How to use Symantec IT Management Suite to remediate against BlackLotus Part 1 – Reporting

Determining Whether a BIOS Update Is Required

The first step in preparing for Microsoft’s upcoming security changes—specifically, the rollout of new Secure Boot certificates via a cumulative Windows Update in 2026 — is to verify whether each device is running a BIOS version that meets the minimum requirements.

Major OEMs such as HP and Dell provide documentation listing the minimum BIOS versions necessary to ensure compatibility with the new certificates. Devices that do not meet these requirements must be updated.

HP Devices

HP has made this process simpler by offering a clear indicator that shows whether a device already includes the required BIOS update.
You can check this using the following PowerShell command:

(Get-CimInstance -ClassName Win32_ComputerSystemProduct).Version

This command queries the WMI/CIM class Win32_ComputerSystemProduct and returns the value of the Version property.

Interpretation:

  • If the output contains SBKPFV3, the device already has the required HP BIOS update that prepares it for the new certificates.
  • If SBKPFV3 is not present, the system requires an HP BIOS update to meet the upcoming Secure Boot certificate requirements.

Capturing BIOS Data with Altiris Inventory Solution

By default, Altiris Inventory Solution does not capture this BIOS-related value automatically.
However, as with many scenarios, Symantec IT Management Suite is highly flexible and allows you to extend the inventory easily.

To collect this information, you can simply create a custom inventory and add the required value to the inventory data.

Once the value has been captured, you can leverage it in Altiris to create meaningful filters and reports.
For example, you might create the following two filters:

  • HP devices meet the minimum BIOS version for BlackLotus
  • HP devices do not meet the minimum BIOS version for BlackLotus

These filters can then be used to quickly identify compliant and non-compliant systems and take appropriate action, such as updating the BIOS on affected devices.

Dell Devices

Dell also provides a regularly updated list of the minimum supported BIOS versions required for the Secure Boot certificate transition. These list serves as the reference point for determining whether devices from these manufacturer needs to be updated.

Report for HP

We have created a custom Altiris report for HP devices that provides a clear overview of BIOS compliance across the environment.

The report compares the installed BIOS version on each HP device with the minimum BIOS version required by HP, based on the official HP affected platforms and minimum BIOS version list.

Report Status Values

Each device is evaluated and assigned one of the following compliance states:

  • NOT_IN_HP_LIST
    The HP model detected by the Altiris Inventory Solution is not listed in HP’s affected platforms and minimum BIOS version documentation.
    This does not necessarily indicate a problem, but the device cannot be validated automatically.
  • OK
    The installed BIOS version meets or exceeds the minimum BIOS version required by HP.
    No action is required for this device.
  • UPDATE_REQUIRED
    The installed BIOS version is lower than the minimum version required by HP.
    A BIOS update is recommended to ensure compliance and mitigate potential security or stability issues.

Benefits of the Report

  • Centralized visibility of HP BIOS compliance
  • Fast identification of devices requiring BIOS updates
  • Clear distinction between compliant, non-compliant, and unsupported models
  • Easy integration into existing Altiris reporting and dashboards

This report helps administrators proactively manage BIOS updates and maintain a secure, compliant HP device fleet.

Here is the HP SQL Query (modify for your own needs…)

SELECT
    d.Computername,
    d.ProductName,
    d.RawBiosVersion,
    d.InstalledBiosVersionOnly,
    d.MinBiosRequired,
   CASE
    WHEN d.MinBiosRequired = '66.00.00' THEN 'TBD'
    WHEN d.MinBiosRequired = '99.00.00' THEN 'NOT_IN_HP_LIST'
    WHEN d.MinBiosRequired IS NULL THEN 'NO_MATCH_IN_HP_LIST'
    WHEN
        (
            CASE
                WHEN d.InstalledBiosVersionOnly LIKE '[A-Z].%' THEN
                    LEFT(d.InstalledBiosVersionOnly, 1) +
                    RIGHT('000' + PARSENAME(d.InstalledBiosVersionOnly, 1), 3) + '000000'
                ELSE
                    RIGHT('000' + PARSENAME(d.InstalledBiosVersionOnly, 3), 3) +
                    RIGHT('000' + PARSENAME(d.InstalledBiosVersionOnly, 2), 3) +
                    RIGHT('000' + PARSENAME(d.InstalledBiosVersionOnly, 1), 3)
            END
        )
        >=
        (
            CASE
                WHEN d.MinBiosRequired LIKE '[A-Z].%' THEN
                    LEFT(d.MinBiosRequired, 1) +
                    RIGHT('000' + PARSENAME(d.MinBiosRequired, 1), 3) + '000000'
                ELSE
                    RIGHT('000' + PARSENAME(d.MinBiosRequired, 3), 3) +
                    RIGHT('000' + PARSENAME(d.MinBiosRequired, 2), 3) +
                    RIGHT('000' + PARSENAME(d.MinBiosRequired, 1), 3)
            END
        )
    THEN 'OK'
    ELSE 'UPDATE_REQUIRED'
END AS HP_BIOS_Compliance

FROM
(
    SELECT
        id.name AS Computername,
        inv.ProductName AS ProductName,
        bios.Version AS RawBiosVersion,

