You are on page 1of 4

Recovering users and systems

Resetting a remote user's password or replacing the user's logon token if it has been lost requires
a challenge/response procedure to be followed.
Contents
Enabling or disabling the self recovery functionality
Performing the self recovery on the client computer
Enabling or disabling the administrator (system and user) recovery functionality
Performing the administrator (system and user) recovery on the client computer
Generating the response code for the administrator (system and user) recovery
Enabling or disabling the self recovery functionality
The Self Recovery option allows the user to reset a forgotten password by answering a set of
security questions. A list of security questions is set by the administrator using ePO. !f the
answers from the user match what has been stored with their self recovery information they
can proceed through the recovery process.
Before you begin
Use this task in ePO to enable or disable the self recovery functionality in the client computer.
Task
For option definitions, click ? in the interface.
1 Click Menu ] Systems ] System Tree. The Systems page appears. Select the desired
group under System Tree.
2 Select the desired System(s}, then click Actions ] Agent ] Modify Policies on a Single
System. The Policy Assignment page for that system appears.
3 Select Endpoint Encryption 1.0.0 from the Product drop-down list. The policy
Categories under Endpoint Encryption appear with the system's assigned policy.
4 Locate the desired User Based Policies policy category, then click Edit Assignments.
The User Based Policies page appears.
5 !f the policy is inherited, select Break inheritance and assign the policy and settings
below next to Inherit from.
6 Select the desired policy from the Assigned policy drop-down list, then click Edit Policy.
The Policy Settings page appears.
NOTE: From this location, you can edit the selected policy, or create a new policy.
NcAfee Endpoint Encryption for PC v6 Patch 1
7 Click Self-Recovery tab, then select or deselect Enable Self-Recovery to enable or
disable the self recovery functionality to the specified user or user group.
S Select Invalidate Self-Recovery after No.of attempts and type the number of attempts.
9 Type the number of Ouestions to be answered to perform the self recovery. The client
user will be prompted with these questions while trying to recover the user account at the
client system.
10 Type the number of Logons before forcing user to set answers to determine how
many times a user can log on without setting their Self Recovery questions and answers.
11 Click + to create a new question, then select the question Language and also type the
Min Answer Length the user must type while configuring the answer to this question.
NOTE: Answers to these questions are typed by the user on the client system during the
recovery process. User is prompted for recovery enrollment during every logon. The user
is allowed to cancel the enrollment until the user exceeds the specified number of logon
attempt. After exceeding the defined number of logon attempt, the Cancel button is
disabled and the user is forced to enroll for self recovery.
12 Click Save in the Policy Settings page, then click Save in the Product Settings page.
13 Send an Agent wake-up call.
Performing the self recovery on the client computer
Use this option on the client computer, if the user's password or the logon token have been
lost, to recover the user.
Before you begin
Ensure that you have successfully enrolled for self recovery on the client system. This task
should be performed by the client user on the client computer.
Task
1 Click Options ] Recovery. The Recovery dialog box appears.
2 Select the Recovery Type as Self Recovery and click OK.
3 Type the Username and click OK. The Recovery dialog box appears with the questions
that the user answered while enrolling for the self recovery.
4 Type the answers for the prompted questions and click Finish. The Change Password
dialog box appears.
5 Type and confirm the New Password and click OK.
Enabling or disabling the administrator (systemand
user} recovery functionality
The client system prompts for authentication at the Pre-Boot logon page to access the system.
!f the user has forgotten the password, the user cannot log on to the system. Resetting the
user's password or replacing their logon token if it has been lost requires a challenge/response
procedure to be followed. The user should start their system, cancel any logon dialogues that
Recovering users and systems
Performing the self recovery on the client computer
NcAfee Endpoint Encryption for PC v6 Patch 1
may appear; they must then click the Recovery button from the Endpoint Encryption Pre-Boot
logon page. This option needs to be enabled in the ePO server before performing this task at
the client systems.
Before you begin
Use this task in ePO to enable or disable the administrator (system and user) recovery
functionality in the client computer.
Task
For option definitions, click ? in the interface.
1 Click Menu ] Systems ] System Tree. The Systems page appears. Select the desired
group under System Tree.
2 Select the desired System(s}, then click Actions ] Agent ] Modify Policies on a Single
System. The Policy Assignment page for that system appears.
3 Select Endpoint Encryption 1.0.0 from the Product drop-down list. The policy
Categories under Endpoint Encryption appear with the system's assigned policy.
4 Locate the desired Product Settings policy category, then click Edit Assignments. The
Product Settings page appears.
5 !f the policy is inherited, select Break inheritance and assign the policy and settings
below next to Inherit from.
6 Select the desired policy from the Assigned policy drop-down list, then click Edit Policy.
The Policy Product Settings page appears.
NOTE: From this location, you can edit the selected policy, or create a new policy.
7 Click Recovery tab, then select or deselect Enabled to enable or disable the system
recovery functionality.
S Select the required Recovery Key size from the Key size drop-down list, then type the
Message to appear on the recovery page.
9 Click Save in the Policy Recovery page, then click Save in the Product Settings page.
10 Send an Agent wake-up call.
Performing the administrator (system and user}
recovery on the client computer
Use this task on the client computer, if the user's password or the logon token have been lost,
to recover the user or the system.
Before you begin
This task should be performed by the client user in the client computer.
Task
1 Restart the client computer.
2 Click Options ] Recovery.
Recovering users and systems
Performing the administrator (system and user) recovery on the client computer
NcAfee Endpoint Encryption for PC v6 Patch 1
3 Select the Recovery Type as Administrator Recovery and click OK. The Recovery
dialog box appears with the Client Code.
NOTE: The client user should read the Client Code and get the Response Code from
the administrator who manages the ePO.
4 Enter the Line 1 of the Response Code in Line 1 field and click Enter.
5 Enter the Line 2 of the Response Code in Line 2 field and click Enter.
NOTE: Each line of the code is checked when it is entered.
6 Click Finish.
Generating the response code for the administrator
(system and user} recovery
Use this task to generate the response code for the administrator (system and user) recovery.
Before you begin
This task should be performed by the administrator in the ePO.
Task
For option definitions, click ? in the interface.
1 Click Menu ] Data Protection ] Encryption Recovery. The Endpoint Encryption
Recovery wizard opens with the text field for Challenge Code.
NOTE: Ask the client user to read the challenge code that appears in the recovery process
page to the administrator.
2 Type the Challenge Code and click Next. The Recovery Type page opens.
3 Select Machine Recovery from the Recovery Type list, then click Next. The Response
Code page opens with response code such as Line 1 and Line 2.
NOTE: Generated Response code depends on the recovery key size set in the policy and
the selected recovery type that is machine recovery or user recovery.
NOTE: The administrator should read the response code to the user.
Recovering users and systems
Generating the response code for the administrator (system and user) recovery
NcAfee Endpoint Encryption for PC v6 Patch 1

You might also like