<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://stage-community-sophos-comv11.telligenthosting.net/cfs-file/__key/system/syndication/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-US"><title type="html">Release Notes &amp;amp; News</title><subtitle type="html" /><id>https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/atom</id><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog" /><link rel="self" type="application/atom+xml" href="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/atom" /><generator uri="http://telligent.com" version="12.1.9.35025">Telligent Community (Build: 12.1.9.35025)</generator><updated>2019-09-04T07:18:00Z</updated><entry><title>Safeguard Enterprise: File Encryption Engine updates for versions 8.10 / 8.20 / 8.30</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-enterprise-file-encryption-engine-updates-for-versions-8-10-8-20-8-30" /><id>https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-enterprise-file-encryption-engine-updates-for-versions-8-10-8-20-8-30</id><published>2021-06-24T00:27:00Z</published><updated>2021-06-24T00:27:00Z</updated><content type="html">Hello Community,

With the introduction of the mini file filter driver, which is part of SafeGuard Enterprise as of version 8.10, Sophos provides regular File Encryption Engine updates that just contain improved filter drivers. These updates are prov...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-enterprise-file-encryption-engine-updates-for-versions-8-10-8-20-8-30"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=942&amp;AppID=23&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>GlennSen</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/glennsen</uri></author><category term="Release Notification" scheme="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/archive/tags/Release%2bNotification" /><category term="safeguard Enterprise" scheme="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/archive/tags/safeguard%2bEnterprise" /><category term="file encryption" scheme="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/archive/tags/file%2bencryption" /></entry><entry><title>SafeGuard Enterprise- SafeGuard Client v8.3.1 (Mac only) / macOS 11 support released</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-enterprise--safeguard-client-v8-3-1-mac-only-macos-11-support-released" /><id>https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-enterprise--safeguard-client-v8-3-1-mac-only-macos-11-support-released</id><published>2021-01-06T15:50:00Z</published><updated>2021-01-06T15:50:00Z</updated><content type="html">Hi Community,&amp;nbsp;
Sophos SafeGuard File Encryption for Mac v8.3.1 and&amp;nbsp;Sophos SafeGuard Device Encryption for Mac v8.3.1 has been released which adds&amp;nbsp;platform support for macOS 11(Big Sur)This release is supported on the following platform...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-enterprise--safeguard-client-v8-3-1-mac-only-macos-11-support-released"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=790&amp;AppID=23&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Shweta</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/shweta</uri></author><category term="safeguard Enterprise" scheme="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/archive/tags/safeguard%2bEnterprise" /><category term="Big Sur" scheme="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/archive/tags/Big%2bSur" /></entry><entry><title>SafeGuard Enterprise – Added platform support for Windows 10 version 2009 / 20H2</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-enterprise-added-platform-support-for-windows-10-version-2009-20h2" /><id>https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-enterprise-added-platform-support-for-windows-10-version-2009-20h2</id><published>2020-12-03T22:50:00Z</published><updated>2020-12-03T22:50:00Z</updated><content type="html">Hello Community,
Overview The SafeGuard Clients 8.00.6.2, 8.10.2.55, 8.20.0.83 and 8.30.0.76 have been successfully tested on the latest Windows 10 feature release version 2009 a.k.a. 20H2 and are now officially supported.  Applies to the following S...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-enterprise-added-platform-support-for-windows-10-version-2009-20h2"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=768&amp;AppID=23&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>GlennSen</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/glennsen</uri></author><category term="Encryption" scheme="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/archive/tags/Encryption" /><category term="safeguard Enterprise" scheme="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/archive/tags/safeguard%2bEnterprise" /></entry><entry><title>SafeGuard File Encryption: Engine build 32 for SafeGuard 8.1.x / 8.2.x / 8.3.x</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-file-encryption-engine-build-32-for-safeguard-8-1-x-8-2-x-8-3-x" /><link rel="enclosure" type="text/html; charset=utf-8" length="68305" href="https://community.sophos.com/kb/en-us/135466" /><id>https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-file-encryption-engine-build-32-for-safeguard-8-1-x-8-2-x-8-3-x</id><published>2020-06-25T14:28:00Z</published><updated>2020-06-25T14:28:00Z</updated><content type="html">&lt;h1&gt;Overview&lt;/h1&gt;
&lt;p&gt;With the introduction of the mini file filter driver, which is part of SafeGuard Enterprise as of version&amp;nbsp;&lt;code&gt;&lt;code&gt;&lt;code&gt;8.10&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;, Sophos provides regular File Encryption Engine updates that just contain improved filter drivers. These updates are provided as Windows Installer Patch files (&lt;code&gt;*.msp&lt;/code&gt;) to allow an easy installation and deployment.&amp;nbsp;As these updates are cumulative, Sophos recommends using the latest version.&lt;/p&gt;
&lt;p&gt;In this KBA you can download build version&amp;nbsp;&lt;code&gt;32&lt;/code&gt;&amp;nbsp;of the filter driver engine. An overview of all File Encryption Engine Updates is available&amp;nbsp;&lt;a href="/kb/en-us/133000" target="_blank"&gt;here&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The following sections are covered:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="/kb/en-us/135466#resolved%20issues"&gt;Resolved Issues&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="/kb/en-us/135466#Improvements"&gt;Resolved Issues&amp;nbsp;(already part of File Encryption Engine build 31)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="/kb/en-us/135466#Download%20and%20installation"&gt;Download and installation&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="/kb/en-us/135466#32-bit%20OS"&gt;Installation for 32-bit OS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="/kb/en-us/135466#64-bit%20OS"&gt;Installation for 64-bit OS&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="/kb/en-us/135466#Patch"&gt;How to verify if the patch is applied&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="/kb/en-us/135466#related%20information"&gt;Related information&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="/kb/en-us/135466#feedback%20and%20contact"&gt;Feedback and contact&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Applies to the following Sophos products and versions&lt;/strong&gt;&lt;br /&gt;SafeGuard Synchronized Encryption 8.1&lt;br /&gt;SafeGuard Synchronized Encryption 8.2&lt;br /&gt;SafeGuard Synchronized Encryption 8.3&lt;br /&gt;SafeGuard File Encryption 8.1&lt;br /&gt;SafeGuard File Encryption 8.2&lt;br /&gt;SafeGuard File Encryption 8.3&lt;br /&gt;SafeGuard Data Exchange 8.1&lt;br /&gt;SafeGuard Data Exchange 8.2&lt;br /&gt;SafeGuard Data Exchange 8.3&lt;/p&gt;
&lt;h1&gt;&lt;a id="Download and installation"&gt;&lt;/a&gt;Resolved issues (new in File Encryption Engine build 32)&lt;/h1&gt;
&lt;div class="content-scrollable-wrapper"&gt;
&lt;table class="content" cellspacing="1" cellpadding="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;Reference&lt;/th&gt;
&lt;th&gt;Symptom / Summary&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15562&lt;/td&gt;
&lt;td&gt;Adobe InDesign fails to save / open documents on a network share covered by an encryption rule&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15340&lt;/td&gt;
&lt;td&gt;SafeGuard 8.10 clients sporadically lock GPO&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15613&lt;/td&gt;
&lt;td&gt;Performance improvements in combination with SolidWorks (requires additional configuration)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15659&lt;/td&gt;
&lt;td&gt;Windows Defender update might fail as long as minifilter is active&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15715&lt;/td&gt;
&lt;td&gt;Using SGPortable on Clients with File Encryption Engine build 31 might cause issues&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h1&gt;Resolved issues (already part of File Encryption Engine build 31)&lt;a id="anchor_1539071761399" name="resolved issues"&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;div class="content-scrollable-wrapper"&gt;
&lt;table class="content" cellspacing="1" cellpadding="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;Reference&lt;/th&gt;
&lt;th&gt;Symptom or Summary&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPFEE-1173&lt;/td&gt;
&lt;td&gt;Local cache corruptions during an update to Windows 10 October 2018 update (W10 version&amp;nbsp;&lt;code&gt;1809&lt;/code&gt;)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14307&lt;/td&gt;
&lt;td&gt;Explorer performance issues in combination with cached files from Windows Quick Access&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14462&lt;/td&gt;
&lt;td&gt;Increased saving time for files located on network locations (specific applications).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14525&lt;/td&gt;
&lt;td&gt;Access rights issues when running specific applications.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14639&lt;/td&gt;
&lt;td&gt;&lt;code&gt;Bluescreen Bugcheck 0x3b (SYSTEM_SERVICE_EXCEPTION)&lt;/code&gt;&amp;nbsp;on Windows 10 version&amp;nbsp;&lt;code&gt;1809&amp;nbsp;&lt;/code&gt;endpoints&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14511&lt;/td&gt;
&lt;td&gt;Performance improvements (boot and runtime)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14853&lt;/td&gt;
&lt;td&gt;Cannot open encrypted Quickbooks project (other applications potentially affected as well),&lt;br /&gt;when SafeGuard File Encryption filter driver is active.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14771&lt;br /&gt;DPSGN-14806&lt;br /&gt;DPSGN-14842&lt;/td&gt;
&lt;td&gt;Several boot performance improvements.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14995&lt;/td&gt;
&lt;td&gt;High performance impact when accessing files on network shares which are not covered by an encryption rule (requires BypassFilesWithoutPolicyVolumes registry key - see KB133022 for details).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14945&lt;/td&gt;
&lt;td&gt;User is unable to save file certain file types (e.g. docx, xlsx).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14987&lt;br /&gt;DPSGN-15016&lt;/td&gt;
&lt;td&gt;User gets file in use error when opening or saving xlsx files on network location.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14513&lt;/td&gt;
&lt;td&gt;License check of 3rd party application (Dataflex) fails - (requires BypassFilesWithoutPolicyVolumes registry key)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14856&lt;br /&gt;DPSGN-15051&lt;/td&gt;
&lt;td&gt;File Encryption driver slows down Windows explorer and search operations on network shares.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15186&lt;br /&gt;DPSGN-15188&lt;br /&gt;DPSGN-15189&lt;br /&gt;DPSGN-15190&lt;/td&gt;
&lt;td&gt;Important security fixes and improvements.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15245&lt;/td&gt;
&lt;td&gt;Files located on a WebDAV share, occasionally cannot be deleted when file encryption minifilter is active.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15014&lt;/td&gt;
&lt;td&gt;Compatibility improvements (requires additional registry modification)&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15265&lt;/td&gt;
&lt;td&gt;System might become unresponsive after re-inserting an encrypted optical media&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15261&lt;/td&gt;
&lt;td&gt;SGPortable.exe (and msvcr71.dll and msvcp71.dll) get encrypted by initial encryption&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15241&lt;/td&gt;
&lt;td&gt;SafeGuard Services not running after update to Windows 10 version 1903 (19H1). This only affects installations of File Encryption Engine build 26.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15209&lt;/td&gt;
&lt;td&gt;Compatibility improvement for Sophos Central Intercept X with EDR.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15267&lt;/td&gt;
&lt;td&gt;Potential file corruptions when creating PDFs from Catia (Dassault Syst&amp;egrave;mes).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15306&lt;/td&gt;
&lt;td&gt;File encryption filter removes SmartScreen block functionality from file properties.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15338&lt;/td&gt;
&lt;td&gt;Sporadic file corruptions when storing XLS files using Microsoft Office 2003 or 2007&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15014&lt;/td&gt;
&lt;td&gt;Generic improvements to prevent file locks during shutdown/restart.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15436&lt;/td&gt;
&lt;td&gt;Deleted encrypted files occasionally cannot be recovered and show huge size in recycle bin&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15441&lt;/td&gt;
&lt;td&gt;Bluescreen / BSOD (Bugcheck 0xd4) on endpoints with Xerox Docushare software installed&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15431&lt;/td&gt;
&lt;td&gt;Windows subsystem for linux no longer working (lxssmanager does not start) on Windows 10 version 1903 (19H1)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15454&lt;/td&gt;
&lt;td&gt;Bluescreen / BSOD SYSTEM_SERVICE_EXCEPTION (&lt;code&gt;Bugcheck 0x3b&lt;/code&gt;) when drag and drop is used for attachments (from MS Outlook to an encrypted folder)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15468,&lt;br /&gt;DPSGN-15472,&lt;br /&gt;DPSGN-15471,&lt;br /&gt;DPPSGN-15462&lt;/td&gt;
&lt;td&gt;3rd party software compatibility fixes for issues introduced in File Encryption Engine build 29&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15383&amp;nbsp;&lt;/td&gt;
&lt;td&gt;Opening encrypted docx / xlsx files may change timestamp (date changed)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15553&lt;/td&gt;
&lt;td&gt;Printing on remote printer (from Homeoffice) not working when minifilter is active&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;h1&gt;Download and installation&amp;nbsp;&amp;nbsp;&lt;/h1&gt;
&lt;p&gt;The installers for version 8.10.x (separate msp files for 32 and 64bit) can be obtained from this&amp;nbsp;&lt;a target="_blank"&gt;download link&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The installer for version 8.20.x / 8.30.x (one msp file which can be applied to all versions) can be obtained from this&amp;nbsp;&lt;a target="_blank"&gt;download link&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;&lt;a name="32-bit OS"&gt;&lt;/a&gt;Installation for 32-bit OS&lt;/h2&gt;
&lt;h3&gt;If the SafeGuard Client is already installed&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Copy the installer patch files to the corresponding endpoint(s)&lt;/li&gt;
&lt;li&gt;Apply the SafeGuard File Encryption Engine update. Example (based on version 8.10):&amp;nbsp;&lt;code&gt;msiexec /update &amp;quot;C:\Install\File Encryption Engine for SGN 8.1 Build 32.msp&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Reboot the endpoint for the changes to take effect&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;Installation together with SafeGuard Client&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Copy the SafeGuard Client and the installer patch files to the corresponding endpoint(s)&lt;/li&gt;
&lt;li&gt;Install the SafeGuard Client together with the File Encryption Engine update. Example (based on version 8.10):&amp;nbsp;&lt;code&gt;msiexec /i C:\Install\SGNClient.msi PATCH=&amp;quot;C:\Install\File Encryption Engine for SGN 8.1 Build 32.msp&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Reboot the endpoint for the changes to take effect&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;&lt;a name="64-bit OS"&gt;&lt;/a&gt;Installation for 64-bit OS&lt;/h2&gt;
&lt;h3&gt;If the SafeGuard Client is already installed&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Copy the installer patch files to the corresponding endpoint(s)&lt;/li&gt;
&lt;li&gt;Apply the SafeGuard File Encryption Engine update. Example (based on version 8.10):&amp;nbsp;&lt;code&gt;msiexec /update &amp;quot;C:\Install\File Encryption Engine for SGN 8.1 Build 32_x64.msp&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Reboot the endpoint for the changes to take effect&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;Installation together with SafeGuard Client&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Copy the SafeGuard Client and the installer patch files to the corresponding endpoint(s)&lt;/li&gt;
&lt;li&gt;Install the SafeGuard Client together with the File Encryption Engine update. Example (based on version 8.10):&amp;nbsp;&lt;code&gt;msiexec /i C:\Install\SGNClient_x64.msi PATCH=&amp;quot;C:\Install\File Encryption Engine for SGN 8.1 Build 32_x64.msp&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Reboot the endpoint for the changes to take effect&lt;/li&gt;
&lt;/ol&gt;
&lt;h1&gt;&lt;a name="Patch"&gt;&lt;/a&gt;How to verify if the patch is applied&lt;a id="anchor_1539071988949" name="How to verify if the patch is applied"&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;p&gt;After the installation, you can see the new File Encryption Engine in the&amp;nbsp;&lt;strong&gt;Installed Updates&amp;nbsp;&lt;/strong&gt;section of&amp;nbsp;&lt;strong&gt;Programs and Features&lt;/strong&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;As this package just contains new filter drivers and no other products components, this update does not change the version or build number of the installed SafeGuard Client. In the SafeGuard Management Center as of version 8.20, the file filter engine version of this update (3.0.0.45) is also listed in the installed features list of the Client.&lt;/p&gt;
&lt;h1&gt;&lt;a id="related information" name="related information"&gt;&lt;/a&gt;Related information&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="/kb/en-us/133000" target="_blank"&gt;File Encryption Engine updates for SafeGuard 8.10.x/8.20/8.30&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="/kb/en-us/124771" target="_blank"&gt;SafeGuard Enterprise: Supported clients on Windows 10 versions&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=672&amp;AppID=23&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Shweta</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/shweta</uri></author><category term="Encryption" scheme="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/archive/tags/Encryption" /><category term="safeguard Enterprise" scheme="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/archive/tags/safeguard%2bEnterprise" /></entry><entry><title>SafeGuard File Encryption: Engine build 31 for SafeGuard 8.1.x / 8.2.x / 8.3.x</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-file-encryption-engine-build-31-for-safeguard-8-1-x-8-2-x-8-3-x" /><link rel="enclosure" type="text/html; charset=utf-8" length="67419" href="https://community.sophos.com/kb/en-us/135080" /><id>https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-file-encryption-engine-build-31-for-safeguard-8-1-x-8-2-x-8-3-x</id><published>2020-03-06T09:49:00Z</published><updated>2020-03-06T09:49:00Z</updated><content type="html">&lt;h1&gt;Overview&lt;/h1&gt;
&lt;p&gt;With the introduction of the mini file filter driver, which is part of SafeGuard Enterprise as of version&amp;nbsp;&lt;code&gt;8.10&lt;/code&gt;, Sophos provides regular File Encryption Engine updates that just contain improved filter drivers. These updates are provided as Windows Installer Patch files (&lt;code&gt;*.msp&lt;/code&gt;) to allow easy installation and deployment.&amp;nbsp;As these updates are cumulative, Sophos recommends using the latest version.&lt;/p&gt;
&lt;p&gt;In this KBA you can download build version&amp;nbsp;&lt;code&gt;31&lt;/code&gt;&amp;nbsp;of the filter driver engine. An overview of all File Encryption Engine Updates is available&amp;nbsp;&lt;a href="/kb/en-us/133000" target="_blank"&gt;here&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Applies to the following Sophos products and versions&lt;/strong&gt;&lt;br /&gt;SafeGuard File Encryption 8.3&lt;br /&gt;SafeGuard File Encryption 8.2&lt;br /&gt;SafeGuard File Encryption 8.1&lt;br /&gt;SafeGuard Synchronized Encryption 8.1&lt;br /&gt;SafeGuard Synchronized Encryption 8.2&lt;br /&gt;SafeGuard Synchronized Encryption 8.3&lt;br /&gt;SafeGuard Data Exchange 8.1&lt;br /&gt;SafeGuard Data Exchange 8.2&lt;br /&gt;SafeGuard Data Exchange 8.3&lt;/p&gt;
&lt;h1&gt;Resolved issues (new in File Encryption Engine build 31)&lt;/h1&gt;
