The Brief: Dell has introduced Dell Command | Secure BIOS Configuration, a cloud-hosted service for managing and enforcing BIOS settings across Dell commercial PCs through Microsoft Intune. The service lets IT administrators configure devices without physical access, on-premises infrastructure, or VPN connectivity. It uses certificate-based authentication, signed configuration payloads, and device binding to authorize BIOS changes.
Dell Command | Secure BIOS Configuration runs on Microsoft Azure, managed by Dell, and it requires supported Dell commercial PCs and BIOS versions, Microsoft Intune, and Azure Active Directory. Security features include Azure Managed HSM-protected signing keys, encrypted and authenticated BIOS sessions, and challenge-response authorization. The service is available through Microsoft Azure Marketplace with agentless deployment.
Read full details of the announcement about Dell Command | Secure BIOS Configuration at dell.com.
Analyst Perspective: Dell Command | Secure BIOS Configuration adds a cloud-managed control plane to an area of endpoint administration that has traditionally required device-level attention. Its integration with Microsoft Intune is significant because it places BIOS policy deployment within an environment enterprise IT teams already use for endpoint management. That reduces the need for a separate workflow.
The service connects Dell commercial PC hardware with cloud administration without requiring an agent on each machine. Device-bound configuration payloads and certificate-based authorization provide controls specific to firmware management, while Azure services handle the supporting security infrastructure.
From a portfolio perspective, the offering extends Dell’s commercial PC management into a managed cloud service. Its value is strongest for organizations managing distributed Dell fleets with Microsoft’s device-management technologies. For enterprise IT, that linkage can make firmware policy management part of an existing governance process without adding another endpoint agent.
Dell changes how IT teams deliver BIOS policies to managed PCs by moving configuration through a cloud service integrated with Intune. Administrators can send configuration payloads without accessing devices directly, making the service suitable for fleets that may not have consistent local network access.
Dell hosts and manages the service on Azure. Devices connect to the cloud service, receive their configuration payloads, authenticate them, and apply the approved settings. The cloud model also removes the need for on-premises infrastructure or VPN connectivity, reducing the network requirements for firmware administration.
Moreover, the agentless deployment model eliminates the need to install additional software on managed PCs. To use the service, organizations need supported Dell commercial PCs and BIOS versions, an active Microsoft Intune environment, and Azure Active Directory.
The company uses several security controls to authorize BIOS configuration. The service signs configuration payloads with cryptographic keys and binds them to specific devices, ensuring that only authorized hardware can receive them. It also uses challenge-response authorization with BIOS-generated random values to help prevent attackers from replaying previously captured configuration commands.
Dell runs the service in a private Azure tenant, while Azure Managed HSM protects the signing keys used for configuration payloads. The service also encrypts and authenticates BIOS sessions to protect communications between devices and the cloud service.
Before a device applies a configuration, these controls authenticate the payload and verify its authorization. This combination helps limit unauthorized firmware changes while giving IT administrators a managed way to distribute approved BIOS settings across supported Dell commercial PCs.
Command | Secure BIOS Configuration is available through the Microsoft Azure Marketplace, giving organizations a direct way to obtain the service within Microsoft’s cloud ecosystem. Native Intune integration also lets administrators use existing policy workflows without adding a separate endpoint-management console for BIOS configuration.
The cloud-hosted service receives automatic updates, so customers do not need to maintain supporting infrastructure. Devices can connect to the service without relying on an internal network or VPN, making it suitable for organizations managing geographically distributed fleets.
Designed specifically for Dell commercial hardware, the service requires supported Dell PCs and BIOS versions, an active Microsoft Intune environment, and Azure Active Directory. Marketplace availability and Intune integration give IT teams a straightforward path to procure and administer the service while keeping BIOS management within their existing Microsoft environment.
Dell Command | Secure BIOS Configuration extends Dell’s commercial PC offering into cloud-based firmware management, connecting endpoint hardware with Microsoft’s device-management ecosystem.
The service will appeal most to organizations managing large Dell fleets, distributed workforces, and existing deployments of Microsoft Intune and Azure Active Directory. In these environments, centralized BIOS administration can help address inconsistent firmware settings while reducing the need for IT staff to access individual devices. Its agentless design also keeps additional software off managed PCs, while cloud delivery removes dependencies on internal networks and VPN connectivity.
For organizations with the required Dell hardware and Microsoft infrastructure, the service provides a dedicated way to bring BIOS configuration into established endpoint-management workflows.
One consideration is the service’s reliance on supported Dell hardware and BIOS versions, Microsoft Intune, and Azure Active Directory. Organizations with mixed-device fleets may need to determine how to manage Dell systems alongside devices from other vendors.
IT teams can reduce deployment issues by reviewing their hardware inventory, testing BIOS policies, and introducing the service in stages before applying it across the wider fleet.
The service gives Dell a way to extend PC management into firmware through cloud administration. Its long-term value will depend on how widely organizations adopt it and how Dell continues to connect hardware security with enterprise management tools.
Agentless deployment and Microsoft integration also give IT teams a straightforward way to add BIOS management to their existing workflows.
Gain valuable perspectives on AI, collaboration tools, and workplace innovation. Subscribe to the Collab Collective newsletter for expert insights delivered directly to you.