Skip to Content

Preboot Manager

Frequently Asked Questions

Click on the question to show the answer. Expand All Answers

  1. Where can I find Wave EMBASSY Security Center on Dell Latitude E-Family and Precision Mobile Workstations?

    For Dell PCs, where Dell ControlPoint is installed, Wave ETS software is launched from Dell ControlPoint Security Manager. However, ETS can be launched directly on these systems by going to Start -> All Programs -> Dell ControlPoint -> Security Manager -> Advanced -> EMBASSY Security Center.

  2. What is Dell ControlPoint (DCP) and how does EMBASSY Trust Suite (ETS) integrate with it?

    Dell ControlPoint is a new Dell application framework that provides an integrated and easy to use interface for managing laptop features including system, network and security settings. To enable security features, DCP utilizes ETS for Dell version 3.0. Users simply select which top level features to activate from DCP which in turn launches ETS for Dell. Once ETS is in use, users have the options of managing an FDE hard drive and a Trusted Platform Module (TPM), for application solutions such as full disk encryption and enabling strong pre-boot and multi-factor authentication.

  3. How can I delete preboot authentication credentials for all enrolled users?

    To clear preboot authentication credentials for all enrolled users, do the following from the ESC Preboot Manager > Advanced screen (or in the Dell BIOS):

  4. a. If both the BIOS system and BIOS admin passwords are set, change the BIOS admin password to a null value.
  5. b. If the BIOS system password is set and the BIOS admin password is not set, first change the BIOS system password to null and set the BIOS admin password to a value. Then change the BIOS admin password to null.
  • Do Dell Latitude™ E-Family Laptops and Precision™ Mobile Workstations ship with a Trusted Platform Module (TPM)?

    Yes. These business class PCs come standard with a TPM that conforms to v 1.2 of the Trusted Computing Group specification. These machines incorporate a TPM as part of an integrated security chip that also includes Dell ControlVault, a hardware container used for storing secrets such as passwords and fingerprint templates.

  • How does ETS for Dell 3.0 use Dell ControlVault?

    ETS for Dell 3.0 uses the Dell ControlVault for securely storing fingerprint templates and other authentication information for an enhanced preboot authentication experience.

  • Can I upgrade my Dell D-Family PC with ETS for Dell version 3.0 and will I get the new ETS features?

    Yes, you can upgrade your x30 series D-Family laptops. The new Seagate Full Disk Encryption features supported in this configuration are single sign on to Windows and Windows password synchronization. Most other new features require Dell Latitude E-Family specific hardware components and are therefore not supported on D-Family machines.

  • Can I upgrade my Dell D-Family PC with ETS for Dell version 3.0 and will I get the new ETS features?

    Yes, you can upgrade your x30 series D-Family laptops. The new Seagate Full Disk Encryption features supported in this configuration are single sign on to Windows and Windows password synchronization. Most other new features require Dell Latitude E-Family specific hardware components and are therefore not supported on D-Family machines.

  • Do I need to upgrade to ETS for Dell version 3.0 to support Seagate Momentus 7200 RPM FDE hard drives?

    No. Previous ETS versions that contain Trusted Drive Manager will support both Seagate Momentus 5400 and 7200 RPM FDE drives.

  • Does the Dell E4300 ultraportable laptop support Seagate Momentus FDE hard drives?

    Yes. The Dell E4300 laptop uses a 2.5” hard drive and therefore is compatible with Seagate FDE drives. However, the Dell E4200 laptop uses solid state drive technology and is therefore not compatible with Seagate FDE drives.

  • What are the differences between ETS for Dell version 3.0 and ETS for Dell version 2.1?

    ETS for Dell version 3.0 includes the following new capabilities:

    • Advanced Windows Logon features for Seagate Momentus™ Full Disk Encryption (FDE) drives.
      • Single sign-on to Windows – increases security while reducing costs associated with password management.
      • Windows password synchronization – support for existing password policies ensures ease of use.
    • New Multi-factor Authentication options for Dell preboot including.
    • Enhanced Security and Usability for Fingerprint Authentication.
    • Integration with Dell ControlPoint and ControlVault.

  • Does my existing EMBASSY Remote Administration Server (ERAS) support ETS for Dell version 3.0?

    Yes. All supported versions of ERAS are fully compatible with ETS for Dell version 3.0. In addition to managing the security features of FDE hard drives, ERAS is used to activate TPMs to secure data on client machines and to protect access to corporate networks.

  • Is EMBASSY® Trust Suite compatible with Vista?
    EMBASSY Trust Suite and Vista Compatibility

    Dell has released ETS "Lite" for Vista as version A14. This package includes Embassy Trust Suite, UPEK drivers, and the NTRU TSS. If your system shipped with a pre-installed copy of Embassy Trust Suite, you can obtain the Vista-compatible version from the Dell website.