&lt;div class="content-scrollable-wrapper"&gt;
&lt;table class="content" cellspacing="1" cellpadding="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;Reference&lt;/th&gt;
&lt;th&gt;Symptom / Summary&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15383&lt;/td&gt;
&lt;td&gt;Opening encrypted docx / xlsx files may change timestamp (date changed)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15553&lt;/td&gt;
&lt;td&gt;Printing on remote printer (from Homeoffice) not working when minifilter is active&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;h1&gt;Improvements&lt;/h1&gt;
&lt;p&gt;This File Encryption Engine update adds&amp;nbsp;&lt;strong&gt;File Header Caching,&lt;/strong&gt;&amp;nbsp;to improve performance (enabled by default).&lt;/p&gt;
&lt;h1&gt;Resolved issues (already part of File Encryption Engine build 30)&lt;/h1&gt;
&lt;div class="content-scrollable-wrapper"&gt;
&lt;table class="content" cellspacing="1" cellpadding="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;Reference&lt;/th&gt;
&lt;th&gt;Symptom or Summary&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPFEE-1173&lt;/td&gt;
&lt;td&gt;Local cache corruptions during an update to Windows 10 October 2018 update (W10 version&amp;nbsp;&lt;code&gt;1809&lt;/code&gt;)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14307&lt;/td&gt;
&lt;td&gt;Explorer performance issues in combination with cached files from Windows Quick Access&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14462&lt;/td&gt;
&lt;td&gt;Increased saving time for files located on network locations (specific applications).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14525&lt;/td&gt;
&lt;td&gt;Access rights issues when running specific applications.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14639&lt;/td&gt;
&lt;td&gt;&lt;code&gt;Bluescreen Bugcheck 0x3b (SYSTEM_SERVICE_EXCEPTION)&lt;/code&gt;&amp;nbsp;on Windows 10 version&amp;nbsp;&lt;code&gt;1809&amp;nbsp;&lt;/code&gt;endpoints&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14511&lt;/td&gt;
&lt;td&gt;Performance improvements (boot and runtime)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14853&lt;/td&gt;
&lt;td&gt;Cannot open encrypted Quickbooks project (other applications potentially affected as well),&lt;br /&gt;when SafeGuard File Encryption filter driver is active.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14771&lt;br /&gt;DPSGN-14806&lt;br /&gt;DPSGN-14842&lt;/td&gt;
&lt;td&gt;Several boot performance improvements.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14995&lt;/td&gt;
&lt;td&gt;High performance impact when accessing files on network shares which are not covered by an encryption rule (requires BypassFilesWithoutPolicyVolumes registry key - see KB133022 for details).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14945&lt;/td&gt;
&lt;td&gt;User is unable to save file certain file types (e.g. docx, xlsx).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14987&lt;br /&gt;DPSGN-15016&lt;/td&gt;
&lt;td&gt;User gets file in use error when opening or saving xlsx files on network location.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14513&lt;/td&gt;
&lt;td&gt;License check of 3rd party application (Dataflex) fails - (requires BypassFilesWithoutPolicyVolumes registry key)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14856&lt;br /&gt;DPSGN-15051&lt;/td&gt;
&lt;td&gt;File Encryption driver slows down Windows explorer and search operations on network shares.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15186&lt;br /&gt;DPSGN-15188&lt;br /&gt;DPSGN-15189&lt;br /&gt;DPSGN-15190&lt;/td&gt;
&lt;td&gt;Important security fixes and improvements.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15245&lt;/td&gt;
&lt;td&gt;Files located on a WebDAV share, occasionally cannot be deleted when file encryption minifilter is active.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15014&lt;/td&gt;
&lt;td&gt;Compatibility improvements (requires additional registry modification)&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15265&lt;/td&gt;
&lt;td&gt;System might become unresponsive after re-inserting an encrypted optical media&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15261&lt;/td&gt;
&lt;td&gt;SGPortable.exe (and msvcr71.dll and msvcp71.dll) get encrypted by initial encryption&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15241&lt;/td&gt;
&lt;td&gt;SafeGuard Services not running after update to Windows 10 version 1903 (19H1). This only affects installations of File Encryption Engine build 26.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15209&lt;/td&gt;
&lt;td&gt;Compatibility improvement for Sophos Central Intercept X with EDR.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15267&lt;/td&gt;
&lt;td&gt;Potential file corruptions when creating PDFs from Catia (Dassault Syst&amp;egrave;mes).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15306&lt;/td&gt;
&lt;td&gt;File encryption filter removes SmartScreen block functionality from file properties.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15338&lt;/td&gt;
&lt;td&gt;Sporadic file corruptions when storing XLS files using Microsoft Office 2003 or 2007&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15014&lt;/td&gt;
&lt;td&gt;Generic improvements to prevent file locks during shutdown/restart.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15436&lt;/td&gt;
&lt;td&gt;Deleted encrypted files occasionally cannot be recovered and show huge size in recycle bin&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15441&lt;/td&gt;
&lt;td&gt;Bluescreen / BSOD (Bugcheck 0xd4) on endpoints with Xerox Docushare software installed&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15431&lt;/td&gt;
&lt;td&gt;Windows subsystem for linux no longer working (lxssmanager does not start) on Windows 10 version 1903 (19H1)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15454&lt;/td&gt;
&lt;td&gt;Bluescreen / BSOD SYSTEM_SERVICE_EXCEPTION (&lt;code&gt;Bugcheck 0x3b&lt;/code&gt;) when drag and drop is used for attachments (from MS Outlook to an encrypted folder)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15468,&lt;br /&gt;DPSGN-15472,&lt;br /&gt;DPSGN-15471,&lt;br /&gt;DPPSGN-15462&lt;/td&gt;
&lt;td&gt;3rd party software compatibility fixes for issues introduced in File Encryption Engine build 29&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;h1&gt;Download and installation&amp;nbsp;&amp;nbsp;&lt;/h1&gt;
&lt;p&gt;The installers for version 8.10.x (separate msp files for 32 and 64bit) can be obtained from this&amp;nbsp;&lt;a target="_blank"&gt;download link&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The installer for version 8.20.x / 8.30.x (one msp file which can be applied to all versions)&amp;nbsp; be obtained from this&amp;nbsp;&lt;a target="_blank"&gt;download link&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Installation for 32-bit OS&lt;/h2&gt;
&lt;h3&gt;If the SafeGuard Client is already installed&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Copy the installer patch files to the corresponding endpoint(s)&lt;/li&gt;
&lt;li&gt;Apply the SafeGuard File Encryption Engine update. Example (based on version 8.10):&amp;nbsp;&lt;code&gt;msiexec /update &amp;quot;C:\Install\File Encryption Engine for SGN 8.1 Build 31.msp&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Reboot the endpoint for the changes to take effect&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;Installation together with SafeGuard Client&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Copy the SafeGuard Client and the installer patch files to the corresponding endpoint(s)&lt;/li&gt;
&lt;li&gt;Install the SafeGuard Client together with the File Encryption Engine update. Example (based on version 8.10):&amp;nbsp;&lt;code&gt;msiexec /i C:\Install\SGNClient.msi PATCH=&amp;quot;C:\Install\File Encryption Engine for SGN 8.1 Build 31.msp&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Reboot the endpoint for the changes to take effect&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;Installation for 64-bit OS&lt;/h2&gt;
&lt;h3&gt;If the SafeGuard Client is already installed&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Copy the installer patch files to the corresponding endpoint(s)&lt;/li&gt;
&lt;li&gt;Apply the SafeGuard File Encryption Engine update. Example (based on version 8.10):&amp;nbsp;&lt;code&gt;msiexec /update &amp;quot;C:\Install\File Encryption Engine for SGN 8.1 Build 31_x64.msp&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Reboot the endpoint for the changes to take effect&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;Installation together with SafeGuard Client&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Copy the SafeGuard Client and the installer patch files to the corresponding endpoint(s)&lt;/li&gt;
&lt;li&gt;Install the SafeGuard Client together with the File Encryption Engine update. Example (based on version 8.10):&amp;nbsp;&lt;code&gt;msiexec /i C:\Install\SGNClient_x64.msi PATCH=&amp;quot;C:\Install\File Encryption Engine for SGN 8.1 Build 31_x64.msp&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Reboot the endpoint for the changes to take effect&lt;/li&gt;
&lt;/ol&gt;
&lt;h1&gt;How to verify if the patch is applied&lt;/h1&gt;
&lt;p&gt;After the installation, you can see the new File Encryption Engine in the&amp;nbsp;&lt;strong&gt;Installed Updates&amp;nbsp;&lt;/strong&gt;section of&amp;nbsp;&lt;strong&gt;Programs and Features&lt;/strong&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;As this package just contains new filter drivers and no other products components, this update does not change the version or build number of the installed SafeGuard Client. In the SafeGuard Management Center as of version 8.20, the file filter engine version of this update (3.0.0.38) is also listed in the installed features list of the Client.&lt;/p&gt;
&lt;h1&gt;Related information&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="/kb/en-us/133000" target="_blank"&gt;File Encryption Engine updates for SafeGuard 8.10.x/8.20/8.30&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="/kb/en-us/124771" target="_blank"&gt;SafeGuard Enterprise: Supported clients on Windows 10 versions&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=578&amp;AppID=23&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Jasmin</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/jasmin</uri></author><category term="safeguard Enterprise" scheme="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/archive/tags/safeguard%2bEnterprise" /><category term="Engine Build" scheme="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/archive/tags/Engine%2bBuild" /></entry><entry><title>Impact of LDAP Channel Binding and LDAP Signing Requirements on SafeGuard Enterprise</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/impact-of-ldap-channel-binding-and-ldap-signing-requirements-on-safeguard-enterprise" /><id>https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/impact-of-ldap-channel-binding-and-ldap-signing-requirements-on-safeguard-enterprise</id><published>2020-01-20T19:03:00Z</published><updated>2020-01-20T19:03:00Z</updated><content type="html">&lt;p&gt;Hi Community,&lt;/p&gt;
&lt;p&gt;In March 2020 Microsoft plans to release a security update on Windows Update that by default enables&amp;nbsp;&lt;strong&gt;LDAP channel binding&lt;/strong&gt;&amp;nbsp;and&amp;nbsp;&lt;strong&gt;LDAP signing&lt;/strong&gt;&amp;nbsp;hardening changes for Active Directory.&lt;br /&gt;Details and technical background of these changes are described in the Microsoft articles linked in the related information section of this KBA.&lt;/p&gt;
&lt;p&gt;When the security settings are enabled and the pre-conditions are not met, especially if SafeGuard Server and computers running the SafeGuard Management Center are not updated with the required Microsoft Security Updates (see&amp;nbsp;&lt;a href="https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8563" target="_blank"&gt;CVE-2017-8563&lt;/a&gt;), the SSL directory authentication does not work any longer.&lt;/p&gt;
&lt;p&gt;For SafeGuard this means that,&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;the Active Directory synchronization may fail with the error &amp;quot;&lt;em&gt;The user name or password is incorrect.&lt;/em&gt;&amp;quot;.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Creating a new Directory connection, using SSL, may fail with the error message &amp;quot;&lt;em&gt;The connection to the requested directory failed. Additional info: The user name or password is incorrect.&lt;/em&gt;&amp;quot;.&lt;/li&gt;
&lt;li&gt;Setting up the LDAP Authentication in the Management Center Wizard may fail with the error message &amp;quot;&lt;em&gt;The connection to the requested directory failed. Additional info: The user name or password is incorrect.&lt;/em&gt;&amp;quot;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Example error messages:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="/cfs-file/__key/communityserver-blogs-components-weblogfiles/00-00-00-00-23/pastedimage1579547303452v1.png"&gt;&lt;img src="/resized-image/__size/320x240/__key/communityserver-blogs-components-weblogfiles/00-00-00-00-23/pastedimage1579547303452v1.png" alt=" " /&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="/cfs-file/__key/communityserver-blogs-components-weblogfiles/00-00-00-00-23/pastedimage1579547303453v2.png"&gt;&lt;img src="/resized-image/__size/320x240/__key/communityserver-blogs-components-weblogfiles/00-00-00-00-23/pastedimage1579547303453v2.png" alt=" " /&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;h1&gt;What to do&lt;/h1&gt;
&lt;p&gt;Ensure that all involved computers are patched with the relevant Microsoft security update for&amp;nbsp;&lt;a href="https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8563" target="_blank"&gt;CVE-2017-8563&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Alternatively you can:&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Disable SSL for the AD connection in the SafeGuard Management Center (not recommended).&lt;/li&gt;
&lt;li&gt;Disable this security setting to switch back to the previous behavior (not recommended).&lt;br /&gt;To explicitly disable the setting, set the&amp;nbsp;&lt;strong&gt;LdapEnforceChannelBinding&amp;nbsp;&lt;/strong&gt;entry to 0 (zero). Details are described in the Microsoft articles, linked in the related information section of this KBA.&lt;/li&gt;
&lt;/ul&gt;
&lt;h1&gt;&lt;a id="related information" name="related information"&gt;&lt;/a&gt;Related information&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft:&amp;nbsp;&lt;a href="https://support.microsoft.com/en-ca/help/4520412/2020-ldap-channel-binding-and-ldap-signing-requirement-for-windows" target="_blank"&gt;2020 LDAP channel binding and LDAP signing requirement for Windows&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft:&amp;nbsp;&lt;a href="https://support.microsoft.com/en-us/help/4034879/how-to-add-the-ldapenforcechannelbinding-registry-entry" target="_blank"&gt;Use the LdapEnforceChannelBinding registry entry to make LDAP authentication over SSL/TLS more secure&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft:&amp;nbsp;&lt;a href="https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/ldap-channel-binding-and-ldap-signing-requirements-update-now/ba-p/921536" target="_blank"&gt;LDAP Channel Binding and LDAP Signing Requirements - Update now scheduled for March 2020&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="/kb/en-us/119605" target="_blank"&gt;Configuring the SafeGuard Enterprise Management Center to establish a LDAP over SSL (LDAPS) connection to the Active Directory&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Sign up to the Sophos Support&amp;nbsp;&lt;a href="https://sms.sophos.com/login" target="_blank"&gt;SMS Notification Service&lt;/a&gt;&amp;nbsp;to get the latest product release information and critical issues.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note: &lt;/strong&gt;Information&amp;nbsp;above&amp;nbsp;taken from&amp;nbsp;&lt;a href="/kb/en-us/135029"&gt;KBA&amp;nbsp;135029&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=539&amp;AppID=23&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>FloSupport</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/flosupport</uri></author></entry><entry><title>Safeguard Enterprise v8.30 Release Notes</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-enterprise-v8-30-is-now-live" /><link rel="enclosure" type="text/html; charset=utf-8" length="126979" href="https://community.sophos.com/kb/en-us/134612" /><id>https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-enterprise-v8-30-is-now-live</id><published>2019-11-28T17:14:00Z</published><updated>2019-11-28T17:14:00Z</updated><content type="html">&lt;p&gt;Hi Community,&lt;/p&gt;
&lt;p&gt;Safeguard Enterprise v8.30 has been released.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt;&amp;nbsp;This version supports Mac OS 10.15 (Catalina).&lt;/p&gt;
&lt;h1&gt;Requirements&lt;/h1&gt;
&lt;div class="content-scrollable-wrapper"&gt;
&lt;table class="content" cellspacing="1" cellpadding="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;Platforms supported&lt;/th&gt;
&lt;th&gt;32 bit&lt;/th&gt;
&lt;th&gt;64 bit&lt;/th&gt;
&lt;th&gt;Recommended&lt;br /&gt;available&lt;br /&gt;disk space&lt;/th&gt;
&lt;th&gt;Recommended&lt;br /&gt;minimum&lt;br /&gt;RAM&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th colspan="5"&gt;SafeGuard Client (Windows)&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Windows 8.1&lt;br /&gt;Pro, Enterprise Edition&lt;/th&gt;
&lt;td&gt;&lt;img id="pastedimage1576536325830v1" class="mceItem mceInsertMediaItem mceInsertMediaItem mceInsertMediaItemImage" style="width:13px;height:13px;" src="/tinymce/plugins/media../../../telligent/img/trans.gif" alt=" " /&gt;&lt;/td&gt;
&lt;td&gt;&lt;img id="pastedimage1576536325830v2" class="mceItem mceInsertMediaItem mceInsertMediaItem mceInsertMediaItemImage" style="width:13px;height:13px;" src="/tinymce/plugins/media../../../telligent/img/trans.gif" alt=" " /&gt;&lt;/td&gt;
&lt;td&gt;100MB&lt;/td&gt;
&lt;td&gt;2GB*&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;&lt;a href="/kb/en-us/124771" target="_blank"&gt;Windows 10 RS3&lt;/a&gt;,&amp;nbsp;&lt;a href="/kb/en-us/124771" target="_blank"&gt;Windows 10 RS4&lt;/a&gt;,&amp;nbsp;&lt;strong&gt;&lt;a href="/kb/en-us/124771" target="_blank"&gt;Windows 10 RS5&lt;/a&gt;,&amp;nbsp;&lt;a href="/kb/en-us/124771" target="_blank"&gt;Windows 10 19H1&lt;/a&gt;,&amp;nbsp;&lt;a href="/kb/en-us/124771" target="_blank"&gt;Windows 10 19H2&lt;/a&gt;&lt;/strong&gt;&lt;br /&gt;Pro, Enterprise, Education&lt;br /&gt;&lt;br /&gt;Windows 10 Enterprise 2015 LTSB, Windows 10 Enterprise 2016 LTSB, Windows 10 Enterprise LTSC 2019&lt;/th&gt;
&lt;td&gt;&lt;img id="pastedimage1576536325830v3" class="mceItem mceInsertMediaItem mceInsertMediaItem mceInsertMediaItemImage" style="width:13px;height:13px;" src="/tinymce/plugins/media../../../telligent/img/trans.gif" alt=" " /&gt;&lt;/td&gt;
&lt;td&gt;&lt;img id="pastedimage1576536325831v4" class="mceItem mceInsertMediaItem mceInsertMediaItem mceInsertMediaItemImage" style="width:13px;height:13px;" src="/tinymce/plugins/media../../../telligent/img/trans.gif" alt=" " /&gt;&lt;/td&gt;
&lt;td&gt;100MB&lt;/td&gt;
&lt;td&gt;2GB*&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th colspan="5"&gt;SafeGuard Client (Mac OS X)&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;&lt;strong&gt;Mac OS High Sierra (OS X 10.13)&lt;/strong&gt;&lt;/th&gt;
&lt;td&gt;&amp;nbsp;&lt;/td&gt;
&lt;td&gt;&lt;img id="pastedimage1576536325831v5" class="mceItem mceInsertMediaItem mceInsertMediaItem mceInsertMediaItemImage" style="width:13px;height:13px;" src="/tinymce/plugins/media../../../telligent/img/trans.gif" alt=" " /&gt;&lt;/td&gt;
&lt;td&gt;100MB&amp;nbsp;&lt;/td&gt;
&lt;td&gt;4GB*&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;&lt;strong&gt;Mac OS Mojave (OS X 10.14)&lt;/strong&gt;&lt;/th&gt;
&lt;td&gt;&amp;nbsp;&lt;/td&gt;
&lt;td&gt;&lt;img id="pastedimage1576536325831v6" class="mceItem mceInsertMediaItem mceInsertMediaItem mceInsertMediaItemImage" style="width:13px;height:13px;" src="/tinymce/plugins/media../../../telligent/img/trans.gif" alt=" " /&gt;&lt;/td&gt;
&lt;td&gt;100MB&amp;nbsp;&lt;/td&gt;
&lt;td&gt;8GB*&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;&lt;strong&gt;Mac OS Catalina (OS X 10.15)&lt;/strong&gt;&lt;/th&gt;
&lt;td&gt;&amp;nbsp;&lt;/td&gt;
&lt;td&gt;&lt;img id="pastedimage1576536325831v7" class="mceItem mceInsertMediaItem mceInsertMediaItem mceInsertMediaItemImage" style="width:13px;height:13px;" src="/tinymce/plugins/media../../../telligent/img/trans.gif" alt=" " /&gt;&lt;/td&gt;
&lt;td&gt;100MB&amp;nbsp;&lt;/td&gt;
&lt;td&gt;8GB*&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th colspan="5"&gt;SafeGuard Management Center&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Windows 8.1&lt;br /&gt;Pro, Enterprise Edition&lt;/th&gt;
&lt;td&gt;&lt;img id="pastedimage1576536325831v8" class="mceItem mceInsertMediaItem mceInsertMediaItem mceInsertMediaItemImage" style="width:13px;height:13px;" src="/tinymce/plugins/media../../../telligent/img/trans.gif" alt=" " /&gt;&lt;/td&gt;
