The ePO - On-prem server allows administrators to assign users from Microsoft Active Directory or User Directory to Drive Encryption managed systems.
The user's authentication credentials, token type, and the user information fields are managed from the ePO - On-prem server. Drive Encryption gives the administrator the freedom of adding and removing the users to and from systems or system groups at any time.