Endpoint Encryption

 View Only

How to set up a Serverless (Standalone) installation of Symantec Endpoint Encryption version 11 

Nov 12, 2014 08:01 PM

Before we begin, I would like to let the reader know that the product for standalone drive encryption installations is Symantec Encryption Desktop.  This guide is intended for managed environments already using Symantec Endpoint Encryption who have a need for a small number of standalone clients that are outside of their domain or for hardware testing.  If you have the need for a small number of unmanaged systems (no management server) that need to be encrypted, I would recommend contacting Symantec Customer Care and getting Symantec Encryption Desktop instead for drive encryption.  This process, though supported in version 8.2.1, is not supported with SEE v11.  Use at your own risk.

For this article, I will be walking through the entire process using Windows 8.1.  The only major difference is that on Windows 8/8.1, you have a different way to install the required .NET Framework versions.  Windows 7 users can skip to step 6, but will need to make sure they have .NET Framework 3.5 and 4.5 installed before they begin.  Both versions can be found here:
http://www.microsoft.com/net/download/earlier-versions

1. Start at the Desktop.  Right click the Windows button and select Control Panel.

SEEv11-Win8.1-1.png

 

2. Select “Programs”.

SEEv11-Win8.1-2.png

 

3. Select “Turn Windows features on or off”.

SEEv11-Win8.1-3.png

 

4. Check the box next to “.NET Framework 3.5 (includes .NET 2.0 and 3.0)” and select “OK”.  Windows will search for the files.

SEEv11-Win8.1-4.png

SEEv11-Win8.1-5.png

 

5. Select “Download files from Windows Update”.  Windows will begin downloading the files, and install them.

SEEv11-Win8.1-6.png

SEEv11-Win8.1-7.png

 

6. Double-click the SEE Management Agent msi file.  The management agent will begin installation.

SEEv11-Win8.1-9.png

 

7. Click “Next”.

SEEv11-Win8.1-10.png

 

8. Click “Next” again.

SEEv11-Win8.1-12.png

 

9. Read the license agreement.  If you accept the terms of the agreement, select “I accept…” and click “Next”.

SEEv11-Win8.1-12_0.png

 

10. Select “None (password authentication only)”, and click “Next”.

SEEv11-Win8.1-13.png

 

11. Click “Next” to accept the default location, or modify it as desired before clicking “Next”.

SEEv11-Win8.1-14.png

 

12. Uncheck the box for “Use SEE Server” and click “Next”.

SEEv11-Win8.1-15B.png

 

13. Click “Next” again.

SEEv11-Win8.1-16.png

 

14. Select a management password.  This password will only be needed to uninstall the product if needed at a later time.  Click “Next”.

SEEv11-Win8.1-17.png

 

15. If you are satisfied with your settings thus far, click “Install”. 

SEEv11-Win8.1-18.png

SEEv11-Win8.1-19.png

 

16. If prompted by User Account Control, make sure the information looks correct by comparing it to the screenshot below (program name, publisher), and select “Yes”.  It should finish installing without additional input.

SEEv11-Win8.1-20.png

 

17. Click “Finish”

SEEv11-Win8.1-21.png

 

18. Double click the SEE Drive Encryption installer.

SEEv11-Win8.1-22.png

 

19. Select “Next”

SEEv11-Win8.1-23.png

 

20. Read the license agreement.  If you accept the terms of the agreement, select “I accept…” and click “Next”.

SEEv11-Win8.1-24.png

 

21. Click “Install”.

SEEv11-Win8.1-25.png

 

22. If prompted by User Account Control, make sure the information looks correct by comparing it to the screenshot below (program name, publisher), and select “Yes”.  It should finish installing without additional input.

SEEv11-Win8.1-26.png

 

23. Click “Finish”.

SEEv11-Win8.1-27.png

 

24. Click the Windows button in the bottom left.  Then click the search icon in the top right, and start typing in “Symantec Endpoint Encryption Manager”.  It should auto-fill and show the program.  Click the program in the list to open it.