        /* letzter Token aus bios.Version, z.B. "R70 Ver. 01.04.06" -> "01.04.06" */
        REVERSE(LEFT(REVERSE(LTRIM(RTRIM(bios.Version))),
                     CHARINDEX(' ', REVERSE(LTRIM(RTRIM(bios.Version))) + ' ') - 1)) AS InstalledBiosVersionOnly,

        /* Mindest-BIOS laut deiner HP-Liste (TBD ausgelassen => NULL) */
        CASE inv.ProductName
		
		
            -- HP Business Notebook PCs
            WHEN 'HP 250R 15.6 inch G9' THEN 'F.14'
            WHEN 'HP 256R 15.6 inch G9' THEN 'F.14'
            WHEN 'HP EliteBook 6 G1a 14 inch AI' THEN '01.02.01'
            WHEN 'HP EliteBook 6 G1a 14 inch Next Gen AI' THEN '01.02.01'
            WHEN 'HP EliteBook 6 G1a 16 inch AI' THEN '01.02.01'
            WHEN 'HP EliteBook 6 G1ah 14 inch' THEN '01.02.01'
            WHEN 'HP EliteBook 6 G1ah 16 inch' THEN '01.02.01'
            WHEN 'HP EliteBook 6 G1i 13 inch AI' THEN '01.02.01'
            WHEN 'HP EliteBook 6 G1i 14 inch AI' THEN '01.02.01'
            WHEN 'HP EliteBook 6 G1i 16 inch AI' THEN '01.02.01'
            WHEN 'HP EliteBook 6 G1iR 14 inch' THEN '01.02.02'
            WHEN 'HP EliteBook 6 G1iR 16 inch' THEN '01.02.02'
            WHEN 'HP EliteBook 8 Flip G1i 13 inch AI' THEN '01.02.05'
            WHEN 'HP EliteBook 8 G1a 13 inch AI' THEN '01.03.03'
            WHEN 'HP EliteBook 8 G1a 13 inch Next Gen AI' THEN '01.03.03'
            WHEN 'HP EliteBook 8 G1a 14 inch AI' THEN '01.03.03'
            WHEN 'HP EliteBook 8 G1a 14 inch Next Gen AI' THEN '01.03.03'
            WHEN 'HP EliteBook 8 G1a 16 inch AI' THEN '01.03.03'
            WHEN 'HP EliteBook 8 G1a 16 inch Next Gen AI' THEN '01.03.03'
            WHEN 'HP EliteBook 8 G1i 13 inch AI' THEN '01.02.05'
            WHEN 'HP EliteBook 8 G1i 14 inch AI' THEN '01.02.05'
            WHEN 'HP EliteBook 8 G1i 14 inch Next Gen AI' THEN '01.02.04'
            WHEN 'HP EliteBook 8 G1i 16 inch AI' THEN '01.02.05'
            WHEN 'HP EliteBook 8 G1i 16 inch Next Gen AI' THEN '01.02.04'
            WHEN 'HP EliteBook X Flip G1i 14 AI' THEN '01.02.23'
            WHEN 'HP EliteBook X G1a 14 inch Next Gen AI' THEN '01.03.11'
            WHEN 'HP EliteBook X G1i 14 AI' THEN '01.02.23'
            WHEN 'HP Fortis Flip G1i 11 inch' THEN '01.01.40'
            WHEN 'HP ProBook 4 G1a 14 inch AI' THEN '01.02.01'
            WHEN 'HP ProBook 4 G1a 16 inch AI' THEN '01.02.01'
            WHEN 'HP ProBook 4 G1ah 14 inch' THEN '01.02.01'
            WHEN 'HP ProBook 4 G1ah 16 inch' THEN '01.02.01'
            WHEN 'HP ProBook 4 G1i 14 inch AI' THEN '01.02.01'
            WHEN 'HP ProBook 4 G1i 16 inch AI' THEN '01.02.01'
            WHEN 'HP ProBook 4 G1iR 14 inch (H)' THEN '01.02.02'
            WHEN 'HP ProBook 4 G1iR 14 inch (U)' THEN '01.02.02'
            WHEN 'HP ProBook 4 G1iR 16 inch (H)' THEN '01.02.02'
            WHEN 'HP ProBook 4 G1iR 16 inch (U)' THEN '01.02.02'
            WHEN 'HP ZBook 8 G1ak 14 inch' THEN '01.03.03'
            WHEN 'HP ZBook 8 G1as 14 inch' THEN '01.03.03'
            WHEN 'HP Elite x360 1040 14 inch G11 2-in-1' THEN '01.07.00'
            WHEN 'HP Elite x360 830 13 inch G11 2-in-1' THEN '01.07.02'
            WHEN 'HP EliteBook 1040 14 inch G11' THEN '01.07.00'
            WHEN 'HP EliteBook 630 13.3 inch G11' THEN '01.07.02'
            WHEN 'HP EliteBook 640 14 inch G11' THEN '01.07.02'
            WHEN 'HP EliteBook 645 14 inch G11' THEN '01.06.01'
            WHEN 'HP EliteBook 660 16 inch G11' THEN '01.07.02'
            WHEN 'HP EliteBook 665 16 inch G11' THEN '01.06.01'
            WHEN 'HP EliteBook 830 13 inch G11' THEN '01.07.02'
            WHEN 'HP EliteBook 835 13 inch G11' THEN '01.06.00'
            WHEN 'HP EliteBook 835 13 inch G11 AI' THEN '01.06.00'
            WHEN 'HP EliteBook 840 14 inch G11' THEN '01.07.02'
            WHEN 'HP EliteBook 845 14 inch G11' THEN '01.06.00'
            WHEN 'HP EliteBook 845 14 inch G11 AI' THEN '01.06.00'
