How to Configure Surface Pro 4 UEFI/BIOS Settings
In this article, you will find out how to enter the Surface Pro 4 UEFI/BIOS settings and how to manage device boot order, devices, security and more.
You might already know that since the first release of Microsoft Surface Pro and Surface 3, Microsoft has implemented a new firmware called Unified Extensible Firmware Interface (UEFI) on those devices. As this new firmware interface allows your Surface boot faster and providing better security improvements.
Starting with Surface Pro 4, Microsoft has created their own Surface UEFI for using with newer devices. This new Surface UEFI is currently used on newer devices including Surface Book and Surface Studio.
In this article, you will find out how to get to the Surface UEFI settings. You will see also about how to configure the UEFI settings to improve the device security, check your device information and more.
- How to access Surface Pro 4 UEFI settings?
- How to Check Your Surface Pro 4 Device Information via UEFI settings?
- How to Configure Device Boot Order on Surface Pro 4?
- How to Manage Device Components on Surface Pro 4?
- How to Protect UEFI settings with a password on Surface Pro 4?
- What is Secure Boot Control?
- What is Trusted Platform Module (TPM)?
You can enter Surface Pro 4 UEFI setup screen only while your device is starting up. Here is how you do that:
- Shut down your Surface.
- Press and hold the Volume Up button on your Surface, then press and release the Power button.
- When you see the Surface logo screen appear, release the Volume Up button. The Surface UEFI screen will appear in a few seconds.
After you have made any changes to the UEFI settings, you can restart your Surface by:
- In Surface UEFI menu, choose Exit, and click on Restart Now
The first displayed page when you enter UEFI settings is PC information page. On the page, you can find out more information about your device identities such as Model, System UUID (Universally Unique Identifier), Serial Number, and Asset Tag. Moreover, it also displays all important system other components version that you might need for troubleshooting.
To change the alternate system boot order on your Surface Pro 4:
- Enter Surface UEFI settings as the instructions above.
- In Surface UEFI menu, go to Boot Configuration page as below:
On the “Configure boot device order” page, you can:
- Rearrange boot order by drag and drop any boot option available in the list.
- Enable or disable any boot option by using the checkbox
- Remove available boot option permanently by using the trash button.
Note If you accidentally delete Windows Boot Manager from your Master Boot Record, simply restart your Surface and Windows Boot Manager will reinstall automatically.
Surface Pro 4 allows you to disable some of your surface device components and features to meet your specific security requirements. You can enable or disable those components by:
- Access Surface UEFI settings as the instructions above.
- In Surface UEFI menu, go to Devices and you will see the following options:
- In my Surface Pro 4 with System UEFI version 106.1427.768, you can choose to enable or disable following device’s components or ports:
- Docking USB Port
- Front Camera
- Rear Camera
- IR Camera
- On-board Audio
- Wi-Fi & Bluetooth
- Type Cover port
You can prevent others from changing your UEFI settings by setting an Administrator Password in UEFI settings. To do that:
- Enter Surface UEFI settings as the instructions above.
- Go to Security section as below:
- To set UEFI password, click on Add or Change button and you will see the following requirements:
- You will need to enter a password in the box with your keyboard or the on-screen keyboard with following criteria:
- Minimum Length: 6 characters
- Maximum Length: 128 characters
- May contain a combination of letters, numbers, and special characters.
- In case that you have already set the password before and you want to remove it, simply leave the password box as blank.
Note If you enter the administrator password incorrectly three times, you’ll be locked out of the UEFI. Restart your Surface to enter the password again.
The Secure Boot is a technology which blocks the loading of uncertified bootloaders and drives. It helps to prevent your Surface being loaded with unauthorized operating systems and malicious software applications.
If you desire to install other operating systems like Ubuntu, or other Linux distributions, you may need to disable this feature in the UEFI settings above.
The Trusted Platform Module (TPM) is a technology that provides a major advancement over BIOS in hardware-based security features. It is a specialized chip that stores RSA encryption keys specific to each Surface device for hardware authentication.
The TPM technology is a requirement of BitLocker disk encryption. The TPM helps you to encrypt/decrypt entire disk without required your complex long passphrases. It means that the encryption key and decryption key are stored within the TPM chip. So your encrypted disks can’t be accessed on other devices.
Other Surface’s UEFI Settings
We have also covered this topic for other Surface PCs as well, to learn more about other Surface’s UEFI settings check the link below:
Best Accessories for Microsoft Surface
With the right set of accessories, you can boost your Surface's productivity to the next level. Here we have some of the best accessories you should get for your Surface devices.
Those are the top must-have accessories for Microsoft Surface devices so far. With Surface Pen, Surface Dock, Surface Precision Mouse, and microSD card will significantly increase your Surface performance, storage, and productivity.