Omitir para ir al contenido principal
  • Hacer pedidos rápida y fácilmente
  • Ver pedidos y realizar seguimiento al estado del envío
  • Cree y acceda a una lista de sus productos
  • Administre sus sitios, productos y contactos de nivel de producto de Dell EMC con Administración de la empresa.

Users with Dell Encryption Enterprise Shield may lose access to files after password change

Resumen: This article provides information regarding users with Dell Encryption Enterprise Shield (formerly Dell Data Protection | Enterprise Edition Shield may lose access to files after password updates with Web based password change tools. ...

Es posible que este artículo se traduzca automáticamente. Si tiene comentarios sobre su calidad, háganoslo saber mediante el formulario en la parte inferior de esta página.

Contenido del artículo


Síntomas

Affected Products:

  • Dell Encryption Enterprise Shield
  • Dell Data Protection | Enterprise Edition Shield

How to Determine the Cause:

When accessing log files in \ProgramData\Dell\Dell Data Protection\Encryption, you may find the following error:

[06.30.15 09:28:45:426 ExternalAuth: 463 E] [SUPPORT] Authentication - Could not unprotect data [MS error = 0x8009000b]

This error is stating that the User’s password that is used to seal encryption keys and policy information about the local computer did not properly sync with active directory.

Third-party password management software is a common cause that can update active directory passwords outside of the local computer.

When this password update happens outside of the operating system, Dell Encryption Enterprise Shield may not be able to properly sync the password once it is changed.

Causa

Not Applicable

Resolución

With version v8.5.2 and later, Dell Encryption Enterprise Shield clients have introduced a registry key that allows for detection of this issue and automatic remediation without a reboot.

To Enable Automatic Reactivation, set this key to:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\CMGShield]

When this triggers, a line in the logs of the client is generated:

Event Engine - Flagging user XXXXXXX@domain.org for automatic reactivation

A new registry key to record how many times this has run is generated as well.

Administrators can monitor how many reactivations have happened per computer with this new key.

This is automatically generated by the shield when a reactivation happens:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\CMGShield]
"AutoReactivationCount"=dword:00000000sts

WSDeactivate is leveraged to fix this situation. Follow the link below for instructions:

How to run WSDeactivate on Dell Data Protection | Enterprise Shield for Windows


To contact support, reference Dell Data Security International Support Phone Numbers.
Go to TechDirect to generate a technical support request online.
For additional insights and resources, join the Dell Security Community Forum.

Propiedades del artículo


Producto comprometido

Dell Encryption

Fecha de la última publicación

05 jul 2023

Versión

8

Tipo de artículo

Solution