Issue
- After entering the correct FDE credentials, Windows fails to boot and you cannot log in to Windows
Solution
- Prerequisites
- Create the FDE Recovery Data File
- Create the ESET Encryption Recovery Media Creator
- Decrypt the Workstation
- Update the ESET Endpoint Encryption Server
I. Prerequisites
- Before decrypting, ensure you are following the appropriate instructions for your system. Visit the Full Disk Encryption Recovery Overview article.
- Ensure a full sector-by-sector backup of the existing hard drive has been created before attempting recovery.
- An Administrator can decrypt a Managed Workstation using the FDE Admin password instead of generating the FDE Recovery Data File (DLPRecovery_*.dat) file.
II. Create the FDE Recovery Data File
-
Select the Workstation you need to decrypt from the EEE Server Workstation list and click Details.
-
Click Tools → FDE Recovery → Recovery File.
-
Create a password and click Download. This password will be required to start the decryption process later.
-
Your browser will prompt you to download the generated file. Select a location to save the file.
III. Create the ESET Encryption Recovery Media Creator
-
Insert an empty USB drive into your computer.
-
Run the utility and click Next to continue.
-
Click Win RE USB 64 bit. For a TPM encrypted system, click EFI USB 32 & 64 bit, as WIN RE ISO 64 bit is not compatible with TPM systems.
-
Select the Destination disk for the recovery media and click Next.
-
Click EEES Managed.
-
Click Browse.
-
Locate the FDE Recovery Data File (DLPRecovery_*.dat) file and click Open.
-
Click Next. If instructed by ESET Support, select additional support files.
-
Click Start.
-
Click Yes.
-
Allow the utility to complete the creation process.
-
Click Finish.
-
Safely eject the USB drive.
IV. Decrypt the Workstation
-
Insert the ESET Encryption Recovery USB drive and boot the Workstation from the USB.
-
Select Decrypt all encrypted disks (managed recovery file).
-
Click Yes.
-
Type the password created in Section II and press Enter.
-
Choose Secure or Performance mode to initiate the decryption process.
-
After the computer has been successfully decrypted, click Ok.
-
Click Shutdown.
V. Update the ESET Endpoint Encryption Server
Decrypting a Managed Workstation outside of Windows will result in an encryption discrepancy. The EEE Server sees the Workstation as encrypted. However, the Workstation has already been decrypted using the ESET Encryption Recovery utility. To resolve this discrepancy, follow the instructions below:
-
After the issue with the Windows installation has been resolved, update the server status of the machine so that a new encryption command can be sent.
-
After re-synchronizing the EEE Server, click Resolve Encryption Discrepancy.
-
Click Yes.