×
×
×
×

BIOS and Driver Updates

Overview

As new hardware components are released, BIOS patches are necessary to ensure that the system can fully support them. This is particularly important for newer CPUs, RAM, and storage devices, where BIOS updates may be required for optimal performance or new features. Some BIOS updates optimize the system's performance by refining hardware initialization, improving power management, or enabling better control over system resources.

Drivers are a critical part of a computer system. As operating systems and software evolve, outdated drivers may no longer be compatible with newer software or operating system versions. Patching drivers ensures continued compatibility, enhancing system functionality and stability. Driver patches introduce new features, optimizations, or better integration with modern hardware, such as supporting newer graphics technologies or offering new functionality for devices.

Hence, it is crucial that you update your system BIOS and drivers regularly. Using Vulnerability Manager Plus, you can deploy driver updates through an Automate Patch Deployment task or manually. BIOS updates must be deployed manually. Password-protected BIOS can also be updated after the BIOS credentials are mapped.

Pre-Requisites

If you want the BIOS updates and Driver Updates to be managed by Vulnerability Manager Plus, go to Threats & Patches → Settings → Patch Database Settings.

Under Select the patches that you wish to manage, ensure that Driver and BIOS are selected under Windows, and then click on Save.

Patch Database Sync

Supported BIOS and Drivers

Refer to this page for the list of supported devices for Driver and BIOS updates.

Note
BIOS and Driver updates are currently supported in Vulnerability Manager Plus from build version 10.0.423. Only the BIOS and drivers listed on the supported applications page can be deployed through the BIOS and Driver Updates feature. Vendors or models that are not listed are not supported through this feature.

If a vendor or model is not listed, download the applicable BIOS or driver package from the hardware vendor and test it on a representative endpoint. Deploy the tested package through Software Deployment. An unlisted package cannot be deployed through the BIOS and Driver Updates feature.

Patching of Password-Protected BIOS

Configuring password protection for the BIOS in the systems of the network is often the first step of defense in preventing unauthorized access to the system. In addition, this also forbids malicious/unauthorized users from making changes to the system's hardware and software configurations.

However, this added security layer can prove to be a hassle, especially when it comes to deploying BIOS updates across the endpoints in your organization's network. Since these updates require authentication via credentials before installation, this would mean relying on the end-users to input the credentials for a successful installation, thus leading to either productivity breaks or a lesser chance of successful installations.

The Password-protected BIOS Patching functionality lets you deploy updates for the protected BIOS, without having to rely on the end-user for password authentication.

To support BIOS patching with password protection on Dell machines, it's essential to have the Dell PowerShell module installed on each endpoint.

  • Navigate to Threats & Patches > Supported Patches and search for the Patch ID - 111808 and click Install/Publish Patches.
Supported Patches search for Dell PowerShell module patch 111808

By leveraging this functionality, you can store the pre-configured BIOS passwords of the end-user systems on the product server. This ensures that the BIOS updates are deployed and the passwords are automatically fetched and installed from the server storage, for a seamless installation.

Note
Refer to this page to learn how to identify if the BIOS on Dell machines is password-protected. You can also deploy Pre-Requisites patch 113598 to check BIOS password-protected status. After it is deployed, the password-protected status is visible.

BIOS credentials are required only when the target BIOS is password-protected. These are BIOS passwords, not domain administrator credentials.

For password-protected BIOS, add and map the credentials before deploying the patches. Here are the steps:

Adding and mapping BIOS credentials

  1. On the product console, navigate to Admin > BIOS Credential Settings (under Patch Settings)
  2. Click on Add BIOS Credential
  3. Enter the Credential Name, Description (optional) and the Password.
  4. You can map the credentials to any of the following:
    • All Computers: Maps the BIOS credentials to all of the computers in the network.
    • Vendor(s): Maps the credentials to specific vendor(s) (Such as Dell and HP).
    • Custom Group(s): Maps the credentials to one or more Custom Groups as required.
  5. Once done, click on Save to add and map the credentials to the required systems.
Add BIOS Credentials
Note
If a Dell BIOS update fails with Invalid Password(s) or Exit Code 7 (Password Validation failure), the mapped BIOS password is missing or incorrect. See Dell BIOS update failed: invalid password.

Deploying BIOS updates

After you map the credentials when required, deploy BIOS updates to the systems manually. BIOS updates are not deployed by Automate Patch Deployment. Do not mix BIOS patches with other patches in the same task.

A BIOS version installed on a golden machine is not captured as part of its operating system image. After imaging a device, deploy the BIOS update separately. If required, automate the post-imaging update with a vendor-supported command or script after validating it on representative hardware.

Resolve BIOS Update Failures

  • Exit Code 2: Restart the endpoint once, then deploy the BIOS update again.
  • Another BIOS update is in progress: Wait for the current update to finish, then redeploy the failed BIOS update as a separate task.

If the failure reports an invalid password, verify that the correct BIOS credential is mapped to the endpoint. For other vendor-specific exit codes, use the vendor's result details before retrying the deployment.

Review the BIOS-Mapping Status of the Systems

You can review and monitor the BIOS-mapping status of all the systems in the network from a single dashboard. To know more about how to review the status of these systems on the console, refer to this page

Related