SCRIPT LIBRARY · POWERSHELL
Skip Dell Boot Password Prompts During Maintenance with Password Bypass
Turn on Dell's Password Bypass so patch reboots don't sit at a power-on password prompt all night, then turn it back off when you're done.
- What it does
- Sets the Dell BIOS Password Bypass option (Disabled, RebootBypass, ResumeBypass, or RebootAndResumeBypass), checking the model supports it and supplying the admin password at runtime when one is set.
- Requires
- Windows PowerShell 5.1
- DellBIOSProvider module (Dell Command | PowerShell Provider), installed or shipped in the package
- Microsoft Visual C++ Redistributable
- Permissions
- Local administrator or SYSTEM on the target PC, plus the BIOS admin password if one is set
- Runs on
- Dell business PCs on Windows 10/11
- Tested
- Parse-checked and dry-run with mocked Dell provider cmdlets in PowerShell 7.4
Part 4 of the thread Dell BIOS passwords, without the pain
If your Dells have a system (power-on) password or a drive password, patch night has a problem. Updates install, the machine restarts, and then it sits at a password prompt until somebody walks up to it on Monday. Half your compliance numbers are waiting on a keyboard.
Dell's Password Bypass setting fixes exactly that. With RebootBypass, a warm restart skips the power-on and drive password prompts; a cold boot from power-off still asks. ResumeBypass does the same for waking from hibernate, and RebootAndResumeBypass does both.
The original post called this an "override" of the BIOS admin password. It isn't. Password Bypass never touches the admin (setup) password, and you still need that password to change the setting when one is set. (That old script also defined a function and never called it, so it didn't do anything at all.) This version sets the mode you ask for, checks the model supports it, and gets the admin password at runtime instead of from the package.
<#
.SYNOPSIS
Sets the Dell BIOS Password Bypass option so reboots and resumes skip the power-on and drive password prompts.
.DESCRIPTION
Password Bypass lets a Dell PC that has a system (power-on) or internal drive password come back from
a restart or resume without stopping at the password prompt. A cold boot still asks. This script
reads the current value, checks the model supports the mode you asked for, and changes it. If a BIOS
admin password is set, the change needs it; pass it as a SecureString or let the script read it from
a Configuration Manager task sequence variable at runtime.
Exit codes: 0 = changed, already set, or not a Dell; 1 = the BIOS refused the change;
2 = provider missing or setting not supported; 3 = admin password needed but not supplied.
.PARAMETER Mode
Disabled, RebootBypass, ResumeBypass, or RebootAndResumeBypass.
.PARAMETER AdminPassword
The BIOS admin password, if one is set.
.PARAMETER PasswordVariable
Task sequence variable to read the admin password from when -AdminPassword isn't given.
.EXAMPLE
.\Set-DellPasswordBypass.ps1 -Mode RebootBypass -AdminPassword (Read-Host -AsSecureString 'BIOS admin password')
.EXAMPLE
.\Set-DellPasswordBypass.ps1 -Mode Disabled
#>
[CmdletBinding(SupportsShouldProcess)]
param(
[Parameter(Mandatory)]
[ValidateSet('Disabled', 'RebootBypass', 'ResumeBypass', 'RebootAndResumeBypass')]
[string]$Mode,
[securestring]$AdminPassword,
[ValidateNotNullOrEmpty()][string]$PasswordVariable = 'BIOSAdminPassword'
)
function Get-TSSecret {
param([string]$Name)
try { $ts = New-Object -ComObject Microsoft.SMS.TSEnvironment -ErrorAction Stop } catch { return $null }
$value = $ts.Value($Name)
if ([string]::IsNullOrEmpty($value)) { return $null }
ConvertTo-SecureString -String $value -AsPlainText -Force
}
function Import-DellProvider {
if (Get-Module -ListAvailable -Name DellBIOSProvider) { Import-Module DellBIOSProvider -ErrorAction Stop; return }
# Fall back to a copy shipped in the package (Save-Module puts it in a version subfolder).
$bundled = Get-ChildItem -Path (Join-Path $PSScriptRoot 'DellBIOSProvider') -Filter 'DellBIOSProvider.psd1' -Recurse -ErrorAction SilentlyContinue | Select-Object -First 1
if ($bundled) { Import-Module $bundled.FullName -ErrorAction Stop; return }
throw 'DellBIOSProvider not found. Install it, or copy the module folder into the package next to this script.'
}
$result = [ordered]@{ ComputerName = $env:COMPUTERNAME; Setting = 'PasswordBypass'; Before = ''; After = ''; Status = ''; Detail = '' }
$manufacturer = (Get-CimInstance -ClassName Win32_ComputerSystem).Manufacturer
if ($manufacturer -notlike 'Dell*') {
$result.Status = 'NotApplicable'; $result.Detail = "Manufacturer is '$manufacturer'."
[pscustomobject]$result; exit 0
}
try { Import-DellProvider }
catch { $result.Status = 'Failed'; $result.Detail = $_.Exception.Message; [pscustomobject]$result; exit 2 }
$item = Get-Item -Path 'DellSmbios:\Security\PasswordBypass' -ErrorAction SilentlyContinue
if (-not $item) {
$result.Status = 'NotSupported'; $result.Detail = 'This model does not expose PasswordBypass.'
