McAfee Endpoint Encryption 7.0 Users Guide and FAQ

Similar documents
McAfee Endpoint Encryption (SafeBoot) User Documentation

ScoMIS Encryption Service

Symantec PGP Whole Disk Encryption Hands-On Lab V 3.7

DPMS2 McAfee Endpoint Encryption New Installation

McAfee Endpoint Encryption Reporting Tool

2. To encrypt the drive for future use, click Yes (Fig 1, 2). This will start the encryption process.

SecureDoc for Mac v6.1. User Manual

MBC WiFi wireless logon: Windows 7 (laptop)

Using Websense Data Endpoint Client Software

ScoMIS Encryption Service

Single Sign-On Portal User Reference (Okta Cloud SSO)

Joining an XP workstation to a domain Version 1.00

E-Pollbook Flash Drive Guide for BitLocker

Only smart people read the manual.

University of Rochester Sophos SafeGuard Encryption for Windows Support Guide

USERS GUIDE. How to acquire an Associate Digital Identity Certificates from the ica Identity Authority and Configure MAS

MICROSOFT BITLOCKER ADMINISTRATION AND MONITORING (MBAM)

Intel Anti-Theft Service

To begin, visit this URL:

BounceBack User Guide

Symantec Endpoint Encryption Full Disk

PaymentNet Federal Card Solutions Cardholder FAQs

Table of Contents. Changing Your Password in Windows NT p. 1. Changing Your Password in Alpha Connection.. pp. 1-3

ASUS WebStorage Client-based for Windows [Advanced] User Manual

Connecting To SOM Network Drives With Windows XP

Utimaco SafeGuard Easy Installation Instructions for Notre Dame installer v2.5

Frequently Asked Questions: Cisco Jabber 9.x for Android

Windows and MAC User Handbook Remote and Secure Connection Version /19/2013. User Handbook

Shutting down / Rebooting Small Business Server 2003 Version 1.00

Installing Your Multifunction to Your Network for the First Time

How do I Configure my bmail Account on Outlook 2013 Using the Google Apps Sync Tool?

Hosting Users Guide 2011

Installation Guides - Information required for connection to the Goldfields Institute s (GIT) Wireless Network

All Colleagues Landing Page

Automatic Setup... 1 Manual Setup... 2 Installing the Wireless Certificates... 18

GoldKey Software. User s Manual. Revision WideBand Corporation Copyright WideBand Corporation. All Rights Reserved.

User s Manual. Transcend JetFlash SecureDrive. Contents

Remote Broadband Access (RBA3) Hertfordshire County Council. vworkspace Client Install

Last updated: October 4, einvoice. Attorney Manual

ZENworks 11 Support Pack 4 Full Disk Encryption Agent Reference. May 2016

User Manual. User Manual for Version

Windows XP Pro: Basics 1

Deposit Direct. Getting Started Guide

SafeGuard Enterprise Web Helpdesk. Product version: 6 Document date: February 2012

User Guide. Copyright 2003 Networks Associates Technology, Inc. All Rights Reserved.

Windows Wireless Network Connection Instructions

PGP Desktop Encrypting Removable Media. May Version 1.3

User guide. Business

EMMA Application v. 4.9 User Manual

Allscripts Mobile Installation Guide for BlackBerry

MFC7840W Windows Network Connection Repair Instructions

Use the below instructions to configure your wireless settings to connect to the secure wireless network using Microsoft Windows Vista/7.

educ Office Remove & create new Outlook profile

How to Connect to YaleSecure (Yale s secure wireless network)

Sophos SafeGuard Native Device Encryption for Mac Administrator help. Product version: 7

Red Hat Linux 7.2 Installation Guide

Sendspace Wizard Desktop Tool Step-By-Step Guide

Symantec Endpoint Encryption Removable Storage

Exchange Outlook Profile/POP/IMAP/SMTP Setup Guide

Sophos SafeGuard Native Device Encryption for Mac quick startup guide. Product version: 7

Introduction. Activating the CFR Module License. CFR Configuration

All Tech Notes and KBCD documents and software are provided "as is" without warranty of any kind. See the Terms of Use for more information.

SafeGuard Enterprise Web Helpdesk

Last modified: November 22, 2013 This manual was updated for the TeamDrive Android client version

Configuring WPA2 for Windows XP

How to Access Coast Wi-Fi

account multiple solutions

Passport installation Windows 8 + Firefox

Configuring Windows 7 to Use Encrypted (WPA-E) Wireless Services a...

Citrix Single Sign-On Self-Service Password Reset

Wireless Network Configuration Guide

In order to enable BitLocker, your hard drive must be partitioned in a particular manner.

Passport Installation. Windows XP + Internet Explorer 8

Using Mac OS X 10.7 Filevault with Centrify DirectControl

WARNING!!: Before installing Truecrypt encryption software on your

System update procedure for Kurio 7 (For build number above 110)

[COGNOS DATA TRAINING FAQS] This is a list of frequently asked questions for a Cognos user

Authorware Install Directions for IE in Windows Vista, Windows 7, and Windows 8

SafeGuard Enterprise Web Helpdesk. Product version: 6.1

McAfee Endpoint Encryption for Files and Folders (EEFF) User Documentation

Download and Install the Citrix Receiver for Mac/Linux

AT&T Global Network Client v6.8.0 and Passport IP Setup Instructions for Broadband VPN Access

Password Manager Windows Desktop Client

VMware Horizon FLEX User Guide

Team Foundation Server 2013 Installation Guide

Encrypt USB Drive to Protect Data

Comodo Disk Encryption

McAfee Endpoint Encryption for PC 7.0

Frequently Asked Questions for logging in to Online Banking

New Online Banking Guide for FIRST time Login

File Management and File Storage

LevelOne MUS GB Smart Flash. User Manual V

Security Service tools user IDs and passwords

4. Click Next and then fill in your Name and address. Click Next again.

CONNECTING TO THE DTS WIRELESS NETWORK USING WINDOWS VISTA

Kepware OPC Server Installation & Activation

Connecting to eduroam using Windows 8

Transcription:

McAfee Endpoint Encryption 7.0 Users Guide and FAQ Table of Contents Introduction... 1 Installation... 1 Boot-Up/Login... 1 Encryption Status... 3 Notes for Encryption... 4 Changing Your Password... 4 Forgotton Password\Recover... 4 Frequently Asked Questions (FAQs)... 7 Introduction Welcome to McAfee Endpoint Encryption. The goal of this project is to protect sensitive data that is stored on the Government of Saskatchewan s laptops. McAfee Endpoint Encryption has been chosen as our encryption tool, which will encrypt all of the data on the internal hard drive of your machine while having minimal disruption to your everyday work. Installation If you are getting a brand new laptop McAfee Endpoint Encryption will come installed. If you are getting this Pushed to you, make sure to follow the instructions in the email. Boot-Up/Login After your first reboot (probably the day after you get your new machine or the day after it is Pushed to your existing machine) you will be greeted with this screen.

Enter your username (the same one as your windows username) and select next. If this is the first time you are logging in you will see this screen. Enter and confirm your password (the same password as Windows) and select OK. If this isn t the first time you will see this screen which will have your username already there and you just enter your password to login. The McAfee Endpoint Encryption product will synchronize your pre-boot password to your Windows password. This is called single sign on (SSO). This means that you will only be required to remember one password and will be required to enter it only once upon boot up. The single sign on may take up to 2 reboots to first synchronize. 2

Encryption Status After the installation of Endpoint Encryption, you can monitor the status of the encryption process by rightclicking on the McAfee icon in the System Tray and choosing Quick Settings then Show Endpoint Encryption Status. Under the Volume Status box, the status will change from C X.X% Encrypted (Encrypting) to Encrypted when the encryption is complete. a. At that time, all data on your laptop/workstation will be fully encrypted. b. Any new files copied or saved to your C:\ drive will be encrypted as well. 3

