How to enable SDE policies on Self-Encrypting Drives

Summary: How to Enable System Data Encryption (SDE) Encryption for Dell Encryption Enterprise or Dell Encryption Personal on computers with Self-Encrypting Drives.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

Affected Products:

  • Dell Encryption Enterprise
  • Dell Data Protection | Enterprise Edition
  • Dell Encryption Personal
  • Dell Data Protection | Personal Edition

Dell Encryption Enterprise (formerly Dell Data Protection | Enterprise Edition Shield) and Dell Encryption Personal (formerly Dell Data Protection | Personal Edition) use a type of file folder-based encryption (FFE) called SDE.

Note: SDE is prevented on a computer using a Self-Encrypting Drive (SED), to prevent encryption conflicts.

Cause

Not Applicable

Resolution

Warning: The next step is a Windows Registry edit:

Add the following registry key:

Key: HKLM\Sofwtare\Microsoft\Windows NT\CurrentVersion\Winlogon\CMgShield
Value Name: AlwaysApplySDE
Value Type: DWORD
Value: 1
Note: v8.12.0.x and later has the registry key added by default.

In the Remote Management Console, check Encrypt with SDE when SED is detected.

Encrypt with SDE when SED is detected
Figure 1: (English Only) Encrypt with SDE when SED is detected

Note: After making a change, save and then commit the policy change.

To contact support, reference Dell Data Security International Support Phone Numbers.
Go to TechDirect to generate a technical support request online.
For additional insights and resources, join the Dell Security Community Forum.

Affected Products

Dell Encryption
Article Properties
Article Number: 000125023
Article Type: Solution
Last Modified: 29 Apr 2024
Version:  10
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.