Reference Guide
Manage Policies
192
The Removable Drive rule can only be used within an Encryption External Media Encryption Rules
policy.
Remove System Data Encryption (SDE)
To completely decrypt SDE encrypted files, apply the following policies:
SDE Encryption Enabled = Not Selected
Encrypt Windows Paging File = Not Selected
Secure Windows Credentials = Not Selected
Authentication
Authentication
Authentication policies allow you to configure user experience and Windows authentication.
Policy descriptions also display in tooltips in the Management Console.
Policy Default Setting Description
Pre-Boot Authentication
This technology provides a secure, tamper-proof environment by preventing data from being read from
the hard disk or operating system until the user enters the correct PBA login credentials. Pre-Boot
Authentication serves as an extension of the BIOS or boot firmware to provide a trusted authentication
layer, separate from the operating system.
Authentication Method Password
Password
Smart Card
Select the type of authentication to use when logging in to the PBA.
Support Information Text
String
Please contact your system administrator.
String 0-512 characters
Text to display on the PBA support information screen. Customize the
message to include specific instructions about how to contact the help
desk or Security administrator. Not entering text in this field results in
no support contact information being available for the user.
Text wrapping occurs at the word level, not the character level. If a
single word is more than approximately 50 characters in length, it does
not wrap and no scroll bar is present, therefore the text is truncated.
The text in this policy is translatable.
PBA Title Text 0-17 characters
0-17 characters
The text to display on the top of the PBA screen. Not entering text in
this field results in no title being displayed. Text does not wrap, so
entering more than 17 characters results in the text being truncated.
The text in this policy is translatable.
Sync Users at PBA Activation Not Selected
Select this option to sync all users of this computer with the PBA
database during PBA activation.
See advanced settings
Windows Authentication
This technology sets definitions around user login, specifically what is required to login (password, smart
card, fingerprint), password recovery options, and password requirements (number of attempts allowed,
password length).
Logon Authentication Policy for
Windows Password and None
The possible VALUES are: