跳至主要內容
  • 簡單快速地下訂單
  • 檢視訂單及追蹤商品運送狀態
  • 建立並存取您的產品清單
  • 使用「公司管理」來管理您的 Dell EMC 網站、產品和產品層級連絡人。

Users with Dell Encryption Enterprise Shield may lose access to files after password change

摘要: This article provides information regarding users with Dell Encryption Enterprise Shield (formerly Dell Data Protection | Enterprise Edition Shield may lose access to files after password updates with Web based password change tools. ...

本文可能採用自動翻譯。如果您對翻譯品質有任何寶貴意見,請使用此頁面底部的表單告訴我們,謝謝。

文章內容


症狀

Affected Products:

  • Dell Encryption Enterprise Shield
  • Dell Data Protection | Enterprise Edition Shield

How to Determine the Cause:

When accessing log files in \ProgramData\Dell\Dell Data Protection\Encryption, you may find the following error:

[06.30.15 09:28:45:426 ExternalAuth: 463 E] [SUPPORT] Authentication - Could not unprotect data [MS error = 0x8009000b]

This error is stating that the User’s password that is used to seal encryption keys and policy information about the local computer did not properly sync with active directory.

Third-party password management software is a common cause that can update active directory passwords outside of the local computer.

When this password update happens outside of the operating system, Dell Encryption Enterprise Shield may not be able to properly sync the password once it is changed.

原因

Not Applicable

解析度

With version v8.5.2 and later, Dell Encryption Enterprise Shield clients have introduced a registry key that allows for detection of this issue and automatic remediation without a reboot.

To Enable Automatic Reactivation, set this key to:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\CMGShield]

When this triggers, a line in the logs of the client is generated:

Event Engine - Flagging user XXXXXXX@domain.org for automatic reactivation

A new registry key to record how many times this has run is generated as well.

Administrators can monitor how many reactivations have happened per computer with this new key.

This is automatically generated by the shield when a reactivation happens:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\CMGShield]
"AutoReactivationCount"=dword:00000000sts

WSDeactivate is leveraged to fix this situation. Follow the link below for instructions:

How to run WSDeactivate on Dell Data Protection | Enterprise Shield for Windows


To contact support, reference Dell Data Security International Support Phone Numbers.
Go to TechDirect to generate a technical support request online.
For additional insights and resources, join the Dell Security Community Forum.

文章屬性


受影響的產品

Dell Encryption

上次發佈日期

05 7月 2023

版本

8

文章類型

Solution