4.2 Performing Recovery Operations

The following sections provide information about the emergency recovery operations you can perform on hard disks.

4.2.1 Decrypting a Drive

Typical scenarios where you might need to decrypt a drive include:

  • ZENworks Full Disk Encryption was removed from the device before the drive was decrypted.

  • Decryption was interrupted abnormally (for example, because of a power failure).

To decrypt a drive:

  1. Make sure you have launched the Emergency Recovery application and loaded the device’s ERI file. See Launching the Emergency Recovery Application.

  2. In the Workbench tree, select the drive you want to decrypt, then click the Partition menu > Decrypt to display the Decrypt Drive dialog box.

  3. Deselect the Decrypt only used sectors option if you want to decrypt all of the drive’s sectors (both used and unused).

    Decrypting all sectors (used and unused) can take significantly longer than decrypting only used sectors.

  4. Click OK to start the decryption process.

4.2.2 Repairing the Master Boot Record

When a Disk Encryption policy is applied to a device, the ZENworks Full Disk Encryption Agent creates a 500 MB partition, referred to as the ZENworks partition, and modifies the master boot record (MBR) to set the ZENworks partition as the boot partition.

It is possible for other applications to modify the MBR and cause the device to no longer boot to the ZENworks partition. If this occurs, you can repair the MBR. Repairing the MBR fixes any problems that prevent the device from booting to the ZENworks partition.

  1. Make sure you have launched the Emergency Recovery application and loaded the device’s ERI file. See Launching the Emergency Recovery Application.

  2. Click the BootChain menu > Repair MBR to display the Repair MBR dialog box.

  3. Click OK to start the repair process.

    The dialog box closes when the repair is complete.

  4. Close the application.

  5. Shut down the device, then restart it.

4.2.3 Restoring the Original Master Boot Record

When a Disk Encryption policy is applied to a Windows device, the ZENworks Full Disk Encryption Agent creates a 500 MB partition, referred to as the ZENworks partition, and modifies the master boot record (MBR) to set the ZENworks partition as the boot partition.

You can restore the original MBR if necessary.

  1. Make sure you have launched the Emergency Recovery application and loaded the device’s ERI file. See Launching the Emergency Recovery Application.

  2. Click the BootChain menu > Restore Original MBR to display the Restore Original MBR dialog box.

  3. Click OK to start the restore process.

    The dialog box closes when the original MBR is restored.

  4. Close the application.

  5. Shut down the device, then restart it.

4.2.4 Erasing the Disk

The Emergency Recovery application can perform a secure erase of a standard hard disk. The process removes all data from the disk. This includes both encrypted and unencrypted volumes.

  1. Make sure you have launched the Emergency Recovery application and loaded the device’s ERI file. See Launching the Emergency Recovery Application.

  2. Click the Administration menu > Erase Harddrive, then follow the prompts.

    It takes approximately 30 to 40 minutes to erase 10 GB of data, so the entire process can take a long time.

  3. When the erasure process is complete, close the application.

  4. Shut down the device.

4.2.5 Setting the Administration Password

The ZENworks Full Disk Encryption components (Full Disk Encryption Agent and ZENworks PBA) have an Administration password that is for internal administrative functions as well as several administrator functions available during ZENworks PBA login. The only time you should need to use this password is in conjunction with Micro Focus Support.

The password is device specific and is randomly generated when a Disk Encryption policy is applied to the device. The password is recorded in ZENworks Control Center in the same location as the device’s ERI file (Full Disk Encryption > Emergency Recovery).

You can use the Emergency Recovery application to assign a new Administrator password to a device.

  1. Make sure you have launched the Emergency Recovery application and loaded the device’s ERI file. See Launching the Emergency Recovery Application.

  2. Click the Administration menu > Set admin-password.

  3. Specify a new password, and then click OK.

  4. Close the application.