This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Remote install Full Disk Encryption

I'm planning a rollout of Sophos Full Disk Encryption to a mobile database.  From the management console can I push out the installation to the client machines?  They are all joined to a Windows domain.  Many connect over a VPN connection to access domain resources.  It's impractical to have all the users travel back to the office in order to have a tech perform the installation. 

This Sophos newbie apologizes if this question has been answered previously.  I wasn't able to find the question when I searched the KB.

Thanks,

m-

Edit: We will be installing SafeGuard Enterprise in order to take advantage of the management server.  Initially, only the FDE will be deployed.

:51788


This thread was automatically locked due to age.
Parents
  • Try section 9.5.3 here: http://www.sophos.com/en-us/medialibrary/PDFs/documentation/sgn_61_ig_eng_installation.pdf?la=en

    You cant use Sophos Management Center to deploy encryptions - however as the installation files are MSI's you can deploy them via a batch file or any other distribution method of your choice. You just need to make sure when the PC restarts the Windows can still access the MSI's so hosting them on a mapped drive might not work.

    Also before the encryption Sophos suggest you run a chkdsk which will complicate matters a little.

    Finally I dont think the hard drive starts encrypting until after the user logs on (I might be wrong here). The first user to log onto the device will be added as a user in the Power On Authentication so be wary of this too. Other users will need to be added manually, either on the device or using the console.

    As we only use laptops we have had to have a technician onsite for each install. If you manage to get them rolled out centerally let me know - would be interesting to hear how you get on.

    :51810
Reply
  • Try section 9.5.3 here: http://www.sophos.com/en-us/medialibrary/PDFs/documentation/sgn_61_ig_eng_installation.pdf?la=en

    You cant use Sophos Management Center to deploy encryptions - however as the installation files are MSI's you can deploy them via a batch file or any other distribution method of your choice. You just need to make sure when the PC restarts the Windows can still access the MSI's so hosting them on a mapped drive might not work.

    Also before the encryption Sophos suggest you run a chkdsk which will complicate matters a little.

    Finally I dont think the hard drive starts encrypting until after the user logs on (I might be wrong here). The first user to log onto the device will be added as a user in the Power On Authentication so be wary of this too. Other users will need to be added manually, either on the device or using the console.

    As we only use laptops we have had to have a technician onsite for each install. If you manage to get them rolled out centerally let me know - would be interesting to hear how you get on.

    :51810
Children
No Data