Management of Native Encryption 5.2.x Interface Reference Guide

Prev

Last Updated: September 17, 2023

FileVault product settings

The product policies provide you with the settings that are required for FileVault management, password settings, and client messaging.

Option definitions

Manage FileVault — Allows you to manage FileVault and receive reports from the client system.

  • Turn On (Enable) FileVault — When enforced, will turn on FileVault on client systems if not already enabled and then manage accordingly. The client systems also report the status to Trellix ePO - On-prem. When you turn on FileVault and enforce this policy to the required client systems, users will see a pop-up message on their client systems requesting that they restart the system. The user must restart the system to enable FileVault to encrypt the system managed by Trellix ePO - On-prem, or choose to postpone the restart until a more convenient time.

  • Destroy FileVault key in standby mode — The FileVault recovery key will be removed from memory when a system goes into a standby mode. This defends against memory related attacks during various sleep states. Resuming from the sleep mode will force a user authentication to bring the key back into memory.

  • Generate a new FileVault key in days (1-360) — Enable this option and specify how frequently the recovery key is to be rotated. This improves security by reducing the validity period of each individual recovery key.

  • Allows users to import recovery key on client — Enable this option to allow users to import the recovery key on client systems. This is useful if end users use the FileVault application to generate new recovery keys.

  • Prompt user to create a new recovery key on already enabled systems — If FileVault is already enabled by the user when MNE policy is enforced, the client system will prompt the user to authenticate using their FileVault password. Once authenticated, the recovery key of the client system can be queried from FileVault and will be escrowed to the Trellix ePO - On-prem database.

Note: If users ignore this request, then recovery of their system cannot be achieved as no recovery key can be escrowed to Trellix ePO - On-prem; FileVault will only release the current recovery key if authentication is provided.

  • Only enable FileVault if DEGO tests pass — If the user has installed the Drive Encryption GO (DEGO) - OSX 2.1.0.xxx on the Mac client system, then FileVault will be enabled only if DEGO tests pass.

Note: Make sure that you have already installed EEGO.zip (DEGO extension) before enabling this option. For more information about the DEGO extension, see the Trellix Drive Encryption Product Guide.

  • Restart timeout period in minutes (1-60) — Defines the length of the restart timeout period.

  • Turn Off (Disable) FileVault — When enforced, will turn off FileVault on client systems. Client systems status will continue to be reported in Trellix ePO - On-prem.

Note: On enabling this option, the Password Settings and Client Messaging functions get disabled.

Do not manage FileVault — When enforced, MNE will not manage FileVault.

  • Report client system status — When enforced, MNE will not manage FileVault, but will report FileVault status and security posture data to Trellix ePO - On-prem allowing you to manage FileVault with a third party management tool, yet report status within Trellix ePO - On-prem. This can be useful to report on BYOD (Bring Your Own Device) or contractor laptops to monitor compliance to company encryption policies.

If FileVault is managed by MNE, or if report-only mode is selected, the client system reports the following information to Trellix ePO - On-prem:

  • FileVault status

  • FileVault mode

  • System information

  • System encryption status

  • FIPS status

Apply password content rules — Allows you to set password settings on to OS X, which will enforce these password settings on the client system.

  • Minimum length (4-40) — The user must create a password of the specified minimum length.

  • Maximum length (4-255) — The user must create a password of the specified maximum length.

  • Require at least one alphabetic character in password — The user must include at least one alphabetic character in creating the password.

  • Require at least one numeric character in password — The user must include at least one numeric character in creating the password.

  • Require password change after days (1-180) — The user must change the password after the specified number of days.

  • Do not apply password content rules to these users (separate users with a semi-colon, for example, user1; user2) — Type the username (short name) of users to make sure the password settings do not apply to the specified users.

  • Display the following message, instead of the default, when enabling FileVault — The user receives this message when FileVault is enabled. If left empty, a default message will be provided.

  • Display the following login banner — Enable this option and provide a login banner for the user to receive this leogin banner after authenticating into FileVault.

  • Display the following message, instead of the default, when FileVault has been disabled by 3rd party tapplication or user — The user receives this message if FileVault is disabled by anything other than MNE. If left empty, a default message will be provided.

