This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Remove Encryption - Safeguard Enterprise

Hi guys!!

I have the following scenario: a Windows Xp Professional SP3 with the SGN client installed. I've made a policy for encryption of the c: and d: volumes. The encryption was set to use the machine key.

Question: I would like to know how we remove the encryption of the volumes. I've tried to change the policy to "No Encryption" but it didn't change anything. Is there any tool for booting and remove the encryption like in Safeguard Easy?

I really appreciate any help!!

Happy new year!!

Roberto

:567


This thread was automatically locked due to age.
Parents
  • HI ssij,

    Thank you for stopping by the SophosTalk community forum and posting your question.

    You can configure the existing security policies or create a separate policy to decrypt a volume. Three things need to happen in order to get the volume decrypting:

    1. A Device Protection policy needs to be configured for the User to be able to decrypt, make sure it's synch'ed to the User before Step 2.
    2. Change the same Device Protection encryption policy from 'Volume Based' to 'No encryption'. Synch this up to the Computer before Step 3.
    3. On the workstation you want to decrypt, go to My Computer which displays the drive letters and icons. Right-click on the volume you want to decrypt. Click on the 'Encryption' tab added by SGN. The 'Media encrypted' check box should now be enabled. Unselect the checkbox, click 'OK' or 'Apply' and watch the drive decrypt.

    The important components to note here are that you are first enabling a User to remove encryption without removing the SGN Client software. This is a User based policy. Second, changing the policy to 'No encryption' is a Computer Based policy which can be applied to Computer and Users in a 'Decryption' group. Lastly, is the action taken to remove the encryption. If your question is asking to be able to change a security policy and without any User action to remove encryption? That is lower security and increases an organization's risk to be non-compliant.

    I don't believe that anyone reading this post would want to come into work one day and hear that everyone's computers are decrypting or have already been decrypted. Yikes!! After you change the security policy back to 'Volume based' encryption, make sure you are checking the classified ads for a new career.

    :1907
Reply
  • HI ssij,

    Thank you for stopping by the SophosTalk community forum and posting your question.

    You can configure the existing security policies or create a separate policy to decrypt a volume. Three things need to happen in order to get the volume decrypting:

    1. A Device Protection policy needs to be configured for the User to be able to decrypt, make sure it's synch'ed to the User before Step 2.
    2. Change the same Device Protection encryption policy from 'Volume Based' to 'No encryption'. Synch this up to the Computer before Step 3.
    3. On the workstation you want to decrypt, go to My Computer which displays the drive letters and icons. Right-click on the volume you want to decrypt. Click on the 'Encryption' tab added by SGN. The 'Media encrypted' check box should now be enabled. Unselect the checkbox, click 'OK' or 'Apply' and watch the drive decrypt.

    The important components to note here are that you are first enabling a User to remove encryption without removing the SGN Client software. This is a User based policy. Second, changing the policy to 'No encryption' is a Computer Based policy which can be applied to Computer and Users in a 'Decryption' group. Lastly, is the action taken to remove the encryption. If your question is asking to be able to change a security policy and without any User action to remove encryption? That is lower security and increases an organization's risk to be non-compliant.

    I don't believe that anyone reading this post would want to come into work one day and hear that everyone's computers are decrypting or have already been decrypted. Yikes!! After you change the security policy back to 'Volume based' encryption, make sure you are checking the classified ads for a new career.

    :1907
Children
No Data