Device Encryption - difference between "Not encrypted" and "Unmanaged"?

I wonder what the Status in the Encryption dashboard means:

under which circumstances is it showing "Not encrypted" and not encrypted & "Unmanaged"?

On the screenshot all have the encryption module installed, except one computer.

The filter is "Computers that are not encrypted".



Edited tags
[edited by: Gladys at 3:03 PM (GMT -7) on 3 Jul 2023]
Parents
  • Hi LHerzog,

    If device encryption shows as "Not encrypted," this means that the CDE is deployed on the device, but an encryption-on policy has not yet been applied, or the device has not yet been encrypted. This can also mean that the policy applied to the device states for it not to be encrypted.

    If the device encryption state shows as "Unmanaged," this means the device is encrypted through other means, but Sophos is not managing the encryption policy on the device. An admin may have manually enabled BitLocker encryption. 

    I'll be following up with our documentation team to ensure this gets documented. 

    Kushal Lakhan
    Team Lead, Global Community Support
    Connect with Sophos Support, get alerted, and be informed.
    If a post solves your question, please use the "Verify Answer" button.
    The New Home of Sophos Support Videos!  Visit Sophos Techvids
  • Hi Kushal, 

    You said above that if it says unmanaged that it means the device is encrypted by something other than Sophos. What would it show if the CDE is deployed but the device is unencrypted by any means?  I believe that I am seeing on my clients that it also says unmanaged in that situation.

    Thanks

Reply Children