BitLocker product settings

The product policies provide you with the settings that are required for BitLocker management, operating system volume, and authentication settings.

Option definitions

Option

Definition

Show/Hide Advanced

Clicking this will show or hide advanced settings within the policy page. All policy options have suitable defaults for those that do not want to define advanced settings.

BitLocker management

  • Manage BitLocker — Allows you to manage BitLocker and receive reports from the client system.

    • Turn On (Enable) BitLocker — When enforced, will turn on BitLocker on client systems and manage accordingly. The client systems also report the status to Trellix ePO - On-prem.

Note: Make sure to note that the encryption strength can't be changed on a previously encrypted client. To change the encryption strength, BitLocker needs to be decrypted, disabled, and then re-enabled by MNE.

  • AES-128 — Configures BitLocker on client systems to use AES-128 algorithm for encryption.

  • AES-256 — Configures

    BitLocker on client systems to use AES-256 algorithm for encryption.

  • XTS-AES-128 — Configures

BitLocker on client systems to use XTS-AES-128 algorithm for encryption.

Note: This algorithm is supported on Windows 10 and above systems only.

Older systems will fall back to the AES-128 algorithm.

  • XTS-AES-256 — Configures BitLocker on client systems to use XTS-AES-256 algorithm for encryption.

Note: This algorithm is supported on Windows 10 and above systems only.

Older systems fall back to the AES-256 algorithm.

  • Rotate recovery keys after a specified number of days

(1-360) — Enable this option and specify how frequently the recovery key is to be rotated. This improves security by reducing the validity period of

each individual recovery key.

  • Remove recovery keys not added by Trellix Management of Native Encryption — Enable this option to remove any pre-existing keys for better security when MNE takes over management. This is useful for BYOD (Bring your Own Device) systems to make sure that any pre-existing non-MNE recovery keys are removed.

Option

Definition

  • Turn Off (Disable) BitLocker — When enforced, turns off BitLocker and decrypt client systems. However, the client systems report the status to Trellix ePO - On-prem.

  • Do not manage BitLocker — When enforced,

    MNE will not manage BitLocker.

  • Report client system status — When enforced, MNE will not manage BitLocker, but will report BitLocker status and security posture data to Trellix ePO - On-prem allowing you to manage BitLocker with a third-party management tool, yet report status within Trellix ePO - On-prem. This can be useful to report on BYOD (Bring Your Own Device) or contractor laptops to monitor compliance to company encryption policies.

If BitLocker is managed by MNE, or report-only mode is enabled, the client system reports the following information to Trellix ePO - On-prem:

  • BitLocker status

  • BitLocker protection status

Note: BitLocker protection is suspended when the administrator alters the policy to change protector on operating system drive during switch-over period. Otherwise, if switching authentication method, the endpoint is unprotected until the new authentication method is fully applied.

  • BitLocker mode

  • System information

Option

Definition

  • System encryption status

  • FIPS status

System authentication

  • System authentication

  • Keep existing non-MNE authentication protector — Allows you to use an option to prevent MNE from replacing an existing BitLocker authentication protector.

  • Trellix Preboot — Allows you to add preboot authentication on client systems. Make sure that Trellix Data Exchange Layer components are installed and set up in your IT infrastructure. See the documentation on  for information about how to install DXL.

  • TPM — Allows you to use the TPM authentication method to protect the operating system volume for TPM supported client systems. A password or PIN is not required to boot Windows.

  • TPM and PIN — Allows you to use TPM

    authentication and a PIN as additional security for TPM supported client systems.

  • TPM and enhanced PIN — Allows you to use an enhanced PIN number as an additional security for TPM supported client systems.

  • Password — Allows you to use password authentication to protect the operating system volume for Windows client systems.

  • Network Unlock — Allows remote

    authentication of BitLocker Fixed Volumes on servers.

  • System authentication (legacy) — These options apply to version 4.x clients.

    • Use Trusted Platform Module (TPM)

— Allows you to use the TPM authentication method to protect the operating system volume for TPM

Option

Definition

supported client systems.

  • Also use PIN — Allows you to use a PIN as an additional security for TPM supported client systems.

  • Use enhanced PIN if

supported — Allows you to use an enhanced PIN as additional security for TPM supported client systems.