[pscustomobject]$result; exit 2
}
if ($item.PossibleValues -and ($item.PossibleValues -notcontains $Mode)) {
$result.Status = 'NotSupported'; $result.Detail = "Model accepts: $($item.PossibleValues -join ', ')"
[pscustomobject]$result; exit 2
}
$result.Before = "$($item.CurrentValue)"
if ($result.Before -eq $Mode) {
$result.Status = 'NoChange'; $result.After = $result.Before
[pscustomobject]$result; exit 0
}
# Changing any setting needs the admin password when one is set.
$adminSet = "$((Get-Item -Path 'DellSmbios:\Security\IsAdminPasswordSet' -ErrorAction SilentlyContinue).CurrentValue)" -ne 'False'
if ($adminSet -and -not $AdminPassword) { $AdminPassword = Get-TSSecret -Name $PasswordVariable }
if ($adminSet -and -not $AdminPassword) {
$result.Status = 'Failed'; $result.Detail = 'A BIOS admin password is set, but none was supplied.'
[pscustomobject]$result; exit 3
}
$exitCode = 0
if ($PSCmdlet.ShouldProcess($env:COMPUTERNAME, "Set PasswordBypass from '$($result.Before)' to '$Mode'")) {
$setArgs = @{ Path = 'DellSmbios:\Security\PasswordBypass'; Value = $Mode; ErrorAction = 'Stop' }
if ($adminSet) { $setArgs.Password = [System.Net.NetworkCredential]::new('', $AdminPassword).Password }
try {
Set-Item @setArgs
$result.Status = 'Changed'
}
catch {
$result.Status = 'Failed'; $result.Detail = $_.Exception.Message; $exitCode = 1
}
finally {
$setArgs.Remove('Password')
}
}
else {
$result.Status = 'WhatIf'
}
$result.After = "$((Get-Item -Path 'DellSmbios:\Security\PasswordBypass' -ErrorAction SilentlyContinue).CurrentValue)"
[pscustomobject]$result
exit $exitCode
Parameters
| Parameter | Type | Default | What it's for |
|---|---|---|---|
-Mode | string | — | Required. Disabled, RebootBypass, ResumeBypass, or RebootAndResumeBypass. |
-AdminPassword | securestring | — | The BIOS admin password, needed only if one is set. In a task sequence, leave it off and use the variable below. |
-PasswordVariable | string | BIOSAdminPassword | Hidden task sequence variable to read the admin password from. |
-WhatIf | switch | — | Shows the current value and what it would change it to. |
Run it
Turn on reboot bypass before a maintenance window, typing the admin password.
.\Set-DellPasswordBypass.ps1 -Mode RebootBypass -AdminPassword (Read-Host -AsSecureString 'BIOS admin password')From a task sequence, reading the hidden BIOSAdminPassword variable.
powershell.exe -NoProfile -ExecutionPolicy Bypass -File .\Set-DellPasswordBypass.ps1 -Mode RebootBypassPut it back when the window closes.
powershell.exe -NoProfile -ExecutionPolicy Bypass -File .\Set-DellPasswordBypass.ps1 -Mode DisabledSee what a machine is set to without changing it.
.\Set-DellPasswordBypass.ps1 -Mode RebootBypass -WhatIfWhat you'll see
ComputerName : PC-0142
Setting : PasswordBypass
Before : Disabled
After : RebootBypass
Status : Changed
Detail :
How it works
- Non-Dells exit 0. Safe to deploy to a mixed collection.
- Load the provider from an installed module, or from a copy shipped next to the script.
- Check the setting exists and accepts your mode.
Get-Item DellSmbios:\Security\PasswordBypassreturns the current value and, on most models, the list of values it accepts. Unsupported means exit 2, not a half-applied change. - Skip it if it's already set. No point writing to the BIOS for nothing.
- Work out if a password is needed. If
IsAdminPasswordSetis true, the script uses-AdminPasswordor the task sequence variable, and exits 3 if it has neither. - Set it and read it back. The
Aftervalue comes from a fresh read of the BIOS, not from what the script hoped it set.
Packaging it
Put the script and the provider in a package, then call it from two short task sequences: one that turns bypass on before patching and one that turns it off after.
$SiteCode = 'ABC'
$SourceShare = '\\sccm01\Sources\Scripts'
$DPGroup = 'All DPs'
$Name = 'Dell - Password Bypass'
$source = Join-Path $SourceShare 'Set-DellPasswordBypass'
New-Item -ItemType Directory -Path $source -Force | Out-Null
Copy-Item .\Set-DellPasswordBypass.ps1 -Destination $source
Save-Module -Name DellBIOSProvider -Path $source
Import-Module (Join-Path $env:SMS_ADMIN_UI_PATH '..\ConfigurationManager.psd1')
Push-Location "$($SiteCode):\"
New-CMPackage -Name $Name -Path $source | Out-Null
Start-CMContentDistribution -PackageName $Name -DistributionPointGroupName $DPGroup
Pop-Location
Take it further
- Tie it to your maintenance windows. Schedule the "on" task sequence an hour before the window opens and the "off" one after it closes, both against the same collection.
- Keep the collection tight. Build it from hardware inventory so it only holds Dells. The script copes with other hardware, but there's no reason to send it there.
- Audit the fleet. A quick
Invoke-Commandthat imports the provider and readsDellSmbios:\Security\PasswordBypasswill show you which machines have bypass left on from some long-forgotten project.
Things that'll trip you up
- It doesn't bypass the admin password. It only skips the power-on and drive password prompts on a restart or resume. BIOS setup still wants the admin password, and so does this script when one is set.
- Leaving it on is a security decision. With RebootBypass on, anyone who can trigger a restart gets past the power-on prompt. Turn it on for the window and back off afterwards, or decide on purpose that it stays on.
- Don't put the admin password in the package. Changing any setting on a protected BIOS needs the admin password, and the easy mistake is to type it into the script. Use a hidden task sequence or collection variable, or build the setting with Dell Command | Configure, which can package it with the password encrypted.
- Not every model has every mode. The script checks the setting's PossibleValues and refuses a mode the model doesn't list, with exit code 2. Run it with -WhatIf on one of each model to see what they accept.