The Log On tab under the Product Settings policy allows you to define the logon settings for the Product Settings policy of Drive Encryption.
Option | Definition |
|---|---|
Enable automatic booting | When enabled, the client system boots automatically without prompting for a Pre-Boot Authentication. The expiration date for auto-booting can also be set. If required, the user can select the UTC time standard option. ImportantIf you enable this option without requiring the use of TPM for automatic booting, the Drive Encryption product does not protect the data on the drive when it is not in use.
|
Allow temporary automatic booting | Allows you to turn (on or off) the PBA screen, with a client-side utility. This eliminates the need to modify the policy in ePO - On-prem, and fully automates patching and other client management scenarios. |
Use of TPM for automatic booting | Select one of these options:
NoteThis option is applicable only for systems installed with Drive Encryption 7.2.0 or later. If you apply a policy to the earlier versions of Drive Encryption with automatic booting enabled and use of TPM set to 'Required', it will leave the client system in an unprotected state since autoboot will be enabled with no protection of the disk encryption key. |
prevent automatic booting when the disk moves system (UEFI only) | This prevents autoboot from functioning when a disk is moved between the systems. |
Log on message | Type a message that appears to the client user. |
Do not display previous user name at log on | Prevents the client system from automatically displaying the user name of the last logged on user on all Drive Encryption logon dialog boxes. |
Enable on screen keyboard | Enables the Pre-Boot On-Screen Keyboard (OSK) and the associated Wacom serial pen driver. When this option is enabled, the pen driver finds supported pen hardware (Panasonic CF-H1 and Samsung Slate 7) and displays the OSK. NoteIf you do not select this option, the BIOS uses mouse emulation. In such a situation, the BIOS treats the digitizer as a standard mouse, which might lead to the cursor being out of sync with the stylus on USB-connected Wacom pen digitizers.
|
Add local domain users (and tag with 'TDE:ALDU') |
|
Enable accessibility | Select this option to sound a beep as a signal when the user moves the focus from one field to the next using mouse or keyboard in the Pre-Boot environment. This option is helpful to visually challenged users. The USB audio functionality allows visually impaired users to hear an audio signal (spoken word) as guidance when the user moves the cursor from one field to the next in the Pre-Boot environment. The USB speakers and headphones can be used to listen to the audio signal. For more details, see Enable Accessibility (USB audio devices) in the Pre-Boot environment. |
Disable pre-boot authentication when not synchronized | Blocks a user from logging on to PBA in the client system, if the client system is not synchronized with the ePO - On-prem server for the set number of days. The user is blocked from logging on to PBA, and can then request the administrator to perform Administrator Recovery to unlock the client system. This allows the client system to boot and communicate with the ePO - On-prem server. NoteThe client system continues to block the user from logging on to the system until synchronization with ePO - On-prem. |
Read username from smartcard | Automatically retrieves the available user information on the client system from the inserted smartcard; hence the Authentication window does not prompt for a user name. The user can then authenticate by typing the correct PIN. You need to enable the matching rules that are required for matching smartcard user principle name (UPN) names with Drive Encryption user names.
NoteThis feature is supported on the Gemalto .Net V2+ tokens, and PIV and CAC tokens. |
Option | Definition |
|---|---|
V7.2 Onwards | Third-party credential providers:
|
Single sign-on (SSO):
| |
Password synchronization:
| |
Preboot user options
| |
Windows username matching
| |
Credential provider bitmap
| |
Require Drive Encryption logon (only supported on V6 clients) — This requires you to mandatorily log on to PBA for EEPC 6.x.x systems, thereby disabling the SSO functionality.
| |
Lock workstation when inactive — The client system is locked when it is inactive for the set time. | |
Duplicate | Duplicates or copies the policy with a different name and this can be assigned to a different user. |
Save | Saves the Product Settings Policy of Drive Encryption. |
Cancel | Exits the current page. |