HP 2 Base Model manual Advanced Settings, Device Administrators group

Page 97

Advanced Settings

Advanced Settings provides the following functions:

Management of the Device Administrators group

Management of drive letters to which Device Access Manager never denies access.

The Device Administrators group is used to exclude trusted users (trusted in terms of device access) from the restrictions imposed by a Device Access Manager policy. Trusted users usually include system administrators. Refer to Device Administrators group on page 89 for more information.

The Advanced Settings view also enables the administrator to configure a list of drive letters to which Device Access Manager will not restrict access for any user.

NOTE: The Device Access Manager background services must be running when the list of drive letters is configured.

To start these services:

1.Apply a Simple Configuration policy, such as denying all non-device administrators access to removable media.

– or –

Open a command prompt window with Administrator privileges, and then type:

sc start flcdlock

Press enter.

2.When the services are started, the drive list can be edited. Enter the drive letters of devices that you do not want Device Access Manager to control.

The drive letters are displayed for physical hard disks or partitions.

NOTE: Whether or not the system drive (typically C) is in this list, access to it will never be denied for any user.

Device Administrators group

When Device Access Manager is installed, a Device Administrators group is created.

The Device Administrators group is used to exclude trusted users (trusted in terms of device access) from the restrictions imposed by a Device Access Manager policy. Trusted users usually include system administrators.

NOTE: Adding a user to the Device Administrators group does not automatically allow the user to access devices. In the Device Class Configuration view, if the Users group is denied access to a device, the Device Administrators group must be granted access in order for members of the group to have access to the device. However, the Simple Configuration view can be used to deny access to device classes for all users who are not members of the Device Administrators group.

To add users to the Device Administrators group:

1.In the Advanced Settings view, click +.

2.Enter the user name of the trusted user.

