Users Guide
Advanced Authentication v8.6
• When a user begins credential enrollment but quits without saving before enrollment is complete, the credentials are enrolled rather
than discarded. To work around this issue, if policy allows the user to modify their own credentials, the user can open the DDP Console,
select the Enrollments tile, select and delete the credentials. Otherwise, an administrator must remove them. [CSF-146]
• Password Manager does not support the Windows 10 web browser, Microsoft Edge. [CSF-281]
• When running on Windows 10, the DDP Console About window displays incorrect BIOS information and an incorrect serial number for
the computer's motherboard. [CSF-291, CSF-301]
• When a contactless smart card is moved across the card reader, a popup notication prompts the user to enroll the smart card. If the
card is moved multiple times in a short length of time, multiple popup notications may simultaneously display. [CSF-293]
• Amended 08/2015 - When using the child installer, no reboot automatically occurs, but a restart is necessary. The user must manually
restart the computer or, to force a restart after installation, add /forcerestart to the installation command. [CSF-336]
• On Windows 10, if the Validity Fingerprint Sensor driver is out-of-date, when PBA is activated, the computer experiences a blue screen.
To work around this issue, ensure that PBA is not enabled by policy, then follow these steps:
1 Install Dell Data Protection then reboot.
2 In Windows Control Panel, navigate to Device Manager.
3 Under Biometric Devices, disable the Validity Fingerprint Sensor.
4 Activate the PBA.
5 After reboot, the Validity Fingerprint Sensor can be re-enabled, and the ngerprint reader functions as expected.
To download the latest Validity Fingerprint Sensor driver, go to http://www.dell.com/support/home/us/en/19/Products/?app=drivers
and select your computer model to check and download the latest driver.
[CSF-349]
• Added 08/2015 - If Microsoft TPM Base Services is improperly installed, the following functionality is aected: HCA provisioning,
ngerprint enrollment in the DDP Console/Security Console, and BitLocker Manager operation. For more information and to work
around this issue, refer to this KB article: http://www.dell.com/support/article/us/en/19/SLN296706. [CSF-454]
Preboot Authentication v8.6
• Upgrade from v8.1 or v8.2 to v8.6 on a computer with a SED installed and PBA activated fails. [CSF-449, CSF-461]
• Upgrade on a computer with a LiteOn M3 series SSD installed and PBA activated fails due to the small disk size. To work around this
issue, before upgrading, deprovision the PBA. After upgrade, the PBA can be reactivated. [CSF-528]
• With PBA activated on Dell Latitude E7450, navigation of the Advanced Boot Options menu is not possible because the native keyboard
is not available. To work around this issue, deactivate the PBA, access the Advanced Boot Options menu, and keyboard navigation is
available. [DDPLP-286]
• When running Windows 10 on a computer with smart card authentication through PBA activated, after resuming from hybrid sleep,
single sign-on fails. [DDPLP-308]
• To protect communications against the OpenSSL CVE-2014-3566 vulnerability, Dell Enterprise Server v8.5.1 and DDP Enterprise Server
- Virtual Edition v9.0 and later are set to communicate using TLS, by default. However, SED and HCA v8.6 clients communicate with
Enterprise Server using SSL. This means that when running Enterprise Server v8.5.1 and later, SED or HCA v8.6 clients with Preboot
Authentication activated will fail to communicate with Enterprise Server. To work around this issue, refer to knowledge base article
SLN296006 at http://www.dell.com/support/article/us/en/19/SLN296006. This workaround must be implemented as soon as
possible, in order to prevent PBA client communication issues with Enterprise Server v8.5.1 or Virtual Edition v9.0 and later.
[DDPUP-733, DDPMTR-1331]
• On Dell Latitude E7250, E7350, E7450, and Venue Pro 11 (Model 7139), recovery fails with Dell Opal SED Recovery Utility one-time
unlock of the drive. To work around this issue, use the recovery key to unlock a drive on one of these models. [DDPUP-763]
SED Client v8.6
• Amended 08/2015 - When using the child installer, the installer will eect a reboot only if necessary. To force a restart after installation,
add /forcerestart to the installation command. [CSF-246]
30
Endpoint Security Suite Pro Technical Advisories v1.8
Technical Advisories