[KB7192] Enable or disable Full Disk Encryption Pre-Boot Authentication in ESET Endpoint Encryption Client

Issue

ESET Endpoint Encryption (EEE) Client and EEE Server are separate products from ESET Full Disk Encryption (EFDE)

The article below applies only to the EEE Client or EEE Server and not EFDE.

Visit What's new in ESET Full Disk Encryption to view EFDE content.

Details


Click here to expand

Disable Pre-Boot Authentication also known as Maintenance Mode is a feature that enables a Full Disk Encrypted (FDE) Workstation to restart without requiring the user to authenticate in the pre-boot environment. This may be used by system administrators who are working remotely and want to restart Windows but there is no one physically present to type credentials at the pre-boot screen.

  • This feature can be useful when performing software updates or configuration changes that require Windows to restart.
  • This feature is optional and disabled by default. After the configured period or number of restarts without authentication has been reached, authentication is required again.

Solution

Do not leave workstations in Maintenance Mode

While Maintenance Mode is enabled on a workstation, the system will boot with no authentication and therefore is not secure from threats.

Prerequisites

  • ESET Endpoint Encryption v4.9.2 or later
  • A Workstation is Encrypted and using EFI Boot Mode

Use ESET Endpoint Encryption Server to disable Pre-Boot Authentication

  1. Log in to the ESET Endpoint Encryption (EEE) Server.

  2. Click Workstations, select the applicable Workstation and click Details.

  3. Click Pre-Boot Authentication.

  4. Select Disable.
Figure 1-1
 
  1. Select one of the available options and type a value. Click Disable.
Figure 1-2
 
  1. Type your EEE Server login password and click OK.
Figure 1-3
 
  1. In the Workstation Details tab, a Workstation Status will display.
Figure 1-4
  1. This will remain enabled on the Workstation until the condition set has been met.
 

Use ESET Endpoint Encryption Server to enable Pre-Boot Authentication

  1. Log in to the ESET Endpoint Encryption (EEE) Server.

  2. Click Workstations, select the applicable Workstation and click Details.

  3. Click Pre-Boot Authentication.

  4. Select Enable.
Figure 1-5
 
  1. Click Enable.
Figure 1-6
 
 

Use ESET Endpoint Encryption command line tool to enable or disable Pre-Boot Authentication

  1. Use Maintenance mode to enable or disable Pre-Boot Authentication