Skip to content

Lenovo ThinkShield SE350 System Lockdown

Complete procedure for managing Lenovo ThinkEdge SE350 servers with ThinkShield Key Vault Portal, including system registration and lockdown mode deactivation.


Overview

The Lenovo ThinkEdge SE350 features System Lockdown Mode - a security feature that ensures the system is only used by its intended recipient. When activated, the server cannot boot until authorized through the ThinkShield Key Vault Portal.


Prerequisites

Item Details
Portal Access ThinkShield Key Vault Portal account
Customer ID Organization's unique customer ID (in portal URL)
Network Server must have network connectivity for online activation
Browser Access to server's IMM/XCC web interface

ThinkShield Key Vault Portal

Portal URL

https://portal.naea1.uds.lenovo.com/<CUSTOMER_ID>

Customer ID

The number at the end of the URL is your organization's Customer ID. This is critical - using the wrong ID will prevent you from managing your devices.

Authorized Users

User Email
Jeff Brooks jeff.brooks@hamilton.co.uk
Stuart Taylor stuart.taylor@hamilton.co.uk
Jacky Yung jacky.yung@hamilton.co.uk
Gary Farquharson gary.farquharson@hamilton.co.uk

Part 1: Registering a New SE350

When receiving a new Lenovo SE350, it must be registered to the portal before deployment.

Steps

  1. Log into the ThinkShield Key Vault Portal
  2. Navigate to Devices or Systems
  3. Click Add Device or Register New System
  4. Enter the server's:
  5. Serial Number
  6. Machine Type Model (MTM)
  7. UUID (if required)
  8. Assign to appropriate device group
  9. Save registration

Bulk Registration

Multiple devices can be registered via CSV upload if processing a large batch.


Part 2: Checking System Lockdown Status

Access via IMM/XCC Web Interface

  1. Connect to the server's management IP address
  2. Log into the Integrated Management Module (IMM) or XClarity Controller (XCC)
  3. Navigate to: BMC ConfigurationSecuritySystem Lockdown Mode

Lockdown Status Indicators

Status Meaning
Asserted System is locked - cannot boot OS
De-asserted System is unlocked - normal operation
ThinkShield Portal Activation via portal required
XClarity Controller Can be unlocked locally via XCC

Part 3: Deactivating System Lockdown Mode

Use this procedure when a server shows "System Lockdown Mode: Asserted".

Step 1: Generate Challenge Code

  1. Log into the server's IMM/XCC web interface
  2. Navigate to: BMC ConfigurationSecuritySystem Lockdown Mode
  3. Move the slider from Asserted to De-asserted
  4. A popup appears with a Challenge Code
  5. Copy this code - you'll need it for the portal

Challenge Code Validity

The challenge code is time-sensitive. Complete the activation process promptly.

Step 2: Get Response from Portal

  1. Open the ThinkShield Key Vault Portal in a new browser tab
  2. Find and click on the correct system (match serial number)
  3. Click Manually Activate
  4. Enter the Challenge Code from Step 1
  5. Click Generate Response
  6. Copy the Response Code displayed

Step 3: Complete Activation

  1. Return to the IMM/XCC popup (still showing challenge code)
  2. Enter the Response Code from Step 2
  3. Click OK
  4. Click Apply
  5. System Lockdown Mode is now De-asserted

System Lockdown Mode Options

Lockdown Triggers

From the IMM/XCC interface, you can configure automatic lockdown triggers:

Trigger Description
Motion Detection Locks if server is moved/tilted
Chassis Intrusion Locks if cover is opened
Network Disconnect Locks if management network lost
Manual Assertion Administrator manually locks system

Control Mode Settings

Mode Description Security Level
ThinkShield Portal Requires portal activation Highest
XClarity Controller Can unlock locally via XCC Medium

Portal Mode is Permanent

Once System Lockdown Mode Control is set to ThinkShield Portal, it cannot be changed back to XClarity Controller. This is by design for security.


Troubleshooting

Challenge Code Verification Failed

If the portal cannot verify the challenge code:

  1. Check the system clock is accurate on both server and your computer
  2. Request a counter reset from IT administrator
  3. Generate a new challenge code and try again

Cannot Access IMM/XCC

  • Verify network connectivity to management port
  • Try default credentials if recently reset
  • Use the USB/Serial console for recovery

Device Not Found in Portal

  • Verify you're using the correct Customer ID in the URL
  • Check the device was properly registered
  • Confirm serial number matches exactly

Lockdown Asserted After Power Loss

  • This is expected behavior if motion/intrusion triggers are enabled
  • Follow the deactivation procedure above
  • Consider disabling sensitive triggers if causing frequent lockouts

Quick Reference Commands

XCC CLI Commands (if available)

# Check lockdown status
show system lockdown

# View security settings
show security

# Display system information
show system

BMC Navigation Path

BMC Configuration → Security → System Lockdown Mode

Security Best Practices

  1. Limit Portal Access - Only authorized personnel should have portal credentials
  2. Use Strong Passwords - Both for portal and IMM/XCC interfaces
  3. Enable UEFI PAP - Prevents unauthorized XCC reset when in XClarity Controller mode
  4. Document Registrations - Keep records of all registered devices and their status
  5. Regular Audits - Periodically review portal for unauthorized devices

References