Endpoint Security Suite Enterprise - Spiceworks

Transcription

Dell Data Protection Endpoint Security SuiteEnterpriseAdvanced Installation Guide v1.4

Notes, cautions, and warningsNOTE: A NOTE indicates important information that helps you make better use of your product.CAUTION: A CAUTION indicates either potential damage to hardware or loss of data and tells you how to avoid the problem.WARNING: A WARNING indicates a potential for property damage, personal injury, or death. 2017 Dell Inc. All rights reserved.Dell, EMC, and other trademarks are trademarks of Dell Inc. or its subsidiaries. Other trademarks maybe trademarks of their respective owners.Registered trademarks and trademarks used in the Dell Data Protection Encryption, Endpoint Security Suite, Endpoint Security SuiteEnterprise, and Dell Data Guardian suite of documents: DellTM and the Dell logo, Dell PrecisionTM, OptiPlexTM, ControlVaultTM, LatitudeTM,XPS , and KACETM are trademarks of Dell Inc. Cylance , CylancePROTECT, and the Cylance logo are registered trademarks of Cylance,Inc. in the U.S. and other countries. McAfee and the McAfee logo are trademarks or registered trademarks of McAfee, Inc. in the US andother countries. Intel , Pentium , Intel Core Inside Duo , Itanium , and Xeon are registered trademarks of Intel Corporation in the U.S.and other countries. Adobe , Acrobat , and Flash are registered trademarks of Adobe Systems Incorporated. Authen Tec and Eikon are registered trademarks of Authen Tec. AMD is a registered trademark of Advanced Micro Devices, Inc. Microsoft , Windows , andWindows Server , Internet Explorer , MS-DOS , Windows Vista , MSN , ActiveX , Active Directory , Access , ActiveSync ,BitLocker , BitLocker To Go , Excel , Hyper-V , Silverlight , Outlook , PowerPoint , OneDrive , SQL Server , and Visual C areeither trademarks or registered trademarks of Microsoft Corporation in the United States and/or other countries. VMware is a registeredtrademark or trademark of VMware, Inc. in the United States or other countries. Box is a registered trademark of Box. DropboxSM is aservice mark of Dropbox, Inc. GoogleTM, AndroidTM, GoogleTM ChromeTM, GmailTM, YouTube , and GoogleTM Play are either trademarks orregistered trademarks of Google Inc. in the United States and other countries. Apple , Aperture , App StoreSM, Apple RemoteDesktopTM, Apple TV , Boot CampTM, FileVaultTM, iCloud SM, iPad , iPhone , iPhoto , iTunes Music Store , Macintosh , Safari ,and Siri are either servicemarks, trademarks, or registered trademarks of Apple, Inc. in the United States and/or other countries. GO ID ,RSA , and SecurID are registered trademarks of Dell EMC. EnCaseTM and Guidance Software are either trademarks or registeredtrademarks of Guidance Software. Entrust is a registered trademark of Entrust , Inc. in the United States and other countries.InstallShield is a registered trademark of Flexera Software in the United States, China, European Community, Hong Kong, Japan, Taiwan,and United Kingdom. Micron and RealSSD are registered trademarks of Micron Technology, Inc. in the United States and othercountries. Mozilla Firefox is a registered trademark of Mozilla Foundation in the United States and/or other countries. iOS is atrademark or registered trademark of Cisco Systems, Inc. in the United States and certain other countries and is used under license.Oracle and Java are registered trademarks of Oracle and/or its affiliates. Other names may be trademarks of their respective owners.SAMSUNGTM is a trademark of SAMSUNG in the United States or other countries. Seagate is a registered trademark of SeagateTechnology LLC in the United States and/or other countries. Travelstar is a registered trademark of HGST, Inc. in the United States andother countries. UNIX is a registered trademark of The Open Group. VALIDITYTM is a trademark of Validity Sensors, Inc. in the UnitedStates and other countries. VeriSign and other related marks are the trademarks or registered trademarks of VeriSign, Inc. or its affiliatesor subsidiaries in the U.S. and other countries and licensed to Symantec Corporation. KVM on IP is a registered trademark of VideoProducts. Yahoo! is a registered trademark of Yahoo! Inc. This product uses parts of the 7-Zip program. The source code can be found at7-zip.org. Licensing is under the GNU LGPL license unRAR restrictions (7-zip.org/license.txt).Endpoint Security Suite Enterprise Advanced Installation Guide2017 - 05Rev. A02

