This is an abstract from a Microsoft Ignite session, taking place November 4-8 in Florida:
Managing Surface UEFI BIOS settings with Microsoft Intune
Karan Dhillon, Daniel Gerrity
Introducing Device Firmware Management Configuration Interface (DFCI) as managed through Microsoft Intune for Surface devices. Now you can lock down the BIOS menu as part of Windows Autopilot device setup and manage BIOS settings for all your devices from the Microsoft 365 Device Management Admin Center. Learn how to add DFCI management to your Autopilot deployment, configure settings for boot options and hardware restrictions, and retire devices from DFCI management.
https://www.microsoft.com/en-us/ignite
https://myignite.techcommunity.microsoft.com/sessions/79751
See-also:
https://docs.microsoft.com/en-us/windows/client-management/mdm/uefi-csp