&lt;td&gt;&lt;img id="pastedimage1576536325831v9" class="mceItem mceInsertMediaItem mceInsertMediaItem mceInsertMediaItemImage" style="width:13px;height:13px;" src="/tinymce/plugins/media../../../telligent/img/trans.gif" alt=" " /&gt;&lt;/td&gt;
&lt;td&gt;1GB&lt;/td&gt;
&lt;td&gt;1GB*&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;&lt;a href="/kb/en-us/124771" target="_blank"&gt;Windows 10 RS3&lt;/a&gt;,&amp;nbsp;&lt;a href="/kb/en-us/124771" target="_blank"&gt;Windows 10 RS4&lt;/a&gt;,&amp;nbsp;&lt;a href="/kb/en-us/124771" target="_blank"&gt;Windows 10 RS5&lt;/a&gt;,&amp;nbsp;&lt;a href="/kb/en-us/124771" target="_blank"&gt;Windows 10 19H1&lt;/a&gt;,&amp;nbsp;&lt;a href="/kb/en-us/124771" target="_blank"&gt;Windows 10 19H2&lt;/a&gt;&lt;br /&gt;Pro, Enterprise, Education&lt;br /&gt;&lt;br /&gt;Windows 10 Enterprise 2015 LTSB,&amp;nbsp;Windows 10 Enterprise 2016 LTSB,&amp;nbsp;Windows 10 Enterprise LTSC 2019&lt;/th&gt;
&lt;td&gt;&lt;img id="pastedimage1576536325832v10" class="mceItem mceInsertMediaItem mceInsertMediaItem mceInsertMediaItemImage" style="width:13px;height:13px;" src="/tinymce/plugins/media../../../telligent/img/trans.gif" alt=" " /&gt;&lt;/td&gt;
&lt;td&gt;&lt;img id="pastedimage1576536325832v11" class="mceItem mceInsertMediaItem mceInsertMediaItem mceInsertMediaItemImage" style="width:13px;height:13px;" src="/tinymce/plugins/media../../../telligent/img/trans.gif" alt=" " /&gt;&lt;/td&gt;
&lt;td&gt;1GB&lt;/td&gt;
&lt;td&gt;1GB*&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Windows Server 2012 / Server 2012 R2&lt;/th&gt;
&lt;td&gt;&amp;nbsp;&lt;/td&gt;
&lt;td&gt;&lt;img id="pastedimage1576536325832v12" class="mceItem mceInsertMediaItem mceInsertMediaItem mceInsertMediaItemImage" style="width:13px;height:13px;" src="/tinymce/plugins/media../../../telligent/img/trans.gif" alt=" " /&gt;&lt;/td&gt;
&lt;td&gt;1GB&lt;/td&gt;
&lt;td&gt;2GB*&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Windows Server 2016&amp;nbsp;&lt;/th&gt;
&lt;td&gt;&amp;nbsp;&lt;/td&gt;
&lt;td&gt;&lt;img id="pastedimage1576536325832v13" class="mceItem mceInsertMediaItem mceInsertMediaItem mceInsertMediaItemImage" style="width:13px;height:13px;" src="/tinymce/plugins/media../../../telligent/img/trans.gif" alt=" " /&gt;&lt;/td&gt;
&lt;td&gt;1GB&lt;/td&gt;
&lt;td&gt;2GB*&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Windows Server 2019&lt;/th&gt;
&lt;td&gt;&amp;nbsp;&lt;/td&gt;
&lt;td&gt;&lt;img id="pastedimage1576536325832v14" class="mceItem mceInsertMediaItem mceInsertMediaItem mceInsertMediaItemImage" style="width:13px;height:13px;" src="/tinymce/plugins/media../../../telligent/img/trans.gif" alt=" " /&gt;&lt;/td&gt;
&lt;td&gt;2GB&lt;/td&gt;
&lt;td&gt;4GB*&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th colspan="5"&gt;SafeGuard Enterprise Server&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Windows Server 2012 / Server 2012 R2&lt;/th&gt;
&lt;td&gt;&amp;nbsp;&lt;/td&gt;
&lt;td&gt;&lt;img id="pastedimage1576536325832v15" class="mceItem mceInsertMediaItem mceInsertMediaItem mceInsertMediaItemImage" style="width:13px;height:13px;" src="/tinymce/plugins/media../../../telligent/img/trans.gif" alt=" " /&gt;&lt;/td&gt;
&lt;td&gt;1GB&lt;/td&gt;
&lt;td&gt;2GB*&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Windows Server 2016&lt;/th&gt;
&lt;td&gt;&amp;nbsp;&lt;/td&gt;
&lt;td&gt;&lt;img id="pastedimage1576536325832v16" class="mceItem mceInsertMediaItem mceInsertMediaItem mceInsertMediaItemImage" style="width:13px;height:13px;" src="/tinymce/plugins/media../../../telligent/img/trans.gif" alt=" " /&gt;&lt;/td&gt;
&lt;td&gt;1GB&lt;/td&gt;
&lt;td&gt;2GB*&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Windows Server 2019&lt;/th&gt;
&lt;td&gt;&amp;nbsp;&lt;/td&gt;
&lt;td&gt;&lt;img id="pastedimage1576536325832v17" class="mceItem mceInsertMediaItem mceInsertMediaItem mceInsertMediaItemImage" style="width:13px;height:13px;" src="/tinymce/plugins/media../../../telligent/img/trans.gif" alt=" " /&gt;&lt;/td&gt;
&lt;td&gt;2GB&lt;/td&gt;
&lt;td&gt;4GB*&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;p&gt;Windows Small Business Server and Windows Server Essentials are not supported.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;* Not all of this memory is used by SafeGuard Enterprise.&lt;/p&gt;
&lt;h1&gt;&lt;a id="Windows (Client and Backend)" name="Windows (Client and Backend)"&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;h1&gt;Windows (Client and Backend)&lt;/h1&gt;
&lt;h2&gt;Client&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Internet Explorer Version 10 or higher&lt;/li&gt;
&lt;li&gt;Supported Web browsers for password encrypted files are MS Internet Explorer 11, MS Edge (Windows), Chrome (Windows, Android, OS X), Firefox (Windows, Android, OS X) and Opera (Windows, Android, OS X)&lt;/li&gt;
&lt;li&gt;.NET Framework 4.5&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;a id="Windows Server/Management Center" name="Windows Server/Management Center"&gt;&lt;/a&gt;Server/Management Center&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;.NET Framework 4.5&lt;/li&gt;
&lt;li&gt;Internet Explorer Version 10 or higher&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;SafeGuard Database&lt;/h2&gt;
&lt;p&gt;The supported SQL Server versions can be found&amp;nbsp;&lt;a href="/kb/en-us/112780" target="_blank"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;&lt;a id="Noticeable changes" name="Noticeable changes"&gt;&lt;/a&gt;Noticeable Changes / New Features&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Added support for macOS 10.15 (Catalina)&lt;/li&gt;
&lt;li&gt;Added support for Windows 10 November 2019 Update (also known as Windows 10 19H2, Windows 10 version 1909)&lt;/li&gt;
&lt;li&gt;Encryption keys of a machine with a Sophos endpoint that supports reporting a health state, can now also be automatically removed when using Location Based Encryption.&lt;/li&gt;
&lt;li&gt;It is now possible for a security officer that has been promoted from Active Directory to authenticate and allow an action when additional officer authentication has been defined.&lt;/li&gt;
&lt;li&gt;The &amp;ldquo;About&amp;rdquo; box now shows the installed modules and the versions of the driver and the modules.&lt;/li&gt;
&lt;li&gt;BitLocker Password Protector can now also be configured as primary logon method.&lt;/li&gt;
&lt;li&gt;Changes in the HTML5 Wrapper (&amp;ldquo;Password Protect a File&amp;rdquo;)
&lt;ul&gt;
&lt;li&gt;Supports putting more than one file in one HTML5 encrypted file&lt;/li&gt;
&lt;li&gt;Password rules are now displayed&lt;/li&gt;
&lt;li&gt;Support for Safari&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;OpenSSL components are upgraded to version 1.1.1&lt;/li&gt;
&lt;li&gt;Bitlocker Challenge/Response module has been removed&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Improved Outlook Add-In (32bit MS Outlook only)&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;a id="Known Issues" name="Known Issues"&gt;&lt;/a&gt;Known Issues&lt;/h2&gt;
&lt;h3&gt;&lt;a id="KI SafeGuard Management Center" name="KI SafeGuard Management Center"&gt;&lt;/a&gt;SafeGuard Management Center&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;There are some GUI layout problems on machines configured for resolutions other than 96 DPI.&lt;/li&gt;
&lt;li&gt;Management Console log events may not be created when calling similar functionality concurrently via the SafeGuard&amp;nbsp;API.&lt;/li&gt;
&lt;li&gt;Clients which have been registered as members of a domain, will not be updated properly in the SafeGuard Management Center, if they are moved to a Windows Workgroup.&lt;/li&gt;
&lt;li&gt;Starting a new remote desktop session to a computer where a Management Center or Server upgrade is in progress will cause the upgrade to fail. The new remote desktop session will execute RunOnce registry entries to delete the Local Cache and the SafeGuard registry entries.&lt;/li&gt;
&lt;li&gt;User auto-registration of SafeGuard 6.0 Clients.&lt;br /&gt;When the SafeGuard&amp;nbsp;Client has version 6.0 and users log on using the format name@domain or domain\name, then auto-registration of these users leads to a problem with the Active Directory synchronization later. Instead of moving the auto-registered user to the correct organizational unit, the Active Directory synchronization instead will generate a duplicate user object. This issue can be solved by importing new users into the Management Center before they do their first logon on the Client.&amp;nbsp;Another workaround would be to correct the pre-Windows 2000 user name of the user in the auto-registered folder in the Management Center (via Context Menu &amp;gt; Properties). If a duplicate user object already exists, the one imported from Active Directory should be deleted.&lt;/li&gt;
&lt;li&gt;When&amp;nbsp;the database schema is automatically upgraded during the first start of an upgraded Management Center, a backup is created. If there is an automatic backup scheduled, this needs to be adapted again afterwards. DPSGN-4728&lt;/li&gt;
&lt;li&gt;File Encryption policies still offers &amp;lt;Program Files&amp;gt; as placeholder, this is in there for compatibility reasons with older clients, but will no longer have an effect for SafeGuard 8.1 or newer Clients. DPSGN-13725&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;a id="KI SafeGuard Enterprise Server" name="KI SafeGuard Enterprise Server"&gt;&lt;/a&gt;SafeGuard Enterprise Server&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;A reboot is required before re-installing the SafeGuard Server&lt;br /&gt;Although there is no explicit message to do so, a reboot is required after uninstalling SafeGuard Server components and before reinstalling them. (DEF49516)&lt;/li&gt;
&lt;li&gt;The method&amp;nbsp;&lt;strong&gt;CreateDirectoryConnection&lt;/strong&gt;&amp;nbsp;does not run on a SafeGuard&amp;nbsp;Server alone. The machine must also have the SafeGuard&amp;nbsp;Management Console installed for this API.&lt;/li&gt;
&lt;li&gt;Slow upgrade process of SafeGuard Server and Management Center. DPSGN-3884&lt;br /&gt;The upgrade of the SafeGuard Server and Management Center may take a long time. Do not cancel or interrupt the upgrade process.&lt;/li&gt;
&lt;li&gt;When using Internet Explorer on a Server 2016 / 2019 to open the WebHelpDesk Website, it needs to be ensured that&amp;nbsp;https://&amp;lt;servername&amp;gt;&amp;quot; and/or &amp;quot;https://&amp;lt;server IP&amp;gt;&amp;quot; are added to the &amp;quot;Trusted sites&amp;quot;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;a id="KI SafeGuard Data Exchange Client" name="KI SafeGuard Data Exchange Client"&gt;&lt;/a&gt;SafeGuard Data Exchange Client&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Not all options are shown when operating a device as&amp;nbsp;&lt;strong&gt;Portable Device&lt;/strong&gt;.&lt;br /&gt;When operating a removable media in&amp;nbsp;&lt;strong&gt;Portable Device&lt;/strong&gt;&amp;nbsp;mode, some of the options of SafeGuard DX are not available in Windows Explorer. Overlay icons indicating a file&amp;#39;s encryption status are missing as well as the menu option introduced by SafeGuard DX in a file&amp;#39;s context menu. Nevertheless any applicable encryption policy is enforced for files that reside on the removable device, regardless whether it is referenced via the&amp;nbsp;&lt;strong&gt;Portable Device&lt;/strong&gt;&amp;nbsp;tree or the assigned drive letter.&lt;/li&gt;
&lt;li&gt;User elevation for encrypted executable.&lt;br /&gt;If an encrypted executable or installation package is started and requires a user elevation, it may happen that the elevation doesn&amp;#39;t take place and the executable is not started.&lt;/li&gt;
&lt;li&gt;Access to key ring after closing a remote session (RDP).&lt;br /&gt;A user&amp;#39;s key ring is no longer accessible after an established remote session has been closed. The client machine has to be rebooted in order to restore full access to the user&amp;#39;s key ring. Just logging off and on is not sufficient to regain access to the key ring.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;a id="KI SafeGuard Synchronized Encryption" name="KI SafeGuard Synchronized Encryption"&gt;&lt;/a&gt;SafeGuard Synchronized Encryption&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;SafeGuard Outlook Add-in&lt;/strong&gt;: When sending more than one encrypted file (for example, textfile.txt and spreadsheet.xls) the file contents could get interchanged. The Texfile.txt includes the Excel content and spreadsheet.xls includes the textfile content. DPSGN-7503&lt;br /&gt;This issue can be avoided by installing the recommended MS Office Updates.&lt;br /&gt;Update for Microsoft Outlook 2010 (KB3114570) 32-Bit Edition --&amp;gt; Microsoft Outlook 2010 (14.0.7165.5000) SP2 MSO (14.0.7165.5000).&lt;br /&gt;Update for Microsoft Outlook 2010 (KB3114756) --&amp;gt; Microsoft Outlook 2010 (14.0.7166.5000) SP2 MSO (14.0.7166.5000).&lt;/li&gt;
&lt;li&gt;Under certain circumstances the Outlook Add-In might take to long to load and automatically gets disabled by Outlook.&lt;/li&gt;
&lt;li&gt;Files do not get encrypted when uploaded using the&amp;nbsp;&lt;strong&gt;Send to Dropbox&lt;/strong&gt;&amp;nbsp;option of the context menu. This happens, because the application that performs the upload (Dropbox.exe) is configured as ignored application and therefore the file encryption status does not change. DPSGN-6326&lt;/li&gt;
&lt;li&gt;Defining web browsers as&amp;nbsp;&lt;strong&gt;in&lt;/strong&gt;&amp;nbsp;application is not recommended. Because of the variety of existing browsers and their plugins this might cause compatibility issues. DPSGN-9673&lt;/li&gt;
&lt;li&gt;Encryption of files fails in a&amp;nbsp;&lt;strong&gt;OneDrive&lt;/strong&gt;&amp;nbsp;synchronization folder if a new file is created using the Windows Explorer Extension (for example, right mouse click|New|Microsoft Word Document|). DPSGN-6091&lt;/li&gt;
&lt;li&gt;Using ZIP files in Office documents.&lt;br /&gt;If a ZIP archive included in an encrypted Office Document, is moved out of the document it will contain plain files, regardless of encryption policy. Reason: When a ZIP file is&amp;nbsp;&lt;strong&gt;drag and dropped&amp;nbsp;&lt;/strong&gt;into, for example MS Word, then the ZIP file will be read by Word and therefore it is unencrypted in Word. When the ZIP file later on is drag and dropped out from Word into a directory, Win Explorer (not authenticated application) takes over and the file will be created unencrypted. Workaround: Encrypt the file manually (context menu of the file). DPSGN-9179&lt;/li&gt;
&lt;li&gt;Password encryption / decryption with MS Edge browser is not working on Windows computers with a single core processor.&lt;/li&gt;
&lt;li&gt;In MS Office documents embedded objects (for example, MS Excel objects in MS Word) requires the definition of the corresponding application as&amp;nbsp;&lt;strong&gt;in&lt;/strong&gt;&amp;nbsp;application as well. DPSGN-7085&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;a id="KI SafeGuard File Encryption" name="SafeGuard File Encryption"&gt;&lt;/a&gt;SafeGuard File Encryption&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;EFS is not supported. The EFS attribute can neither be set nor removed from files or folders and access to EFS encrypted files is denied. DPFEE-1149&lt;/li&gt;
&lt;li&gt;Encrypted MS Office files stored on SharePoint get decrypted when they are modified. DPSGN-13628&lt;/li&gt;
&lt;li&gt;NTFS Compression is not supported, files will be automatically decompressed.&lt;/li&gt;
&lt;li&gt;Sophos recommends the use of SSD drives for best possible performance.&lt;/li&gt;
&lt;li&gt;SafeGuard file encryption modules are not compatible with MarkAny&amp;#39;s file filter driver cbfltfs.sys. Using both products together can result in BSODs or a not starting operating system.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;UAC virtualization is not supported, which can result in compatibility issues with 3rd party software (applies to all file encryption modules).&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;a id="KI General" name="KI General"&gt;&lt;/a&gt;General&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Fast user switching is not supported and must be disabled.&lt;/li&gt;
&lt;li&gt;The Windows 10 feature&amp;nbsp;&lt;strong&gt;Improved Boot Up Experience&lt;/strong&gt;&amp;nbsp;is not supported and can cause several issues on clients that are part of a workgroup, it therefore needs to be disabled see&amp;nbsp;&lt;a href="/kb/en-us/128152" target="_blank"&gt;SafeGuard File Encryption, SafeGuard BitLocker Client: Login to SafeGuard Credential Provider fails to unlock the User&amp;#39;s keyring on Windows 10 (version 1709) when the machine is part of a Workgroup&lt;/a&gt;&amp;nbsp;for details.&lt;/li&gt;
&lt;li&gt;Direct modifications to the original Sophos product MSI Installer Packages are not supported.&amp;nbsp;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;SafeGuard 6.0 Clients cannot auto-register new users who log in with an alternate user principle name (UPN) suffix. It is recommended to use NetBIOS usernames on SafeGuard 6.0 Clients or older.&lt;/li&gt;
&lt;li&gt;Internet Explorer Warning when downloading SGPortable&lt;br /&gt;SafeGuard Cloud Storage automatically uploads SGPortable.exe to the Cloud. However, if downloaded with Internet Explorer, its Smart Screen Filter may block the download. Please ignore the warning, that SGPortable.exe is not trusted and accept the download anyway. After download SGPortable.exe reports that MSVCP71.dll is missing. Downloading this DLL from the internet will finally resolve the problem.&lt;/li&gt;
&lt;li&gt;SafeGuard Enterprise is not fully compatible to using Windows accounts with an empty password. If a computer is member of a workgroup (i.e. not in a domain) and the last user tile on the logon screen represents a user with an empty password at all, any password entered in the Safeguard credential provider for this user will successfully log on this user. Moreover, if a wrong password is entered for a different user, this can result in the user with the empty password being logged on instead of the selected user.&lt;/li&gt;
&lt;li&gt;The SafeGuard Credential Provider used to logon to the OS offers &amp;nbsp;&lt;strong&gt;Username&lt;/strong&gt;&amp;nbsp;and&amp;nbsp;&lt;strong&gt;Password&lt;/strong&gt;&amp;nbsp;fields in the&amp;nbsp;&lt;strong&gt;Set up a PIN&lt;/strong&gt;&amp;nbsp;dialog on Windows 10. Workaround: Use the SafeGuard Token tile for logon with Token. DPSGN-5823&lt;/li&gt;
&lt;li&gt;File Tracking events are note reported when writing files on optical media fails, if the medium is burned in mastered mode. The File Tracking feature supports the&amp;nbsp;&lt;strong&gt;Live File System&lt;/strong&gt;&amp;nbsp;format only and not the&amp;nbsp;&lt;strong&gt;Mastered Disc Format&lt;/strong&gt;.&amp;nbsp;&amp;nbsp;DPSGN-9709&lt;/li&gt;
&lt;li&gt;BitLocker recovery keys are not rotated after use if the recovery is not done using the Management Center or WebHelpDesk (for example, using Sophos Secure Workspace). DPSGN-9902&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;a id="KI Compatibility" name="KI Compatibility"&gt;&lt;/a&gt;Compatibility&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Sophos SafeGuard LAN Crypt is not compatible with SafeGuard 8.3.&lt;/li&gt;
&lt;li&gt;Synchronization of keyring is possible with Sophos Mobile Control 8.0 an newer versions (requires at least Sophos Secure Workspace 8.5 on the mobile device).&lt;/li&gt;
&lt;li&gt;Synchronization of BitLocker recovery keys requires at least Sophos Mobile Control 8.0.&lt;/li&gt;
&lt;li&gt;SafeGuard Enterprise has not been tested in conjunction with an installed Novell Client for Windows. Restrictions may apply as there is no intercommunication between the logon components of both products.&lt;/li&gt;
&lt;li&gt;AbsoluteSoftware Computrace.&lt;br /&gt;SafeGuard Device Encryption fails to install on machines which have AbsoluteSoftware Computrace with activated&amp;nbsp;&lt;strong&gt;track-0 based persistent agent&lt;/strong&gt;&amp;nbsp;installed.&lt;/li&gt;
&lt;li&gt;Compatibility to imaging tools has not been tested and is therefore not supported by Sophos.&lt;/li&gt;
&lt;li&gt;Windows Defender: The Controlled Folder Access feature is not supported and can interfere with SafeGuard.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;BitLocker Management is not supported on Apple&amp;#39;s Boot Camp&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;a id="KI Token/Smart card" name="KI Token/Smart card"&gt;&lt;/a&gt;Token/Smart card&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Disconnecting an USB smartcard reader is not detected properly when using the Gemalto .NET smartcard middleware.&lt;br /&gt;In this case, the desktop will not be locked automatically. This does not apply to pulling the smartcard from the reader, which works as expected. (DEF66637)&lt;/li&gt;
&lt;li&gt;Smart Card/Token PIN with special characters does not work with some middlewares (DPSGN-3674).&lt;br /&gt;Defining a PIN that contains special characters (for example, &amp;auml;, &amp;uuml;, &amp;ouml;) might lead to issues with several middlewares.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;a id="KI Not supported" name="KI Not supported"&gt;&lt;/a&gt;Not supported&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;The SafeGuard Client does not support logon with Microsoft accounts (formally known as Windows Live ID).&lt;/li&gt;
