Endpoint Encryption

 View Only
  • 1.  Endpoint encryption - remove computer effect?

    Posted Apr 21, 2015 04:03 PM

    Hello, I have overtaken a project to clean up the SEE database of old computers. I have a group of computers that were running SEE that have not checked in for months. Waht is the correct process to remove the computers? I have computers that were reimaged with the same AD computer name. I am afraid to delete the computer as I have seen that it may also delete the computer object in AD? This may be false info but I just want to be sure I do not cause the computer's to be deleted from AD. If I click delete from the SEE console what should the end user expect? If the agent ever comes back online, what will happen? Thanks!



  • 2.  RE: Endpoint encryption - remove computer effect?

    Posted Apr 23, 2015 01:55 PM

    A different UUID is assigned when the device is encrypted, so if a system was reimaged, and comes back on the network, it will be a new entity as far as the database is concerned.  At that point, you would have two of the same machine name in the database.

    Since it will be tied to a different UUID in Windows objects as well, deleting the old entry should not cause a Windows AD deletion, as the globally unique ID for both the system in AD and the product should not be the same as the original system.  I would simply try it with a test system and see your results.

    Typically, we recommend that the system be deleted in AD prior to being reimaged, at which point it will only show in the Deleted Objects container in our product.

    Generally, if two entries exist for the same system name in our database, it is safe to remove the older entry.