Onboarding Devices in ThinkShield Firmware Assurance

Onboarding Devices in ThinkShield Firmware Assurance

ThinkShield Firmware Assurance (TSFA) offers advanced firmware integrity monitoring and remediation before the operating system boots, fully integrated with Device Management. To create a Device Management account, you must have a Lenovo ID and receive an email invitation from Lenovo.

ThinkShield Firmware Assurance supports an automated process that simplifies the onboarding of devices into your organization. Any Lenovo Windows device can be automatically claimed on the ThinkShield Firmware Assurance platform by installing the TSFA provisioning package. After the admin account is set up, the Organization Admin can invite additional users and assign roles and permissions. 
Info
The setup is unique for the organization and must not be shared.

Automatically Adding Windows Devices

To automatically add a Windows device, select the appropriate onboarding method for your TSFA-enabled device. The installation package includes the TSFA agent and supporting files specific to the device architecture (x64 or ARM).
  1. Go to Device Management > Devices page.
  2. Click the ✚ Onboard Device button.
  3. Select OS type: Windows
  4. Choose the onboarding method: Standard or ARM.
  5. Click Next.

Downloading Provisioning Pack Agent 

Download the Lenovo Provisioning Pack for LDO to provision clients and download the agent.

Onboarding Devices

  1. Select the device(s) you want to onboard.
  2. Click Onboard Devices. This starts the claiming process, which may take between 5 minutes and 1 hour. 
  3. From the dropdown menus, set the following:
    1. Installer Expiration: 7 days/30 days/60 days/90 days/365 days.
    2. Maximum Usage: 5K Devices/10K Devices/50K Devices.
  4. Select Download Installer. 
  5. UDCSetup.exe will be downloaded. You can:
    1. Run it on the current device,
    2. Distribute it to multiple devices, or
    3. Save it to a USB drive for on-premises installation.
  6. Navigate to the folder where the installer was downloaded and run UDCSetup.exe as an Administrator.
Info
  1. After installation is complete, the device will appear in Device Management > Devices within the organization portal.
  2. Once a TSFA license is assigned to a TSFA-enabled device, Device Management will begin monitoring firmware integrity and displaying TSFA status.

Troubleshooting

One of the most common issues users may encounter is a device remaining in a Pending status. To resolve this, try the following alternative solutions:
  1. Check network connectivity: Ensure the device is connected to the network.
  2. Verify license assignment: Confirm that the device has a valid assigned license.
  3. Check the BIOS version: If the BIOS is outdated, the device may not be able to install the required TSFA agent properly.