Jump to content

Completely disable Bitlocker administration


Recommended Posts

Completely disable Bitlocker administration
Hello.
I have a problem when I try to disable the encryption functionality with BitLocker.

I don't want Kaspersky to manage Bitlocker on my computers because I want to manually decide which computers should be encrypted. That is, I want to disable this function completely. To do this I tried the following (unsuccessfully):

1. from the Kaspersky Endpoint Security Cloud | Security Mananger | Encription console, I disabled this option.
2. In "Current encryption status" it says "Encryption Management is not enabled in profiles".
3. In addition, in all security profiles, in "Management settings | Encryption" the option "Disable encryption" is checked.

The problem is that when I encrypt a computer disk, after a few minutes, it is automatically decrypted by Kaspersky.
If I have a computer without Kaspersky and with the disk encrypted, after installing Kaspersky, the disk is decrypted! I don't want that!

How can I completely disable the functionality to manage encryption of Kaspersky computers?

I am using Kaspersky Endpoint Security Cloud Pro platform, and the clients have installed versions 12.3.0.493 and 12.2.0, on Windows 10 and Windows 11.

Thank you very much.
 

Link to comment
Share on other sites

Strange behavior of the product, I think it would be better to open a request to technical support.

in a cloud solution you cannot customize a package directly from the control panel by selecting which components will be installed ...

you can use a "raw" package ... but I'm not sure if it will be convenient, and if the system will not restore missing components (I have no way to check).

1. try uninstalling the KES client from your device while keeping the administration agent (so as not to lose connection to the server).
2. get the "raw" KES package -

Спойлер

.thumb.png.aae042ff05676d0a9e986de89e260f84.png

 

3. unzip and start the installation manually ...
At one stage of the wizard you will encounter component selection, make sure you have selected all the items you need ... and have disabled the encryption components.

Спойлер

1782722086_.png.9563161c2e983c7881ee3a502ac0301d.png

 

 check

Link to comment
Share on other sites

Am 11.12.2023 um 20:16 schrieb eduramallo:

Completely disable Bitlocker administration
Hello.
I have a problem when I try to disable the encryption functionality with BitLocker.

I don't want Kaspersky to manage Bitlocker on my computers because I want to manually decide which computers should be encrypted. That is, I want to disable this function completely. To do this I tried the following (unsuccessfully):

1. from the Kaspersky Endpoint Security Cloud | Security Mananger | Encription console, I disabled this option.
2. In "Current encryption status" it says "Encryption Management is not enabled in profiles".
3. In addition, in all security profiles, in "Management settings | Encryption" the option "Disable encryption" is checked.

The problem is that when I encrypt a computer disk, after a few minutes, it is automatically decrypted by Kaspersky.
If I have a computer without Kaspersky and with the disk encrypted, after installing Kaspersky, the disk is decrypted! I don't want that!

How can I completely disable the functionality to manage encryption of Kaspersky computers?

I am using Kaspersky Endpoint Security Cloud Pro platform, and the clients have installed versions 12.3.0.493 and 12.2.0, on Windows 10 and Windows 11.

Thank you very much.
 

Hello,

in KES Cloud Product you are not able to disable to install the Bitlocker component. You are only able to enabe/disable encryption according to your License type.

However to be able to decide which devices to decrypt and to encrypt you must assign Groups. Create a Group "Decrypted" and a group "Encrypted" and assign user/devices to them you desire.

Then create a security profile with enabled encryption for Group encryption and another one with disabled encryption for decrypted devices. Disable encrytion in default Security Profile which will prevent encrypting new devices by default.

I hope I have been able to help you and remain

with Best Regards

 

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...