Note: It is recommended to enable the hardware test option under BitLocker advanced settings to make sure pre-boot supports enhanced PINs.

  • Fall back to Password if no TPM is available (Windows 8 and above) — Allows you to use password authentication for client systems that do not support TPM.

Note: If the Use Trusted Platform Module (TPM), Also use PIN, and Fall back to Password if no TPM is available (Windows 8 and above) options are all enabled and the current protector is the passphrase protector, then the client system is compliant to the policy.

  • Password (Windows 8 and above) — Allows you to use password authentication to protect the operating system volume for client systems that are installed with Windows 8 or above.

    Note: If you enable this option, Windows 7 systems automatically fall back to using TPM with PIN, as password is not supported for Windows 7 systems.

Option

Definition

  • Automatic (Network) — Data volumes are encrypted and protected; they automatically unlock when mounted if the server provides a key to do so. Access rules need to be defined in Server Settings along with this policy.

    • Also encrypt OS volume with protection disabled — Allows you to encrypt the client system's operating system volume, although the protection mechanism is disabled. If this is left deselected, the OS volume is not encrypted.

Authentication Settings

Minimum pin length (4-20) — Enter the minimum PIN length from 4 to 20 that you would like to set for the PIN number.

Minimum password length (8-99) — Enter the minimum password length from 8 to 99 that you would like to set for the password.

Maximum number of times user can postpone activation (1-10) — Enable this option and enter the maximum number of times from 1 to 10 to

postpone activation.

End user messaging

Provide a custom URL for the BitLocker recovery screen in preboot (Windows 10 and above) — Enable this option to enter a custom URL that will

Option

Definition

appear in the pre-boot BitLocker recovery screen on Windows 10 systems. The user needs to copy this URL on a web page of another system for information about retrieving the recovery key.

Recovery URL — Enter the URL that will appear in

the pre-boot BitLocker recovery screen.

BitLocker advanced settings

You can choose to enable, disable, or not manage the following options:

  • Enable hardware test (requires reboot before encryption, not applicable to automatic (network) unlock) — Enable this option to perform hardware test for the required client systems before BitLocker starts protecting the system.

Note: Make sure that the user restarts the client system after it's encrypted. The system will not start encrypting until a successful hardware test is completed.

This makes sure that systems that do not support BitLocker because of hardware compatibility issues can be easily recovered after they fail to boot.

  • Activate on platforms (for example slates/ tablets) that indicate no pre-boot input support (use with caution) — Enable this option to allow activation on tablets, even when the slate/tablet reports that a keyboard is not available in pre-boot.

  • Only encrypt used space during initial encryption of volumes (Windows 8 and above) — Allows you to encrypt only the used space of the volumes for client systems, significantly speeding up initial encryption. This is applicable for systems installed with Windows 8 or above.

Option

Definition

Note: Sensitive data that was previously deleted from the file system may not be protected, as not all sectors are protected.

  • Reduce restart delays by preventing memory overwrite of BitLocker secrets during shutdown (use with caution) — Improves restart performance by skipping key-zeroization during the restart process. This leaves systems more vulnerable to very sophisticated memory attacks.

  • Re-measure TPM validation data after a BitLocker recovery, to reduce the chances of further recoveries (Windows 8 and above) — After a BitLocker recovery, the system boot is re-measured using the TPM to ensure that it is current, therefore reducing the risk of reoccurrence of a recovery scenario caused by a boot measurement change.

  • Allow use of BitLocker To Go (Windows 8 and above) — Allows you to encrypt removable media. This option is automatically enabled.

  • Deny write access to fixed data volumes not protected by BitLocker — Enable this option to deny right access to fixed volumes for client systems that are not protected by BitLocker. This will prevent users from writing data to unprotected volumes until they are fully protected, thus improving data security.

  • Require hardware-based encryption (Windows 8 and above) — Enable this option to ensure that BitLocker will only activate with self-encrypting drives.

    • Fallback to software-based encryption if hardware-based encryption is not supported — Enable this option to allow BitLocker to use

Option

Definition

software encryption if a self-encrypting drive is not available. Used in combination with the parent option, this allows a preference to be stated for self-encrypting drives.

Duplicate

Duplicates or copies the policy settings with a different name and this can be assigned to a different user.

Save

Saves the product settings policy of MNE.