            WHEN 'HP EliteBook 860 16 inch G11' THEN '01.07.02'
            WHEN 'HP EliteBook 860 16 inch G10' THEN '01.10.00'
            WHEN 'HP EliteBook 865 16 inch G11' THEN '01.06.00'
            WHEN 'HP EliteBook 865 16 inch G11 AI' THEN '01.06.00'
            WHEN 'HP ProBook 440 14 inch G11' THEN '01.07.00'
            WHEN 'HP ProBook 440 16 inch G11' THEN '01.07.00'
            WHEN 'HP ProBook 445 14 inch G11' THEN '01.06.01'
            WHEN 'HP ProBook 465 16 inch G11' THEN '01.06.01'
            WHEN 'HP Dragonfly 13.5 inch G4' THEN '01.10.00'
            WHEN 'HP Elite x360 1040 14 inch G10' THEN '01.10.00'
            WHEN 'HP Elite x360 830 13 inch G10' THEN '01.10.00'
            WHEN 'HP EliteBook 1040 14 inch G10' THEN '01.10.00'
            WHEN 'HP EliteBook 630 13.3 inch G10' THEN '01.10.00'
            WHEN 'HP EliteBook 640 14 inch G10' THEN '01.10.00'
            WHEN 'HP EliteBook 645 14 inch G10' THEN '01.11.01'
            WHEN 'HP EliteBook 650 15.6 inch G10' THEN '01.10.00'
            WHEN 'HP EliteBook 655 15.6 inch G10' THEN '01.11.01'
            WHEN 'HP EliteBook 835 13 inch G10' THEN '01.10.03'
            WHEN 'HP EliteBook 840 14 inch G10' THEN '01.10.00'
            WHEN 'HP EliteBook 860 16 inch G10' THEN '01.10.00'
            WHEN 'HP ProBook 440 14 inch G10' THEN '01.10.00'
            WHEN 'HP ProBook 445 14 inch G10' THEN '01.11.01'
            WHEN 'HP ProBook 450 15.6 inch G10' THEN '01.10.00'
            WHEN 'HP ProBook 455 15.6 inch G10' THEN '01.11.01'
            WHEN 'HP Dragonfly Folio 13.5 inch G3' THEN '01.16.00'
            WHEN 'HP Elite Dragonfly 13.5 inch G3' THEN '01.16.00'
            WHEN 'HP Elite x360 1040 14 inch G9' THEN '01.16.01'
            WHEN 'HP Elite x360 830 13 inch G9' THEN '01.16.01'
            WHEN 'HP EliteBook 1040 14 inch G9' THEN '01.16.01'
            WHEN 'HP EliteBook 630 13 inch G9' THEN '01.16.00'
            WHEN 'HP EliteBook 640 14 inch G9' THEN '01.16.00'
            WHEN 'HP EliteBook 645 14 inch G9' THEN '01.20.00'
            WHEN 'HP EliteBook 650 15.6 inch G9' THEN '01.16.00'
            WHEN 'HP EliteBook 655 14 inch G9' THEN '01.20.00'
            WHEN 'HP EliteBook 830 13 inch G9' THEN '01.16.01'
            WHEN 'HP EliteBook 835 13 inch G9' THEN '01.14.00'
            WHEN 'HP EliteBook 840 14 inch G9' THEN '01.16.01'
            WHEN 'HP EliteBook 845 14 inch G9' THEN '01.14.00'
            WHEN 'HP EliteBook 855 16 inch G9' THEN '01.14.00'
            WHEN 'HP EliteBook 860 16 inch G9' THEN '01.16.01'
            WHEN 'HP ProBook 440 14 inch G9' THEN '01.16.00'
            WHEN 'HP ProBook 445 14 inch G9' THEN '01.20.00'
            WHEN 'HP ProBook 450 14 inch G9' THEN '01.16.00'
            WHEN 'HP ProBook 455 14 inch G9' THEN '01.20.00'
            WHEN 'HP Elite X2 G4' THEN '01.33.00'
            WHEN 'HP EliteBook 735 G6' THEN '01.32.00'
            WHEN 'HP EliteBook 745 G6' THEN '01.32.00'
            WHEN 'HP EliteBook 830 G6' THEN '01.33.00'
            WHEN 'HP EliteBook 840 G6' THEN '01.33.00'
            WHEN 'HP EliteBook 840 G6 Healthcare Edition' THEN '01.33.00'
            WHEN 'HP EliteBook 846 G6' THEN '01.33.00'
            WHEN 'HP EliteBook 846 G6 Healthcare Edition' THEN '01.33.00'
            WHEN 'HP EliteBook 850 G6' THEN '01.33.00'
            WHEN 'HP EliteBook x360 1040 G6' THEN '01.33.00'
            WHEN 'HP ProBook 640 G5' THEN '01.33.00'
            WHEN 'HP ProBook 650 G5' THEN '01.33.00'
            WHEN 'HP Zhan 66 Pro A 14 G3' THEN '01.22.00'
            WHEN 'HP Elitebook 860 16 inch G11 Notebook PC' THEN '01.07.02'
            WHEN 'HP Elitebook 830 G7 Notebook PC' THEN '01.22.00'
            WHEN 'HP Elitebook 840 G7 Notebook PC' THEN '01.22.00'
            WHEN 'HP ProBook 450 G8 Notebook PC' THEN '01.22.00'
            WHEN 'HP ProBook 450 G7' THEN '01.26.00'
            WHEN 'HP Elitebook 660 16 inch G11 Notebook PC' THEN '01.07.02'
