
Enterprise Edition Administrator Guide 39
Commonly Used Scenarios
• To install each client individually, the child executable files must first be extracted from the master installer, as shown in
Extract the Child Installers from
the Master Installer.
• The default location of log files is: C:\ProgramData\Dell\Dell Data Protection.
• If your computer has DDP|A installed now or has had it in
stalled in the past, be sure to follow the steps in
Interoperability before you continue.
• The computer restart has been suppressed in these examples but is
eventually required for completion of the installation
process.
• You will be securing access to this computer using advanced authentication
credentials that are managed and enrolled
using Dell Data Protection | Security Tools. DDP|ST is now the primary manager of your authentication credentials for
Windows Sign-in, including Windows password, fingerprints, and smart cards. Picture password, PIN, and fingerprint
credentials enrolled using the Microsoft Operating System will not be recognized at Windows Sign-in.
To continue using the Microsoft Operating System to manage your credentials, uninstall DDP|ST.
• If the computer targeted for encryption is
equipped with a Hardware Crypto Accelerator or a self-encrypting drive, ensure
that the Active Directory option,
User Must Change Password at Next Logon
, is disabled. Preboot Authentication does
not support this Active Directory option.
• Dell recommends that you do not change the authentication method after P
reboot Authentication has been activated
(SED) or HCA policy has been set to True (HCA). If you must switch to a different authentication method, you must
either:
• Remove all the users from the PBA,
and then re-enroll the users.
or
• Deactivate the PBA(SED) or set the HCA policy to False (HCA), change
the authentication method, and then
re-activate the PBA (SED) or set the HCA policy to True (HCA).
• On computers equipped with a Hardware Crypto Accelerator or a
self-encrypting drive, to use smart cards with Preboot
Authentication, the following registry value must be set on the client computer:
[HKLM\SOFTWARE\DigitalPersona\P
olicies\Default\SmartCards]
"MSSmartcardSupport"=dword:1
0 or no key = Smart Card Support Off, 1 = Smart Card Support On
Comentarios a estos manuales