&lt;li&gt;The SafeGuard Client does not support the Windows 8.1 / Windows 10 logon methods like PIN and Picture, MS Hello, Virtual Smartcards, MS Passport, etc.&lt;/li&gt;
&lt;li&gt;Microsoft Azure based SQL database and Azure based Active Directory&lt;/li&gt;
&lt;li&gt;If BitLocker is managed by SafeGuard, it is not allowed to manage it in parallel via MBAM (Microsoft BitLocker Administration and Monitoring), the manage-bde command line tool, Group Policies (besides the settings listed in the ReleaseNotes) or the Windows Control Panel.&lt;/li&gt;
&lt;li&gt;Only the Bitlocker Logon modes listed in the authentication policy in the Management Center are supported.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;The BitLocker C/R dialog in UEFI cannot be used with touch screens as it has no on-screen keyboard. The dialog has to be used with a physical keyboard.&lt;/li&gt;
&lt;li&gt;When storing the BitLocker startup key on a SafeGuard Data Exchange (DX) encrypted USB stick, then it won&amp;#39;t be possible to use it to unlock the boot volume. This is because the unlock is executed before Windows starts and at this phase no DX filter driver for decryption of the key exists.&lt;/li&gt;
&lt;li&gt;The fingerprint reader Validity VFS5011 is not supported by the SafeGuard Client for logon.&lt;/li&gt;
&lt;li&gt;Defining File Encryption rules for a domain DFS is not possible.&lt;/li&gt;
&lt;li&gt;The encryption of files in a Box cloud storage folder is no longer possible due to changes in the Box client. DPSGN-14331&lt;/li&gt;
&lt;li&gt;Google Drive file stream is not supported. The local file cache location must be excluded from file encryption to avoid data corruption. DPSGN-15116&lt;/li&gt;
&lt;li&gt;The auto-detection of OneDrive / OneDrive for Business as Cloud Storage provider does not work in the latest versions of Onedrive. A workaround is described in&amp;nbsp;&lt;a href="/kb/en-us/125710"&gt;KB125710&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;a id="KI Limitations" name="KI Limitations "&gt;&lt;/a&gt;Limitations&amp;nbsp;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;BitLocker configuration via GPOs.&lt;br /&gt;Only BitLocker group policies settings (GPOs) mentioned below, should be configured if BitLocker is managed by SafeGuard. Required settings are automatically applied during the installation of the client.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Require additional authentication at startup&lt;/li&gt;
&lt;li&gt;Allow BitLocker without a compatible TPM&lt;/li&gt;
&lt;li&gt;Enable use of BitLocker authentication requiring pre-boot keyboard input on slates&lt;/li&gt;
&lt;li&gt;Configure minimum PIN length for startup&lt;/li&gt;
&lt;li&gt;Turn on TPM backup to Active Directory Domain Services&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;All other BitLocker group policies must be left to default. Otherwise they might be overruled by SafeGuard policies or even lead to conflicts with the SafeGuard BitLocker management.&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;When enabling the SafeGuard policy&amp;nbsp;&lt;strong&gt;BitLocker Logon mode&lt;/strong&gt;&amp;nbsp;with the setting&amp;nbsp;&lt;strong&gt;TPM + PIN&lt;/strong&gt;&amp;nbsp;(default), consider that tablet PCs require an external keyboard to enter the TPM PIN during Pre-Boot phase. The on screen keyboard cannot be used to enter the PIN. It is recommended to use a TPM only policy for such devices.&lt;/li&gt;
&lt;li&gt;BitLocker encryption dialog keeps reappearing on Windows Slate computers (for example, MS Surface Pro 5) - DPSGN-3922&lt;br /&gt;On Windows Slate computers, the BitLocker encryption dialog keeps reappearing and encryption does not start. This occurs when the group policy setting&amp;nbsp;&lt;strong&gt;Enable use of BitLocker authentication requiring pre-boot keyboard input on slates&lt;/strong&gt;&amp;nbsp;is not set and TPM+PIN or password authentication is mandated by the authentication policy. Enabling the group policy setting or changing the authentication policy resolves this issue.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Virtualization platform support.&lt;br /&gt;The SafeGuard Client only supports VMware Workstation and Player as virtualization platform. All other platforms like VMware ESX/ESXi Server, Microsoft Virtual PC, Microsoft Hyper-V are not supported. VirtualBox is incompatible with SafeGuard 8.3 and might cause BSODs (IRQL_NOT_LESS_OR_EQUAL).&lt;/li&gt;
&lt;li&gt;Takeover of BitLocker data drives in standalone mode&lt;br /&gt;When the SafeGuard Client is run in standalone mode, then already encrypted BitLocker data drives are taken over in the moment when the client config package is applied. In order that this can succeed, all data drives must be unlocked before the client config package is applied. Locked data drives are ignored which means that their recovery password won&amp;#39;t be written to the key backup file.&lt;/li&gt;
&lt;li&gt;Rotation of the recovery password.&lt;br /&gt;The recovery password is changed automatically for managed clients once a recovery is executed. For standalone clients the recovery password remains unchanged after a recovery, but it can be changed manually be uninstalling the client config package and installing it again.&lt;/li&gt;
&lt;li&gt;Windows 8.1 / Windows 10&amp;nbsp;&lt;strong&gt;fast startup&lt;/strong&gt;&amp;nbsp;option affects some behavior of SafeGuard Enterprise&lt;br /&gt;If the new Fast startup option in Windows 8.1 and higher is turned on as Microsoft recommends, some behavior in SafeGuard Enterprise is affected. For system services like the SafeGuard Authentication service the fast startup is technically seen identical with hibernation. So all SafeGuard Enterprise functionality triggered by the boot process is affected and needs a restart instead of shutdown/boot. One example is the registration of new users as SafeGuard user during first Windows logon after machine boot process. In order to have the self-enrollment enabled upon next boot a warm-boot has to be initiated or a complete shutdown/cold-boot has to be forced.&lt;/li&gt;
&lt;li&gt;According to the recommendation of Intel, also Sophos recommends, to disable Intel Rapid Start Technology when using software-based encryption.&amp;nbsp;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Recovery of unmanaged BitLocker volumes not supported for standalone configurations - DPSGN-3901&lt;br /&gt;Access to BitLocker-encrypted volumes which have not been taken over by SafeGuard (i.e., when no SafeGuard encryption policy for them exists) cannot be recovered via the SafeGuard Management Center. This issue is limited to standalone client configurations.&lt;/li&gt;
&lt;li&gt;Trusted application configuration breaks when update changes application path. DPSGN-3720&lt;br /&gt;Some application updates change the absolute path of their executables. In these cases, SGN&amp;#39;s policy configuration for trusted applications needs to be updated as well. For example,&lt;br /&gt;Symantec Anti-Virus&amp;nbsp;installs to a directory path containing its version number. The configuration for SafeGuard trusted applications needs to be changed to point to the new path where the executable is found.&lt;/li&gt;
&lt;li&gt;Microsoft Internet Explorer fails to download encrypted files from Dropbox - DPSGN-2088&lt;br /&gt;Files encrypted with SafeGuard Cloud Storage cannot be downloaded using Microsoft Internet Explorer.&lt;/li&gt;
&lt;li&gt;FIPS mode not supported on Windows 8 clients. DPSGN-1257&lt;br /&gt;SafeGuard Enterprise does not support managing BitLocker encryption on Windows 8 clients with enabled GPO setting&amp;nbsp;&lt;strong&gt;System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing&lt;/strong&gt;. Recovery of such clients, using the SafeGuard Management Center, is not possible. Note that FIPS mode on Windows 8.1 and Windows 10 clients is supported.&lt;/li&gt;
&lt;li&gt;User workflow is affected when uploading encrypted files using a browser
&lt;ul&gt;
&lt;li&gt;Encrypted documents that are uploaded using a browser end-up encrypted on the server. This may break some functionality users are used to (for example, document preview, server-side document indexing, in-browser editing etc.).&lt;/li&gt;
&lt;li&gt;The plain content of encrypted documents can&amp;rsquo;t be accessed by server-side processes. This, for example prevents servers from indexing documents and thus breaks/limits search capabilities.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;MS Office 365 offers direct storing of files in the cloud (OneDrive). If this functionality is used and the Office 365 apps, for example,&amp;nbsp;MS Word, are defined as&amp;nbsp;&lt;strong&gt;In&lt;/strong&gt;&amp;nbsp;application you have to configure the path&amp;nbsp;&lt;strong&gt;&lt;code&gt;&amp;lt;Local App Data&amp;gt;\Microsoft&lt;/code&gt;&lt;/strong&gt;&amp;nbsp;in the application based policy as an exclusion from encryption. This avoids an unencrypted upload of files to the cloud. DPSGN-9615&lt;/li&gt;
&lt;li&gt;Windows Search cannot look into encrypted files and is therefore not able to index content of encrypted files.&lt;/li&gt;
&lt;li&gt;SafeGuard file encryption modules are incompatible with OneDrive&amp;#39;s Files On-Demand feature (introduced with Windows 10 Fall Creators Updated). Please refer to&amp;nbsp;&lt;a href="/kb/en-us/127669" target="_blank"&gt;Incompatibility of SafeGuard File Encryption modules and OneDrive Files On-Demand feature&lt;/a&gt;&amp;nbsp;for full details.&lt;/li&gt;
&lt;li&gt;The SafeGuard file encryption related modules do not support roaming profiles or folder re-directions.&lt;/li&gt;
&lt;li&gt;The SafeGuard Outlook Add-In is only available for 32 bit versions of Outlook.&lt;/li&gt;
&lt;li&gt;When copying files from a local location to either a Network Share or a Removable Media, the Explorer&amp;#39;s calculation of speed and time remaining might not be working correctly anymore. DPSGN-14821&lt;/li&gt;
&lt;/ul&gt;
&lt;h1&gt;&lt;a id="Antivirus products tested with the SafeGuard Enterprise" name="Antivirus products tested with the SafeGuard Enterprise"&gt;&lt;/a&gt;Anti-Virus products tested with SafeGuard Enterprise&lt;/h1&gt;
&lt;div&gt;SafeGuard Enterprise has been successfully tested together with the Anti-Virus&amp;nbsp;products by Sophos as well as the following:&lt;/div&gt;
&lt;div&gt;
&lt;div class="content-scrollable-wrapper"&gt;
&lt;table class="data" border="1" cellspacing="1" cellpadding="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;
&lt;p&gt;Manufacturer&lt;/p&gt;
&lt;/th&gt;
&lt;th&gt;
&lt;p&gt;Product&lt;/p&gt;
&lt;/th&gt;
&lt;th&gt;
&lt;p&gt;Version&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Symantec&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Endpoint Protection&lt;/td&gt;
&lt;td&gt;14.2.4815.1101.105&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;McAfee&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Total Protection&lt;/td&gt;
&lt;td&gt;16.0 R20&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Microsoft&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Defender&amp;nbsp;&lt;/td&gt;
&lt;td&gt;Antimalware Client Version: 4.18.1909.6&lt;br /&gt;Engine Version: 1.1.16400.2&lt;br /&gt;Antivirus Version: 1.303.1727.0&lt;br /&gt;Antispyware Version: 1.303.1727.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Trend-Micro&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Anti-virus+ Security&lt;/td&gt;
&lt;td&gt;16.0.1151&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Kaspersky&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Internet Security&amp;nbsp;&lt;/td&gt;
&lt;td&gt;20.0.14.1085&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&amp;nbsp;&lt;/div&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h1&gt;&lt;a id="Mac OS X Device Encryption Client" name="Mac OS X Device Encryption Client"&gt;&lt;/a&gt;Mac OS X Device Encryption Client&lt;/h1&gt;
&lt;h2&gt;Limitations&lt;/h2&gt;
&lt;h3&gt;&lt;a id="MAC Directory users" name="MAC Directory users"&gt;&lt;/a&gt;Directory users&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;FileVault 2 requires either a local account or a mobile account. Please create a mobile account for Active Directory users if they should be able to activate FileVault 2 or if they should be enabled for FileVault 2.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;a id="MAC Inventory reporting" name="MAC Inventory reporting"&gt;&lt;/a&gt;Inventory reporting&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Drives are only reported if they reside on a GUID partition table. Volumes within an Apple Partition Map or Master Boot Record Partition scheme are not visible in the drive inventory.&lt;/li&gt;
&lt;li&gt;The encryption status is sometimes not updated in the inventory view until the Mac is rebooted.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Limitations on macOS 10.13&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;The FileVault recovery key is not changed after usage if the system disk is formatted using APFS.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;a id="MAC Apple Open Directory" name="MAC Apple Open Directory"&gt;&lt;/a&gt;Apple Open Directory&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Open Directory users/computers are not supported.&lt;br /&gt;Pure Open Directory network users (without a mobile account) are asked for their password to enable FileVault 2 or to get enabled for FileVault 2, even though the operation will fail.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;a id="MAC Encryption" name="MAC Encryption"&gt;&lt;/a&gt;Encryption&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Only the system disk (partition) will be encrypted.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;a id="MAC Known issues" name="MAC Known issues"&gt;&lt;/a&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;It may happen that the recovery key is not available in SafeGuard during the very first restart after enabling the disk encryption, it will be available after a subsequent restart in this case.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;When the SafeGuard system menu is activated, it may take some time until the SafeGuard icon is displayed in the system menu bar.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;It may take up to 5 minutes until the correct encryption state is shown in the SafeGuard preference pane after FileVault 2 encryption has finished.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Adding the currently logged in user is only provided when the synchronization with the SafeGuard Server is working.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;The Decrypt System Disk button in the preference pane may be enabled while the encryption is currently running and the preference pane is opened immediately after login and the security officer has assigned a&amp;nbsp;&lt;strong&gt;No Encryption&lt;/strong&gt;&amp;nbsp;policy. Pressing the button will result in an error and the encryption continues. After some minutes, the button will be disabled.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;The installation, upgrade and uninstallation of SafeGuard Disk Encryption for Mac can take longer (up to 5 - 20 minutes), if your Mac is located behind a firewall. In order to speed up the installation, either disconnect it from any network or allow direct Internet access. Please note that this is a general OS X issue and is caused by the verification of the digital signature via Apple servers, with which SafeGuard&amp;rsquo;s files are signed.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;No users are added if FileVault2 was enabled with disk-password: If the system disk is encrypted using the command line tool &amp;#39;&lt;strong&gt;diskutil cs convert / -passphrase ..&lt;/strong&gt;&amp;#39;, a FileVault2 POA gets activated which asks for the disk password.In general it is possible to add additional users when the disk password is known, but this is currently not implemented by SGDE. This would require a new dialog which asks for the users password and for the disk password. Once a user is available in FileVault2, adding additional users works.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;User &amp;amp; Computers: On a Mac, the Owner flag has no effect! Only the first user FV2-user will be reported as Owner. It&amp;#39;s not possible to switch the Owner!&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;VMware Fusion: If Sophos SafeGuard Native Device Encryption is installed in a virtual machine, please ensure that virtual hard disks are configured with the bus type SCSI. Otherwise the disks appear as external drive and they are not reported in the inventory of the management center. To change the bus type, shut down the virtual machine and the go to Virtual Machine &amp;gt; Settings &amp;gt; Hard Drive &amp;gt; Advanced options &amp;gt; Bus type: change to SCSI&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;SafeGuard Device Encryption for Mac does not support Apple bootcamp.&lt;/li&gt;
&lt;/ul&gt;
&lt;h1&gt;&lt;a id="MAC OS X File Encryption Client" name="MAC OS X File Encryption Client"&gt;&lt;/a&gt;Mac OS X File Encryption Client&lt;/h1&gt;
&lt;h2&gt;&lt;a id="MAC System requirements" name="MAC System requirements"&gt;&lt;/a&gt;System requirements&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Sophos SafeGuard Enterprise: SafeGuard File Encryption for Mac needs a SafeGuard Enterprise backend, from which it obtains its encryption policies and the encryption keys. During the installation process of the Mac client you will be required to provide and import a SafeGuard Enterprise Client Configuration ZIP file, in order to bind the Mac to its SafeGuard backend.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;SSL trust to the SafeGuard Server must be configured on client. Please make certain that the correct SSL certificates of the SafeGuard Server(s) are imported into the Mac&amp;rsquo;s System keychain only, and not in the user&amp;rsquo;s Login keychain.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;Communication between SafeGuard OS X Client and SafeGuard Server is only supported with IPv4.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Supported client languages: The supported client languages are English, German, and French.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&amp;nbsp;&lt;/h2&gt;
&lt;h2&gt;&lt;a id="MAC Compatibility and upgrades" name="MAC Compatibility and upgrades"&gt;&lt;/a&gt;Compatibility and upgrades&lt;/h2&gt;
&lt;p&gt;The compatibility of this release of SafeGuard File Encryption for Mac with previous releases and modules of Sophos is as follows:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Only SafeGuard File Encryption for Mac is used:&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Install SafeGuard File Encryption for Mac and import the SafeGuard Enterprise Client Configuration ZIP file.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;SafeGuard File Encryption for Mac and SafeGuard Disk Encryption for Mac version 8.3 are used together on the same Mac:&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Both products take care of each other and can be installed, and uninstalled in any order.&lt;/li&gt;
&lt;li&gt;If one product is upgraded from a previous version to 8.3 the second product needs to be upgraded as well.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Anti-Virus software&lt;/h2&gt;
&lt;p&gt;Usually anti-virus software works in two modes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Manual or scheduled mode or&lt;/li&gt;
&lt;li&gt;Real time scanning or On-access scan mode&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The following applies for both modes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Whichever scanning mode you are using, it is not recommended to scan the encrypted files in their original location. This is because you cannot find a virus within an encrypted file.&lt;/li&gt;
&lt;li&gt;Instead, it is strictly recommended to scan all files in the corresponding SafeGuard Secured volumes. This returns the unencrypted file content and therefore viruses can be detected.&lt;/li&gt;
&lt;li&gt;Please test, whether the on-access scanner of the installed anti-virus product finds a virus in files on SafeGuard Secured volumes. Please see instructions about the EICAR test file below.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Sophos Enterprise Anti-Virus for Mac / Sophos Central as well as the below mentioned anti-virus products have been tested with SafeGuard File Encryption for Mac and detect viruses on SafeGuard Secured volumes in both modes under the following circumstances:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Scan now or Scan local drives:&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Make sure you always scan the SafeGuard Secured volumes or you risk missed detection. If you happen to scan it through the original path, you can do so, it won&amp;rsquo;t do any harm, but you won&amp;rsquo;t find any virus, as the file content you scan is encrypted.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;On-access scanning:&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you have installed SafeGuard File Encryption for Mac, please make sure that the on-access scanner of Sophos Anti-Virus for Mac is turned on and its feature Scan Files on network volumes is switched on as well. This will allow the file content on a SafeGuard Secured volume to be scanned on-access.&lt;/p&gt;
