[KB7160] Decrypt a Managed system that is unable to start Windows in ESET Endpoint Encryption

Issue

ESET Endpoint Encryption (EEE) Client and EEE Server are separate products from ESET Full Disk Encryption (EFDE)

The article below applies only to the EEE Client or EEE Server and not EFDE.

Visit What's new in ESET Full Disk Encryption to view EFDE content.

  • After entering the correct FDE credentials, Windows fails to boot and you cannot log in to Windows

Solution

  1. Prerequisites
  2. Create the FDE Recovery Data File
  3. Create the ESET Encryption Recovery Media Creator
  4. Decrypt the Workstation
  5. Update the ESET Endpoint Encryption Server

I. Prerequisites

  • Before decrypting, ensure you are following the appropriate instructions for your system. Visit the Full Disk Encryption Recovery Overview article.
  • Ensure a full sector-by-sector backup of the existing hard drive has been created before attempting recovery.
  • An Administrator can decrypt a Managed Workstation using the FDE Admin password instead of generating the FDE Recovery Data File (DLPRecovery_*.dat) file.

II. Create the FDE Recovery Data File

  1. Select the Workstation you need to decrypt from the EEE Server Workstation list and click Details.

    Figure 1-1
  2. Click ToolsFDE Recovery → Recovery File.

    Figure 1-2
  3. Create a password and click Download. This password will be required to start the decryption process later.

    Figure 1-3
  4. Your browser will prompt you to download the generated file. Select a location to save the file.


III. Create the ESET Encryption Recovery Media Creator

  1. Insert an empty USB drive into your computer.

    USB Media

    Ensure that the USB device has a FAT32 formatted partition. The partition is required to set up the ESET Recovery Media Creator.

  2. Download the ESET Encryption Recovery Utility.

  3. Run the utility and click Next to continue.

    Figure 2-1
  4. Click Win RE USB 64 bit. For a TPM encrypted system, click EFI USB 32 & 64 bit, as WIN RE ISO 64 bit is not compatible with TPM systems.

    Architecture of host system

    When creating a Win RE USB, the architecture (x86/x64) of the host system running the utility must match the target system needing recovery.

    Figure 2-2
  5. Select the Destination disk for the recovery media and click Next.

    Figure 2-3
  6. Click EEES Managed.

    Figure 2-4
  7. Click Browse.

    Figure 2-5
  8. Locate the FDE Recovery Data File (DLPRecovery_*.dat) file and click Open.

    Figure 2-6
  9. Click Next. If instructed by ESET Support, select additional support files.

    Figure 2-7
  10. Click Start.

    Figure 2-8
  11. Click Yes.

    Figure 2-9
  12. Allow the utility to complete the creation process.

    Figure 2-10
  13. Click Finish.

    Figure 2-11
  14. Safely eject the USB drive.


IV. Decrypt the Workstation

  1. Insert the ESET Encryption Recovery USB drive and boot the Workstation from the USB.

  2. Select Decrypt all encrypted disks (managed recovery file).

    Figure 3-1
  3. Click Yes.

    Figure 3-2
  4. Type the password created in Section II and press Enter.

    Figure 3-3
  5. Choose Secure or Performance mode to initiate the decryption process.

    Do not shut down

    Ensure that you let the process complete and do not shut down or power the machine off.

    Figure 3-4
  6. After the computer has been successfully decrypted, click Ok.

    Figure 3-5
  7. Click Shutdown.

    Figure 3-6

V. Update the ESET Endpoint Encryption Server

Decrypting a Managed Workstation outside of Windows will result in an encryption discrepancy. The EEE Server sees the Workstation as encrypted. However, the Workstation has already been decrypted using the ESET Encryption Recovery utility. To resolve this discrepancy, follow the instructions below:

  1. After the issue with the Windows installation has been resolved, update the server status of the machine so that a new encryption command can be sent.

  2. After re-synchronizing the EEE Server, click Resolve Encryption Discrepancy.

    Figure 4-1
  3. Click Yes.

    Review dialog

    Review the dialog before clicking Yes, No or Cancel. Clicking No will erase the EEE Server's record of all the encryption data for this Workstation. Do not click No if the Workstation is still encrypted. 

    Figure 4-2