Many thanks for your answer, localzuk, I really appreciate your time and interest.
TPM could be a great solution, but it means adding more hardware since it's not included on motherboard, so it's discard (I need a method that doesn't require special hardware)
I can't install a physical lock on the case, neither lock bios or boot menu. The user must be able to use the computer, add new drives or even format hard drive using a tool in a usb drive if he needs. It's even desirable (althought not 100% needed) that user can make a backup of the system disk via cloning, and restoring it when needed. BUT I don't want the user to clone disk and use the operative system and all configurations and programs in a different machine, since it's intended to be used only on this computer (I hope that my explanation is ok, hehe)
I know that there is no infallible method for this, but is better having a security method that can be skipped to have no security method at all. If I add some kind of protection, at least the user will have to make some research.
I've been reading something about hostid, and if I can tie the operative system to something depending on hardware, it is an important "first step".
Many thanks again, I hope someone can lend me a hand.
Regards