After installing the SafeGuard Client using MSIEXEC with ADDLOCAL parameters, no SafeGuard Credential Provider is available for logon to Windows. As a result, the initial user synchronization doesn't happen. The user status remains "unknown" (greyed out in Client status). Another effect may be that no inventory information of the client is sent to the SafeGuard server.
When installing the SafeGuard Client using MSIEXEC with ADDLOCAL parameters (see Knowledge Base Artikel 108426) to add certain modules of the client, the command didn't contain "CredentialProvider" to install the SafeGuard Credential Provider.
This can be validated with the installer logfile (e.g. with this logging parameters: msiexec /i SGNClient.msi /L*vx) or after the installation by checking the registry.
Example for a wrong installation:
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\BEBC449AE5D424242B01E2F3714779C9] "Client"="" "SectorBasedEncryption"="BaseEncryption" "SecureDataExchange"="Client" "BaseEncryption"="Client" "CredentialProvider"="-Client"
Applies to the following Sophos products and versions SafeGuard Device Encryption
When installing the SafeGuard Client with MSIEXEC with ADDLOCAL parameters, make sure that "CredentialProvider" is listed in the command.
Example for the installation of the Volume-based Encryption and Data Exchange modules:
msiexec /i C:\SGN\SGNClient.msi ADDLOCAL=Client,BaseEncryption,SectorBasedEncryption,CredentialProvider,SecureDataExchange
Example of a correct installation:
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\5B3BEB4CCF62158488C223C23744AE1A] "Client"="" "SectorBasedEncryption"="BaseEncryption" "SecureDataExchange"="Client" "BaseEncryption"="Client" "CredentialProvider"="Client" "ConfigurationProtection"="-Client" "BitLockerSupport"="-BaseEncryption"
The SafeGuard Credential Provider can be added to the installation by using the complete MSIEXEC command which should have been used in the first place. After a reboot, the SafeGuard Credential Provider should be available and the initial user synchronization should complete.
If the installation was performed correctly but the SafeGuard Credential Provider is not available, please see the article on the related information section of this page.
SafeGuard Enterprise: The SafeGuard Credential Provider tile is not available on systems with a Validity fingerprint device and OmniPass software installed
If you've spotted an error or would like to provide feedback on this article, please use the section below to rate and comment on the article. This is invaluable to us to ensure that we continually strive to give our customers the best information possible.
Every comment submitted here is read (by a human) but we do not reply to specific technical questions. For technical support post a question to the community. Or click here for new feature/product improvements. Alternatively for paid/licensed products open a support ticket.