Notes for Encryption McAfee Endpoint Encryption 7.0 User Guide and FAQ You can work on your machine while the initial encryption is executing it will continue to run seamlessly in the background. You can also safely shut down your machine while the initial encryption is running, although it is recommended that you leave your machine running if possible until the encryption completes. Your entire hard disk will be encrypted. Any file that is moved from your machine to a network share, email, or another machine will NOT be encrypted. This encryption product will only protect your local machine. Be aware of the encryption implications when transferring files to another medium. When traveling with your laptop, do not place the machine in standby mode. You should shut down completely. This will require you to re-authenticate to the McAfee Endpoint Encryption product when you restart it. Putting your machine in standby mode will not require you to re-authenticate with Endpoint Encryption, and can put your data at risk. Be extra diligent in remembering your password. The process that makes it difficult for an unauthorized person to decrypt your hard drive also makes it (somewhat) cumbersome to recover your password. The best method for protecting data is to not put it on your machine in the first place. Only data that has an immediate business need, especially that of a confidential/sensitive nature should be stored on your machine. It is best that you do not keep any confidential/sensitive data on your machine if at all possible. Defense in depth is the best way to protect your data, and that starts with not keeping unneeded data on your laptop in the first place. Where practical, the first choice for any data storage should be on a network drive (either G: or H: drives). Changing Your Password You can change your Windows password the same way you always have. The McAfee Endpoint Encryption product will synchronize your pre-boot password to your Windows password. This usually happens very fast but even if it doesn t your machine will automatically sync with the server every 2 hours without user intervention (provided that it is on and connected to the GOS network) and get updated automatically with this password change. Note that if your passwords do become out of synch, you can manually change your Endpoint Encryption password to your Windows password. See the FAQ here on how to do this. Forgotten Password\Recovery The same process that makes it difficult for an outsider to decrypt your machine also makes it somewhat difficult to recover your password if you forget it. Therefore, it is highly recommended that you make a concerted effort to remember your password. If you have forgotten your password, you can use the following method to unlock your machine. Note that this method also applies if your ID has become disabled due to too many password-guessing attempts. 4

1. If you have attempted to log on unsuccessfully 10 times, your ID will be disabled. You will see the following dialog box if your ID is disabled: Please note this when calling the Service Desk. 2. At boot up, click the Options link on the bottom left of the screen, and then choose Recovery. 3. The recovery screen will now be displayed. Select the "Administrator Recovery radio button and select OK. 5

4. You will now want to call the Service Desk (787-5000) for assistance and inform them that you need your McAfee Endpoint Encryption password reset. If your ID has become disabled (see Step 1), make sure that you convey this to the Service Desk. 5. Give the Service Desk technician the 18-character Client code (challenge) that should now be displayed on the screen. 6. You will then want to click Next. The Service Desk will provide you with a 20-character code (response) that you should now enter into Line 1 on the Recovery screen (then hit Enter ) and either a 6-character code or a 14-character code (depending on what kind of recovery is being done) which you enter into Line 2 (then hit Enter ) and then select Finish. 6

7. If you enter the numbers incorrectly, you will get the following dialog box: If you get this screen, click the OK button to go back to Step 6 and re-enter the characters. 8. If you successfully enter the characters, you will either be prompted for a new password twice (the password provided by the Service Desk) or your machine will go right into Windows (depending on what kind of recovery is being done). 9. Use the same password to log into Windows and you will immediately be prompted to make a new password. Your new password will be automatically synced with McAfee Endpoint and you will be able to use it the next time you reboot. Frequently Asked Questions (FAQs) Q: Do I have to remember a separate password for Endpoint Encryption? A: No. Your Endpoint Encryption and Windows passwords will sync whenever you change your Windows password. You will be required to provide this password when your machine boots. Q: Since my passwords are synced, do I have to enter the password a second time in order to log into Windows? A: By default, no. Your machine is set up to utilize a functionality called single sign on (SSO), which will automatically provide your credentials to Windows and log you in (after you provide them at pre-boot). Q: How do I log on as a different Windows user than my Endpoint Encryption user? A: You must first log off of Windows. You can then log back on as a different user through the Windows logon screen. 7

