Skip to Content

Preboot Manager

Frequently Asked Questions

Click on the question to show the answer. Expand All Answers

  1. Does my existing EMBASSY Remote Administration Server (ERAS) support Dell PBA

    Yes. All supported versions of ERAS are fully compatible with Dell PBA In addition to managing the security features of FDE hard drives, ERAS is used to activate TPMs to secure data on client machines and to protect access to corporate networks.

  2. What is Dell ControlPoint (DCP) and how does EMBASSY Trust Suite (ETS) integrate with it?

    Dell ControlPoint is a new Dell application framework that provides an integrated and easy to use interface for managing laptop features including system, network and security settings. To enable security features, DCP utilizes Dell PBA Users simply select which top level features to activate from DCP which in turn launches ETS for Dell. Once ETS is in use, users have the options of managing an FDE hard drive and a Trusted Platform Module (TPM), for application solutions such as full disk encryption and enabling strong pre-boot and multi-factor authentication.

  3. How can I delete preboot authentication credentials for all enrolled users?

    To clear preboot authentication credentials for all enrolled users, do the following from the ESC Preboot Manager > Advanced screen (or in the Dell BIOS):

    • a. If both the BIOS system and BIOS admin passwords are set, change the BIOS admin password to a null value.
    • b. If the BIOS system password is set and the BIOS admin password is not set, first change the BIOS system password to null and set the BIOS admin password to a value. Then change the BIOS admin password to null.
  4. Do Dell Latitude™ E-Family Laptops and Precision™ Mobile Workstations ship with a Trusted Platform Module (TPM)?

    Yes. These business class PCs come standard with a TPM that conforms to v 1.2 of the Trusted Computing Group specification. These machines incorporate a TPM as part of an integrated security chip that also includes Dell ControlVault, a hardware container used for storing secrets such as passwords and fingerprint templates.

  5. How does Dell PBA use Dell ControlVault?

    Dell PBA uses the Dell ControlVault for securely storing fingerprint templates and other authentication information for an enhanced Preboot authentication experience.

  6. Can I upgrade my Dell D-Family PC with Dell PBA and will I get the new ETS features?

    No, you cannot upgrade your x30 series D-Family laptops to the latest version of ETS for Dell. The last version of ETS for Dell compatible with x30 series D-family laptops that are available on is Most new features that appear in the latest versions of ETS for Dell require Dell Latitude E-Family specific hardware components and are therefore not supported on D-Family machines.

  7. Do I need to upgrade to Dell PBA to support Seagate Momentus 7200 RPM FDE hard drives?

    No. Previous ETS versions that contain Trusted Drive Manager will support both Seagate Momentus 5400 and 7200 RPM FDE drives.

  8. What are the differences between Dell PBA and Dell PBA

    Dell PBA includes the following new capabilities:

    • Support for Samsung and all OPAL-compliant self-encrypting drives.
    • Advanced Windows Logon features for Seagate Momentus™ Full Disk Encryption (FDE) drives.
    • Single sign-on to Windows – increases security while reducing costs associated with password management.
    • Windows password synchronization – support for existing password policies ensures ease of use.
    • <
    • New Multi-factor Authentication options for Dell Preboot.
    • Enhanced Security and Usability for Fingerprint Authentication.
    • Integration with Dell ControlPoint and ControlVault.

  9. What are the Dell Systems which can take advantage of all new features included in ETS for Dell PBA

    Dell Latitude E4200, E4300, E5400, E5500, E6400, E6400 ATG, E6500

    Dell Precision Mobile Workstation M2400, M4400

  10. When I try to enroll fingerprints for domain users I get the following error: “Cannot write to fingerprints database.”

    If you encounter this problem, you will need to download a patch to fix it. Please follow this link for instructions to correct this issue: Download Newest ETS

  11. Where can I find Wave EMBASSY Security Center on Dell Latitude E-Family and Precision Mobile Workstations?

    For Dell PCs, where Dell ControlPoint is installed, Wave ETS software is launched from Dell ControlPoint Security Manager. However, ETS can be launched directly on these systems by going to Start -> All Programs -> Dell ControlPoint -> Security Manager -> Advanced -> EMBASSY Security Center.

  12. What is Preboot Manager?

    Preboot Manager provides security for a system when it is not turned on.  This option requires that a user’s identity be authenticated before the computer boots up.  Preventing the operating system from loading means unauthorized users are effectively shut out of the system, so that if the PC is stolen or lost, it secures the data on the hard drive from being exposed.

    The Preboot Manager guides the administrative user through setting up the appropriate system level passwords.  The administrator can then set up Preboot Authentication by using a fingerprint scanner or a Smart Card in place of the passwords.  The Preboot Manager is used to configure the security settings, set the passwords and enroll the Smart Card or fingerprint.

    If a fingerprint scanner is not embedded in this system, Preboot Manager supports UPEK sensors.  If a Smart Card was not included with this system, please contact the system manufacturer.

  13. What is Preboot Manager Protecting?

    Preboot Manager secures the BIOS, hard disk and operating system from unauthorized access in case the laptop is lost or stolen. You can use a smart card or fingerprint for system access.

  14. Who can configure Preboot Manager?

    Only a Windows system administrator or a user with administrative rights is able to set up Preboot Authentication using Preboot Manager. A limited user who does not have administrative rights will have access to change the Smart Card PIN.

  15. The Embassy Trust Suite software that came loaded on my machine has been uninstalled. Where can I find a download for this program?

    This is relevant for the new Dell Computers that are shipping with the Embassy Trust Suite Software with Preboot Authentication Manager.

    If for any reason, the software is removed, or you installed a corporate image into the computer, and later on you determine that you want to use the software you need to go to the dell website and download it.

    1. Using Internet Explorer, go to
    2. Under Select a Product, either enter the Service Tag of your computer or the Product Model
    3. then go to Select a Tool, choose Drivers & Downloads, Click on Go
    4. Select the Operating System of your computer (i.e. Microsoft Windows XP)
    5. Click on Find Downloads
    6. Expand on Security
    7. Choose the option Wave System Corp – Application, Download and install
    8. Restart your computer
  16. I performed a Windows update and now when I try to use my UPEK fingerprint reader I get errors.

    Go to the Dell web site at, navigate to the Drivers And Download Section then download the SmartCard controller under Chipset. Once downloaded, install and reboot computer. More information can be found here.

  17. Does the Dell E4300 ultraportable laptop support Seagate Momentus FDE hard drives?

    Yes. The Dell E4300 laptop uses a 2.5” hard drive and therefore is compatible with Seagate FDE drives. However, the Dell E4200 laptop uses solid state drive technology and is compatible with the Samsung line of solid state self-encrypting drives. These drives can be purchased from Dell and managed by ETS for Dell version

Additional Support

If you need additional information, please submit a Support Request Form. Customer Service will contact you within one business day with a response to your inquiry. To ensure quality customer service, please include your email address and a detailed description of the issue/inquiry.

Support Request Form