Reference Guide

Manage Policies
140
Legal Notice Text
Self Help Questions (Pre-8.0 clients)
Windows Encryption > Policy-Based
Encryption
Common Encrypted Folders
OS Update Encryption Rules
Windows Encryption > BitLocker Encryption
Default Folder Location to Save Recovery
Password
Data Guardian > Cloud Encryption Help File Name
Help File Contents
Excluded Folders
Excluded Files
Data Guardian > Protected Office
Documents
Office Protected Clip Board Unauthorized Text
Office Protected Document Tamper Prompt
Offline Key Generation Escrow Reminder Text
Office Protected Files Cover Page Notice
Windows Encryption
Windows Encryption
A word about types of encryption: SDE is designed to encrypt the operating system and program files.
To accomplish this purpose, SDE must be able to open its encryption key while the operating system is
booting without intervention of a password by the user. Its intent is to prevent alteration or offline attacks
on the operating system by an attacker. SDE is not intended for user data. Common and User key
encryption are intended for sensitive user data because they require a user password to unlock
encryption keys.
Policy descriptions also display in tooltips in the Management Console. In this table, master policies are
in bold font.
Policy Default Setting Description
Full Disk Encryption (FDE)
This technology manages drives using software-based Full Disk Encryption. Authentication by users
through a Pre-Boot Authentication environment (before the operating system has booted) is required to
unlock the drive.