Reference Guide
Manage Policies
300
Media containing Time Machine backups are not
supported. However, media recognized by
computers as Time Machine backup destinations
are automatically whitelisted, to allow backups to
continue. All other removable media with Time
M
achine backups are handled based on EMS
Access to unShielded Media
and
EMS Block Access
to UnShieldable Media
policies.
EMS Scan External Media Not Selected
Selected allows removable media to be scanned
every time it is inserted.
When this policy is Not Selected and the Windows
Media Encryption policy is Selected, only new and
changed files are encrypted.
More...
A scan occurs at every insertion so
that any files added to the removable
media without authenticating can be
caught. Files can be added to the
media if authentication is declined,
but encrypted data cannot be
accessed. The files added are not
encrypted in this case, so the next
time the media is authenticated (to
work with encrypted data), any files
that may have been added are
scanned and encrypted.
EMS Access to unShielded Media Read Only
Block, Read Only, Full Access
When this policy is set to Block Access, you have
no access to removable media unless it is
encrypted.
Choosing either Read
-Only or Full Access allows
you to decide what media to e
ncrypt.
If you choose not to encrypt removable storage
and this policy is set to Full Access, you have full
read/write access to removable media.
If you choose not to encrypt removable media
and this policy is set to Read
-Only, you cannot
read or delete ex
isting files on the unencrypted
media, but no files can be edited on, or added to,
the media unless it is encrypted.
EMS Block Access to UnShieldable Media Selected
Block access to any removable media that is less
than 55 MB and thus has insufficient stor
age
capacity to host Encryption External Media (such
as a 1.44MB floppy disk).
All access is blocked if EMS Encrypt External
Media and this policy are both selected. If EMS
Encrypt External Media is True, but this policy is
False, data can be read from the
unencryptable
media, but write access to the media is blocked.
If EMS Encrypt External Media is False, then this
policy has no effect and access to unencryptable
media is not impacted.
See advanced settings
Policy Default Setting Description
Media Encryption Settings
This technology allows definition of what media encryption events to retain in logs.