Administrator Guide

Dell Data Protection | Endpoint Security Suite Enterprise for VDI with VMware | 02/2017
2. Refer to Endpoint Security Suite Enterprise documentation for scripted or System Center Configuration
Manager (SCCM) deployment methods.
Note: Step 2 is beyond the scope of this document.
5.4 System Data Encryption (SDE)
Note: DO NOT enable SDE in a VDI environment or Encrypt Windows Page File. This configuration is not
supported. If this feature is turned on the host will experience high disk IO and CPU utilization due to a file
encryption sweep occurring that will affect the VM’s that are assigned this policy. Contact Dell Support for
assistance if this policy needs to be configured in the environment.
5.5 Removable Media Encryption (EMS) Install
Note: If you wish to install the EMS piece only and not ATP at the same time, Create desktops using the
steps listed below. It can be installed on persistent or non-persistent desktops
1. Create Master VM and install applications user will need. Install the Endpoint Security Suite Enterprise
client at this point as described in section 5.7.1 and 5.7.3 following.
2. When the Endpoint Security Suite Enterprise client is installed shutdown the machine but do not restart it.
3. Create Desktop pool of either persistent or non-persistent desktops on Horizon administration console.
4. Verify USB redirection in user’s session.
From VMWare pull down menu located at top of VDI session, the following Icons should be visible.
If the devices marked above do not appear in session menu then USB redirection is not enabled
or session needs to be updated.
Note: Refer to the VMware Horizon 7 security document for guidance on using USB redirection securely.
5. Insert Removable media
Click Devices, in our example the USB device is an Alcor Micro Mass Storage.
Click Alcor Micro Mass Storage.
Refer to section 6.2.5 section below for EMS policy configuration.