            WHEN 'HP Elitebook 640 14 inch G9 Notebook PC' THEN '01.22.00'
            WHEN 'HP Elitebook 840 14 inch G10 Notebook PC' THEN '01.10.00'
            WHEN 'HP Elitebook 840 14 inch G9 Notebook PC' THEN '01.16.01'
            WHEN 'HP Elitebook 850 G7 Notebook PC' THEN '01.22.00'
            WHEN 'HP Elitebook 8 G1i 16 inch Notebook AI PC' THEN '01.02.05'
            WHEN 'HP Elitebook 840 14 inch G11 Notebook PC' THEN '01.07.02'
            WHEN 'HP Elitebook 840 G8 Notebook PC' THEN '01.22.00'
            WHEN 'HP Elitebook 650 15.6 inch G10 Notebook PC' THEN '01.22.00'
            WHEN 'HP Elitebook 840 G8 Notebook PC' THEN '01.22.00'
            WHEN 'HP Elitebook 860 16 inch G9 Notebook PC' THEN '01.16.01'
            WHEN 'HP EliteBook 860 16 inch G10 Notebook PC' THEN '01.10.00'
            WHEN 'HP Elitebook 840 14 inch G11 Notebook PC' THEN '01.07.02'
            WHEN 'HP Elitebook 830 G8 Notebook PC' THEN '01.22.00'
            WHEN 'HP Elitebook 830 13 inch G9 Notebook PC' THEN '01.16.01'
            WHEN 'HP Elitebook 830 13 inch G10 Notebook PC' THEN '01.10.00'
            WHEN 'HP Elitebook 830 13 inch G11 Notebook PC' THEN '01.07.02'
            WHEN 'HP Elitebook 8 G1i 14 inch Notebook AI PC' THEN '01.02.05'
            WHEN 'HP Elitebook 8 G1i 13 inch Notebook AI PC' THEN '01.02.05'
            WHEN 'HP ProBook 640 G8 Notebook PC' THEN '01.22.00'
            WHEN 'HP ProBook 650 G8 Notebook PC' THEN '01.22.00'
            WHEN 'HP ProBook 440 G8 Notebook PC' THEN '01.22.00'
            WHEN 'HP EliteBook 630 13.3 inch G11 Notebook PC' THEN '01.07.02'
            WHEN 'HP EliteBook 640 14 inch G11 Notebook PC' THEN '01.07.02'
            WHEN 'HP Elite x360 830 13 inch G11 2-in-1 Notebook PC' THEN '01.07.02'
            WHEN 'HP ProBook 450 15.6 inch G10' THEN '01.10.00'
            WHEN 'HP EliteBook 650 15.6 inch G9 Notebook PC' THEN '01.16.00'
            WHEN 'HP EliteBook 6 G1i 13 inch Notebook AI PC' THEN '01.02.01' 
            WHEN 'HP ZBook 15 G6' THEN '01.33.00'
            WHEN 'HP ZBook Firefly 16 inch G11 Mobile Workstation PC' THEN '01.07.02'
            WHEN 'HP ZBook Firefly 14 inch G11 Mobile Workstation PC' THEN '01.07.02'
            WHEN 'HP ZBook 17 G6' THEN '01.33.00'
            WHEN 'HP ZBook 15 G6' THEN '01.33.00'
            WHEN 'HP ZBook Fury 15.6 inch G8 Mobile Workstation PC' THEN '01.22.00'
            WHEN 'HP ZBook Power 15.6 inch G8' THEN '01.22.00'
            WHEN 'HP ZBook Fury 15 G7 Mobile Workstation' THEN '01.22.00'
            WHEN 'HP ProBook 630 G8 Notebook' THEN '01.22.00'
            WHEN 'HP ProBook 440 14 inch G9 Notebook PC' THEN '01.16.00' 
            WHEN 'HP ProBook 440 G7' THEN '01.26.00'
            WHEN 'HP 470 G8 Notebook PC' THEN '01.22.00'
            WHEN 'HP ProBook 440 14 inch G10 Notebook PC' THEN '01.10.00'
            WHEN 'HP ProBook 450 15.6 inch G10 Notebook PC' THEN '01.10.00'
            WHEN 'HP Pro SFF 400 G9 Desktop PC' THEN '02.19.01'
            WHEN 'HP EliteBook 640 14 inch G10 Notebook PC' THEN '01.10.00'
            WHEN 'HP EliteBook 850 G8 Notebook PC' THEN '01.22.00'
            WHEN 'HP ProBook 630 G8 Notebook PC' THEN '01.22.00'
            WHEN 'HP EliteBook 835 13 inch G11 Notebook PC' THEN '01.06.00'
            WHEN 'HP Elite x360 1040 14 inch G11 2-in-1 Notebook PC' THEN '01.07.00'
            WHEN 'HP EliteBook x360 1030 G7 Notebook PC' THEN '01.22.00'
            WHEN 'HP Elite x360 830 13 inch G10 2-in-1 Notebook PC' THEN '01.10.00'
            WHEN 'HP ZBook Power 15.6 inch G8 Mobile Workstation PC' THEN '01.22.00'
            WHEN 'HP ZBook Fury 16 G9 Mobile Workstation PC' THEN '01.16.00'
            WHEN 'HP EliteBook 6 G1i 16 inch Notebook AI PC' THEN '01.02.01'
            WHEN 'HP ZBook Fury G1i 16 inch Mobile Workstation PC' THEN '0101.18'
            WHEN 'HP EliteBook 8 Flip G1i 13 inch Notebook AI PC' THEN '01.02.05'
           