&lt;p&gt;If you are using other anti-virus software, make sure that your product is able to detect viruses, too. You can use the&amp;nbsp;&lt;a href="http://www.eicar.org/86-0-Intended-use.html" target="_blank"&gt;EICAR Anti-Malware test file&lt;/a&gt;&amp;nbsp;for testing purposes.&lt;/p&gt;
&lt;div class="content-scrollable-wrapper"&gt;
&lt;table class="data" border="1" cellspacing="1" cellpadding="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;
&lt;p&gt;Manufacturer&lt;/p&gt;
&lt;/th&gt;
&lt;th&gt;
&lt;p&gt;Product&lt;/p&gt;
&lt;/th&gt;
&lt;th&gt;
&lt;p&gt;Version&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Symantec&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Endpoint Protection Cloud&lt;/td&gt;
&lt;td&gt;8.3 Build 45&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Kaspersky&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Endpoint Security&lt;/td&gt;
&lt;td&gt;11.0.0.501c&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Trend-Micro&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Anti-Virus&amp;nbsp;for Mac&lt;/td&gt;
&lt;td&gt;10.0.1681&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;h4&gt;Virus Scanner limitations&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Virus Scanners option&amp;nbsp;&lt;strong&gt;move to Quarantine&lt;/strong&gt;&amp;nbsp;will not work for all Virus Scanners&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Most of the virus scanners stop their manual scan if they would leave the current file system. Because the secured mount points act as a file system boundary, they will not be included in the manual scan and must be scanned separately.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;a id="MAC Particularities and limitations" name="MAC Particularities and limitations"&gt;&lt;/a&gt;Particularities and limitations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The menu icons in the Finder right-click menu do not change the color when &amp;quot;Dark Mode&amp;quot; is enabled (macOS10.14)&lt;/li&gt;
&lt;li&gt;Files can be accessed via two different paths: the original path and the SafeGuard File Encryption Secured Volume (mount point). Transparent encryption works only on the SafeGuard Secured Volumes.&lt;/li&gt;
&lt;li&gt;Blacklisted folders: SafeGuard File Encryption for Mac OS X makes certain that folders that are important for OS X to function properly are not and cannot be encrypted by a SafeGuard administrator. Even if a SafeGuard Security Officer specifies an encryption policy for a folder on the blacklist, the client software of SafeGuard File Encryption for Mac OS X will not encrypt file is this folder. This is the list of folders on the blacklist:
&lt;ul&gt;
&lt;li&gt;Folders without sub-folders:
&lt;ul&gt;
&lt;li&gt;&amp;lt;Root&amp;gt;/&lt;/li&gt;
&lt;li&gt;&amp;lt;Root&amp;gt;/Volumes/&lt;/li&gt;
&lt;li&gt;&amp;lt;User Profile&amp;gt;/&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Folders including their sub-folders:&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&amp;lt;Root&amp;gt;/bin/&lt;/li&gt;
&lt;li&gt;&amp;lt;Root&amp;gt;/sbin/&lt;/li&gt;
&lt;li&gt;&amp;lt;Root&amp;gt;/usr/&lt;/li&gt;
&lt;li&gt;&amp;lt;Root&amp;gt;/private/etc/&lt;/li&gt;
&lt;li&gt;&amp;lt;Root&amp;gt;/dev/&lt;/li&gt;
&lt;li&gt;&amp;lt;Root&amp;gt;/Applications/&lt;/li&gt;
&lt;li&gt;&amp;lt;Root&amp;gt;/System/&lt;/li&gt;
&lt;li&gt;&amp;lt;Root&amp;gt;/Library/&lt;/li&gt;
&lt;li&gt;&amp;lt;User Profile&amp;gt;/Library/&lt;/li&gt;
&lt;li&gt;&amp;lt;Removables&amp;gt;/Backups.backupdb/&lt;/li&gt;
&lt;li&gt;&amp;lt;Removables&amp;gt;/SGPortable/&lt;/li&gt;
&lt;li&gt;&amp;lt;Removables&amp;gt;/System Volume Information/&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;OSXFuse provides its Secured Volumes as devices.This has several consequences:
&lt;ul&gt;
&lt;li&gt;Volumes will be shown on your OS X Desktop, if configured in the Finder Preferences. Or you can find them using the Finder option&amp;nbsp;&lt;strong&gt;Go &amp;gt; Computer&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;The OS X feature&amp;nbsp;&lt;strong&gt;Browse All Versions&lt;/strong&gt;&amp;nbsp;is not supported in Secured Volumes.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;It is not guaranteed that policies for SafeGuard File Encryption for Mac can be applied immediately (for example, a mounted Secured Folder cannot be unmounted, because files in it are open.) To be on the safe side, please log out and log in again.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;General Settings policies for Mac must be assigned to the corresponding machines. Assigning the policies to a user has no effect (for example, to define the connection interval).&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;File Encryption policies must be assigned/activated for users or groups that contain the corresponding user objects.&amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;Resetting user password without using Account Preferences (for example resetting password with Active Directory) leads to following problem described in OS X Support KB entry TS5362. As long as you do not apply the solution mentioned there, you will not be able to read encrypted files and will get errors like&amp;nbsp;&lt;strong&gt;A keychain cannot be found to store KEK&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;When you move files from one mount point to another, files will be copied and not moved&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;After fully restoring a Mac with an Apple Time Machine backup on which SafeGuard 8.3 was active (either Device Encryption or File Encryption) it might be that the synchronization with the SafeGuard Enterprise Server does not work anymore.&lt;br /&gt;&lt;br /&gt;This is because the spool daemon user (_sgsd) is wrongly created with a different&amp;nbsp;numerical UID compared to the original installation in some cases by the Time Machine&amp;nbsp;recovery process.&lt;br /&gt;&lt;br /&gt;To resolve this issue please perform the following steps as root user on the terminal (using sudo) until synchronization works again (not all steps may be required):
&lt;ul&gt;
&lt;li&gt;Re-inforce the permissions of the spool directory:&amp;nbsp;&lt;code&gt;#chown -R root:_sgsd /var/spool/sg&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Delete the current spool directory such that permissions are re-created:&amp;nbsp;&lt;code&gt;#rm &amp;ndash;rf /var/spool/sg&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Delete the stale PID-lock file of the SGSD daemon:&amp;nbsp;&lt;code&gt;# rm &amp;ndash;f /tmp/sgsd.pid&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Cloud Storage Provider&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;The synchronization folder of a cloud storage provider must not be located beneath another encryption rule, for example,&amp;nbsp;it is not possible to set encryption rules on&amp;nbsp;&lt;code&gt;&amp;lt;Documents&amp;gt;&lt;/code&gt;&amp;nbsp;and&amp;nbsp;&lt;code&gt;&amp;lt;Documents&amp;gt;/SyncFolder&lt;/code&gt;. To encrypt data stored in a cloud, the cloud synchronization folder must be stored somewhere else, for example,&amp;nbsp;&lt;code&gt;~/SyncFolder&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Terminal points to the wrong cloud folder.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;The overlay icons of the Cloud Storage Provider are no longer visible if an encryption rule for the Cloud folder exists.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Folders with encryption rule cannot be shared with SMB. (DPSGN-1114)&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Folders that can be accessed by multiple users (aka&amp;nbsp;&lt;strong&gt;shared folder&lt;/strong&gt;, for example,&amp;nbsp;&lt;strong&gt;/opt/secured&lt;/strong&gt;): Only the first user gets a secured mount point. The second user gets an error message (Folder is already in use).&lt;br /&gt;For the other user to get the mount point the user currently having it needs to log out first.&amp;nbsp;&lt;strong&gt;Note&lt;/strong&gt;: This does not affect folders that only belong to one user (like the majority of folders underneath the user home directory (&lt;code&gt;/Users/username/&lt;/code&gt;).&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;If iTunes is running while a mount point is created on Documents, the iTunes database cannot be accessed afterwards, because iTunes follows the renamed folder and tries to open the encrypted database.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Reopening applications when logging out and back in is not supported (shut down/restart/logoff-logon) (Keep applications open feature)&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Terminal: When a mount point for some path like for example,&amp;nbsp;&lt;code&gt;&lt;strong&gt;~/Documents&lt;/strong&gt;&lt;/code&gt;&amp;nbsp;is created any terminal whose current working directory (cwd) points to this very path should be exited and re-opened.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Finder &amp;amp; Dock will be restarted if a new local file system mount point is created. (This means that the restart does not happen for cloud provider, network and removable mount points)&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;The SafeGuard encryption file system doesn&amp;#39;t support permanent version storage (only HFS). Copying a file to a mount point will erase existing previous versions. (This is also the case when copying to a network share)&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Time Machine: restore must be done using the .sophos_safeguard_xxx Folder&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Encryption rules on NFS-Shares are not supported&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Encrypted removable devices formatted with NTFS can only be mounted read only&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;You cannot set up an encryption rule on the root path of an internal disk&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Writing encrypted files on CD/DVD is not supported&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Over-mounted folders show the size (capacity and available space) of the disk on which the mount point is created instead of the actual folder size (DPSGN-1095). for example,&amp;nbsp;if an encryption rule for&amp;nbsp;&lt;code&gt;~/Documents&lt;/code&gt;&amp;nbsp;exists, showing the file system info of the directory with Get Info in the Finder will show the capacity of the system disk instead of the actual size used by&amp;nbsp;&lt;code&gt;~/Documents&lt;/code&gt;.&lt;br /&gt;Workaround: Navigate into the secured mount point, select all files and then do right click&amp;nbsp;&lt;strong&gt;Get Info&lt;/strong&gt;&amp;nbsp;in the Finder. This will show the correct size of the directory occupied on disk.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Moving an over-mounted directory in the icon view creates an alias (DPSGN-941)&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;~/Public/Drop Box encryption rules are not supported&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Every user who can access our mount point is impersonated as the user who started the mount point &amp;ndash; even the root user!&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Only the user who started the mount point as well as the root user may access the mount point (FUSE allow_root option)&lt;/li&gt;
&lt;li&gt;However every file system request from our mount point towards the original/underyling FS is issued as the user who started the mount point&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Some examples:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A file in a directory&amp;nbsp;&lt;code&gt;&lt;strong&gt;/enc root:wheel rwx r-x r-x&lt;/strong&gt;&lt;/code&gt;&amp;nbsp;can not be written even if the user elevated privileges with sudo and issues the commando as root&lt;/li&gt;
&lt;li&gt;Touching a file as root in this directory will end up with the privileges john:wheel rw r r instead of the expected root:wheel rw r r&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;The path of an encryption rule must not contain a comma (DPSGN-2757)&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Finder: Tag search doesn&amp;#39;t work&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;The name of a Secured Folder (this is usually the name of the last directory of an encryption rule) must not exceed 238 characters.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Network shares which have a policy applied and are automatically mounted at startup cannot be detected by Sophos File Encryption. It is not possible to overmount such mount points. The original mount point can&amp;#39;t be removed (also see Finder: does not have an eject button). There is no difference if auto mount point is created in&amp;nbsp;&lt;strong&gt;/mnt/&lt;/strong&gt;&amp;nbsp;or&amp;nbsp;&lt;strong&gt;/Volumes/&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Aliases/symlinks to a directory where the alias/symlink is assigned a different key than the target directory should be avoided as it represents a conflict in which key to use.&lt;br /&gt;The Mac FE client will do an alphabetic sorting on the rules and the one that comes last alphabetically will be applied, for example:&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Create a folder for example,&amp;nbsp;&lt;strong&gt;&lt;code&gt;/Users/john/enc&lt;/code&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Create a symlink to that folder, for example,&amp;nbsp;/Users/john/lnkenc&lt;/li&gt;
&lt;li&gt;Create an encryption rule for&amp;nbsp;&lt;strong&gt;&lt;code&gt;&amp;lt;User Profile&amp;gt;\enc&lt;/code&gt;&lt;/strong&gt;&amp;nbsp;with Personal Key&lt;/li&gt;
&lt;li&gt;Create an encryption rule for the link with a different key, for example,&amp;nbsp;&lt;code&gt;&lt;strong&gt;&amp;lt;User Profile&amp;gt;\lnkenc&lt;/strong&gt;&lt;/code&gt;&amp;nbsp;with&amp;nbsp;&lt;strong&gt;Root Key&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;-&amp;gt; In this case the Root Key is used as encryption key as&amp;nbsp;&lt;strong&gt;lnkenc&lt;/strong&gt;&amp;nbsp;comes alphabetically after&amp;nbsp;&lt;strong&gt;enc&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;If Sophos SafeGuard File Encryption is installed in a VMware Fusion virtual machine, please ensure that virtual hard disks are configured with the bus type SCSI. Otherwise the disks appear as external drive and encryption rules won&amp;#39;t be applied correctly. To change the bus type, shut down the virtual machine and the go to Virtual Machine &amp;gt; Settings &amp;gt; Hard Drive &amp;gt; Advanced options &amp;gt; Bus type: change to SCSI&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;In contrast to Windows, OS X does not support file filter drivers which can be used to provide transparent encryption on all locations. To get transparent encryption on OS X, SafeGuard creates mount points for a set of commonly used locations (Desktop, Documents, Pictures, Music, Movies, Downloads, cloud storage provider synchronization folders, removable devices and network shares) which replace the original folder. Now all file operations are redirected through this mount point and the content can be read as usually, because encryption and decryption will be done automatically. If these locations do not fit the requirements, some locations can be excluded from encryption or a policy with defined locations can be used instead (recommended). Use of that technology can lead to the scenario that encrypted files that are moved to folders where no encryption rule is defined, and therefor no mount point for transparent decryption exists, stays encrypted (persistent encryption) and cannot read instantly. They have to be decrypted manually first.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Interoperabilty with Cloud Storage Provider
&lt;ul&gt;
&lt;li&gt;Most of the Cloud Storage Providers and SafeGuard are using so called Finder Sync Extensions to display a badge for the files in the Finder. OS X can only handle one single Finder Sync Extension per folder to show badges for the files. As encrypted files can be on every location, SafeGuard registers for the root directory which includes also the cloud storage provider sync folders and this prevents the cloud storage provider sync folders from displaying their status badges and an error notification from the cloud storage provider may be displayed. This can be ignored.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Permanent Version Storage Error.&lt;br /&gt;Permanent Version Storage is only available on Apple&amp;rsquo;s own file system HFS+. As SafeGuard replaces the original folder with a mount point OS X displays a warning message that the version storage is not available for this file. But these files are still included in Time Machine backups. They can be accessed on a hidden folder. For each mount point SafeGuard creates, there exists also a hidden folder .sophos_safeguard_[Folder Name] on the same location. To restore a single file, the hidden folder has to be selected in Time Machine, for example,&amp;nbsp;Instead of ~/Documents/MyDoc.docx ~/.sophos_safeguard_Documents/MyDoc.docx has to be restored.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;It is not possible to execute script or applications from a mount point. To get separation of access between allowed applications and not allowed applications from reading encrypted content it was necessary to deactivate caches of the OS. Otherwise not allowed applications are able to read content in plain and IN apps may get encrypted content. Workaround: the executables have to moved from the mount point to a normal folder or the executables have to be started using the hidden folder, &amp;nbsp;instead of&amp;nbsp;&lt;code&gt;~/Downloads/test.sh ~/.sophos_safeguard_Downloads/test.sh&lt;/code&gt;&amp;nbsp;has to be used.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;When a removable device is plugged in or a network share gets mounted, there may be a password prompt for an administrative account from&amp;nbsp;&lt;strong&gt;sgfsa&lt;/strong&gt;. This password prompt can be ignored. If there is no mount point created for the device or network share, please re-insert the device or connect again to the the network share.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;AirDrop creates empty files on Downloads mount point. DPSGN-15254&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&amp;nbsp;&lt;/h4&gt;
&lt;h2&gt;&lt;a id="Additional Known issues" name="Additional Known issues"&gt;&lt;/a&gt;Known issues&lt;/h2&gt;
&lt;p&gt;Check the known issues for this SafeGuard Enterprise release, since improper configuration of certain options may cause unexpected behaviour.&lt;/p&gt;
&lt;p&gt;Note the following additional known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;SafeGuard File Encryption&amp;nbsp;for Mac 8.3 supports a maximum of 24 secured mount points. Note that this limit only applies to the top level mount points &amp;ndash; Nested encryption rules are not affected and can be unlimited (e.g. the rules ~/Documents, ~/Documents/keyA, ~/Documents/keyB will result in only one secured mount point being created).&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;The installation, upgrade and uninstallation of SafeGuard File Encryption for Mac can take longer (up to 5 &amp;ndash; 20 minutes), if your Mac is located behind a firewall, which prevents direct access to the Internet. In order to speed up the installation in such a case, either disconnect it from any network or allow direct Internet access. Please note that this is a general issue with OSX Gatekeeper and is caused by the verification of the digital signature via Apple servers, with which SafeGuard&amp;rsquo;s files are signed.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Creation of mobile user accounts at OS X login with confirmation by user: Do not require confirmation of the OS X user before creating a mobile account, as the user can select Don&amp;rsquo;t Create. Selecting this option will create an incomplete OS X user, for example a user that does not have a local home directory.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Show icon preview&lt;br /&gt;For performance reasons it is recommended to turn off the Finder option&amp;nbsp;&lt;strong&gt;Show icon preview&lt;/strong&gt;.&lt;br /&gt;This is particularly valid for slow devices or network shares, on which a big number of encrypted files are located.&lt;br /&gt;Note that application-specific icons (for example Microsoft Office for Mac) are also influenced by the Finder option&amp;nbsp;&lt;strong&gt;Show icon preview&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;If a file was received with MS Outlook, sent by an GMail Web Client, the attached, encrypted file can not be transparently decrypted. Workaround: Decrypt the file manually, via context menu. DPSGN-7449.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Mounted DMG files, which are located in a Secured Folder (mount point), are invalidated during the upgrade of SafeGuard Device or File Encryption, because the mount point is re-created during the upgrade. When the client installers are upgraded, the DMG files of the product should either be stored outside of a mount point or only the DMG file for the product which is currently installed should be mounted. DPSGN-7675&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;It is not supported to run virtual machine images stored on secured mount points. Doing so may cause the virtualization application to fail or even freeze your Mac and require a hard reboot. Workaround: Move the virtual machine image to a location that is not covered by a SafeGuard encryption rule (secured mount point).&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;When SafeGuard Synchronized Encryption policy rules are applied it is not possible to execute applications that are located on secured mount points. This applies to executing applications both with the OS X Finder as well as from the Terminal. Workaround: Move the application to a location that is not covered by a SafeGuard Synchronized Encryption policy rule. This limitation does not apply to location based encryption policies.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Copy performance on network shares covered by a SafeGuard Encryption policy may under certain circumstances (very large and/or many files) be considerably lower than the usual native network performance. Workaround: When experiencing such a situation please use the new&amp;nbsp;&lt;strong&gt;Direct Paste&lt;/strong&gt;&amp;nbsp;functionality offered in the right click context menu of the Finder or use the Terminal to copy the files.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Mac OS 10.13 and SafeGuard File Encryption 8.30