Q. My passwords are not synced, but I know both my Endpoint Encryption and Windows password. A. There are some instances where your passwords will not sync properly between Endpoint Encryption and Windows. If you currently can log onto Endpoint Encryption, you can manually set this password to your Windows password by following the instructions below: 1. Enter your Endpoint Encryption credentials at pre-boot. Do not hit OK. 2. Check the box Change password and then press OK. 3. You will be prompted to enter a new password. Enter your Windows password (twice) and select OK. 4. Your Endpoint Encryption password should now be changed and synched with your Windows password. Q: My password does not work on the pre-boot screen. What should I do? A: If you have recently changed your Windows password, try entering your previous password. There are some instances where your Endpoint Encryption password could potentially become out of sync with your Windows password. If entering your old password works it will sync after you login to the network. Q: My pre-boot password still does not work. Now what? A: Call the Service Desk and follow the Forgotten Password instructions. Q: Are files that I save on network shares encrypted as well? A: No, only files on your local machine s hard drive are encrypted. Q: Are files that I store on my thumb drive/external hard drive encrypted? A: No, only files on your local machine s hard drive are encrypted. Q: If I send a file to a colleague in email, is it encrypted? A: No, only files on your local machine s hard drive are encrypted. Q: Can I work on my machine while it is performing the initial encryption? A: Yes. You may notice a slight decrease in performance while this process is executing, but this decreased performance will cease when the encryption has completed (usually 4-5 hours). Q: Can I shut my machine down while it is encrypting? A: Yes, but it is not recommended that you do so. If possible, you should wait for the encryption process to complete before shutting your machine down. If you have to shut it down, it will resume where it left off on the next start-up. Q: How do I know when my machine has finished encrypting my hard drive? A: You can display the status of the hard drive encryption by looking at the Encryption Status. Q: How do I know if my machine is still encrypted? A: You can display the status of the hard drive encryption by looking at the Encryption Status. Q: Is my machine protected if I put it into Standby mode? A: Not completely. Since your machine will not require you to re-authenticate to Endpoint Encryption when bringing it out of Standby, it is recommended that you turn off your machine when travelling with it or when leaving for the day. 8

Q: Now that I have encryption on my machine, do I still have to be wary of the files that I store on it? A: Yes. Encryption is only one piece of the security puzzle. It is best to have only data on your machine that has an immediate business need. It is recommended that any critical data be stored on a network drive/share. This will also address the need to back up this data. (Think of if your machine is lost or stolen if your data is on a network share, you will still have access to it.) Q: Why does the password recovery process seem so painful? A: The same process that allows you to recover your password may also allow someone with nefarious intent to do so as well. We do not want to make it too easy for this to happen. Q: How come my keyboard/mouse doesn t work correctly in the pre-boot environment? A: Certain keyboards and mice (especially the wireless versions) do not always work correctly in the preboot environment. Try rebooting your machine to see if it clears up any issues. If not, you will need to use a standard USB keyboard and/or mouse. Note that you can navigate in the pre-boot environment with just your keyboard (utilizing the TAB and ENTER keys), so you should not have to necessarily change out your mouse if it is not working. Q: What type of encryption is used? A: The entire contents of the hard drive are encrypted using the government standard AES-256 encryption algorithm. See description here. Document Version: 1.0 Doc Created by: Aaron Bassani Date: May 22, 2013 Doc Revised by: Date: 9