		   
            -- HP Desktops
            WHEN 'HP ProBook 4 G1i 14 inch Notebook AI PC' THEN '01.02.01'
            WHEN 'HP ProBook 4 G1i 16 inch Notebook AI PC' THEN '01.02.01'
	    WHEN 'HP ProDesk 4 Tower G1i Desktop AI PC' THEN '02.02.02'
	    WHEN 'HP Elite Mini 600 G9 Desktop PC' THEN '02.19.01'
	    WHEN 'HP Elite SFF 600 G9 Desktop PC' THEN '02.19.01'
	    WHEN 'HP Pro Tower 400 G9 PCI Desktop PC' THEN '02.19.01'
	    WHEN 'HP Pro Tower 400 G9' THEN '02.19.01'
            WHEN 'HP Pro Mini 400 G9 Desktop PC' THEN '02.19.01'

			
	    -- HP Desktop Workstations
	    WHEN 'HP Z2 Tower G4 Workstation' THEN '01.08.13'


            --NOT in HP List--
            WHEN 'HP EliteBook 840 G5' THEN '99.00.00'
            WHEN 'HP EliteDesk 800 G3 DM 35W' THEN '99.00.00'
            WHEN 'HP EliteDesk 800 G3 SFF' THEN '99.00.00'
            WHEN 'HP Elite Mini 800 G9 Desktop PC' THEN '99.00.00'
            WHEN 'HP EliteDesk 800 G5 Desktop Mini' THEN '99.00.00'
            WHEN 'HP ProBook 450 G6' THEN '99.00.00'
            WHEN 'HP 470 17 inch G10 Notebook PC' THEN '99.00.00'
            WHEN 'HP ProDesk 400 G5 MT' THEN '99.00.00'
            WHEN 'HP ProDesk 400 G5 SFF' THEN '99.00.00'
            WHEN 'HP ProDesk 400 G6 MT' THEN '99.00.00'
            WHEN 'HP EliteDesk 800 G6 Desktop Mini PC' THEN '99.00.00'
            WHEN 'HP EliteDesk 800 G5 SFF' THEN '99.00.00'
            WHEN 'HP ProOne 400 G1 AiO' THEN '99.00.00'
            WHEN 'HP Elite Mini 600 G9 Desktop PC' THEN '99.00.00'
            WHEN 'HP EliteBook 850 G5' THEN '99.00.00'
            WHEN 'HP 470 17 inch G9 Notebook PC' THEN '99.00.00'
            WHEN 'HP 470 G7 Notebook PC' THEN '99.00.00'
            WHEN 'HP ProDesk 600 G5 SFF' THEN '99.00.00'
            WHEN 'HP ProDesk 600 G1 TWR' THEN '99.00.00'
            WHEN 'HP ProDesk 600 G3 SFF' THEN '99.00.00'
            WHEN 'HP ZBook 15u G5' THEN '99.00.00'
            WHEN 'HP ProDesk 400 G6 Desktop Mini PC' THEN '99.00.00'
            WHEN 'HP Pro Mini 400 G9 Desktop PC' THEN '99.00.00'
            WHEN 'HP ProBook 460 16 inch G11 Notebook PC' THEN '99.00.00'
            WHEN 'HP ProDesk 400 G1 MT' THEN '99.00.00'
            WHEN 'HP Z240 Tower Workstation' THEN '99.00.00'
            WHEN 'HP EliteBook 830 G5' THEN '99.00.00'
            WHEN 'HP ProBook 470 G5' THEN '99.00.00'
            WHEN 'HP ProBook 460 16 inch G11 Notebook PC' THEN '99.00.00'
            WHEN 'HP EliteBook x360 1040 G5' THEN '99.00.00'
            WHEN 'HP 250 G8 Notebook PC' THEN '99.00.00'
            WHEN 'HP 255 G7 Notebook PC' THEN '99.00.00'
            WHEN 'HP ProDesk 400 G3 DM' THEN '99.00.00'
            WHEN 'HP ProDesk 400 G3 DM' THEN '99.00.00'
            WHEN 'HP ProBook 470 G5' THEN '99.00.00'
            WHEN 'HP EliteDesk 800 G3 TWR' THEN '99.00.00'
            WHEN 'HP ProBook 450 G5' THEN '99.00.00'
            WHEN 'HP ProDesk 400 G5 Desktop Mini' THEN '99.00.00'
            WHEN 'HP EliteDesk 800 G4 SFF' THEN '99.00.00'
            WHEN 'HP ProDesk 400 G5 DM' THEN '99.00.00'
            WHEN 'HP 260 G3 DM' THEN '99.00.00'
            WHEN 'HP Compaq Elite 8300 CMT' THEN '99.00.00'
            WHEN 'HP EliteDesk 800 G3 TWR' THEN '99.00.00'
            WHEN 'HP EliteDesk 800 G4 DM 35W' THEN '99.00.00' 
            WHEN 'HP ProBook 440 G6' THEN '99.00.00'
            WHEN 'HP EliteDesk 800 G6 Small Form Factor PC' THEN '99.00.00'
            WHEN 'HP ProDesk 400 G7 Microtower PC' THEN '99.00.00'
            WHEN 'HP Pavilion Desktop 590-p0xxx' THEN '99.00.00'
            WHEN 'HP EliteBook 850 G3' THEN '99.00.00'
            WHEN 'HP 250 G6 Notebook PC' THEN '99.00.00'
            WHEN 'HP Compaq Elite 8300 MT' THEN '99.00.00'
            WHEN 'HP Z230 Tower Workstation' THEN '99.00.00'
            WHEN 'HP 250 G6 Notebook PC' THEN '99.00.00'
            WHEN 'HP 250 G7 Notebook PC' THEN '99.00.00'
            WHEN 'HP Dragonfly 13.5 inch G4 Notebook PC' THEN '99.00.00'
            WHEN 'HP EliteBook x360 1030 G3' THEN '99.00.00'


