Install Guide
Table Of Contents
- Dell Endpoint Security Suite Enterprise Advanced Installation Guide v3.0
- Contents
- Introduction
- Requirements
- Registry Settings
- Install Using the Master Installer
- Uninstall the Master Installer
- Install Using the Child Installers
- Uninstall Using the Child Installers
- Data Security Uninstaller
- Commonly Used Scenarios
- Provision a Tenant
- Configure Advanced Threat Prevention Agent Auto Update
- Pre-Installation Configuration for SED UEFI, and BitLocker Manager
- Designate the Dell Server through Registry
- Extract Child Installers
- Configure Key Server
- Use the Administrative Download Utility (CMGAd)
- Configure Encryption on a Server Operating System
- Configure Deferred Activation
- Troubleshooting
- Glossary
Configure Encryption on a Server Operating
System
Enable Encryption on a Server Operating System
NOTE:
Encryption of server operating systems converts User encryption to Common encryption.
1. As a Dell administrator, log in to the Management Console.
2. Select Endpoint Group (or Endpoint), search for the endpoint or endpoint group to enable, select Security Policies, and
then select the Server Encryption policy category.
3. Set the following policies:
● Server Encryption - Select to enable Encryption on a server operating system and related policies.
●
SDE Encryption Enabled - Select to turn on SDE encryption.
● Encryption Enabled - Select to turn on Common encryption.
● Secure Windows Credentials - This policy is Selected by default.
When the Secure Windows Credentials policy is Selected (the default), all files in the \Windows\system32\config files
folder are encrypted, including Windows credentials. To prevent Windows credentials from being encrypted, set the
Secure Windows Credentials policy to Not Selected. Encryption of Windows credentials occurs independently of the
SDE Encryption Enabled policy setting.
4. Save and commit the policies.
Customize Activation Logon Dialog
The Activation Logon dialog displays:
● When an unmanaged user logs on.
● When the user selects Activate Dell Encryption from the Encryption icon's menu, located in the notification area.
Set Encryption External Media Policies
The
original encrypting computer
is the computer that originally encrypts a removable device. When the original computer is
a
protected server
- a server with Encryption on a server operating system installed and activated - and the protected server
first detects the presence of a removable device, the user is prompted to encrypt the removable device.
17
96 Configure Encryption on a Server Operating System