&lt;ul&gt;
&lt;li&gt;Secured Folders (mount points) may appear in the Devices section of the Finder sidebar. Those entries can be removed manually (contextual menu, Remove from Sidebar), but reappear again with the next login.&lt;/li&gt;
&lt;li&gt;It may happen, that the encryption icons are not displayed in the Finder. This is especially the case when the machine was rebooted or when the Cover Flow view (⌘4) is enabled in Finder. To show the icons again you can either switch to another folder and then back to the original folder or disable and enable the Sophos SafeGuard Finder extension in the Extensions system preferences.&lt;/li&gt;
&lt;li&gt;Note: the encryption icons are only displayed for local folders in&amp;nbsp;the home directory (/Users/username), for example Documents, and for encrypted files on data volumes, removable devices and network shares.&lt;/li&gt;
&lt;li&gt;The performance on network shares may be very poor. This is caused by the smb implementation in macOS 10.13. When copy&amp;amp;paste or duplicate several files in parallel, timeouts may happen which result in partly copied files. In general cifs seems to be more robust instead of smb, i.e. instead of connecting to smb://server/share use cifs://server/share.&lt;/li&gt;
&lt;li&gt;Several log entries from osascript may be written to the system.log file when encryption rules on a network share or removable device are configured (osascript[xxxx]: AppleEvents: received mach msg which wasn&amp;#39;t complex type as expected in getMemoryReference).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=512&amp;AppID=23&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Jasmin</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/jasmin</uri></author><category term="safeguard Enterprise" scheme="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/archive/tags/safeguard%2bEnterprise" /><category term="Catalina Support" scheme="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/archive/tags/Catalina%2bSupport" /><category term="v8.30" scheme="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/archive/tags/v8-30" /></entry><entry><title>SafeGuard File Encryption: Engine build 30 for SafeGuard 8.1.x / 8.2.x</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-file-encryption-engine-build-30-for-safeguard-8-1-x-8-2-x" /><id>https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-file-encryption-engine-build-30-for-safeguard-8-1-x-8-2-x</id><published>2019-11-14T15:42:00Z</published><updated>2019-11-14T15:42:00Z</updated><content type="html">&lt;h1&gt;Overview&lt;/h1&gt;
&lt;p&gt;With the introduction of the mini file filter driver, which is part of SafeGuard Enterprise as of version&amp;nbsp;&lt;code&gt;8.10&lt;/code&gt;, Sophos provides regular File Encryption Engine updates that just contain improved filter drivers. These updates are provided as Windows Installer Patch files (&lt;code&gt;*.msp&lt;/code&gt;) to allow easy installation and deployment.&amp;nbsp;As these updates are cumulative, Sophos recommends using the latest version.&lt;/p&gt;
&lt;p&gt;In this blog post, you can download build version&amp;nbsp;&lt;code&gt;30&lt;/code&gt;&amp;nbsp;of the filter driver engine. An overview of all File Encryption Engine Updates is available&amp;nbsp;&lt;a href="/kb/en-us/133000" target="_blank"&gt;here&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
&lt;h1&gt;Resolved issues (new in File Encryption Engine build 30)&lt;/h1&gt;
&lt;div class="content-scrollable-wrapper"&gt;
&lt;table class="content" cellspacing="1" cellpadding="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;Reference&lt;/th&gt;
&lt;th&gt;Symptom / Summary&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15338&lt;/td&gt;
&lt;td&gt;Sporadic file corruptions when storing XLS files using Microsoft Office 2003 or 2007&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15014&lt;/td&gt;
&lt;td&gt;Generic improvements to prevent file locks during shutdown/restart.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15436&lt;/td&gt;
&lt;td&gt;Deleted encrypted files occasionally cannot be recovered and show huge size in recycle bin&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15441&lt;/td&gt;
&lt;td&gt;Bluescreen / BSOD (&lt;code&gt;Bugcheck 0xd4&lt;/code&gt;) on endpoints with Xerox Docushare software installed&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15431&lt;/td&gt;
&lt;td&gt;Windows subsystem for linux no longer working (lxssmanager does not start) on Windows 10 version 1903 (19H1)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15454&lt;/td&gt;
&lt;td&gt;Bluescreen / BSOD&amp;nbsp;&lt;code&gt;SYSTEM_SERVICE_EXCEPTION (Bugcheck 0x3b)&lt;/code&gt;&amp;nbsp;when drag and drop is used for attachments (from MS Outlook to an encrypted folder)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15468,&lt;br /&gt;DPSGN-15472,&lt;br /&gt;DPSGN-15471,&lt;br /&gt;DPPSGN-15462&lt;/td&gt;
&lt;td&gt;3rd party software compatibility fixes for issues introduced in File Encryption Engine build 29&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;h1&gt;Resolved issues (already part of File Encryption Engine build 28)&lt;a id="anchor_1539071761399" name="resolved issues"&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;div class="content-scrollable-wrapper"&gt;
&lt;table class="content" cellspacing="1" cellpadding="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;Reference&lt;/th&gt;
&lt;th&gt;Symptom or Summary&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPFEE-1173&lt;/td&gt;
&lt;td&gt;Local cache corruptions during an update to Windows 10 October 2018 update (W10 version&amp;nbsp;&lt;code&gt;1809&lt;/code&gt;)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14307&lt;/td&gt;
&lt;td&gt;Explorer performance issues in combination with cached files from Windows Quick Access&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14462&lt;/td&gt;
&lt;td&gt;Increased saving time for files located on network locations (specific applications).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14525&lt;/td&gt;
&lt;td&gt;Access rights issues when running specific applications.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14639&lt;/td&gt;
&lt;td&gt;&lt;code&gt;Bluescreen Bugcheck 0x3b (SYSTEM_SERVICE_EXCEPTION)&lt;/code&gt;&amp;nbsp;on Windows 10 version&amp;nbsp;&lt;code&gt;1809&amp;nbsp;&lt;/code&gt;endpoints&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14511&lt;/td&gt;
&lt;td&gt;Performance improvements (boot and runtime)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14853&lt;/td&gt;
&lt;td&gt;Cannot open encrypted Quickbooks project (other applications potentially affected as well),&lt;br /&gt;when SafeGuard File Encryption filter driver is active.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14771&lt;br /&gt;DPSGN-14806&lt;br /&gt;DPSGN-14842&lt;/td&gt;
&lt;td&gt;Several boot performance improvements.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14995&lt;/td&gt;
&lt;td&gt;High performance impact when accessing files on network shares which are not covered by an encryption rule (requires BypassFilesWithoutPolicyVolumes registry key - see KB133022 for details).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14945&lt;/td&gt;
&lt;td&gt;User is unable to save file certain file types (e.g. docx, xlsx).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14987&lt;br /&gt;DPSGN-15016&lt;/td&gt;
&lt;td&gt;User gets file in use error when opening or saving xlsx files on network location.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14513&lt;/td&gt;
&lt;td&gt;License check of 3rd party application (Dataflex) fails - (requires BypassFilesWithoutPolicyVolumes registry key)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14856&lt;br /&gt;DPSGN-15051&lt;/td&gt;
&lt;td&gt;File Encryption driver slows down Windows explorer and search operations on network shares.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15186&lt;br /&gt;DPSGN-15188&lt;br /&gt;DPSGN-15189&lt;br /&gt;DPSGN-15190&lt;/td&gt;
&lt;td&gt;Important security fixes and improvements.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15245&lt;/td&gt;
&lt;td&gt;Files located on a WebDAV share, occasionally cannot be deleted when file encryption minifilter is active.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15014&lt;/td&gt;
&lt;td&gt;Compatibility improvements (requires additional registry modification)&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15265&lt;/td&gt;
&lt;td&gt;System might become unresponsive after re-inserting an encrypted optical media&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15261&lt;/td&gt;
&lt;td&gt;SGPortable.exe (and msvcr71.dll and msvcp71.dll) get encrypted by initial encryption&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15241&lt;/td&gt;
&lt;td&gt;SafeGuard Services not running after update to Windows 10 version 1903 (19H1). This only affects installations of File Encryption Engine build 26.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15209&lt;/td&gt;
&lt;td&gt;Compatibility improvement for Sophos Central Intercept X with EDR.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15267&lt;/td&gt;
&lt;td&gt;Potential file corruptions when creating PDFs from Catia (Dassault Syst&amp;egrave;mes).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15306&lt;/td&gt;
&lt;td&gt;File encryption filter removes SmartScreen block functionality from file properties.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;h1&gt;Download and installation&amp;nbsp;&amp;nbsp;&lt;/h1&gt;
&lt;p&gt;The installers for version 8.10.x can be obtained from this&amp;nbsp;&lt;a target="_blank"&gt;download link&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The installers for version 8.20.x can be obtained from this&amp;nbsp;&lt;a target="_blank"&gt;download link&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Installation for 32-bit OS&lt;/h2&gt;
&lt;h3&gt;If the SafeGuard Client is already installed&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Copy the installer patch files to the corresponding endpoint(s)&lt;/li&gt;
&lt;li&gt;Apply the SafeGuard File Encryption Engine update. Example (based on version 8.10):&amp;nbsp;&lt;code&gt;msiexec /update &amp;quot;C:\Install\File Encryption Engine for SGN 8.1 Build 30.msp&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Reboot the endpoint for the changes to take effect&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;Installation together with SafeGuard Client&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Copy the SafeGuard Client and the installer patch files to the corresponding endpoint(s)&lt;/li&gt;
&lt;li&gt;Install the SafeGuard Client together with the File Encryption Engine update. Example (based on version 8.10):&amp;nbsp;&lt;code&gt;msiexec /i C:\Install\SGNClient.msi PATCH=&amp;quot;C:\Install\File Encryption Engine for SGN 8.1 Build 30.msp&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Reboot the endpoint for the changes to take effect&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;&lt;a name="64-bit OS"&gt;&lt;/a&gt;Installation for 64-bit OS&lt;/h2&gt;
&lt;h3&gt;If the SafeGuard Client is already installed&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Copy the installer patch files to the corresponding endpoint(s)&lt;/li&gt;
&lt;li&gt;Apply the SafeGuard File Encryption Engine update. Example (based on version 8.10):&amp;nbsp;&lt;code&gt;msiexec /update &amp;quot;C:\Install\File Encryption Engine for SGN 8.1 Build 30_x64.msp&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Reboot the endpoint for the changes to take effect&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;Installation together with SafeGuard Client&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Copy the SafeGuard Client and the installer patch files to the corresponding endpoint(s)&lt;/li&gt;
&lt;li&gt;Install the SafeGuard Client together with the File Encryption Engine update. Example (based on version 8.10):&amp;nbsp;&lt;code&gt;msiexec /i C:\Install\SGNClient_x64.msi PATCH=&amp;quot;C:\Install\File Encryption Engine for SGN 8.1 Build 30_x64.msp&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Reboot the endpoint for the changes to take effect&lt;/li&gt;
&lt;/ol&gt;
&lt;h1&gt;How to verify if the patch is applied&lt;a id="anchor_1539071988949" name="How to verify if the patch is applied"&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;p&gt;After the installation, you can see the new File Encryption Engine in the&amp;nbsp;&lt;strong&gt;Installed Updates&amp;nbsp;&lt;/strong&gt;section of&amp;nbsp;&lt;strong&gt;Programs and Features&lt;/strong&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;As this package just contains new filter drivers and no other products components, this update does not change the version or build number of the installed SafeGuard Client. In the SafeGuard Management Center version 8.20, the file filter engine version of this update (3.0.0.34) is also listed in the installed features list of the Client.&lt;/p&gt;
&lt;h1&gt;Related information&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="/kb/en-us/133000" target="_blank"&gt;File Encryption Engine updates for SafeGuard 8.10.x/8.20&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="/kb/en-us/124771" target="_blank"&gt;SafeGuard Enterprise: Supported clients on Windows 10 versions&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=500&amp;AppID=23&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Jasmin</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/jasmin</uri></author></entry><entry><title>SafeGuard Enterprise: macOS Catalina support</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-enterprise-macos-catalina-support" /><id>https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-enterprise-macos-catalina-support</id><published>2019-10-22T17:40:00Z</published><updated>2019-10-22T17:40:00Z</updated><content type="html">&lt;h1 style="font-size:1.5rem;margin:1em 0px;padding:0px;line-height:34.56px;font-weight:normal;color:#464a4f;font-style:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;background-color:#ffffff;"&gt;&lt;strong&gt;Overview&lt;/strong&gt;&lt;/h1&gt;
&lt;p style="margin:1.5em 0px;line-height:1.5em;font-size:15px;color:#464a4f;font-family:sophos-regular, &amp;#39;Helvetica Neue&amp;#39;, Helvetica, Arial, sans-serif;font-style:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;background-color:#ffffff;"&gt;Apple has released macOS version 10.15 (Catalina) on the 11th of October 2019. SafeGuard version 8.20.0 and previous versions of SafeGuard Disk Encryption and File Encryption for Mac, do not support this new Operating System and may not function correctly.&lt;/p&gt;
&lt;p style="margin:1.5em 0px;line-height:1.5em;font-size:15px;color:#464a4f;font-family:sophos-regular, &amp;#39;Helvetica Neue&amp;#39;, Helvetica, Arial, sans-serif;font-style:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;background-color:#ffffff;"&gt;To be able to use macOS Catalina (10.15) together with SafeGuard Enterprise, you need to install version 8.30 which is currently planned to be available in November 2019.&lt;/p&gt;
&lt;p style="margin:1.5em 0px;line-height:1.5em;font-size:15px;color:#464a4f;font-family:sophos-regular, &amp;#39;Helvetica Neue&amp;#39;, Helvetica, Arial, sans-serif;font-style:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;background-color:#ffffff;"&gt;&lt;strong style="font-weight:bold;"&gt;Note:&amp;nbsp;&lt;/strong&gt;SafeGuard Enterprise 8.30 will support macOS 10.13, 10.14 and 10.15.&lt;/p&gt;
&lt;h1 style="font-size:1.5rem;margin:1em 0px;padding:0px;line-height:34.56px;font-weight:normal;color:#464a4f;font-style:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;background-color:#ffffff;"&gt;&lt;strong&gt;What to do&lt;/strong&gt;&lt;/h1&gt;
&lt;p style="margin:1.5em 0px;line-height:1.5em;font-size:15px;color:#464a4f;font-family:sophos-regular, &amp;#39;Helvetica Neue&amp;#39;, Helvetica, Arial, sans-serif;font-style:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;background-color:#ffffff;"&gt;Sophos is planning to release a new version of SafeGuard, version 8.30, that supports this new operating system, in November 2019.&lt;/p&gt;
&lt;p style="margin:1.5em 0px;line-height:1.5em;font-size:15px;color:#464a4f;font-family:sophos-regular, &amp;#39;Helvetica Neue&amp;#39;, Helvetica, Arial, sans-serif;font-style:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;background-color:#ffffff;"&gt;Until this version is available, we recommend to refrain from updating existing systems to macOS 10.15 or installing a not supported SafeGuard Client on the new Operating System. &lt;/p&gt;
&lt;p style="margin:1.5em 0px;line-height:1.5em;font-size:15px;color:#464a4f;font-family:sophos-regular, &amp;#39;Helvetica Neue&amp;#39;, Helvetica, Arial, sans-serif;font-style:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;background-color:#ffffff;"&gt;Related KBA: &lt;a href="/kb/en-us/134791"&gt;https://community.sophos.com/kb/en-us/134791&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=481&amp;AppID=23&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Vincent Vanbiervliet</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/vincent-vanbiervliet</uri></author></entry><entry><title>SafeGuard File Encryption: Engine build 29 for SafeGuard 8.1.x / 8.2.x</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-file-encryption-engine-build-29-for-safeguard-8-1-x-8-2-x" /><id>https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-file-encryption-engine-build-29-for-safeguard-8-1-x-8-2-x</id><published>2019-10-18T20:57:00Z</published><updated>2019-10-18T20:57:00Z</updated><content type="html">&lt;h1&gt;Please note: &lt;a href="/kb/en-us/134816" target="_blank"&gt;Advisory: SafeGuard File Encryption Engine - build 29 withdrawn&lt;/a&gt;&lt;/h1&gt;
&lt;h1&gt;Overview&lt;/h1&gt;
&lt;p&gt;With the introduction of the mini file filter driver, which is part of SafeGuard Enterprise as of version&amp;nbsp;&lt;code&gt;8.10&lt;/code&gt;, Sophos provides regular File Encryption Engine updates that just contain improved filter drivers. These updates are provided as Windows Installer Patch files (&lt;code&gt;*.msp&lt;/code&gt;) to allow an easy installation and deployment.&amp;nbsp;As these updates are cumulative, Sophos recommends using the latest version.&lt;/p&gt;
&lt;p&gt;In this post you can download build version&amp;nbsp;&lt;code&gt;29&lt;/code&gt;&amp;nbsp;of the filter driver engine. An overview of all File Encryption Engine Updates is available&amp;nbsp;&lt;a href="/kb/en-us/133000" target="_blank"&gt;here&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
&lt;h1&gt;Resolved issues (new in File Encryption Engine build 29)&lt;/h1&gt;
&lt;div class="content-scrollable-wrapper"&gt;
&lt;table class="content" cellspacing="1" cellpadding="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;Reference&lt;/th&gt;
&lt;th&gt;Symptom / Summary&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15338&lt;/td&gt;
&lt;td&gt;Sporadic file corruptions when storing XLS files using Microsoft Office 2003 or 2007&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15014&lt;/td&gt;
&lt;td&gt;Generic improvements to prevent file locks during shutdown/restart.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15436&lt;/td&gt;
&lt;td&gt;Deleted encrypted files occasionally cannot be recovered and show huge size in recycle bin&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15441&lt;/td&gt;
&lt;td&gt;Bluescreen / BSOD (Bugcheck 0xd4) on endpoints with Xerox Docushare software installed&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15431&lt;/td&gt;
&lt;td&gt;Windows subsystem for linux no longer working (lxssmanager does not start) on Windows 10 version 1903 (19H1)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;h1&gt;Resolved issues (already part of File Encryption Engine build 28)&lt;a id="anchor_1539071761399" name="resolved issues"&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;div class="content-scrollable-wrapper"&gt;
