Users Guide

Table Of Contents
Preboot Authentication
Previously, on some computers with Security Tools and Preboot Authentication enabled, the computer would not boot after
entering credentials into the PBA logon screen, and the computer would halt at a black screen with the words "Parity Error".
[DDPLP-137]
Technical Advisories v8.4.1
Encryption
After installation, HCA encryption and the Preboot Authentication environment are not provisioned until after the computer
reboots a second time and the user provides the Encryption Administrator Password. [DDPC-448]
The Shield does not detect password changes for non-domain accounts when the password is reset from another account.
As a result, when the non-domain user attempts to logon again, the logon fails because the Shield did not synchronize the
password change. [DDPC-490]
Advanced Authentication
Amended 12/2014 - Fingerprint enrollment does not prevent the user from using fingerprints from different fingers when
enrolling a single finger. [MMW-212]
Preboot Authentication
Single Sign-on intermittently fails on computers with self-encrypting drives on which Preboot Authentication is activated.
[DDPLP-144]
When replacing a provisioned self-encrypting drive (with the Preboot Authentication environment active) with a new self-
encrypting drive and provisioning the Preboot Authentication environment, after the new SED is provisioned, the old SED
can no longer be recovered. [DDPLP-150, MMW-581]
On the Dell Latitude Rugged Extreme, the user is able to detach the tablet from the dock. However, the dock is needed to
log in through the PBA. Detach the tablet only after the PBA authentication step is complete. [DDPLP-162, DDPLP-163]
After successfully authenticating to the Preboot Authentication environment, the computer will not complete Single Sign-on.
Instead, the computer halts at the Windows Logon screen for another user. Microsoft Windows 8.1 defaults to the Logon
screen for the previously authenticated user. To complete logon, return to the User Tiles screen by selecting the back arrow
in the top right of the screen and then selecting the correct user tile for the user authenticated in the PBA. SSO data
captured by the PBA may still be present and once the user tile is selected, Windows authentication may be completed
automatically. [MMW-564]
Resolved Technical Advisories v8.4
Advanced Authentication
Pre-enrolled Contactless Smart Card users are no longer lost after joining the computer to the domain. [28386/DDPC-61,
MMW-347]
Technical Advisories v8.4
Encryption
When USB external media with little or no space available are inserted into Shielded computers to be encrypted, users
receive no indication that the media are full and will not be encrypted. [DDPC-243]
Technical Advisories
49