           --To be defined by HP--
           WHEN 'HP Elite x2 G8 Tablet' THEN '66.00.00'
           WHEN 'HP Z4 G4 Workstation' THEN '66.00.00'


            ELSE NULL
        END AS MinBiosRequired

    FROM Inv_SW_BIOS_Element bios
    JOIN Inv_Agent_Plugin_Inventory inv
        ON inv._ResourceGuid = bios._ResourceGuid
    JOIN Inv_AeX_AC_Identification id
        ON id._ResourceGuid = bios._ResourceGuid
    WHERE inv.ProductName LIKE 'HP %'
) d

Report for DELL

In addtion to the HP Report we have created a custom Altiris report for DELL devices that provides a clear overview of BIOS compliance across the environment.

The report compares the installed BIOS version on each Dell device with the minimum BIOS version required by Dell, based on the official Dell minimum BIOS version list.

Report Status Values

Each device is evaluated and assigned one of the following compliance states:

  • NO_MATCH_IN_DELL_TABLE
    The Dell model detected by the Altiris Inventory Solution is not listed in Dell minimum Bios Version list documentation.
    This does not necessarily indicate a problem, but the device cannot be validated automatically.
  • OK
    The installed BIOS version meets or exceeds the minimum BIOS version required by Dell.
    No action is required for this device.
  • UPDATE_REQUIRED
    The installed BIOS version is lower than the minimum version required by Dell.
    A BIOS update is recommended to ensure compliance and mitigate potential security or stability issues.

Benefits of the Report

  • Centralized visibility of Dell BIOS compliance
  • Fast identification of devices requiring BIOS updates
  • Clear distinction between compliant, non-compliant, and unsupported models
  • Easy integration into existing Altiris reporting and dashboards

This report helps administrators proactively manage BIOS updates and maintain a secure, compliant Dell device fleet.

