
88 Installation Guide
Encrypt
Tem p
Internet
Files
Tru e False
True encrypts the path listed in the environment variable
CSIDL_INTERNET_CACHE with the User Data Encryption
Key.
To reduce encryption sweep time, the client clears the contents
of CSIDL_INTERNET_CACHE for initial encryption, as well as
updates to this policy.
This policy is applicable when using Microsoft Internet Explorer
only.
Encrypt
User Profile
Docs
Tru e False
True encry pts:
• The users profile (C:\Users\jsmith) on Windows 7 with the
User Data Encryption Key
• \Users\Public on Windows 7 with the Common Encryption
Key
Encrypt
Windows
Paging File
Tru e False
True encrypts the Windows paging file. A change to this policy
requires a reboot.
Managed
Services
String - maximum of 100 entries of 500 characters each (up to a
maximum of 2048 characters)
When a Service is managed by this policy, the Service is started
only after the user is logged in and the client is unlocked. This
policy also ensures that the Service managed by this policy is
stopped before the client is locked during logoff. This policy can
also prevent a user logoff if a Service is unresponsive.
Syntax is one Service name per line. Spaces in the Service name
are supported.
Wildcards are not supported.
Managed Services will not be started if an unmanaged user logs
on.
Secure
Post-Encrypt
ion Cleanup
Three
Pass
Overwrite
Single Pass Overwrite
No
Overwrite
No Overwrite, Single-pass Overwrite, Three-pass Overwrite,
Seven-pass Overwrite
Once folders specified via other policies in this category have
been encrypted, this policy determines what happens to the
unencrypted residue of the original files:
• No Overwrite deletes it. This value yields the fastest
encryption processing.
• Single-pass Overwrite overwrites it with random data.
• Three-pass Overwrite overwrites it with a standard pattern of
1s and 0s, then with its complement, and then with random
data.
• Seven-pass Overwrite overwrites it with a standard pattern of
1s and 0s, then with its complement, and then with random data
five times. This value makes it most difficult to recover the
original files from memory, and yields the most secure
encryption processing.
Prevent
Unsecured
Hibernation
Tr ue False True False
When enabled, the client will not allow computer hibernation if
the client is unable to encrypt the hibernation data.
Secure
Windows
Hibernation
File
Tr ue False True False
When enabled, the hibernation file will be encrypted only when
the computer enters hibernation. The client will disengage
protection when the computer comes out of hibernation,
providing protection without impacting users or applications
while the computer is in use.
Works tation
Scan Priority
High Norm
Highest, High, Normal, Low, Lowest
Specifies the relative Windows priority of encrypted folder
scanning.
User
Encrypted
Folders
String - maximum of 100 entries of 500 characters each (up to a
maximum of 2048 characters)
A list of folders on the endpoint hard drive to be encrypted with
the User Data Encryption Key or excluded from encryption.
This policy applies to all drives classified by Windows as Hard
Disk Drives. You cannot use this policy to encrypt drives or
external media whose type displays as Removable Disk, use EMS
Encrypt External Media instead.
Comentarios a estos manuales