Jump to content

Data collection for troubleshooting the KES Bitlocker management error "The policy can not be applied" [KES for Windows]


Recommended Posts

Antipova Anna
Posted

Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.

This article is about Kaspersky Endpoint Security for Windows (KES for Windows)

In cases when Bitlocker encryption of a certain volume is started using KES Bitlocker management, and the product returns the following error:

Event type: The policy can not be applied.

Action: Encryption
Reason: The system drive is not compatible with the Microsoft BitLocker encryption.
Type of encryption: disk encryption
User: ....

and the same error is being logged in the Kaspersky Event Log as well, the following data should be collected in order to troubleshoot the issue.

Step-by-step guide

  1. KES runtime traces collected during the error registration.

    1. Run KES product, turn traces on.
    2. Run "avp.com PBATESTRESET" command.
    3. Restart the product.
    4. Retry disk encryption and verify that the error has been logged again. Stop collecting traces and provide them for analysis.
  2. Output of the following commands:
    manage-bde -status 
    wmic /namespace:\\ROOT\CIMV2\Security\MicrosoftVolumeEncryption path Win32_EncryptableVolume GET
    from the client host in question.
    Listed commands should be executed in the elevated command prompt.

  3. GSI https://support.kaspersky.com/common/diagnostics/3632

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...