&lt;table class="content" cellspacing="1" cellpadding="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;Reference&lt;/th&gt;
&lt;th&gt;Symptom or Summary&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPFEE-1173&lt;/td&gt;
&lt;td&gt;Local cache corruptions during an update to Windows 10 October 2018 update (W10 version&amp;nbsp;&lt;code&gt;1809&lt;/code&gt;)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14307&lt;/td&gt;
&lt;td&gt;Explorer performance issues in combination with cached files from Windows Quick Access&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14462&lt;/td&gt;
&lt;td&gt;Increased saving time for files located on network locations (specific applications).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14525&lt;/td&gt;
&lt;td&gt;Access rights issues when running specific applications.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14639&lt;/td&gt;
&lt;td&gt;&lt;code&gt;Bluescreen Bugcheck 0x3b (SYSTEM_SERVICE_EXCEPTION)&lt;/code&gt;&amp;nbsp;on Windows 10 version&amp;nbsp;&lt;code&gt;1809&amp;nbsp;&lt;/code&gt;endpoints&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14511&lt;/td&gt;
&lt;td&gt;Performance improvements (boot and runtime)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14853&lt;/td&gt;
&lt;td&gt;Cannot open encrypted Quickbooks project (other applications potentially affected as well),&lt;br /&gt;when SafeGuard File Encryption filter driver is active.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14771&lt;br /&gt;DPSGN-14806&lt;br /&gt;DPSGN-14842&lt;/td&gt;
&lt;td&gt;Several boot performance improvements.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14995&lt;/td&gt;
&lt;td&gt;High performance impact when accessing files on network shares which are not covered by an encryption rule (requires BypassFilesWithoutPolicyVolumes registry key - see KB132922 for details).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14945&lt;/td&gt;
&lt;td&gt;User is unable to save file certain file types (e.g. docx, xlsx).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14987&lt;br /&gt;DPSGN-15016&lt;/td&gt;
&lt;td&gt;User gets file in use error when opening or saving xlsx files on network location.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14513&lt;/td&gt;
&lt;td&gt;License check of 3rd party application (Dataflex) fails - (requires BypassFilesWithoutPolicyVolumes registry key)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14856&lt;br /&gt;DPSGN-15051&lt;/td&gt;
&lt;td&gt;File Encryption driver slows down Windows explorer and search operations on network shares.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15186&lt;br /&gt;DPSGN-15188&lt;br /&gt;DPSGN-15189&lt;br /&gt;DPSGN-15190&lt;/td&gt;
&lt;td&gt;Important security fixes and improvements.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15245&lt;/td&gt;
&lt;td&gt;Files located on a WebDAV share, occasionally cannot be deleted when file encryption minifilter is active.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15014&lt;/td&gt;
&lt;td&gt;Compatibility improvements (requires additional registry modification)&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15265&lt;/td&gt;
&lt;td&gt;System might become unresponsive after re-inserting an encrypted optical media&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15261&lt;/td&gt;
&lt;td&gt;SGPortable.exe (and msvcr71.dll and msvcp71.dll) get encrypted by initial encryption&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15241&lt;/td&gt;
&lt;td&gt;SafeGuard Services not running after update to Windows 10 version 1903 (19H1). This only affects installations of File Encryption Engine build 26.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15209&lt;/td&gt;
&lt;td&gt;Compatibility improvement for Sophos Central Intercept X with EDR.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15267&lt;/td&gt;
&lt;td&gt;Potential file corruptions when creating PDFs from Catia (Dassault Syst&amp;egrave;mes).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15306&lt;/td&gt;
&lt;td&gt;File encryption filter removes SmartScreen block functionality from file properties.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;h1&gt;Download and installation&amp;nbsp;&lt;/h1&gt;
&lt;p&gt;The File Encryption Engine Update build&amp;nbsp;&lt;code&gt;29&lt;/code&gt;&amp;nbsp;can be applied to SafeGuard Client version&amp;nbsp;&lt;code&gt;8.10.0.323,&lt;/code&gt;&amp;nbsp;&lt;code&gt;&lt;a href="/kb/en-us/133358" target="_blank"&gt;8.10.2.55&lt;/a&gt;&amp;nbsp;and 8.20.0.83&lt;/code&gt;. It automatically updates previously installed File Encryption Engine Updates.&lt;/p&gt;
&lt;p&gt;The installers for version 8.10.x can be obtained from this&amp;nbsp;&lt;a target="_blank"&gt;download link&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The installers for version 8.20.x can be obtained from this&amp;nbsp;&lt;a target="_blank"&gt;download link&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;&lt;a name="32-bit OS"&gt;&lt;/a&gt;Installation for 32-bit OS&lt;/h2&gt;
&lt;h3&gt;If the SafeGuard Client is already installed&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Copy the installer patch files to the corresponding endpoint(s)&lt;/li&gt;
&lt;li&gt;Apply the SafeGuard File Encryption Engine update. Example (based on version 8.10):&amp;nbsp;&lt;code&gt;msiexec /update &amp;quot;C:\Install\File Encryption Engine for SGN 8.1 Build 29.msp&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Reboot the endpoint for the changes to take effect&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;Installation together with SafeGuard Client&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Copy the SafeGuard Client and the installer patch files to the corresponding endpoint(s)&lt;/li&gt;
&lt;li&gt;Install the SafeGuard Client together with the File Encryption Engine update. Example (based on version 8.10):&amp;nbsp;&lt;code&gt;msiexec /i C:\Install\SGNClient.msi PATCH=&amp;quot;C:\Install\File Encryption Engine for SGN 8.1 Build 29.msp&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Reboot the endpoint for the changes to take effect&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;&lt;a name="64-bit OS"&gt;&lt;/a&gt;Installation for 64-bit OS&lt;/h2&gt;
&lt;h3&gt;If the SafeGuard Client is already installed&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Copy the installer patch files to the corresponding endpoint(s)&lt;/li&gt;
&lt;li&gt;Apply the SafeGuard File Encryption Engine update. Example (based on version 8.10):&amp;nbsp;&lt;code&gt;msiexec /update &amp;quot;C:\Install\File Encryption Engine for SGN 8.1 Build 29_x64.msp&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Reboot the endpoint for the changes to take effect&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;Installation together with SafeGuard Client&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Copy the SafeGuard Client and the installer patch files to the corresponding endpoint(s)&lt;/li&gt;
&lt;li&gt;Install the SafeGuard Client together with the File Encryption Engine update. Example (based on version 8.10):&amp;nbsp;&lt;code&gt;msiexec /i C:\Install\SGNClient_x64.msi PATCH=&amp;quot;C:\Install\File Encryption Engine for SGN 8.1 Build 29_x64.msp&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Reboot the endpoint for the changes to take effect&lt;/li&gt;
&lt;/ol&gt;
&lt;h1&gt;&lt;a name="Patch"&gt;&lt;/a&gt;How to verify if the patch is applied&lt;a id="anchor_1539071988949" name="How to verify if the patch is applied"&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;p&gt;After the installation, you can see the new File Encryption Engine in the&amp;nbsp;&lt;strong&gt;Installed Updates&amp;nbsp;&lt;/strong&gt;section of&amp;nbsp;&lt;strong&gt;Programs and Features&lt;/strong&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;As this package just contains new filter drivers and no other products components, this update does not change the version or build number of the installed SafeGuard Client. In the SafeGuard Management Center version 8.20, the file filter engine version of this update (3.0.0.31) is also listed in the installed features list of the Client.&lt;/p&gt;
&lt;h1&gt;&lt;a id="related information" name="related information"&gt;&lt;/a&gt;Related information&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="/kb/en-us/133000" target="_blank"&gt;File Encryption Engine updates for SafeGuard 8.10.x/8.20&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="/kb/en-us/124771" target="_blank"&gt;SafeGuard Enterprise: Supported clients on Windows 10 versions&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=472&amp;AppID=23&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>FloSupport</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/flosupport</uri></author></entry><entry><title>SafeGuard Enterprise Windows Client Patch 1908 version 8.00.6</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-enterprise-windows-client-patch-1908-version-8-00-6" /><id>https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-enterprise-windows-client-patch-1908-version-8-00-6</id><published>2019-09-30T23:08:00Z</published><updated>2019-09-30T23:08:00Z</updated><content type="html">&lt;h1&gt;Overview&lt;/h1&gt;
&lt;p&gt;A security and compatibility patch for SafeGuard Enterprise Windows Client version 8.00.0.251 and SafeGuard Enterprise Windows Client 8.00.5 has been released to address numerous issues.&lt;/p&gt;
&lt;p&gt;The 8.00.6 security and compatibility patch&amp;nbsp;includes all fixes from the previous 8.00.5 Client Rollup patch.&lt;/p&gt;
&lt;p&gt;It is highly recommended to upgrade all SafeGuard Client installations running version 8.00.0.251 or 8.00.5.x on Microsoft Windows.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Applies to the following Sophos products and versions&lt;/strong&gt;&lt;br /&gt;SafeGuard BitLocker Client 8.0&lt;br /&gt;SafeGuard Cloud Storage 8.0&lt;br /&gt;SafeGuard File Encryption 8.0&lt;br /&gt;SafeGuard Synchronized Encryption 8.0&lt;br /&gt;SafeGuard Data Exchange 8.0&lt;/p&gt;
&lt;h1&gt;&lt;a id="Resolved issues (compared to SafeGuard version 8.00.0.251)"&gt;&lt;/a&gt;Resolved issues (compared to SafeGuard version 8.00.0.251)&lt;/h1&gt;
&lt;div class="content-scrollable-wrapper"&gt;
&lt;table class="content" cellspacing="1" cellpadding="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;Reference&lt;/th&gt;
&lt;th&gt;Symptom / Summary&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-10618&lt;/td&gt;
&lt;td&gt;SGN Authentication Service crashes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-12668&lt;/td&gt;
&lt;td&gt;SafeGuard services fail to start, referencing the WS2_32.dll&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-11347&lt;/td&gt;
&lt;td&gt;Saving encrypted files occasionally fails&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-12230&lt;/td&gt;
&lt;td&gt;Task Manager hangs during shutdown&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-10120&lt;/td&gt;
&lt;td&gt;Numerous Smartcard/Token logon related issues&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-11686&lt;/td&gt;
&lt;td&gt;Significant delay when locking the desktop&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-11064&lt;/td&gt;
&lt;td&gt;Outlook Add-In not working reliably&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-12036&lt;/td&gt;
&lt;td&gt;Outlook Add-In strips file extensions&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-11848&lt;/td&gt;
&lt;td&gt;SGN Master Service crashes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-12233&lt;/td&gt;
&lt;td&gt;Password change for other user than logged on not possible&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-12033&lt;/td&gt;
&lt;td&gt;HTML Re-cryption not working in latest versions of Firefox and Google Chrome&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-11404&lt;/td&gt;
&lt;td&gt;BEDevCtl.exe crashes, causing a missing SafeGuard Credential Provider&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-10874&lt;/td&gt;
&lt;td&gt;Data partitions not encrypted on NVME drives (BitLocker)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-11839&lt;/td&gt;
&lt;td&gt;BitLocker rollout improvements&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-10599&lt;/td&gt;
&lt;td&gt;BitLocker Challenge/Response: Encryption not starting if no recovery partition is available&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-10918&lt;/td&gt;
&lt;td&gt;BSOD: PAGE_FAULT_IN_NONPAGED_AREA (referencing lcencvm.sys) BugCheck 50&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-12782&lt;/td&gt;
&lt;td&gt;LocalCache corruptions on machines running File Based Encryption&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-13146&lt;br /&gt;DPSGN-13154&lt;/td&gt;
&lt;td&gt;Improved compatibility with Sophos Endpoint and Sophos Central&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-12619&lt;/td&gt;
&lt;td&gt;BSOD: BEFlt.sys - 0x00000050 PAGE_FAULT_IN_NONPAGED_AREA&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-13775&lt;/td&gt;
&lt;td&gt;Credential Provider issues with Windows 10 built-in VPN when using UID and Password authentication&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-13128&lt;/td&gt;
&lt;td&gt;BSOD: BugCheck 50 in combination with SafeGuard File Encryption driver&amp;nbsp;(referencing lcencvm.sys)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-13714&lt;/td&gt;
&lt;td&gt;BitLocker PIN reset not working after recovery&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-13748&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Encrypt according to policy&lt;/strong&gt;&amp;nbsp;option and initial encryption wizard not working&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;h1&gt;&lt;a id="Download and installation"&gt;&lt;/a&gt;Resolved issues (compared to SafeGuard version 8.00.5)&lt;a id="anchor_1568980837676" name="Resolved issues (compared to SafeGuard version 8.00.5)"&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;div class="content-scrollable-wrapper"&gt;
&lt;table class="content" cellspacing="1" cellpadding="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;Reference&lt;/th&gt;
&lt;th&gt;Symptom / Summary&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14137&lt;/td&gt;
&lt;td&gt;SGFileEncWizard.exe appears to hang when trying manually to encrypt the files&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14365&lt;/td&gt;
&lt;td&gt;sgn_masterservicen.exe crashed due to an unhandled exception (0xc0000005)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14822&lt;/td&gt;
&lt;td&gt;Password change fails with&amp;nbsp;the error message &amp;quot;The specified account does not exist&amp;quot; in specific scenarios.&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-13606&lt;/td&gt;
&lt;td&gt;Credential Provider interface empty after SGNAuthService crash/restart&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-11436&lt;/td&gt;
&lt;td&gt;User chooses &amp;#39;Sign out&amp;#39; but does not get signed out (lParam = 0xC0000000)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14156&lt;/td&gt;
&lt;td&gt;Blue screen UNEXPECTED_KERNEL_MODE_TRAP (7f) after upgrade or installation on Windows 10 version 1803 /1809 /1903&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15312&lt;/td&gt;
&lt;td&gt;File encryption related issues after cumulative updates (as of July 2019) on Windows 10 version 1809 / 1903&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;h1&gt;&lt;a id="Download and installation"&gt;&lt;/a&gt;Download and installation&lt;/h1&gt;
&lt;h4&gt;&lt;strong&gt;Download:&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;The package can be obtained from the SafeGuard Enterprise download section on&amp;nbsp;&lt;a href="https://www.sophos.com/en-us/support/downloads/data-protection/safeguard-enterprise.aspx" target="_blank"&gt;sophos.com&lt;/a&gt;&amp;nbsp;or directly using this link:&amp;nbsp;&lt;a target="_blank"&gt;Download&lt;/a&gt;&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;Installation&lt;/strong&gt;:&lt;/h4&gt;
&lt;p&gt;The client security and compatibility patch&amp;nbsp;can be applied to SafeGuard Client version 8.00.0.251 and 8.00.5.x running on Microsoft Windows only.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Important&lt;/strong&gt;: For clients running Windows 7 SP1, it is critical to install all Windows security patches before applying the patch.&lt;/p&gt;
&lt;h4&gt;If the SafeGuard Client 8.00.0.251 is already installed&lt;/h4&gt;
&lt;ol&gt;
&lt;li&gt;Copy the installer patch file to the corresponding computer(s).&lt;/li&gt;
&lt;li&gt;Apply the SafeGuard Client Rollup patch.&lt;br /&gt;Example:&amp;nbsp;&lt;strong&gt;msiexec /update C:\Install\SGN8006Patch1908_x64.msp&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Reboot the machine for the changes to take effect.&amp;nbsp;After installing, the machine gets automated reboot if installation done via command line. If you want to control the reboot, use the /norestart switch.&lt;/li&gt;
&lt;/ol&gt;
&lt;h4&gt;If the SafeGuard Client 8.00.5.x is already installed&lt;/h4&gt;
&lt;ol&gt;
&lt;li&gt;Copy the installer patch file and the SGN8006Patch1908.cmd to the corresponding computer(s).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Run the&lt;/strong&gt;&amp;nbsp;&lt;strong&gt;SGN8006Patch1908.cmd&lt;/strong&gt;&amp;nbsp;in an administrative CMD. This will ensure that the pre-requisites are met and the Patch gets installed.&lt;/li&gt;
&lt;li&gt;Reboot the machine for the changes to take effect.&lt;/li&gt;
&lt;/ol&gt;
&lt;h4&gt;Installation of SafeGuard Client with the patch&lt;/h4&gt;
&lt;ol&gt;
&lt;li&gt;Copy the SafeGuard Client and the installer patch files to the corresponding computer(s).&lt;/li&gt;
&lt;li&gt;Install the SafeGuard Client with the Rollup patch.&lt;br /&gt;For example:&amp;nbsp;&lt;strong&gt;msiexec /i C:\Install\SGNClient_x64.msi PATCH=C:\Install\SGN8006Patch1908_x64.msp&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Reboot the machine for the changes to take effect.&amp;nbsp;After installing, the machine gets automatically rebooted if the installation is done via command line. If you want to control the reboot, use the /norestart switch.&lt;/li&gt;
&lt;/ol&gt;
&lt;h1&gt;&lt;a id="How to verify if the patch is applied"&gt;&lt;/a&gt;How to verify if the patch is applied&lt;/h1&gt;
&lt;p&gt;The security and compatibility patch&amp;nbsp;comes in the form of a Windows Installer Minor Upgrade Patch and updates the version number of the Sophos SafeGuard Client that is displayed in Apps &amp;amp; features / Programs and Features to 8.00.6.2&lt;/p&gt;
&lt;p&gt;Additionally the version in the SafeGuard about box has been updated and the clients report the new version using the machine inventory, which can be displayed in the SafeGuard Management Center.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Limitations:&amp;nbsp;&lt;/strong&gt;This Hotfix Rollup is not compatible with SafeGuard LAN Crypt.&lt;/p&gt;
&lt;h1&gt;&lt;a id="related information" name="related information"&gt;&lt;/a&gt;Related information&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="/kb/en-us/134503" target="_blank"&gt;Microsoft&amp;#39;s July / August updates on Windows 10 1809 / 1903 break several file encryption capabilities of SafeGuard Enterprise 8.00.5&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="/kb/en-us/131934" target="_blank"&gt;Windows Client Patch 1804 for SafeGuard products&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://msdn.microsoft.com/en-us/library/windows/desktop/aa372024(v=vs.85).aspx" target="_blank"&gt;Microsoft: Standard Installer Command-Line Options&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="/kb/en-us/124771" target="_blank"&gt;SafeGuard Enterprise: Supported clients on Windows 10 versions&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=457&amp;AppID=23&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>FloSupport</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/flosupport</uri></author><category term="SafeGuard Enterprise Windows Client Patch 1908 version 8.00.6" scheme="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/archive/tags/SafeGuard%2bEnterprise%2bWindows%2bClient%2bPatch%2b1908%2bversion%2b8-00-6" /></entry><entry><title>File Encryption Engine updates for SafeGuard 8.10 / 8.20</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/file-encryption-engine-updates-for-safeguard-8-10-8-20" /><id>https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/file-encryption-engine-updates-for-safeguard-8-10-8-20</id><published>2019-09-25T20:17:00Z</published><updated>2019-09-25T20:17:00Z</updated><content type="html">&lt;h1&gt;Overview&lt;/h1&gt;
&lt;p&gt;With the introduction of the mini file filter driver, which is part of SafeGuard Enterprise as of version 8.10, Sophos provides regular File Encryption Engine updates that just contain improved filter drivers. These updates are provided as Windows Installer Patch files (*.msp) to allow an easy installation and deployment.&lt;/p&gt;
&lt;p&gt;In this post, you can find links to all available updates of the filter driver engine. As these updates are cumulative, Sophos recommends using the latest version.&lt;/p&gt;
