This article details how to use a new PGP Whole Disk Encryption policy feature available in PGP Universal Server versions 2.9.0 - 2.12.0 to disable user-initiated disk decryption.
User-Initiated Whole Disk Encryption Permissions
PGP Universal Server 2.9.0 - 2.12.0 allow administrators to apply more granular PGP Whole Disk Encryption policy to managed PGP Desktop clients. Administrators can configure various permissions for user-initiated PGP Whole Disk Encryption for internal and removable disks.
The permission options for internal and removable disks include:
Allow User Management - Selecting this option means a user can add or remove other passphrase users from the user's device.
Allow Encryption - Selecting this option means users can initiate encryption of internal and/or removable disks. Automatic disk encryption during setup is not affected by this policy.
Allow Decryption - Selecting this option means users can initiate decryption of internal and/or removable disks. If you do not enable this option, users will not be able to decrypt disks. Decryption after license expiration is not affected by this policy.
Store Decryption policy on fixed disks - When selected, the policy that specifies whether users can initiate decryption of the disk is stored on the encrypted disk. When the policy is stored on the disk, current and future versions of PGP Whole Disk Encryption, as well as Windows PE tools and other recovery methods, will all be prevented from decrypting the disk. This information is not stored on removable disks.
When user-initiated decryption is disabled, the user receives a pop-up PGP Error stating
Your administrator has disabled user controlled whole disk decryption when trying to decrypt the disk.
To disable user-initiated decryption of disks:
Log in to the PGP Universal Server administrative interface.
Click Policy>Internal User Policy.
Select the desired policy to edit from the Internal User Policy card.
From the Policy Options, click the Edit button next to PGP Desktop Settings.
Select the WDE tab.
Under User-initiated Whole Disk Encryption Permissions, remove the checkmark next to Allow Decryption for the desired disk type.
Note: Selecting the option to Store decryption policy on fixed disks will also prevent user-initiated decryption using a PGP Whole Disk Encryption recovery disk.
Click Save twice to apply the updated setting for the policy.
Imported Document ID: TECH149197
Subscribing will provide email updates when this Article is updated. Login is required.
Thanks for your feedback. Let us know if you have additional comments below. (requires login)
Subscribed to the Article.
Unable to subscribe
Thanks for your additional feedback !!!
Enterprise Support Virtual Agent
Rate Me :
Tell us more:
Welcome! My name is Sami, the Enterprise Support Virtual Agent answering technical support questions.