
The Group Policy Object Editor (GPOE) displays. Right-click the new Group Policy Object on the navigation tree.The new Group Policy Object you created is displayed in the navigation tree. Type the name of the Group Policy Object you wish to create.The New GPO (Group Policy Object Editor) window displays. Right-click Group Policy Objects on the navigation tree.

This option should be used only when using extreme caution. If that is not possible, using the Server Commands and decrypting a single machine is then recommended. Symantec recommends instead to decrypt systems on an as-needed basis using the local method. It is always recommended to create separate GPO and assign machines to this GPO for the sole purpose of decrypting. Do NOT modify any existing policies with this setting. WARNING:This is a highly sensitive setting and could result in all your machines being decrypted unintentionally. Using a Remote Decryption policy to decrypt machines Using the SEE Native policy, it is highly recommended to create a separate group to assign machines to for the sole purpose of decrypting. It is always recommended to create separate SEE Native policy and assign designated machines to this policy for the sole purpose of decrypting. Using a Decryption Policy via GPO or SEE Native policy Once a machine is decrypting, it is not possible to reverse the process so proceed with extreme caution.ģ. In order to decrypt a system via the server commands, login go the SEE Management Console, find the machine using the Computer Status Report, right click the machine and then select the option to decrypt: Server Commands Method to Decrypt a machine Important tip: If you have multiple disks, such as a C: (boot) drive and a D: (data) drive, decrypt the D drive first:Ģ. Next, check the box next to the drive you wish to decrypt, and click "Decrypt": On the right side, click the chevron expansion symbol to show all the disks. Click the Internal Drives tab to see the disks available. Enter the credentials for the SEE Client Administrator:ģ.

First open the Symantec Endpoint Encryption Client Administrator from the Start menu:Ĭonfirm the User Account Control dialog to permit the SEE Client Administrator to open.Ģ. TIP: Make sure the system is plugged into AC power in order to encrypt or decrypt systems.ġ. The remote decryption policy is used by policy administrators to decrypt all encrypted disk partitions on computers protected by Symantec Endpoint Encryption-Full Disk without having to physically send a client administrator to the location(s) of the computers.