SEEv11-Win8.1-28.png

 

25. If prompted by User access Control, click “Yes”.  The management console will open.

SEEv11-Win8.1-29.png

SEEv11-Win8.1-30.png

 

26. Expand “Symantec Endpoint Encryption Software Setup”, and click “Management Agent”.

SEEv11-Win8.1-31.png

SEEv11-Win8.1-32.png

 

27. Note that “Password Attempts” references Drive Encryption only, while “Password Complexity” is for Removable Media only.  Drive Encryption passwords will be the same as the Windows login password, and complexity will be handled by Windows settings.  Apply any changes you wish, and click “Finish”.  You will be prompted to save the package, and it will automatically generate both 32- and 64-bit client packages.

SEEv11-Win8.1-33.png

SEEv11-Win8.1-34.png

 

28. In the Management Console, select “Drive Encryption”.  Under the first page, Client Administrators, select “Add”.

SEEv11-Win8.1-35.png

 

29. Enter a Client Administrator credential.  This is an account that should be able to get past pre-boot authentication in the event that your user account does not work for some reason, or you have forgotten the passphrase.  You can add as many of these accounts as you wish, but there must be at least one to continue.  After adding the username and password for the account, click “OK”.

SEEv11-Win8.1-36.png

 

30. When you have entered the Client Admins that you want, click “Next”.

SEEv11-Win8.1-37.png

 

31. On the next screen, select “Next”.

SEEv11-Win8.1-38.png

 

32. Select whether or not to use Recovery Questions for self-recovery if you are locked out or have forgotten your password.  You can define the questions now, or define them when the packages are installed.  For ease of use at this point, I elected not to predefine them.  Click “Next”.

SEEv11-Win8.1-39.png

 

33. The login screen can be modified, but that is a process for another day.  For my purposes here, leave the default selected, and click “Next”.

SEEv11-Win8.1-40.png

 

34. I recommend leaving the defaults for security, but you can choose to have it also remember the last Username.  Click “Next”.

SEEv11-Win8.1-41.png

 

35. You can select 128- or 256-bit encryption.  Make sure it is set on 256, and click “Next”.

SEEv11-Win8.1-42.png

 

36. Help Desk is not something that a standalone would really use, but if you were to install on a few systems, you could potentially deploy it to another system.  It will be absolutely useless for a single system, as you would need access to the system to use it, and you would only need to use it when you have no access to the system.  Leaving it checked for a standalone installation will not have any negative effects, but you can uncheck it if you wish.  Click “Finish”.

SEEv11-Win8.1-43.png

 

37. You will be prompted to save the packages.  Find the location where you want to save them, and select “Save”.

SEEv11-Win8.1-44.png

SEEv11-Win8.1-45.png

 

38. Now that we have our packages, we will install them.  First, select the SEE Management Agent created in the above steps.  64-bit systems should select the package with x64 at the end of the name.  Double click the installer.

SEEv11-Win8.1-46.png

 

39. If prompted by User access Control, click “Yes”.  The publisher will be “Unknown”, as it was generated on your system.

SEEv11-Win8.1-47.png

 

40. Installation will proceed and finish without more input.  After installation completes, it will prompt you for a reboot.  For this first reboot, select “No”.

SEEv11-Win8.1-48.png

SEEv11-Win8.1-49.png

 

41. Double click the SEE Drive Encryption Client package.  Like the Management Agent, 64-bit systems should select the package with x64 at the end of the name.  Double click the installer.

SEEv11-Win8.1-50.png

42. If prompted by User access Control, click “Yes”.  The publisher will be “Unknown”, as it was generated on your system.

