To access the data on an encrypted computer, the user must go through the PBA. If the Enable automatic booting option is not enabled, the client user is presented with the PBA screen when the system is restarted after activating Drive Encryption.
During the first pre-boot after activation, the user needs to initialize the user account with the default password and enroll for self recovery (if enabled in the policy).
Note
Make sure that at least one manually added user is assigned to the client system. For example, this could be an admin user assigned to all systems.
During the initialization process, users set up their pre-boot credentials to unlock the disk.
Note
At least one Drive Encryption user must be assigned to Drive Encryption on each client; this could be an administrative user.