This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Notification: Data protection is off

In my Sophos Endpoint application I got a notification with 'Data protection is off'. Where in the Sophos Central portal do I turn it on?

 



This thread was automatically locked due to age.
Parents
  • I seems there are answers to this post. Is there any updated articles I can look for? The articles seemed to have be moved. Our Sophos Central is not stating anything is wrong yet the devices state "Data protection is off" Our Device Encryption licence limit is not even close to being full either. 




  • I am testing a theory and maybe you guys can confirm.   From what we found out, the data protection is using Windows BitLocker to encrypt.  We use SCCM to turn on BitLocker and then after the set up, manually install Sophos Cloud under an account with administrative privileges.  I have a couple of machines that doesn't show any notifications of Data Protection (just Your Computer is Protected notification) so I am wondering it shows Data Protection off because BitLocker was already implemented so Sophos doesn't report it's on?

    I hope the links are updated too...

  • Basically Central Encryption is managing Bitlocker. 

    So if you "install" the Encryption part of Central Encryption via Central, the endpoint will load the Encryption Module.

    If the module is loaded on the Endpoint but no Policy for encryption is in place, the Endpoint will show "Data Protection is off". 

     

    Data Protection needs a Policy. If you have a own Management (by SCCM for example), you do not need the Bitlocker Management by Central. So to speak, you do not need to load the encryption module to your Endpoints.

    But you can not use any encryption feature by central. There can be only one Encryption management. 

    https://www.sophos.com/en-us/medialibrary/PDFs/factsheets/sophos-central-device-encryption-dsna.pdf

     

    If you press "Manage Endpoint Software" under Computers, you can deselect the Encryption Part. 

     

     

    __________________________________________________________________________________________________________________

  • Thank you for your reply!

     

    James

Reply Children
No Data