McAfee Endpoint Encryption
(formerly SafeBoot Device Encryption)

As part of Kent State's continued efforts to secure sensitive data, Information Services has procured data encryption software for use on all university-owned, Windows-based laptop and desktop computers. The new software is called McAfee Endpoint Encryption, and it provides full-disk encryption that protects data stored on your computer regardless of which directory it is saved to on your hard drive. McAfee Endpoint Encryption will protect the data in the event that your computer is stolen; however, it does not protect data sent via e-mail or saved to external media, such as CDROMs or USB drives.

McAfee Endpoint Encryption is not a substitute for following safe computing practices:

Remember

  • Do
    • Continue to lock or logout of your workstation anytime you walk away
    • Remove sensitive data that is no longer needed from your computer
    • Change your password at least twice a year
  • Don't
    • Open e-mails or attachments you weren't expecting
    • Disable anti-virus, firewall or Windows update software
    • Share your password with anyone (even the Helpdesk)


McAfee Endpoint Encryption FAQs
 

Things to avoid / that will damage the McAfee Endpoint Encryption pre-boot OS environment and system MBR.

  • Improper shutdown during the initial encryption process.
  • Repartitioning your disk drive.
  • Running 3rd party disk defragmentation utilities that ignore the “unmovable” file flag.
 
Q1. What happens if I forget my password?
A1. Call the Helpdesk to have a one-time recovery code generated.
Note: You will need to have access to the computer in question.
 
Q2. I changed my password using FlashWord and now I can’t login to McAfee Endpoint Encryption?
A2. Try to login to McAfee Endpoint Encryption using your previous password; if this does not work, call the Helpdesk to have a one-time recovery code generated. (See Q1).
 
Q3. Will McAfee Endpoint Encryption replace Cryptainer?
A3. McAfee Endpoint Encryption's whole disk encryption will eliminate the need for Cryptainer.
 
Q4. Who is eligible for McAfee Endpoint Encryption?
A4. Full-time / part-time faculty / staff and student employee’s using University purchased PCs that are running Windows XP or Vista
 
Q5. I have an Apple computer; can I use McAfee Endpoint Encryption on my Mac?
A5. FileVault is the recommended solution for encrypting files on computers running OS X (10.4 and 10.5)
 
Q6. How is licensing handled for McAfee Endpoint Encryption?
A6. We currently have a license to handle 10250 users and 2050 machines; each install of McAfee Endpoint Encryption automatically deducts one machine from our license when it checks into the server for the first time. The user count is also automatically deducted when we import users from active directory.
 
Q7. Is Altiris being bundled with McAfee Endpoint Encryption?
A7. Yes, the installer does include Altiris; however you can uncheck it during the installation to only install McAfee Endpoint Encryption.
 
Q8. Can you give us an idea of what the user sees, and/or is forced to do in their day-to-day work?
A8. McAfee Endpoint Encryption will install a pre-boot (pre-Windows) login, required to unlock the hard drive. The user will be prompted to login to the pre-boot screen anytime he/she reboots his/her PC (the login information is simply the user’s FlashWord userID and password).
 
Q9. Does McAfee Endpoint Encryption encrypt network drives?
A9. McAfee Endpoint Encryption will only encrypt internal hard drives per the system it is installed on.
 
Q10. Does McAfee Endpoint Encryption have any effect on existing Windows applications?
A10. McAfee Endpoint Encryption is transparent to the Windows operating system. The only component that runs in Windows is the driver and agent, which is used to synchronize new users, passwords, encryption policies and audit information.
 
Q11. Is it possible to re-image a PC that has McAfee Endpoint Encryption on it?
A11. Formatting or re-imaging a system with a fresh ghost image will effectively remove any trace of McAfee Endpoint Encryption and the encrypted data that was on the drive.
 
Q12. I just installed SafeBoot 4.2 and can't force a manual synchronization using the agent?
A12. SafeBoot 4.2 is not able to synchronize new users or password changes during the initial encryption process.

If you need immediate assistance with a McAfee Endpoint Encryption related issues, please call the University Helpdesk

 

This page is maintained by:
End User Support Services
and Security and Compliance

 
 

This page was last modified on June 25, 2008