Advanced Settings 89

Image 97
Contents HP ProtectTools First Edition January Document Part Number Table of contents HP ProtectTools Security Manager Drive Encryption for HP ProtectTools select models only File Sanitizer for HP ProtectTools 100 107 102112 Introduction to security Application FeaturesModule Key features HP ProtectTools featuresHP ProtectTools features Drive Encryption for HP ProtectTools Credential Manager for HP ProtectToolsFile Sanitizer for HP ProtectTools Device Access Manager for HP ProtectToolsComputrace for HP ProtectTools formerly LoJack Pro Privacy Manager for HP ProtectToolsEmbedded Security for HP ProtectTools select models only Page Achieving key security objectives Restricting access to sensitive dataProtecting against targeted theft Creating strong password policies Additional security elements Managing HP ProtectTools passwordsAssigning security roles Additional security elements Backing up and restoring HP ProtectTools credentials Creating a secure passwordGetting started with the Setup Wizard Page HP ProtectTools Security Manager Administrative Console Opening HP ProtectTools Administrative Console Security Users Credentials Using Administrative ConsoleSetting up authentication for your computer Configuring your systemLogon Policy Managing users SettingsSession Policy SpareKey CredentialsFingerprints Face Smart cardUpdates and Messages Configuring your applicationsGeneral tab Applications tabHP ProtectTools Security Manager Opening Security Manager Using the Security Manager dashboard HP ProtectTools desktop gadget Security Applications StatusBlue-OK My Logons Password ManagerAdding logons Editing logons Organizing logons into categories Using the Logons menuManaging your logons Password Manager icon settings Assessing your password strengthClick Add Logon VeriSign Identity Protection VIPClick Continue Changing your Windows password SettingsCredential Manager Enrolling your fingerprints Setting up your SpareKeyClick the Administration tab Setting up a smart cardUnder Central Management, click Setup Wizard Initializing the smart cardEnrolling scenes for face logon Configuring the smart cardClick Create PIN Advanced User SettingsClick OK HP ProtectTools Security Manager Your personal ID card Setting your preferencesFingerprint tab Show scan quality feedback Backing up and restoring your dataClick Back up data Click Restore data Drive Encryption for HP ProtectTools select models only Opening Drive Encryption General tasks Click FeaturesActivating Drive Encryption for standard hard drives Activating Drive Encryption for self-encrypting drivesHardware encryption Software encryptionLogging in after Drive Encryption is activated Deactivating Drive EncryptionPcmcia readers Smart cardsUSB readers Protect your data by encrypting your hard drive Click SettingsDisplaying encryption status Under My Data, click Drive EncryptionAdvanced tasks Managing Drive Encryption administrator taskRecovering encryption keys Backup and recovery administrator taskBacking up encryption keys Privacy Manager for HP ProtectTools select models only Opening Privacy Manager Managing Privacy Manager Certificates Setup proceduresRequesting a Privacy Manager Certificate Click Request a Privacy Manager CertificateImporting a third-party certificate Setting up a Privacy Manager CertificateViewing Privacy Manager Certificate details Setting a default Privacy Manager CertificateRenewing a Privacy Manager Certificate Click Certificate detailsRestoring a Privacy Manager Certificate Deleting a Privacy Manager CertificateRevoking your Privacy Manager Certificate Click AdvancedAdding Trusted Contacts Managing Trusted ContactsAdding a Trusted Contact Adding Trusted Contacts using Microsoft Outlook contacts Deleting a Trusted Contact Viewing Trusted Contact detailsChecking revocation status for a Trusted Contact Configuring Privacy Manager for Microsoft Outlook Using Privacy Manager in Microsoft OutlookSigning and sending an e-mail message Sealing and sending an e-mail message Using Privacy Manager in a Microsoft Office 2007 documentViewing a sealed e-mail message Signing a Microsoft Office document Configuring Privacy Manager for Microsoft OfficeAdding a suggested signers signature line Encrypting a Microsoft Office documentSending an encrypted Microsoft Office document Removing encryption from a Microsoft Office documentViewing a signed Microsoft Office document Viewing an encrypted Microsoft Office document Restoring Privacy Manager Certificates and Trusted Contacts Backing up Privacy Manager Certificates and Trusted ContactsCentral administration of Privacy Manager File Sanitizer for HP ProtectTools Shredding Free space bleaching Opening File Sanitizer Setting a free space bleaching schedule Setting a shred scheduleSelecting a predefined shred profile Selecting or creating a shred profileCustomizing a shred profile High Security Medium Security Low SecurityCustomizing a simple delete profile Page Using a key sequence to initiate shredding Manually shredding one asset Using the File Sanitizer iconManually shredding all selected items Aborting a shred or free space bleaching operation Manually activating free space bleachingViewing the log files Click Bleach NowDevice Access Manager for HP ProtectTools select models only Opening Device Access Manager Simple Configuration Configuring device accessStarting the background service Device Class ConfigurationPage Allowing access for a user or a group Denying access to a user or groupDevice class All devices Individual device Allowing access to a specific device for one user of a group Removing settings for a user or a group Jita ConfigurationResetting the configuration Creating an extendable Jita for a user or group Creating a Jita for a user or groupDisabling a Jita for a user or group Device Administrators group Advanced SettingsUnmanaged Device Classes ESATA SupportPage Go to https//cc.absolute.com Theft recoveryEmbedded Security for HP ProtectTools select models only Enabling the embedded security chip in Computer Setup Initializing the embedded security chip Setting up the basic user account Encrypting files and folders Using the personal secure driveSending and receiving encrypted e-mail Changing the Basic User Key password Restoring certification data from the backup file Creating a backup fileBacking up and restoring Resetting a user password Changing the owner passwordMigrating keys with the Migration Wizard Localized password exceptions Page Special key handling BiosBios What to do when a password is rejected Glossary Device access control policy Cryptographic service provider CSPEmergency recovery archive CryptographyEncryption File System EFS Power-on authenticationFingerprint Free space bleachingRestore RebootRevocation password Sata device modeSuggested signer Windows administratorToken Trusted ContactIndex Face JitaPage
Related manuals
Manual 87 pages 16.32 Kb