Cancel

Exits the current page.

Security Posture Report settings

Security posture reporting allows you to report the endpoints that meet your required security posture settings for your organization.

The security posture report settings allow you to define the criteria for securing endpoints. This policy has no effect on the management of the endpoint; it simply defines the tests that the endpoints run to assure its data protection security posture.

Each specific posture test passes unless there is a specific reason for failing. For example, a system without data volumes passes all data volume tests, because there are no data volumes to fail. This reporting is primarily designed to report failures against specific criteria.

Note: You can view the overall result of security posture reporting tests by navigating to Menu Systems System Tree systems. Select the required system, then click Native Encryption Security posture reporting.

Option definitions

  • OS Volume — Enable this option to test the OS volume against the selected criteria.

  • Data Volume(s) — Enable this option to test data volumes against the selected criteria.

Note: If the system doesn't have data volumes, the data volume tests will pass each of the posture tests.

  • Used space on selected volumes(s) should be fully encrypted (recommended) — Enable this option to report that the system is secure only if the used space on the selected volume types is fully encrypted.

  • Selected volumes require authentication (recommended) — Enable this option to report that the system is secure only if the selected volume types require user authentication, network unlock, or TPM authentication.

  • Selected volume(s) should use a minimum encryption strength of: — Enable this option to report that the system is secure only if the selected volume types use at least:

    • AES-128 — Can use AES-128 or AES-256.

    Note: Systems that are activated with higher strength algorithm AES-256 and Security Posture set to Algorithm AES-128 displays as pass.

    • AES-256 — Must use AES-256.

  • Selected volume(s) should be FIPS-compliant — Enable this option to report that the system is secure only if the selected volume types are FIPS-compliant. (Note: Systems that were activated prior to being managed by MNE cannot be verified as FIPS compliant)

  • Duplicates - Duplicates or copies the security posture settings with a different name.

  • Save - Saves the security posture settings policy of MNE

  • Exit -  Exits the current page.

System recovery

The Enter serial number (FileVault) or recovery key ID (BitLocker) pane allows you to type the serial number of the client system to receive the recovery key of that client system.

Option definitions

Option

Definition

Serial number (FileVault) or recovery key ID (BitLocker)

Type the serial number or recovery key ID of the client system that you received from the user.

Back

Navigates to the previous page.

Next

Navigates to the next page.

Cancel

Exits the current page.

Recovery key

The Recovery key from serial number/ recovery key ID pane allows you to view the recovery key to send it to the user.

Option definitions

Option

Definition

Recovery keys

Displays the response code and the codes are phonetically arranged in the table.

Can't find your key? Search for it here.

Allows you to search for your key, if you are unable to find your key.

Close

Exits the current page.

Import recovery key

You must manually import the recovery key of the client system to the Trellix ePO - On-prem database using the Data Protection or System Tree menu.

Data Protection menu

Option

Definition

Enter serial number

Type the serial number of the client system that you received from the user.

Enter recovery key

Type the recovery key of the client system that you received from the user.

Ok

Imports the recovery key of the client system to the

Trellix ePO - On-prem database.

Cancel

Exits the current page.

System Tree menu

Option

Definition

Enter recovery key

Type the recovery key of the client system that you had selected.

Ok

Imports the recovery key of the client system to the

Trellix ePO - On-prem database.

Cancel

Exits the current page.

MNE server settings

Enable rotating the recovery keys when the system recovery is performed through MNE recovery pages and DPSSP.

Option

Definition

Recovery is performed through MNE recovery pages

Enable this option to rotate the recovery keys when the recovery is performed through MNE recovery pages.

Recovery is performed through Data Protection Self Service Portal

Enable this option to rotate the recovery keys when the recovery is performed through DPSSP.

Note: Key rotation after the recovery process is not available for Mac OS X systems.

Revealed through web API

Enable this option to reveal the rotated recovery keys through web API.

Automatic (network) unlock of volumes for system under

Click Edit network rule, select whether you wish to grant or deny access for systems in this branch by selecting GRANTED or DENIED respectively, then click Apply.

Browse through the System Tree View, select the

required system or group, and click OK.

Add rule

Click to add the rule selected.

Save

Saves the server settings for MNE.

Cancel

Exits the current page.