    If you are upgrading from XP to Vista, Please follow the upgrade instructions:
    XP to Vista Upgrade

    ETS Enterprise Security Dell Edition 3.x and Wave ETS 6.x fully support the Windows Vista OS.

    Previous versions of these products do not support the Windows Vista OS.

    Upgrading to a Vista-compatible version of ETS

    • Dell customers should visit the Dell website for updates. (For more information on obtaining updates for your Dell computer, please see the following article PBA-002.)
    • If you purchased ETS Enterprise through Envoy Data or Dell, you will need to purchase a new license.
  • What is Preboot Manager?

    Preboot Manager provides security for a system when it is not turned on.  This option requires that a user's identity be authenticated before the computer boots up.  Preventing the operating system from loading means unauthorized users are effectively shut out of the system, so that if the PC is stolen or lost, it secures the data on the hard drive from being exposed.

    The Preboot Manager guides the administrative user through setting up the appropriate system level passwords.  The administrator can then set up Preboot Authentication by using a fingerprint scanner or a Smart Card in place of the passwords.  The Preboot Manager is used to configure the security settings, set the passwords and enroll the Smart Card or fingerprint.

    If a fingerprint scanner is not embedded in this system, Preboot Manager supports UPEK sensors.  If a Smart Card was not included with this system, please contact the system manufacturer.

  • What is Preboot Manager Protecting?

    Preboot Manager secures the BIOS, hard disk and operating system from unauthorized access in case the laptop is lost or stolen. You can use a smart card or fingerprint for system access.

  • Who can configure Preboot Manager?

    Only a Windows system administrator or a user with administrative rights is able to set up Preboot Authentication using Preboot Manager. A limited user who does not have administrative rights will have access to change the Smart Card PIN.

  • The Embassy Trust Suite software that came loaded on my machine has been uninstalled. Where can I find a download for this program?

    This is relevant for the new Dell Computers that are shipping with the Embassy Trust Suite Software with Preboot Authentication Manager.

    If for any reason, the software is removed, or you installed a corporate image into the computer, and later on you determine that you want to use the software you need to go to the dell website and download it.

  • Using Internet Explorer, go to support.dell.com/support
  • Under Select a Product, either enter the Service Tag of your computer or the Product Model
  • then go to Select a Tool, choose Drivers & Downloads, Click on Go
  • Select the Operating System of your computer (i.e. Microsoft Windows XP)
  • Click on Find Downloads
  • Expand on Security
  • Choose the option Wave System Corp - Application, Download and install
  • Restart your computer
  • I performed a Windows update and now when I try to use my UPEK fingerprint reader I get errors.

    Go to the Dell web site at www.support.dell.com, navigate to the Drivers And Download Section then download the SmartCard controller under Chipset. Once downloaded, install and reboot computer. More information can be found here.

  • When I try to enroll fingerprints for domain users I get the following error: "Cannot write to fingerprints database."

    If you encounter this problem, you will need to download a patch to fix it. Please follow this link for instructions to correct this issue: Download Newest ETS

  • How to Delete Fingerprints from the computer?

    The following steps outline how to delete fingerprints using the Dell Preboot Manager Enrollment Wizard.

    • Choose EMBASSY Security Center - appears as shortcut on the Desktop
    • click Preboot Manager
    • Choose EMBASSY Security Center
    • At Enroll Fingerprints Click on Enroll
    • Click Select
    • Click Locations (This allows you to choose local users or domain users)
    • If you need to change User Name and Domain click Select Other User
    • Click Locations (This allows you to choose local users or domain users)
    • Click Advanced
    • Enter part or all of the Username you want to un-enroll fingerprints
    • Click " Find Now ";
    • Choose the user you want and click OK
    • Swipe your finger to authenticate
    • You are now presented with a screen that shows 2 hands
    • Click on a fingerprint. A screen will appear that says: Do you want to delete this fingerprint?
    • Click Yes
    • Continue this process until all fingerprints have been deleted
    • Click finish

    See Also: (a graphical representation)

    Steps to Delete Users Fingerprints Credentials

  • I am receiving an error which states the EULA.txt file cannot be located?

    There has been instances, when the EULA.txt file is not found giving the following error:

    "The End User License Agreement(EULA) could not be located."

    Look at the following Knowledge Base Article for details on how to resolve this issue.

    ESC-014

  • What are the Dell Systems which include ETS for Dell version 3.0 as a standard feature?

    Dell Latitude E4200, E4300, E5400, E5500, E6400, E6400 ATG, E6500

    Dell Precision Mobile Workstation M2400, M4400

  • Additional Support

    If you need additional information, please submit a Support Request Form. Customer Service will contact you within one business day with a response to your inquiry. To ensure quality customer service, please include your email address and a detailed description of the issue/inquiry.

    Support Request Form