Contents1 Introduction.7Before You Begin. 7Using This Guide. 8Contact Dell ProSupport. 82 Requirements. 10All Clients. 10All Clients - Prerequisites. 10All Clients - Hardware.10All Clients - Language Support. 11Encryption Client. 11Encryption Client Prerequisites. 12Encryption Client Hardware.12Encryption Client Operating Systems. 12External Media Shield (EMS) Operating Systems.12Server Encryption Client.13Server Encryption Client Prerequisites. 14Server Encryption Client Hardware.14Server Encryption Client Operating Systems.14External Media Shield (EMS) Operating Systems.15Advanced Threat Prevention Client. 16Advanced Threat Prevention Operating Systems. 16Advanced Threat Prevention Ports. 16BIOS Image Integrity Verification.16SED Client.17OPAL Drivers. 17SED Client Prerequisites. 18SED Client Hardware.18SED Client Operating Systems. 19Advanced Authentication Client. 19Advanced Authentication Client Hardware.20Advanced Authentication Client Operating Systems. 20BitLocker Manager Client. 21BitLocker Manager Client Prerequisites.21BitLocker Manager Client Operating Systems.21Authentication Options. 22Encryption Client.22SED Client. 23BitLocker Manager.243 Registry Settings. 25Encryption Client Registry Settings.25Advanced Threat Prevention Client Registry Settings.28Dell Data Protection Endpoint Security Suite EnterpriseContents3

SED Client Registry Settings.29Advanced Authentication Client Registry Settings. 31BitLocker Manager Client Registry Settings. 314 Install Using the ESSE Master Installer. 33Install Interactively Using the ESSE Master Installer. 33Install by Command Line Using the ESSE Master Installer.365 Uninstall Using the ESSE Master Installer.39Uninstall the ESSE Master Installer. 39Command Line Uninstallation. 396 Install Using the Child Installers. 40Install Drivers. 41Install Encryption Client. 41Command Line Installation.41Install Server Encryption Client. 43Install Server Encryption Interactively. 44Install Server Encryption Using the Command Line. 47Activate Server Encryption.49Install Advanced Threat Prevention Client.51Command Line Installation.52Install Web Protection and Firewall.53Command Line Installation.53Install SED Management and Advanced Authentication Clients. 54Command Line Installation.55Install BitLocker Manager Client. 55Command Line Installation.557 Uninstall Using the Child Installers. 57Uninstall Web Protection and Firewall. 58Command Line Uninstallation. 58Uninstall Encryption and Server Encryption Client.58Process.58Command Line Uninstallation. 59Uninstall Advanced Threat Prevention.60Command Line Uninstallation.60Uninstall SED and Advanced Authentication Clients.60Process. 61Deactivate the PBA. 61Uninstall SED Client and Advanced Authentication Clients.61Uninstall BitLocker Manager Client. 62Command Line Uninstallation. 628 Commonly Used Scenarios. 63Encryption Client, Advanced Threat Prevention, and Advanced Authentication. 64SED Client (including Advanced Authentication) and External Media Shield. 654Dell Data Protection Endpoint Security Suite EnterpriseContents

BitLocker Manager and External Media Shield. 65BitLocker Manager and Advanced Threat Prevention. 669 Provision a Tenant for Advanced Threat Prevention. 67Provision a Tenant. 6710 Configure Advanced Threat Prevention Agent Auto Update. 7111 Pre-Installation Configuration for One-time Password, SED UEFI, and BitLocker.72Initialize the TPM.72Pre-Installation Configuration for UEFI Computers. 72Enable Network Connectivity During UEFI Preboot Authentication. 72Disable Legacy Option ROMs. 73Pre-Installation Configuration to Set Up a BitLocker PBA Partition. 7312 Set GPO on Domain Controller to Enable Entitlements. 7413 Extract the Child Installers from the ESSE Master Installer. 7714 Configure Key Server for Uninstallation of Encryption Client Activated Against EE Server.78Services Panel - Add

Install Drivers - Download the appropriate drivers and firmware based on your authentication hardware. Install Encryption Client - use these instructions to install the Encryption client, which is the component that enforces security policy, whether a computer is connected to the