Users Guide

Technical Advisories v8.6.1
No Technical Advisories were introduced in v8.6.1.
Technical Advisories v8.6
Encryption Client
Added 09/2015 - In order to add new features, functionality, and the newest operating systems, Enterprise Edition for
Windows will support Windows XP through Shield version 8.5.
Added 08/2015 - If Microsoft TPM Base Services is improperly installed, the following functionality is affected: HCA
provisioning, fingerprint enrollment in the DDP Console/Security Console, and BitLocker Manager operation. For more
information and to work around this issue, refer to this KB article: http://www.dell.com/support/article/us/en/19/
SLN296706. [CSF-454]
If HCA policy is disabled or the HCA encryption algorithm is changed during encryption, the computer may experience a blue
screen after reboot or at PBA logon. [DDPMTR-282]
During SDE encryption, a popup notification displays to prompt the user to cancel encryption when an application is waiting
for encryption of a file to complete. If this occurs rapidly during a short length of time, multiple notifications may
simultaneously display. [DDPMTR-943]
Due to Microsoft's change in the way Windows handles stopping a critical service, stopping a DDP service such as
CMGShield service, EMS service, or the Dell Data Protection | Encryption process in Task Manager will result in the
computer experiencing a blue screen. [DDPMTR-945]
In Windows 10, when using EMS Explorer to open a 5GB file on encrypted removable media an error displays, "The... file is
too large for notepad," and the file does not open. [DDPMTR-990]
When opening a file on encrypted removable media through EMS Explorer on a non-Shielded computer, if the removable
media is removed without being ejected, the file remains in the computer's Ems Explorer Temporary Files folder in clear text
after the file is closed. Properly ejecting the removable media properly removes these clear-text files. [DDPMTR-1157]
After recovery of a computer running Windows 10 with HCA policy enabled, if HCA policy is then disabled the computer
experiences a blue screen rather than decrypting as expected. [DDPMTR-1303]
Advanced Authentication
When a user begins credential enrollment but quits without saving before enrollment is complete, the credentials are enrolled
rather than discarded. To work around this issue, if policy allows the user to modify their own credentials, the user can open
the DDP Console, select the Enrollments tile, select and delete the credentials. Otherwise, an administrator must remove
them. [CSF-146]
Password Manager does not support the Windows 10 web browser, Microsoft Edge. [CSF-281]
When running on Windows 10, the DDP Console About window displays incorrect BIOS information and an incorrect serial
number for the computer's motherboard. [CSF-291, CSF-301]
When a contactless smart card is moved across the card reader, a popup notification prompts the user to enroll the smart
card. If the card is moved multiple times in a short length of time, multiple popup notifications may simultaneously display.
[CSF-293]
Amended 08/2015 - When using the child installer, no reboot automatically occurs, but a restart is necessary. The user must
manually restart the computer or, to force a restart after installation, add /forcerestart to the installation command.
[CSF-336]
On Windows 10, if the Validity Fingerprint Sensor driver is out-of-date, when PBA is activated, the computer experiences a
blue screen. To work around this issue, ensure that PBA is not enabled by policy, then follow these steps:
1. Install Dell Data Protection then reboot.
2. In Windows Control Panel, navigate to Device Manager.
3. Under Biometric Devices, disable the Validity Fingerprint Sensor.
4. Activate the PBA.
5. After reboot, the Validity Fingerprint Sensor can be re-enabled, and the fingerprint reader functions as expected.
To download the latest Validity Fingerprint Sensor driver, go to http://www.dell.com/support/home/us/en/19/Products/?
app=drivers and select your computer model to check and download the latest driver.
[CSF-349]
When running Windows 10 on Dell Latitude E7250 or E7450, when the computer resumes from sleep, hibernation, warm
boot, or cold boot, the user may be unable to authenticate with an enrolled contactless smart card. To work around this
issue, change the policy to require only password authentication. The user should log on and re-enroll the contactless smart
card. After re-enrollment, the user will be able to log on with the contactless smart card. [CSF-362]
Technical Advisories
67