The administrator must configure DPSSP server settings within ePO - On-prem to allow a user to obtain the recovery key or response code on the client system using DPSSP.
Make sure that you have installed the dpssp.zip extension on the ePO - On-prem server before performing this task.
Log on to the ePO - On-prem server as an administrator.
Click → → .
On the left pane, select DPSSP Settings and click Edit to open the Edit DPSSP Settings page.
Enable the Self Service Portal option.
Next to ePO user, type the ePO - On-prem user name.
Note
Make sure that the ePO - On-prem user name that you enter has the permission to perform recovery operations in Drive Encryption. We recommend that you create a specific ePO - On-prem user for DPSSP recoveries, and limit the permission set privileges to Drive Encryption recovery only.
Next to Authentication, select the Active Directory sever that the users need to authenticate to.
Note
Make sure to note that the administrator has selected the registered AD in ePO - On-prem.
Next to Logging, enable the Log authentication attempts and Log user activity options.
Next to Blocking, enable the Enable IP address blocking option, and perform the following operations:
Block IP address after (failed logins) — Type the numeric value to block the IP address after the specified number of unsuccessful logon attempts.
Unblock after (minutes) — Type the numeric value in minutes to unblock the respective IP address after the specified number of minutes.
Note
To instantly unblock an IP address, refer to the How to instantly unblock a user or IP address section.
Next to Blocking, enable the Enable user blocking option, and perform the following operations:
Block user after (failed logins) — Type the numeric value to block the user after the specified number of unsuccessful logon attempts.
Unblock after (minutes) — Type the numeric value in minutes to unblock the respective user after the specified number of minutes.
Note
If you either install the
dpssp.zipextension or restart the ePO - On-prem system, you cannot block or unblock users for 10 minutes.Note
To instantly unblock a user, refer to the How to instantly unblock a user or IP address section.
Next to Session, type the numeric value in minutes to log off the user's session after the specified number of minutes.
Click Save.