SELECT
    d.Computername,
    d.ProductName,
    d.InstalledBiosVersion,
    d.MinBios2023,
    CASE
        WHEN d.MinBios2023 IS NULL THEN 'NO_MATCH_IN_DELL_TABLE'
        WHEN
            /* Installed >= Minimum (string-safe comparison) */
            (RIGHT('000' + PARSENAME(d.InstalledBiosVersion, 3), 3) +
             RIGHT('000' + PARSENAME(d.InstalledBiosVersion, 2), 3) +
             RIGHT('000' + PARSENAME(d.InstalledBiosVersion, 1), 3))
            >=
            (RIGHT('000' + PARSENAME(d.MinBios2023, 3), 3) +
             RIGHT('000' + PARSENAME(d.MinBios2023, 2), 3) +
             RIGHT('000' + PARSENAME(d.MinBios2023, 1), 3))
        THEN 'OK'
        ELSE 'UPDATE_REQUIRED'
    END AS SecureBoot2023_Compliance
FROM
(
    SELECT
        id.Name        AS Computername,
        inv.ProductName AS ProductName,
        bios.Version    AS InstalledBiosVersion,
        /* ===== Minimum BIOS Version with 2023 Certificate ===== */
        CASE inv.ProductName
        /* --- Dell Consumer / Desktop --- */
        WHEN 'Dell 14 DC14250' THEN '1.1.1'
        WHEN 'Dell 14 DC14255' THEN '1.4.1'
        WHEN 'Dell 14 Plus 2-in-1 DB04250' THEN '1.6.0'
        WHEN 'Dell 14 Plus 2-in-1 DB04255' THEN '1.4.1'
        WHEN 'Dell 14 Plus DB14250' THEN '1.6.0'
        WHEN 'Dell 14 Plus DB14255' THEN '1.4.1'
        WHEN 'Dell 14 Premium DA14250' THEN '1.3.2'
        WHEN 'Dell 15 DC15250' THEN '1.2.1'
        WHEN 'Dell 15 DC15255' THEN '1.3.1'
        WHEN 'Dell 16 DC16250' THEN '1.3.0'
        WHEN 'Dell 16 DC16251' THEN '1.3.0'
        WHEN 'Dell 16 DC16255' THEN '1.0.1'
        WHEN 'Dell 16 DC16256' THEN '1.0.1'
        WHEN 'Dell 16 Plus 2-in-1 DB06250' THEN '1.6.0'
        WHEN 'Dell 16 Plus DB16250' THEN '1.6.0'
        WHEN 'Dell 16 Plus DB16255' THEN '1.4.1'
        WHEN 'Dell 16 Premium DA16250' THEN '1.5.0'
        WHEN 'Dell 24 All-in-One EC24250' THEN '1.7.1'
        WHEN 'DELL 27 All-in-One EC27250' THEN '1.7.1'
        WHEN 'Dell Laptop DC14255' THEN '1.4.1'
        WHEN 'Dell Slim ECS1250' THEN '1.6.2'
        WHEN 'Dell Tower ECT1250' THEN '1.6.2'
        WHEN 'Dell Tower Plus EBT2250' THEN '1.8.1'
        /* --- Dell G-Series --- */
        WHEN 'Dell G15 5510' THEN '1.36.0'
        WHEN 'Dell G15 5511' THEN '1.39.0'
        WHEN 'Dell G15 5515' THEN '1.28.1'
        WHEN 'Dell G15 5520' THEN '1.35.0'
        WHEN 'Dell G15 5525' THEN '1.24.0'
        WHEN 'Dell G15 5535' THEN '1.16.0'
        WHEN 'Dell G16 7620' THEN '1.35.0'
        /* --- Dell Pro --- */
        WHEN 'Dell Pro 13 Plus PB13250' THEN '2.6.1'
        WHEN 'Dell Pro 13 Plus PB13255' THEN '1.7.0'
        WHEN 'Dell Pro 13 Premium PA13250' THEN '2.6.1'
        WHEN 'Dell Pro 14 Essential PV14250' THEN '1.1.1'
        WHEN 'Dell Pro 14 PC14250' THEN '1.7.0'
        WHEN 'Dell Pro 14 PC14255' THEN '1.7.0'
        WHEN 'Dell Pro 14 Plus PB14250' THEN '2.6.1'
        WHEN 'Dell Pro 14 Plus PB14255' THEN '1.7.0'
        WHEN 'Dell Pro 14 Premium PA14250' THEN '2.6.1'
        WHEN 'Dell Pro 15 Essential PV15250' THEN '1.0.0'
        WHEN 'Dell Pro 15 Essential PV15255' THEN '1.2.1'
        WHEN 'Dell Pro 16 PC16250' THEN '1.7.0'
        WHEN 'Dell Pro 16 PC16255' THEN '1.7.0'
        WHEN 'Dell Pro 16 Plus PB16250' THEN '2.6.1'
        WHEN 'Dell Pro 16 Plus PB16255' THEN '1.7.0'
        WHEN 'Dell Pro Laptop PC14250' THEN '1.7.0'
        WHEN 'Dell Pro Laptop PC16250' THEN '1.7.0'
        /* --- Inspiron --- */
        WHEN 'Inspiron 15 3511' THEN '1.40.0'
        WHEN 'Inspiron 15 3520' THEN '1.35.0'
        WHEN 'Inspiron 15 3530' THEN '1.23.2'
        WHEN 'Inspiron 16 5620' THEN '1.31.0'
        WHEN 'Inspiron 16 5630' THEN '1.24.1'
        WHEN 'Inspiron 3020 Desktop' THEN '1.29.1'
        WHEN 'Inspiron 3030' THEN '1.19.1'
        /* --- Latitude (häufigste Modelle) --- */
        WHEN 'Latitude 3410' THEN '1.36.0'
        WHEN 'Latitude 3420' THEN '1.44.0'
