
By Evan Forrest (SurfaceTip)
UEFI or Unified Extensible Firmware Interface is a new motherboard firmware standard that allows your PC to boot faster and has more security features. Starting with Surface Pro 4, Microsoft has developed its own UEFI firmware for use with its future devices. This new Surface UEFIÂ is currently used on newer devices including Surface Go, Surface Pro, Surface Laptop, Surface Book, Surface Laptop Studio, and Surface Studio.
In this article, you will find out how to enter the Surface Laptop UEFI settings. You will also learn how to configure the UEFI settings to improve the device security, check your device information, and more.
Table of contents
- How to access Surface Laptop UEFI settings?
- How to Check Your Surface Laptop Device Information via UEFI Settings?
- How to Configure Device Boot Order on Surface Laptop
- How to Manage Device Components on Surface Laptop
- How to change your Surface Laptop Date and Time via Surface UEFI?
- How to Protect UEFI settings with a Password on Surface Laptop
- What is Secure Boot Control?
- What is the Trusted Platform Module (TPM)?
- Other Surface UEFI Settings
1 How to access Surface Laptop UEFI settings?
You can enter the Surface Laptop UEFI setup screen only while your device is starting up. Here is how you do that:
- Shut down your Surface Laptop.
- Press and hold the Volume Up (F4) key on your Surface, then press and release the Power Key next to the Del key.
- When you see the Surface logo appear, release the Volume Up button. The Surface UEFI screen will appear in a few seconds.
After you have made any changes to the UEFI settings, you can restart your Surface by:
- In the Surface UEFI menu, choose Exit, and click on Restart Now
2 How to Check Your Surface Laptop Device Information via UEFI Settings?
The first displayed page when you enter UEFI settings is the PC information page. On the page, you can find out more information about your device identities such as Model, System UUID (Universally Unique Identifier), Serial Number, and Asset Tag. Moreover, it also displays other essential system information and component versions that you might need for troubleshooting.
See also: How to manage asset tag on Surface Laptop.
3 How to Configure Device Boot Order on Surface Laptop
To change the alternate system boot order on your Surface Laptop :
- Enter Surface UEFI settings as per the instructions above.
- In the Surface UEFI menu, go to the Boot Configuration page as below:
On the “Configure boot device order” page, you can:
- Rearrange the boot order by dragging and dropping any boot option available on the list.
- Enable or disable any boot option by using the checkbox
- Remove available boot options permanently by using the trash button.
4 How to Manage Device Components on Surface Laptop
Surface Laptop allows you to disable some of your surface device components and features to meet your specific security requirements. You can enable or disable those components by:
- Access Surface UEFI settings as per the instructions above.
- In the Surface UEFI menu, go to Devices and you will see the following options:
- In my Surface Laptop 3 with System UEFI version 6.22.140, you can choose to enable or disable the following device’s components or ports:
- Docking USB Port
- All Cameras (Front Camera and IR Camera)
- On-board Audio
- Wi-Fi & Bluetooth
- Bluetooth
5 How to change your Surface Laptop Date and Time via Surface UEFI?
The new Surface UEFI now allows you to set your Surface Laptop’s date and time right on the UEFI settings page. To check or set a date and time for your Surface Laptop:
- Enter Surface UEFI settings as per the instructions above.
- In the Surface UEFI menu, go to the Date and Time page as below:
- To set a new date and time, select the edit box and type your new date and time.
- Press Enter to apply changes.
6 How to Protect UEFI settings with a Password on Surface Laptop
You can prevent others from changing your UEFI settings by setting an Administrator Password in UEFI settings. To do that:
- Enter Surface UEFI settings as per the instructions above.
- Go to the Security section below:
- To set the UEFI password, click on Add or Change button and you will see the following requirements:
- You will need to enter a password in the box with your keyboard or the on-screen keyboard with the following criteria:
- Minimum Length: 6 characters
- Maximum Length: 128 characters
- May contain a combination of letters, numbers, and special characters.
- If you have set the password before and want to remove it, simply leave the password box blank.
7 What is Secure Boot Control?
The Secure Boot is a technology that blocks the loading of uncertified bootloaders and drives. It helps to prevent your Surface from being loaded with unauthorized operating systems and malicious software applications.
If you desire to install other operating systems like Ubuntu, or other Linux distributions, you may need to disable this feature in the UEFI settings above.
8 What is the Trusted Platform Module (TPM)?
The Trusted Platform Module (TPM) is a technology that provides a major advancement over BIOS in hardware-based security features. It is a specialized chip that stores RSA encryption keys specific to each Surface device for hardware authentication.
TPM technology is a requirement of BitLocker disk encryption. The TPM helps you to encrypt/decrypt the entire disk without requiring your complex long passphrases. It means that the encryption key and decryption key are stored within the TPM chip. So your encrypted disks can’t be accessed on other devices.
Other Surface UEFI Settings
We have also covered this topic for other Surface PCs as well. To learn more about other Surface UEFI settings check the link below:
COMMENTS
Let us know what you think!
We appreciate hearing your thoughts, questions, and ideas about “How to Configure Surface Laptop UEFI/BIOS Settings”.
On my device Volume Up is on F4. F6 is not working as described in that case.
I have surface laptop 3 and its SSD drive was not working (showing only surface logo and stuck on that) and when try to install thru windows 10 USB it shows the disk but no option to select.
HDD replace windows installed its working fine, but when shut down and press power button after one hour it shows surace logo then off and keep on repeating it and after 10 to 15 attempts it start and works fine, Restart work fine and even if shut down and withing 5 to 10 min Start button pressed, it works fine, but only after some time it gave issue with start up.
Any one have any cluse wts the issue or any one have idea how to upgrade BIOS, its 9.106.140, 4/30/2021