WinSecWiki > Security Settings > Local Policies > User Rights > User Rights In-Depth > Modify firmware values

Modify firmware environment values

AKA: SeSystemEnvironmentPrivilege, Modify firmware environment values

Default assignment: Administrators

This right does NOT have anything to do with system environment variables (e.g. %COMPUTERNAME%). 

This right controls authority to modify firmware values which are stored in non volatile RAM on non-x86 computers. According to Microsoft all versions of Windows require this right for upgrades. The only firmware value on x86 computers this right controls access to is the Last Known Good setting. x64 computers store boot information (boot.ini settings) in non volatile RAM, so you must have this right to run bootcfg.exe and System Properties\Startup and Recovery.

Back to top

 

Upcoming Webinars
    Additional Resources