Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

First restart after encryption and no recovery key has been created, locked out.

Hi there,

I was beginning a first time roll-out of Sophos Easy to a few laptops but have one locked out laptop and apparently no way to recover it. Two laptops encrypted fine (this is using Sophos Policy manager to configure), the third laptop completed the encryption phase after a couple of days and the first restart after was away from base and so no contact with our Sophos server.

So, first POA and the workstation is 'locked out'. All recovery options I'm aware of require a recovery key file which was never created. Goes without saying that this is incredibly annoying, not to mention damaging if we have pretty quickly lost all data on this machine because Sophos will lock out even if it hasn't sent a recovery file to the server.

Is there anything to try? I've tried slaving the drive to another machine to confirm that it is actually encrypted, it was.

If a separate hard disk is installed in this locked laptop, and encrypted with the same credentials but this time make sure a key was created, can this be used to decrypt the first hard disk?

Thanks in advance.

:35287


This thread was automatically locked due to age.
  • Hi R_Fluent,

    could you specify what 'locked out' means? is there no POA on the machine or is the POA not loading completely? Or does the POA even load completely and states that the machine is locked and requires a Challenge/Response?

    "If a separate hard disk is installed in this locked laptop, and encrypted with the same credentials but this time make sure a key was created, can this be used to decrypt the first hard disk?"

    This is not possible as encryption keys change with every installation.

    Cheers,

    Chris

    :35777
  • Locked out as in the POA dialogue used the words 'This workstation is locked' in red text.

    This thread can be closed as we will no longer be using Sophos to encrypt our machines.

    :35779