cableEnrollment
Image devices from an imaging station: pick a station, see what is on its PXE network, and enrol one machine with brand-specific guidance or a whole rack at once.
1Imaging station
2Devices on st-1
4 on PXE
refresh
checklistBefore PXE boot: one firmware visit per device
- Security Chip (TPM2): set to Enabled, then Clear Security Chip once
- Secure Boot: set to Enabled AND Reset to Setup Mode (clears the factory keys)
- Save & Exit, then boot the device from the network (PXE)
With this state set, everything after Start imaging runs hands-off: signed install, key enrolment, TPM2 sealing, verification - no BIOS visit afterwards.