Contact
Servers, storage & data centre

Server boot & security: BOSS, NS204i, TPM and Secure Boot

Servers, storage & data centre6 min read

By Humphrey Theodore K. Ng’ambi

Updated 13 September 2026

Dell logoLenovo logo

Two small, easily-overlooked parts of a server spec do outsized work: the boot device the operating system lives on, and the security silicon that decides whether the boot process can be trusted. Both show up as cryptic option codes on a quote — BOSS, NS204i, TPM 2.0, Secure Boot — and both are worth understanding before you buy, especially second-hand.

Boot-optimised storage: keep the OS off the data drives

Running the operating system on one of your main data drives is wasteful and fragile: it burns a hot-swap bay, and a single boot-disk failure takes the machine down. The modern answer is a dedicated boot-optimised storage device — a small card carrying two mirrored M.2 SSDs whose only job is to hold the OS, keeping the front bays free for data and surviving a drive failure.

Dell BOSS (Boot Optimized Storage Solution)

Dell's BOSS is a small add-in card that mirrors the operating system across two M.2 SSDs, keeping it off the front data bays. Dell describes the current NVMe generation, BOSS-N1, as "a RAID solution that is designed for booting a server's operating system" (Dell BOSS-N1 User's Guide).

BOSS-S1 / BOSS-S2BOSS-N1
Drives2 × M.2 SATA (6 Gbps) SSD1 or 2 × 80 mm M.2 NVMe enterprise SSD (480 GB or 960 GB)
RAIDHardware RAID 1 (mirror)Fixed-function RAID 1 (mirror), or RAID 0 on a single drive
Hot-plugYes (BOSS-S2)Yes, rear-facing module (except the internal modular variant)
InterfacePCIe adapterPCIe Gen 3
Managed byiDRAC / OpenManage / CLIiDRAC / OpenManage / CLI, UEFI RAID utility in BIOS (F2)

BOSS-S1/S2 use SATA M.2 SSDs; BOSS-N1 is the newer NVMe generation with a rear-serviceable, hot-plug module and LED status. The card supports a maximum of two M.2 drives presented as one mirrored virtual disk.

HPE NS204i

HPE's equivalent is the NS204i, which HPE's QuickSpecs describe as "a dedicated hardware RAID 1 solution" for buyers who want to "separate their data plane from their OS plane" (HPE OS Boot Device Options QuickSpecs). Its defining traits:

  • Two M.2 NVMe SSDs (commonly 480 GB) that it auto-creates as a RAID 1 mirror with automatic drive rebuild.
  • "As the NS204i is a hardware boot device, only RAID 1 mode is supported and it will not operate in any other RAID mode" — it presents to the OS and to iLO as a single directly-connected NVMe drive, not a RAID controller.
  • It is "plug-and-play with no need to configure or manage the device," using the operating system's native Windows, Linux or VMware NVMe drivers, so no custom driver is needed.
  • It does not consume a front drive bay, leaving all bays for data, and it "meets the certification requirements of VMware and Microsoft Storage Spaces Direct."

Common variants are the NS204i-p (a PCIe card, Gen10/Gen10 Plus), the NS204i-u (a universal, hot-plug module on Gen11 that no longer occupies a PCIe slot), and Synergy/riser forms (NS204i-d, NS204i-r, NS204i-t).

Why it matters: a mirrored boot pair means a single boot-SSD failure does not down the server, and separating OS from data makes rebuilds and drive swaps cleaner. On a refurbished machine, confirm the BOSS/NS204i card and both M.2 SSDs are actually fitted (they are frequently pulled before resale), that the mirror is healthy, and — because these are flash devices — that the SSDs still have reasonable write-endurance left.

TPM 2.0: the hardware root of trust

A Trusted Platform Module (TPM) is a small, tamper-resistant cryptoprocessor that implements the international ISO/IEC 11889 standard (the Trusted Computing Group's TPM 2.0 Library Specification). It is the hardware root of trust for the machine. In practice it:

  • Generates and stores cryptographic keys in silicon, so they never sit in plain memory — for example the volume-encryption keys used by BitLocker on Windows Server.
  • Holds Platform Configuration Registers (PCRs) that record measurements of the firmware and boot components, which can only be extended, never rewritten to an arbitrary value.
  • Carries a unique manufacturer-embedded Endorsement Key that anchors device identity and remote attestation.

A TPM 2.0 device is not itself tied to a firmware type, but Windows requires the platform to run in native UEFI mode — not legacy BIOS or CSM — to use a TPM 2.0. That is a Microsoft platform requirement rather than a limitation of the chip (Microsoft — TPM recommendations). On enterprise servers the TPM is usually a small pluggable module (Dell, HPE and Lenovo each sell their own TPM 2.0 modules), and modern platforms increasingly offer a firmware TPM as well.

Secure Boot and the chain of trust

Secure Boot is a UEFI firmware feature. As Microsoft puts it, a PC with UEFI firmware and a TPM "can be configured to load only trusted OS bootloaders": at power-on the firmware verifies that its own code is digitally signed, then "examines the bootloader's digital signature to verify that it hasn't been modified," and refuses to run anything that is unsigned or tampered with (Microsoft — Secure the Windows boot process). That blocks bootkits and rootkits — malware that tries to load before the operating system and hide from it.

Secure Boot is one link in a chain that modern server operating systems build on:

StageWhat it does
Secure BootUEFI runs only bootloaders/firmware with a valid, trusted signature (prevention)
Trusted BootThe bootloader verifies the OS kernel, which verifies every subsequent boot component
ELAM (Early-Launch Anti-Malware)An anti-malware driver loads before other boot drivers and screens them
Measured BootThe firmware records a hash of each component into the TPM; the TPM signs the log so a remote server can attest the machine's health

Measured Boot and Secure Boot are, in Microsoft's words, "only possible on PCs with UEFI 2.3.1 and a TPM chip."

Why it matters: TPM 2.0 plus UEFI Secure Boot are prerequisites for current security baselines and features — BitLocker/volume encryption, measured boot and attestation, and the hardening expected of Windows Server 2022/2025 and many compliance regimes. On refurbished hardware, verify that a TPM 2.0 module is fitted (or a firmware TPM is available) and can be enabled, and that the server is set to UEFI mode rather than legacy BIOS — a server stuck in legacy boot cannot use any of the above.

Server Hub configures BOSS/NS204i mirrors, TPM 2.0 and UEFI Secure Boot as part of the pre-ship checklist on refurbished servers.

The Server Hub briefing

South African IT hardware news, once a week.

What’s new, what it costs in rand, and what it means for the kit you run — servers and storage, networking, backup power, surveillance and print. Every claim checked against a named source.

One email a week. No third-party sharing, and unsubscribe from any issue.