompted to type a correct password each time you try to access the storage drive.
• Single Password
When a Single NVMe password is set, the user must enter the user NVMe password to access files and
applications on the storage drive.
• Dual Password (User + Admin)
The admin NVMe password is set and used by a system administrator. It enables the administrator to
access any storage drive in a system or any computer connected in the same network. The administrator
24
ThinkPad T14 Gen 5/P14s Gen 5 AMD/T16 Gen 3 Linux User Guide