Follow these recommendations to make sure that your data is protected during and after the encryption process.
Re-provisioning a Trellix Drive Encryption encrypted disk
To repurpose a disk encrypted with Drive Encryption, the system has to go through the DE de-activation process so that no remnants of DE remain before going through the reimaging process. Alternatively, if the encrypted disk was reimaged, the process of re-provisioning should include the deletion of the EPE partition.
Back up the system before you encrypt it, and perform regular backups
As with any roll out and deployment, it is good practice to back up the system before installing Drive Encryptionto ensure data is not lost in the unlikely event that a problem occurs. The DETech recovery tools can also be used to decrypt and recover any unbootable disks. Refer to the DETech User Guide for more information.
Note
When upgrading Drive Encryption, the Mfeepehost service must not be stopped manually or by third-party software because this can cause problems. In addition, during an upgrade, the system must be kept powered on until the software (both Host and Encryption Provider portions) completes installing.
CHKDSK /r Clean up the disk before you encrypt it
Hard disks that are damaged, or have a high number of undiscovered bad sectors, might fail during the full disk encryption process. Run a CHKDSK /r command prior to installing Drive Encryption to make sure the disk is healthy. Optionally, run the OEM diagnostic tools to make sure that all other hardware components are working correctly.
Understand the supported tokens/readers for Drive Encryption
Make sure that the supported reader drivers are installed in your client system before trying to install Drive Encryption. Make sure to obtain the correct drivers from the manufacturers' web sites and review their release notes to avoid any known issues with the tokens or readers. The supported tokens and readers are listed in these KB articles:
Maintain separate test and production clients
Enterprise administrators are advised to maintain separate test and production environments. Modification to the production server should be limited. Use the test system to test software updates, driver updates, and Windows Service Packs prior to updating the production systems.
Build and test recovery tools
The administrator needs to be aware that there will be changes to the normal client boot process due to installing Drive Encryption. Administrators are advised to:
Create and test the customized DETech WinPE V3 or V4 (for UEFI systems) Disk with Drive Encryption drivers installed.
Create and test an DETech Standalone Boot disk.
Do a phased deployment
For an efficient deployment, perform phased deployment in order to scale the deployment process. Create deployment tasks and deploy Drive Encryption to systems arranged in groups or batches in the System Tree. You can also base it on a specific tag in ePolicy Orchestrator.
Add a user to the client system
You should add at least one user to the client system for Drive Encryption to activate on the client.
Perform disk recovery on decrypted disks
Wherever possible, as a best practice, if you need to perform any disk recovery activities on a disk protected with Drive Encryption, we recommend that you first decrypt the disk. For more information about decrypting the Drive Encryptioninstalled system, see Trellix Drive Encryption 8.0.x Product Guide and the DETech User Guide.
Automatic Repair should be disabled for Windows 10 and above systems
Automatic Repair of an encrypted disk for Windows 8 and above systems might destroy the encrypted operating system files without any notification and cause permanent boot problems. However, previous versions of Windows display a confirmation message before starting the repair. Windows 8 launches into Automatic Repair immediately if a problem is detected, leaving little scope to prevent destruction of encrypted data.
To disable Automatic Repair, run this command from an administrative command prompt: bcdedit /set {current} recoveryenabled No
Educate your client users about Password/Token/PIN secrecy
Educate your client users to understand that they are responsible for the security of their password, PIN, or token details. Encourage them to change their password, or request a new PIN, if they feel that it might have been compromised.
Make sure password strength is sufficient
Make sure that your password policy is strong enough for your requirements.