This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Safeguard on Windows 10 Issue

Good day. I hope someone can assist me.

We have a client running Sophos Safeguard. Safe Guard Management center is on a server local on their network, we are running management center version 8.00.0.251 and also version 8.00.0.251 on the clients.

The environment is a mix of windows 7 and Windows 10 devices. I have one windows 10 device which I am having an issue with.

I have successfully encrypted other windows 10 devices on this environment. Our policy is set to TPM+KEY in the Authentication Policy. 

So as per other - we install SGxClientPreinstall then we install SGNClient_x64 with the Typical settings. After a reboot we install Managed Client (Default) and reboot again.

After this reboot once we log in with the user account, BitLocker prompts the user to enter a PIN whereafter it will reboot and start encryption. 

With this one device, which is a brand new laptop shipped with Windows 10 Professional we are getting below:

 

First Prompt :

 

 

The user types in a PIN, but then we get this:

This is the first time we get this on a windows 10 device. I must mention this user currently is also using another windows 10 device (Once this laptop is encrypted he will get this one) the current windows 10 device he is using encrypted with no problem.)

We want the user to enter a pin and be prompted for the pin after BIOS. 

 

As I mentioned this is a brand new laptop what was not encrypted before.

 

Any assistance will be greatly appreciated.

 

Regards

 



This thread was automatically locked due to age.
Parents
  • Hi - The drive is probably encrypted already and Sophos is attempting to remove TPM and then add TPM and PIN. You can't though remove the only key protector.

    I would use manage-bde command applets to sort this.

    Admin command prompt - 

    manage-bde -status c:

    This will list the key protectors at the bottom. These are the methods used to secure the encryption. The numerical password is the recovery key, but it should list the others below that.

     

    Could you tell us what's listed there please?

     

    However

    You can add protectors here - You will probably want to use

    manage-bde -protectors -add c: -TPMAndPIN 

    This will then prompt for a SIX digit PIN. Note that Sophos window prompts for FOUR digits but this is NOT correct for newer versions of Win10 - it's now 6. I'm hoping for an update in the next release for this please Sophos! :) 

    I would then reboot once the PIN has set and then check if the Sophos window complains. It shouldn't as the above has added a key protector and there won't be just the one now.

Reply
  • Hi - The drive is probably encrypted already and Sophos is attempting to remove TPM and then add TPM and PIN. You can't though remove the only key protector.

    I would use manage-bde command applets to sort this.

    Admin command prompt - 

    manage-bde -status c:

    This will list the key protectors at the bottom. These are the methods used to secure the encryption. The numerical password is the recovery key, but it should list the others below that.

     

    Could you tell us what's listed there please?

     

    However

    You can add protectors here - You will probably want to use

    manage-bde -protectors -add c: -TPMAndPIN 

    This will then prompt for a SIX digit PIN. Note that Sophos window prompts for FOUR digits but this is NOT correct for newer versions of Win10 - it's now 6. I'm hoping for an update in the next release for this please Sophos! :) 

    I would then reboot once the PIN has set and then check if the Sophos window complains. It shouldn't as the above has added a key protector and there won't be just the one now.

Children