Start a Conversation

Unsolved

T

8 Posts

1455

January 9th, 2020 05:00

Decryption Question

Hi All,

 

I was handed the task of administering the DDP environment a few years back at my current job. A question for the community:

 

1. If I decrypt a laptop (running the DDP client version 8.3) does this process decrypt the files for all the user profiles on the laptop or just for the currently logged in user?

 

Thanks,

Tim

January 14th, 2020 08:00

@TB73 

I'm going to assume you are using the DDP file folder based encryption (FFE) solution (aka policy-based encryption). DDP also has a full disk encryption, self-encrypting drive, encryption external media, and bitlocker solution. FFE is the most popular choice, hence my assumption.

In FFE, we can use three types of encryption keys:

  • System Data Encryption (SDE)
  • Common Encryption
  • User Encryption 

95% of environments use some combination of SDE with Common.

During the default decryption/uninstall option, as long as you enter an authorize DDP admin, it will decrypt all data using the encryption keys associated with the machine name. 

If you just turn policy (via Admin console) to off and you use User Encryption, then each user will perform the decryption when they log in. Otherwise the decryption will occur once an authorized user logs into the system for SDE/Common. 

Let me know if you need further clarification

-Brian

L4 Dell Data Security | #IWork4Dell

8 Posts

January 16th, 2020 06:00

Hi Brian,

 

Great information - thanks.

Here is what I have set at the Enterprise level within the DDP console. Let me know what my option are here:

Under the Windows Encryption Policy Category:

Fixed Storage:

SDE Encryption Enabled = False

 

General Settings:

Encryption Enabled = True

Application Data Encryption Key = Common

User Data Encryption Key = User

 

Regards,

Tim

January 21st, 2020 10:00

Tim,

 My apologies about the wait. My profile is undergoing some revisions, which made it inaccessible for a bit. 

It looks like you are using Common/User based encryption keys only. In that case, the specific user would need to log in to decrypt user encrypted data (which typically is only documents).

Let me know if you have any further questions. 

-Brian

L4 | Dell Data Security #IWork4Dell

No Events found!

Top