Endpoint Showing as not Protected in Dell Security Management Console or Remote Management Console when the Shield Shows as In-Compliance
概要: Endpoints show as not protected in Dell Security Management Console or RMC even though the shield console on the endpoint shows as in-compliance. A full sweep has been completed, and the inventory check has finished. ...
この記事は次に適用されます:
この記事は次には適用されません:
この記事は、特定の製品に関連付けられていません。
すべての製品パージョンがこの記事に記載されているわけではありません。
現象
Affected Products:
- Dell Data Protection | Encryption
原因
This may occur when a Self-Encrypting Drive (SED) is installed.
解決方法
- To check for a SED or FVE on the drive, open the
CMGShield.logfile that is locatedC:\ProgramData\Dell\Dell Data Protection\Encryption. - Search for the term CanApplySDE.
Line 4275: [10.29.15 11:21:57:535 IShieldMode: 335 I] CanApplySDE? - No (SED present = 1, FVE Provisioned = 0, FVE Decrypting = 0, Always Apply= 0, FVE Disks=0)
- If
SED present =1, then the drive that is installed on the computer is recognized as a Self-Encrypting drive and ifFVE Provisioned = 1then the drive is Full Volume Encrypted.
Note: While using both FVE and SED is supported, it is recommended to only use one or the other to avoid performance issues.
Warning: The next step is a Windows Registry edit:
- Back up the Registry before proceeding, reference How to Back Up and Restore the Registry in Windows
.
- Editing the Registry can cause the computer to become unresponsive on the next reboot.
- Contact Dell Data Security International Support Phone Numbers for assistance if you have concerns about performing this step.
- To force System Data Encryption (SDE) on a SED, use the
AlwaysApplySDEregistry key:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\CMGShield] "AlwaysApplySDE"=dword:00000001
Note:
AlwaysApplySDE defaults to 1 in Dell Data Protection Encryption Shield versions between v8.9.3 and v8.11. Starting in version v8.12 there is support for a server policy (introduced server side in v9.5) which controls this. The policy defaults to false server-side, but the client defaults to true if the policy is not received from the server meaning that a v8.12 client with a v9.4.1 server behaves the same as a v8.11 client.
- Once you have updated the registry or policy (or if the computer does not have a SED or FVE), force an inventory and policy update on the computer. This can be done by adding the
RefreshInventoryregistry key:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\CMGShield DWORD:RefreshInventory: Value:1
And then checking for new policies (for more information, reference How to Check for Policy Updates for Dell Data Security.)
- If the above steps do not resolve the issue, contact Dell Data Security International Support Phone Numbers.
対象製品
Dell Encryption文書のプロパティ
文書番号: 000129608
文書の種類: Solution
最終更新: 09 7月 2026
バージョン: 9
質問に対する他のDellユーザーからの回答を見つける
サポート サービス
お使いのデバイスがサポート サービスの対象かどうかを確認してください。