
Installation Guide 89
User
Encryption
Algorithm
AES256
AES 256, Rijndael 256, AES 128, Rijndael 128, 3DES
Encryption algorithm used to encrypt data at the individual user
level. You can specify different values for different users of the
same endpoint.
User Data
Encryption
Key
User Common User Common User
Common, User, User Roaming
Choose a key to indicate who should be able to access files
encrypted by the following policies, and where:
• User Encrypted Folders
• Encrypt Outlook Personal folders
• Encrypt Temporary Files (\Documents and
Settings\username\Local Settings\Temp only)
• Encrypt Temporary Internet Files
• Encrypt User Profile Documents
Select:
• Common if you want User Encrypted Files/Folders to be
accessible by all managed users on the endpoint where they were
created (the same level of access as Common Encrypted
Folders), and encrypted with the Common Encryption
Algorithm.
• User if you want these files to be accessible only to the user
who created them, only on the endpoint where they were created
(the same level of access as User Encrypted Folders), and
encrypted with the User Encryption Algorithm.
• User Roaming if you want these files to be accessible only to
the user who created them, on any encrypted Windows
endpoint, and encrypted with the User Encryption Algorithm.
If you elect to incorporate an encryption policy to encrypt entire
disk partitions, it is recommended to use the default SDE
encryption policy, rather than Common or User. This ensures
that any operating system files that are encrypted are accessible
during states when the managed user is not logged in.
Policy
Aggress
Protect
for All
Fixed
Drives
and Ext
Drives
PCI
Reg
Data
Breach
Reg
HIPAA
Reg
Basic
Protect
for All
Fixed
Drives
and Ext
Drives
(Def)
Basic
Protect
for All
Fixed
Drives
Basic
Protect
for Sys
Drive
Only
Basic
Protect
for Ext
Drives
Enc Dis Description
Removable Storage Policies
EMS
Encrypt
External
Media
Tr ue False True False
This policy is the “master policy” for all Removable Storage
policies. A False value means that no encryption of removable
storage takes place, regardless of other policy values.
A True value means that all Removable Storage encryption
policies are enabled.
EMS
Exclude
CD/DVD
Encryption
False Tr ue False encrypts CD/DVD devices.
EMS Access
to
unShielded
Media
Block Read only Full Access
Read
only
Full
Access
Block, Read Only, Full Access
Note that this policy interacts with the Port Control System -
Storage Class: External Drive Control policy. If you intend to set
this policy to Full Access, ensure that Storage Class: External
Drive Control is not set to Read Only or Blocked.
When this policy is set to Block Access, you have no access to
removable storage unless it is encrypted.
Choosing either Read-Only or Full Access allows you to decide
what removable storage to encrypt.
If you choose not to encrypt removable storage and this policy is
set to Full Access, you have full read/write access to removable
storage.
If you choose not to encrypt removable storage and this policy is
set to Read-Only, you cannot read or delete existing files on the
unencrypted removable storage, but the client will not allow any
files to be edited on, or added to, the removable storage unless it
is encrypted.
EMS
Encryption
Algorithm
AES256 AES 256, Rijndael 256, AES 128, Rijndael 128, 3DES
Comentarios a estos manuales