[KB7928] Single Sign-On (SSO) synchronization in ESET Endpoint Encryption

Issue

ESET Endpoint Encryption (EEE) Client and EEE Server are separate products from ESET Full Disk Encryption (EFDE)

The article below applies only to the EEE Client or EEE Server and not EFDE.

Visit What's new in ESET Full Disk Encryption to view EFDE content.

  • Single Sign-On (SSO) synchronization for ESET Endpoint Encryption is out-of-sync

Details

SSO is a managed version of ESET Endpoint Encryption (EEE) feature.

EEE will automatically synchronize the User's Windows password with their EEE Full Disk Encryption (FDE) pre-boot password when:

  • user changes their Windows password locally from their machine (using CTRL+ALT+DEL → Change Password)
  • user signs into their Windows profile on their machine

The password can become out-of-sync when a user:

  • has changed their Windows password on another workstation
  • has their Windows password changed for them on a server (for example, using Active Directory on the Domain server)
  • has attempted to change their Windows password but the machine was booted using a different User's pre-boot credentials

Solution

The user must re-sync all of their machines individually, as SSO is controlled locally.

  1. Go to the FDE pre-boot screen.

  2. Type the old password and then the new password at the Windows screen (sync will be performed when you log in to Windows).
    If the old password does not work, you can reset the Full Disk Encryption password using Lost Details or Reset Password

Known SSO issue with ESET Endpoint Encryption 4.9.4

Following Windows Feature update installation, you may find that SSO does not re-sync automatically after changing your Windows password. If you have been affected by this problem, then upgrade to ESET Endpoint Encryption version 5.0.0 or later, follow the password recovery steps above, and log in to Windows manually to allow SSO to re-sync automatically.