Encryption Management

Disk Encryption

NPAV EDR provides centralized encryption management with support for Full Disk Encryption, File and Folder Encryption, Removable Media Encryption, Microsoft BitLocker, and macOS FileVault 2. The solution enables centralized monitoring of encryption status, comprehensive reporting, secure storage of encryption recovery keys with multiple recovery options, and supports automatic encryption of removable storage devices while preventing data from being copied to unencrypted removable media.

Key capabilities include:

  • Full Disk Encryption (FDE): Encrypts entire system and data drives to ensure data remains protected even if a device is lost or stolen.
  • Removable Media Encryption: Secures USB flash drives and other removable storage devices, ensuring data remains encrypted when transferred between systems.
  • BitLocker Management: Enables centralized deployment, monitoring, and management of Microsoft BitLocker encryption policies across managed endpoints.
  • Centralized Encryption Monitoring: Provides real-time visibility into the encryption status of all managed computers and storage devices from a single management console.
  • Reporting and Compliance: Generates comprehensive encryption reports for auditing, compliance, and security monitoring, with export capabilities for further analysis.
  • Centralized Recovery Key Management: Securely stores and manages encryption Recovery IDs and Recovery Keys in a centralized repository, enabling authorized administrators to recover encrypted devices when required.
  • Multiple Recovery Options: Supports multiple recovery mechanisms, including recovery using Recovery Keys, Recovery IDs, and BitLocker recovery methods, ensuring secure and reliable access to encrypted data during recovery scenarios.

Follow the Below Steps to Use Disk Encryption

Retrieving Drive Details from the EDR Console

  • Log in to the EDR console.
  • Navigate to the Disk Encryption menu.
  • Select the client machine
  • Click the status button to fetch the latest drive information

How to apply Encrypt drive setting

  • Navigate to the Disk Encryption Menu
  • Select The client machine
  • Click on setting button
  • Select the drive you intend to encrypt, and then choose your preferred encryption method.
  • Use the toggle switch to enable encryption. Enabling the toggle will initiate drive encryption
  • Click on Apply Setting button

Lock Encrypted drive

  • Navigate to disk encryption menu bar
  • Select The client machine
  • Click on Setting button
  • Select the encrypted drive and setting checkbox
  • Use the toggle switch to lock drive
  • Click on Apply Setting button

Centralized encryption management, including encryption status monitoring, report generation and export, and centralized storage and management of Recovery IDs and Recovery Keys for secure device recovery.

Folder Encryption

Encrypts specific files and folders to protect personal or confidential data. Prevents unauthorized access, even if malware or ransomware tries to steal files, they remain unreadable. Encrypted files can only be accessed after unlocking Folder Encryption.

Steps to Configure Folder Encryption

1. Login to EDR Console
Access the NPAV Endpoint Detection and Response (EDR) console with your administrator credentials.

  • Use admin username and password
  • Ensure secure login from a trusted device

2. Go to Policy Management
Navigate to the policy management section where encryption settings can be configured.

  • EDR Console → Policy Management
  • Locate the list of existing policies
  • Confirm you have rights to edit policies

3. Select and Edit Policy
Choose the policy you want to apply encryption to and open it for editing.

  • Click on the desired policy
  • Select Edit Policy option

4. Open Shield Tab
Access the Shield tab to configure file and folder encryption options.

  • Policy Settings → Shield Tab
  • Enable File/Folder Encryption option
  • Ensure shield protection is enabled

5. Add Files/Folders for Encryption
Specify the files or folders you want encrypted and select the encryption mode.

  • Add file/folder paths
  • Choose encryption mode (Used Space Only or Full Space)
  • Confirm entries

6. Save Policy
Save the updated policy to apply encryption settings.

  • Click Save Policy
  • Verify changes are stored

7. Apply Policy to PC
Deploy the updated policy to target PCs so encryption is enforced.

  • Apply the policy to selected endpoints
  • Confirm encryption is active on those systems