2.1 Moving a Device to a Zone Where Endpoint Security Management Is Not Active

When you move a device to a zone where Endpoint Security Management is not active (or the Endpoint Security Agent feature is disabled or not installed with the ZENworks Agent), all security policies are cleared from the device and the Endpoint Security Agent is either uninstalled or disabled.

To move a device:

  1. If a Microsoft Data Encryption policy is applied to the device with Removable Data Drive encryption enabled, ensure users can still access any drives encrypted by the policy after moving the device. For more information, see Removal Best Practices in the ZENworks Endpoint Security Policies Reference.

  2. Unregister the device. See Unregistering a Device in the ZENworks Discovery, Deployment, and Retirement Reference.

    This clears all security policies and removes the device as a registered device in the zone.

  3. Register the device in the new zone. See Manually Registering a Device in the ZENworks Discovery, Deployment, and Retirement Reference.

    After the device registers in the zone, the ZENworks Agent uninstalls or disables the Endpoint Security Agent. It is uninstalled if the Endpoint Security Management license is not active or if the Endpoint Security Agent is not configured as an installed feature of the ZENworks Agent. It is disabled if the license is active but the agent is configured as a disabled feature of the ZENworks Agent.