        WHEN 'Latitude 3510' THEN '1.36.0'
        WHEN 'Latitude 3520' THEN '1.44.0'
        WHEN 'Latitude 3540' THEN '1.25.1'
        WHEN 'Latitude 5300' THEN '1.37.0'
        WHEN 'Latitude 5310' THEN '1.30.0'
        WHEN 'Latitude 5320' THEN '1.46.0'
        WHEN 'Latitude 5340' THEN '1.24.1'
        WHEN 'Latitude 5350' THEN '1.16.1'
        WHEN 'Latitude 5400' THEN '1.41.1'
        WHEN 'Latitude 5401' THEN '1.42.1'
        WHEN 'Latitude 5410' THEN '1.38.1'
        WHEN 'Latitude 5450' THEN '1.16.2'
        WHEN 'Latitude 5430' THEN '1.32.1'
        WHEN 'Latitude 5440' THEN '1.25.1'
        WHEN 'Latitude 5510' THEN '1.38.1'
        WHEN 'Latitude 5520' THEN '1.46.0'
        WHEN 'Latitude 5540' THEN '1.24.1'
        WHEN 'Latitude 5550' THEN '1.16.2'
        WHEN 'Latitude 7420' THEN '1.42.0'
        WHEN 'Latitude 7430' THEN '1.34.1'
        WHEN 'Latitude 7440' THEN '1.25.1'
        WHEN 'Latitude 7450' THEN '1.16.0'
        WHEN 'Latitude 7320 Detachable' THEN '1.43.0'
        WHEN 'Latitude 7350 Detachable' THEN '1.14.1'
        /* --- OptiPlex --- */
        WHEN 'OptiPlex 3070' THEN '1.35.0'
        WHEN 'OptiPlex 3080' THEN '2.33.0'
        WHEN 'OptiPlex 3090' THEN '2.27.0'
        WHEN 'OptiPlex 5070' THEN '1.35.0'
        WHEN 'OptiPlex 5080' THEN '1.33.0'
        WHEN 'OptiPlex 7090 Tower' THEN '1.37.0'
        /* --- Precision --- */
        WHEN 'Precision 3440' THEN '1.36.0'
        WHEN 'Precision 3450' THEN '1.37.0'
        WHEN 'Precision 3550' THEN '1.38.1'
        WHEN 'Precision 3560' THEN '1.46.0'
        WHEN 'Precision 5570' THEN '1.35.0'
        WHEN 'Precision 5860 Tower' THEN '3.1.1'
        /* --- Vostro --- */
        WHEN 'Vostro 15 3510' THEN '1.40.0'
        WHEN 'Vostro 15 3520' THEN '1.35.0'
        WHEN 'Vostro 14 3420' THEN '1.35.0'
        WHEN 'Vostro 3501' THEN '1.41.0'
        WHEN 'Vostro 3400' THEN '1.41.0'
        /* --- Wyse --- */
        WHEN 'Wyse 5070' THEN '1.38.0'
        WHEN 'Wyse 5470' THEN '1.32.0'
        /* --- XPS --- */
        WHEN 'XPS 13 9310' THEN '3.34.0'
        WHEN 'XPS 13 9340' THEN '1.19.0'
        WHEN 'XPS 13 9315' THEN '1.32.0'
        WHEN 'XPS 15 9520' THEN '1.35.0'
        WHEN 'XPS 17 9720' THEN '1.35.0'
        WHEN 'XPS 13 Plus 9320' THEN '2.24.1'
        ELSE NULL
        END AS MinBios2023
    FROM Inv_SW_BIOS_Element bios
    JOIN Inv_Agent_Plugin_Inventory inv
        ON inv._ResourceGuid = bios._ResourceGuid
    JOIN Inv_AeX_AC_Identification id
        ON id._ResourceGuid = bios._ResourceGuid
) d
WHERE
    d.ProductName LIKE 'Dell%'
 OR d.ProductName LIKE 'Latitude%'
 OR d.ProductName LIKE 'OptiPlex%'
 OR d.ProductName LIKE 'Precision%'
 OR d.ProductName LIKE 'Vostro%'
 OR d.ProductName LIKE 'Inspiron%'
 OR d.ProductName LIKE 'XPS%'
 OR d.ProductName LIKE 'Wyse%'

References & Vendor Documentation

  • HP – Prepare for new Windows Secure Boot certificates: HP provides official guidance on BIOS updates required to support the upcoming Secure Boot certificate changes.
    HP (Original doc: HP Commercial PCs – Prepare for new Windows Secure Boot certificates)
  • Dell – Secure Boot Certificate Transition: Dell publishes a detailed knowledge-base article outlining which Dell platforms will receive BIOS updates that include the new 2023 Secure Boot certificates; they also recommend keeping BIOS up-to-date to ensure compatibility. Dell
  • Lenovo – Microsoft 2011 Secure Boot Certificate Expiration: Lenovo confirms that supported Lenovo Commercial PCs will receive BIOS updates that embed the 2023 Secure Boot certificates. Lenovo Support
  • Microsoft – Secure Boot Certificate Change (2026): Microsoft’s official post explains why the existing 2011 Secure Boot certificates expire in 2026 and why updating to the new 2023 certificates is critical for system integrity and boot security. TECHCOMMUNITY.MICROSOFT.COM

Hinterlasse einen Kommentar