&lt;h1&gt;Resolved issues in latest build version (compared to SafeGuard version 8.10.0.323)&lt;a id="anchor_1539071761399" name="resolved issues"&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;div class="content-scrollable-wrapper"&gt;
&lt;table class="content" cellspacing="1" cellpadding="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;Reference&lt;/th&gt;
&lt;th&gt;Symptom / Summary&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPFEE-1173&lt;/td&gt;
&lt;td&gt;Local cache corruptions during an update to Windows 10 October 2018 update (W10 version 1809)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14307&lt;/td&gt;
&lt;td&gt;Explorer performance issues in combination with cached files from Windows Quick Access&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14462&lt;/td&gt;
&lt;td&gt;Increased saving time for files located on network locations (specific applications).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14525&lt;/td&gt;
&lt;td&gt;Access rights issues when running specific applications.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14639&lt;/td&gt;
&lt;td&gt;Bluescreen Bugcheck 0x3b (SYSTEM_SERVICE_EXCEPTION) on Windows 10 version 1809 endpoints&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14511&lt;/td&gt;
&lt;td&gt;Performance improvements (boot and runtime)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14853&lt;/td&gt;
&lt;td&gt;Cannot open encrypted Quickbooks project (other applications potentially affected as well),&lt;br /&gt;when SafeGuard File Encryption filter driver is active.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14771&lt;br /&gt;DPSGN-14806&lt;br /&gt;DPSGN-14842&lt;/td&gt;
&lt;td&gt;Several boot performance improvements.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14995&lt;/td&gt;
&lt;td&gt;High performance impact when accessing files not covered by an encryption rule (requires BypassFilesWithoutPolicyVolumes registry key)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14945&lt;/td&gt;
&lt;td&gt;User is unable to save file certain file types (e.g. docx, xlsx).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14987&lt;br /&gt;DPSGN-15016&lt;/td&gt;
&lt;td&gt;User gets file in use error when opening or saving xlsx files on network location.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14513&lt;/td&gt;
&lt;td&gt;License check of 3rd party application (Dataflex) fails - (requires BypassFilesWithoutPolicyVolumes registry key)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14856&lt;br /&gt;DPSGN-15051&lt;/td&gt;
&lt;td&gt;File Encryption driver slows down Windows explorer and search operations on network shares.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15186&lt;br /&gt;DPSGN-15188&lt;br /&gt;DPSGN-15189&lt;br /&gt;DPSGN-15190&lt;/td&gt;
&lt;td&gt;Important security fixes and improvements.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN - 15245&lt;/td&gt;
&lt;td&gt;Files located on a WebDAV share, occasionally cannot be deleted when file encryption minifilter is active.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN -15014&lt;/td&gt;
&lt;td&gt;Compatibility improvements&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN - 15265&lt;/td&gt;
&lt;td&gt;System might become unresponsive after re-inserting an encrypted optical media&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN - 15261&lt;/td&gt;
&lt;td&gt;SGPortable.exe (and msvcr71.dll and msvcp71.dll) get encrypted by initial encryption&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN - 15241&lt;/td&gt;
&lt;td&gt;SafeGuard Services not running after update to Windows 10 version 1903 (19H1). This only affects installations of File Encryption Engine build 26.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15209&lt;/td&gt;
&lt;td&gt;Compatibility improvement for Sophos Central Intercept X with EDR.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15267&lt;/td&gt;
&lt;td&gt;Potential file corruptions when creating PDFs from Catia.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15306&lt;/td&gt;
&lt;td&gt;File encryption filter removes SmartScreen block functionality from file properties.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;h1&gt;&lt;br /&gt;Available File Encryption Engine updates&lt;/h1&gt;
&lt;p&gt;&lt;a href="/kb/en-us/134556" target="_blank"&gt;File Encryption Engine build 28 for SafeGuard 8.1 / 8.2&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="/kb/en-us/134436" target="_blank"&gt;File Encryption Engine build 27 for SafeGuard 8.1 / 8.2&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="/kb/en-us/134154" target="_blank"&gt;File Encryption Engine build 25 for SafeGuard 8.1.0&lt;/a&gt;&amp;nbsp;- This File Encryption Engine update contains the same filter driver as SafeGuard version 8.20.0&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="/kb/en-us/134089" target="_blank"&gt;File Encryption Engine build 24 for SafeGuard 8.1.0&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="/kb/en-us/133478" target="_blank"&gt;File Encryption Engine build 23 for SafeGuard 8.1.0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="/kb/en-us/133001" target="_blank"&gt;File Encryption Engine build 22 for SafeGuard 8.1.0&lt;/a&gt;&amp;nbsp;- Important: This update has been integrated in the&amp;nbsp;&lt;a href="/kb/en-us/133358" target="_blank"&gt;SafeGuard Client Hotfix Rollup 1901&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="/kb/en-us/132892" target="_blank"&gt;File Encryption Engine build 19 for SafeGuard 8.1.0&lt;/a&gt;&lt;/p&gt;
&lt;h1&gt;&lt;br /&gt;Related information&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="/kb/en-us/124771" target="_blank"&gt;SafeGuard Enterprise: Supported clients on Windows 10 versions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="/kb/en-us/132922" target="_blank"&gt;Performance impact on systems after installation of SafeGuard 8.10 file encryption module&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="/kb/en-us/133358" target="_blank"&gt;SafeGuard Enterprise Windows Client Patch 1901 version 8.10.2&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=450&amp;AppID=23&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>FloSupport</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/flosupport</uri></author></entry><entry><title>SafeGuard File Encryption: Engine build 28 for SafeGuard 8.1.x / 8.2.x</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-file-encryption-engine-build-28-for-safeguard-8-1-x-8-2-x" /><id>https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/safeguard-file-encryption-engine-build-28-for-safeguard-8-1-x-8-2-x</id><published>2019-09-25T20:14:00Z</published><updated>2019-09-25T20:14:00Z</updated><content type="html">&lt;h1&gt;Overview&lt;/h1&gt;
&lt;p&gt;With the introduction of the mini file filter driver, which is part of SafeGuard Enterprise as of version&amp;nbsp;&lt;code&gt;8.10&lt;/code&gt;, Sophos provides regular File Encryption Engine updates that just contain improved filter drivers. These updates are provided as Windows Installer Patch files (&lt;code&gt;*.msp&lt;/code&gt;) to allow an easy installation and deployment.&amp;nbsp;As these updates are cumulative, Sophos recommends using the latest version.&lt;/p&gt;
&lt;p&gt;In this post, you can download build version&amp;nbsp;&lt;code&gt;28&lt;/code&gt;&amp;nbsp;of the filter driver engine. An overview of all File Encryption Engine Updates is available&amp;nbsp;&lt;a href="/products/safeguard-encryption/b/blog/posts/file-encryption-engine-updates-for-safeguard-8-10-8-20" target="_blank"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Applies to the following Sophos products and versions&lt;/strong&gt;&lt;br /&gt;SafeGuard File Encryption 8.1&lt;br /&gt;SafeGuard File Encryption 8.2&lt;br /&gt;SafeGuard Synchronized Encryption 8.1&lt;br /&gt;SafeGuard Synchronized Encryption 8.2&lt;br /&gt;SafeGuard Data Exchange 8.1&lt;br /&gt;SafeGuard Data Exchange 8.2&lt;br /&gt;SafeGuard Cloud Storage 8.1&lt;br /&gt;SafeGuard Cloud Storage 8.2&lt;/p&gt;
&lt;h1&gt;&lt;a id="Download and installation"&gt;&lt;/a&gt;Resolved issues (new in File Encryption Engine build 28)&lt;/h1&gt;
&lt;div class="content-scrollable-wrapper"&gt;
&lt;table class="content" cellspacing="1" cellpadding="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;Reference&lt;/th&gt;
&lt;th&gt;Symptom / Summary&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15209&lt;/td&gt;
&lt;td&gt;Compatibility improvement for Sophos Central Intercept X with EDR.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15267&lt;/td&gt;
&lt;td&gt;Potential file corruptions when creating PDFs from Catia (Dassault Syst&amp;egrave;mes).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15306&lt;/td&gt;
&lt;td&gt;&amp;nbsp;File encryption filter removes SmartScreen block functionality from file properties.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;h1&gt;Resolved issues (already part of File Encryption Engine build 27)&lt;a id="anchor_1539071761399" name="resolved issues"&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;div class="content-scrollable-wrapper"&gt;
&lt;table class="content" cellspacing="1" cellpadding="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;Reference&lt;/th&gt;
&lt;th&gt;Symptom or Summary&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPFEE-1173&lt;/td&gt;
&lt;td&gt;Local cache corruptions during an update to Windows 10 October 2018 update (W10 version&amp;nbsp;&lt;code&gt;1809&lt;/code&gt;)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14307&lt;/td&gt;
&lt;td&gt;Explorer performance issues in combination with cached files from Windows Quick Access&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14462&lt;/td&gt;
&lt;td&gt;Increased saving time for files located on network locations (specific applications).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14525&lt;/td&gt;
&lt;td&gt;Access rights issues when running specific applications.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14639&lt;/td&gt;
&lt;td&gt;&lt;code&gt;Bluescreen Bugcheck 0x3b (SYSTEM_SERVICE_EXCEPTION)&lt;/code&gt;&amp;nbsp;on Windows 10 version&amp;nbsp;&lt;code&gt;1809&amp;nbsp;&lt;/code&gt;endpoints&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14511&lt;/td&gt;
&lt;td&gt;Performance improvements (boot and runtime)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14853&lt;/td&gt;
&lt;td&gt;Cannot open encrypted Quickbooks project (other applications potentially affected as well),&lt;br /&gt;when SafeGuard File Encryption filter driver is active.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14771&lt;br /&gt;DPSGN-14806&lt;br /&gt;DPSGN-14842&lt;/td&gt;
&lt;td&gt;Several boot performance improvements.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14995&lt;/td&gt;
&lt;td&gt;High performance impact when accessing files on network shares which are not covered by an encryption rule (requires BypassFilesWithoutPolicyVolumes registry key - see KB132922 for details).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14945&lt;/td&gt;
&lt;td&gt;User is unable to save file certain file types (e.g. docx, xlsx).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14987&lt;br /&gt;DPSGN-15016&lt;/td&gt;
&lt;td&gt;User gets file in use error when opening or saving xlsx files on network location.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14513&lt;/td&gt;
&lt;td&gt;License check of 3rd party application (Dataflex) fails - (requires BypassFilesWithoutPolicyVolumes registry key)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-14856&lt;br /&gt;DPSGN-15051&lt;/td&gt;
&lt;td&gt;File Encryption driver slows down Windows explorer and search operations on network shares.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN-15186&lt;br /&gt;DPSGN-15188&lt;br /&gt;DPSGN-15189&lt;br /&gt;DPSGN-15190&lt;/td&gt;
&lt;td&gt;Important security fixes and improvements.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN - 15245&lt;/td&gt;
&lt;td&gt;Files located on a WebDAV share, occasionally cannot be deleted when file encryption minifilter is active.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN -15014&lt;/td&gt;
&lt;td&gt;Compatibility improvements&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN - 15265&lt;/td&gt;
&lt;td&gt;System might become unresponsive after re-inserting an encrypted optical media&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN - 15261&lt;/td&gt;
&lt;td&gt;SGPortable.exe (and msvcr71.dll and msvcp71.dll) get encrypted by initial encryption&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DPSGN - 15241&lt;/td&gt;
&lt;td&gt;SafeGuard Services not running after update to Windows 10 version 1903 (19H1). This only affects installations of File Encryption Engine build 26.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;h1&gt;Download and installation&amp;nbsp;&lt;/h1&gt;
&lt;p&gt;The File Encryption Engine Update build&amp;nbsp;&lt;code&gt;28&lt;/code&gt;&amp;nbsp;can be applied to SafeGuard Client version&amp;nbsp;&lt;code&gt;8.10.0.323,&lt;/code&gt;&amp;nbsp;&lt;code&gt;&lt;a href="/kb/en-us/133358" target="_blank"&gt;8.10.2.55&lt;/a&gt;&amp;nbsp;and 8.20.0.83&lt;/code&gt;. It automatically updates previously installed File Encryption Engine Updates.&lt;/p&gt;
&lt;p&gt;The installers for version 8.10.x can be obtained from this&amp;nbsp;&lt;a target="_blank"&gt;download link&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The installers for version 8.20.x can be obtained from this&amp;nbsp;&lt;a target="_blank"&gt;download link&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;&lt;a name="32-bit OS"&gt;&lt;/a&gt;Installation for 32-bit OS&lt;/h2&gt;
&lt;h3&gt;If the SafeGuard Client is already installed&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Copy the installer patch files to the corresponding endpoint(s)&lt;/li&gt;
&lt;li&gt;Apply the SafeGuard File Encryption Engine update. Example (based on version 8.10):&amp;nbsp;&lt;code&gt;msiexec /update &amp;quot;C:\Install\File Encryption Engine for SGN 8.1 Build 28.msp&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Reboot the endpoint for the changes to take effect&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;Installation together with SafeGuard Client&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Copy the SafeGuard Client and the installer patch files to the corresponding endpoint(s)&lt;/li&gt;
&lt;li&gt;Install the SafeGuard Client together with the File Encryption Engine update. Example (based on version 8.10):&amp;nbsp;&lt;code&gt;msiexec /i C:\Install\SGNClient.msi PATCH=&amp;quot;C:\Install\File Encryption Engine for SGN 8.1 Build 28.msp&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Reboot the endpoint for the changes to take effect&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;&lt;a name="64-bit OS"&gt;&lt;/a&gt;Installation for 64-bit OS&lt;/h2&gt;
&lt;h3&gt;If the SafeGuard Client is already installed&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Copy the installer patch files to the corresponding endpoint(s)&lt;/li&gt;
&lt;li&gt;Apply the SafeGuard File Encryption Engine update. Example (based on version 8.10):&amp;nbsp;&lt;code&gt;msiexec /update &amp;quot;C:\Install\File Encryption Engine for SGN 8.1 Build 28_x64.msp&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Reboot the endpoint for the changes to take effect&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;Installation together with SafeGuard Client&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Copy the SafeGuard Client and the installer patch files to the corresponding endpoint(s)&lt;/li&gt;
&lt;li&gt;Install the SafeGuard Client together with the File Encryption Engine update. Example (based on version 8.10):&amp;nbsp;&lt;code&gt;msiexec /i C:\Install\SGNClient_x64.msi PATCH=&amp;quot;C:\Install\File Encryption Engine for SGN 8.1 Build 28_x64.msp&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Reboot the endpoint for the changes to take effect&lt;/li&gt;
&lt;/ol&gt;
&lt;h1&gt;&lt;a name="Patch"&gt;&lt;/a&gt;How to verify if the patch is applied&lt;a id="anchor_1539071988949" name="How to verify if the patch is applied"&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;p&gt;After the installation, you can see the new File Encryption Engine in the&amp;nbsp;&lt;strong&gt;Installed Updates&amp;nbsp;&lt;/strong&gt;section of&amp;nbsp;&lt;strong&gt;Programs and Features&lt;/strong&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;As this package just contains new filter drivers and no other products components, this update does not change the version or build number of the installed SafeGuard Client. In the SafeGuard Management Center version 8.20, the file filter engine version of this update (3.0.0.28) is also listed in the installed features list of the Client.&lt;/p&gt;
&lt;h1&gt;&lt;a id="related information" name="related information"&gt;&lt;/a&gt;Related information&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="/kb/en-us/133000" target="_blank"&gt;File Encryption Engine updates for SafeGuard 8.10.x/8.20&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="/kb/en-us/124771" target="_blank"&gt;SafeGuard Enterprise: Supported clients on Windows 10 versions&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=449&amp;AppID=23&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>FloSupport</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/flosupport</uri></author><category term="Engine build 28 for SafeGuard 8.1.x / 8.2.x" scheme="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/archive/tags/Engine%2bbuild%2b28%2bfor%2bSafeGuard%2b8-1-x%2b_2F00_%2b8-2-x" /></entry><entry><title>What’s new in Central Device Encryption (CDE) 2.0?</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/what-s-new-in-sophos-central-device-encryption-cde-2-0" /><id>https://stage-community-sophos-comv11.telligenthosting.net/encryption/b/blog/posts/what-s-new-in-sophos-central-device-encryption-cde-2-0</id><published>2019-09-04T14:18:00Z</published><updated>2019-09-04T14:18:00Z</updated><content type="html">&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-blogs-components-weblogfiles/00-00-00-00-23/CDE.png"&gt;&lt;img src="/cfs-file/__key/communityserver-blogs-components-weblogfiles/00-00-00-00-23/CDE.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;We&amp;rsquo;re delighted to announce the launch of Central Device Encryption 2.0 for Windows. Among the great new functionality is secure document sharing &amp;ndash; enabling users to encrypt Outlook attachments and files before sharing them with internal or external colleagues. Admin enhancements include the ability to prompt for a BitLocker password reset, along with greater visibility into device encryption types. Read on for more details!&lt;/p&gt;
&lt;p&gt;Please note, these features are &lt;strong&gt;Windows only&lt;/strong&gt;.&lt;/p&gt;
&lt;h3&gt;&lt;span style="font-size:inherit;"&gt;&lt;strong&gt;Secure document sharing&lt;/strong&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;With a few clicks, users can create a password-protected file. Encrypted files can only be opened by a recipient with the correct password, they simply need a web browser and valid password to access the documents. Furthermore, a new Outlook add-in enables users to encrypt email attachments before sharing them with internal or external colleagues, safe in the knowledge they remain secure.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;a href="/cfs-file/__key/communityserver-blogs-components-weblogfiles/00-00-00-00-23/2019_2D00_09_2D00_06_5F00_9_2D00_58_2D00_30.png"&gt;&lt;img src="/resized-image/__size/960x720/__key/communityserver-blogs-components-weblogfiles/00-00-00-00-23/2019_2D00_09_2D00_06_5F00_9_2D00_58_2D00_30.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="font-size:inherit;"&gt;&lt;strong&gt;Trigger BitLocker password reset&lt;/strong&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;Prompt users to change BitLocker passwords on a regular basis. Admins select the desired reset frequency and receive alerts for users who choose to repeatedly postpone the password change. An immediate password reset prompt can also be sent to specific devices.&lt;/p&gt;
&lt;h3&gt;&lt;span style="font-size:inherit;"&gt;&lt;strong&gt;Enhanced reporting&lt;/strong&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;Sophos Central now provides details of encryption type, either software-based or hardware-based, along with the algorithm used. For example, admins can see that a device&amp;rsquo;s hard drive has been encrypted using software-based AES 256-bit encryption.&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-blogs-components-weblogfiles/00-00-00-00-23/computer_5F00_details2.png"&gt;&lt;img src="/resized-image/__size/960x720/__key/communityserver-blogs-components-weblogfiles/00-00-00-00-23/computer_5F00_details2.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="font-size:inherit;"&gt;&lt;strong&gt;Software-based encryption&lt;/strong&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;Sophos Central Device Encryption will now apply software-based encryption by default, even if devices support hardware-based encryption. Note that existing devices, already encrypted with hardware based encryption, will not be affected.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=444&amp;AppID=23&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>tom_w</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/tom_5f00_w</uri></author></entry></feed>