SEEv11-Win8.1-51.png

 

43. The Drive Encryption will install without further input.  This time, when asked to reboot, select “Yes”.

SEEv11-Win8.1-52.png

SEEv11-Win8.1-53.png

 

44. After the system reboots, you will be prompted to configure self-recovery.  Select “Continue”.

SEEv11-Win8.1-54.png

 

45. Fill out the recovery questions and answers, and select “Save”.

SEEv11-Win8.1-55.png

 

46. Select “Finish”.  Drive Encryption will begin, and you should be able to use the computer as normal.

SEEv11-Win8.1-56.png

SEEv11-Win8.1-57.png

 

At this time, you should create a recovery disk following the article below:
http://www.symantec.com/docs/TECH223783

Some additional Drive Encryption troubleshooting steps can be found here:
http://www.symantec.com/docs/TECH224777

The SEE v11 documentation page is here for your reference as well:
http://www.symantec.com/docs/HOWTO101978

Statistics
0 Favorited
5 Views
0 Files
0 Shares
0 Downloads

Tags and Keywords

Comments

Apr 14, 2015 04:58 AM

How to do unattended installation of symantec FDE on StandAlone EndPoint System on windows 7 64bit Operating system.

Feb 27, 2015 05:33 AM

I have a question. You say that "the product for standalone drive encryption installations is Symantec Encryption Desktop". Does this product exist actually? I mean there is no such product here http://www.symantec.com/encryption/. Symantec has Symantec Encryption Desktop Corporate which is bundle of SEE and other products. But that means that it is not the case for standalone unmanaged installation.

As for the article - it is just perfect! Very detailed reference. You did a very good job documenting the process. Thank you for that!

Feb 27, 2015 04:52 AM

I think this should moved to a separate discussion thread.

Feb 10, 2015 12:03 PM

Hi community thanks for the article work until now really great... Im from ecuador so sorry if i get wrong on any words....

Im install everything on a windows 8.1 (NOT PRO) and the encryptation on the client is to 87% to complete...

 

What if i restart the machine on that stated? or i have to wait until the process complete 100%?

 

There is a issues if i try to install the both the management console and the client packages on my own machine 8.1 and is not PRO?

 

On my bios i have activated LEGACY SUPPORT not the UEFI... im gonna got trouble when i restart?

 

Thanks for read my questions... to be honest im now on this

Jan 15, 2015 03:00 PM

Thanks! Worked like a charm.

Jan 15, 2015 12:07 PM

You should uninstall the Management Agent last.  The order of the other components doesn't matter (i.e. if you have Removable Media Encryption and Drive Encryption), but I would recommend uninstalling Drive Encryption first.  If you reboot before uninstalling Drive Encryption, it may start encryption again.

Jan 15, 2015 11:59 AM

Thanks! I figured as much, so I'm actually decrypting as we speak. What about after that? Will a simple uninstall remove all features? Any specific order to uninstall?

Jan 15, 2015 11:50 AM

The drive can be decrypted from the command line using the client admin credentials.  The command line guide is here:
http://www.symantec.com/docs/DOC7716

The command is:
eedAdminCli --decrypt --disk <number> --au <AdminUserName> --ap <AdminPassword>

 

Jan 15, 2015 08:38 AM

Hi Mike,

I followed this instruction successfully to install a trial version of Endpoint Encryption in serverless mode a while back. So, both the management console and the client packages I created are installed on my own machine (Windows 7).

However, I'm a standalone user, so I should really go with Symantec Encryption Desktop instead. Therefore, I have now purchased and downloaded Symantec Drive Encryption Standalone (without Encryption Server).

But before I install it, I would like to decrypt my drive and completely uninstall the trial version with the management console. How do I proceed to do that? I guess it's not as simple as doing a regular "uninstall" from the Windows Control Panel? Since I would like to first decrypt the drive and remove the pre-boot-logon feature, etc. In the SEE Management agent i can see the drive status (encrypted), but there's no way to decrypt...

I see there are a few .exe files in the (client) installation folder of Drive Encryption. Should I use one of them??

Thanks in advance,

Joel

Nov 24, 2014 05:00 PM

Thank you Mike. For this article. Prooves to be very helpful

Related Entries and Links

No Related Resource entered.