The Self-recovery option allows the user to reset a forgotten password by answering a set of security questions. A list of security questions is set by the administrator using ePO - On-prem. If the answers from the user match what has been stored with their self-recovery information, they can proceed through the recovery process.
A list of security questions is set by the administrator using ePO - On-prem. If the answers from the user match what is stored with their self-recovery information, they can proceed through the recovery process.
Use ePO - On-prem to enable or disable the self-recovery functionality in the client computer.
Click → → , then select a group from the System Tree.
Select a system, then click → → to open the Policy Assignment page for that system.
From the Product drop-down list, select Drive Encryption 7.x. The policy categories under Drive Encryption display the system's assigned policy.
Locate a User Based Policies policy category, then click Edit Assignments to open the User Based Policies page.
If the policy is inherited, select Break inheritance and assign the policy and settings below next to Inherit from.
Select a policy from the Assigned policy drop-down list, then click Edit Policy to open the Policy Settings page.
From this page, you can edit the selected policy, or create a new policy.
On the Self-recovery tab, enable or disable the self-recovery functionality for the specified user or user group.
Select Invalidate self-recovery after no. of attempts and type the number of attempts.
Note
The self-recovery token is invalidated if the user types invalid answers for more than the number of attempts specified in the policy.
Type the number of Questions to be answered to perform the self-recovery. The client user is prompted with these questions when trying to recover the user account at the client system.
Type the number of Logons before forcing user to set answers to determine how many times a user can log on without setting their self-recovery questions and answers.
Click + to create a new question, then select the question Language and type the Min answer length for the answer to this question.
Note
Answers to these questions are typed by the user on the client system during the recovery process. The user is prompted for recovery enrollment during every logon. The user can cancel the enrollment until the user exceeds the specified number of logon attempts. After exceeding the defined number of logon attempts, the Cancel button is disabled and the user is forced to enroll for self-recovery.
Click Save.
Send an agent wake-up call.