Getting Started with TSFA

Getting Started with TSFA

ThinkShield Firmware Assurance (TSFA) evaluates device security posture based on security events generated by managed devices.
TSFA can be used as a standalone solution or together with Lenovo Device Orchestration (LDO). A TSFA license is required to access TSFA functionality in either deployment scenario.

Before you begin:
  1. Make sure the devices are supported by TSFA. For more information, see Supported Devices in TSFA.
  2. Onboard devices using the standard LDO process.
  3. Assign a TSFA license to each device. 

Onboarding Devices

Device onboarding is the process of registering a device in the system so it can be managed and receive additional functionality. The onboarding process is the same as for LDO devices and is described in LDO > Device Management > Onboarding articles. 

After successful onboarding:
  1. The device appears in Device Management > Devices.
  2. The device is ready for license assignment.

Assigning Licenses to Devices

Assigning a TSFA license enables TSFA functionality on a device. Licenses are assigned and managed in Organization Settings > Organization Account.

Purchasing a TSFA license at the organization level does not automatically activate TSFA. You must assign a TSFA license to each device. For more information, see  Assigning and Managing Licenses.

After a license is assigned:
  1. The TSFA plugin is installed on the device.
  2. TSFA data becomes available, and the device status changes to Active. If the device does not appear as Active, see Troubleshooting TSFA.
  3. The device starts reporting firmware events from BIOS and the embedded controller on the device.

How TSFA Collects and Surfaces Device Data

Security events appear on the Issues and Errors tab on the Device Details page. To access these events, go to:  

Device Management > Devices > select a device > Device Details > Issues and Errors, then select Security Events from the search box.

These events are processed using predefined rules to determine the device’s security posture. The system updates the posture automatically as new events are received. For more information, see Device Status and Security Posture.

TSFA device data is available in:
  1. The Dashboard, through TSFA-specific widgets.
  2. Device Management > Devices list, where you can view device-level TSFA information. To view detailed information, select a device to open the Device Details page.
For more information, see:

TS XTR Firmware Intelligence Connector

LDO provides a connector that integrates ThinkShield Firmware Assurance (TSFA) with SentinelOne. Once the connector is configured, whenever a device's security posture changes, such as from Healthy to Unhealthy or from Suspect to Healthy, TSFA automatically sends the corresponding event to SentinelOne.

For more information, see Configuring SentinelOne Connector.