Reference Guide

Manage Policies
134
CONNECTIONS
COMMON_MUSIC
COMMON_PICTURES
COMMON_VIDEO
RESOURCES
PROFILES
%HKCU:regpath%
Includes a numeric or text value stored in the registry for the Current User. If you specify a path but
not an item, the client uses the default value
%HKLM:regpath%
Includes a numeric or text value stored in the registry for the local computer. If you specify a path
but not an item, the client uses the default value
%ENV:envname%
Includes the value of a Windows local environment variable
%%
Includes the % character
Windows Policies that Require Reboot
SDE Encryption Enabled
All PCS policies
Windows Policies that Require Logoff
SDE Encryption Enabled
Advanced Windows Encryption
A word about types of encryption: SDE is designed to encrypt the operating system and program files. In
order to accomplish this purpose, SDE must be able to open its key while the operating system is booting
without intervention of a password by the user. Its intent is to prevent alteration or offline attacks on the
operating system by an attacker. SDE is not intended for user data. Common and User key encryption are
intended for sensitive user data because they require a user password in order to unlock encryption keys.
Policy descriptions also display in tooltips in the Remote Management Console. In this table, master policies
are in bold font.
Policy Default Setting
Self-Encrypting Drive (SED)
This technology manages self-encrypting drives (SEDs). Authentication by users through a Pre-
Boot Authentication environmen
Crypto Erase
Password
String 0-100 characters