Endpoint Encryption
- 
 they are currently running vdi and local computers aren't on a domain. Something I'm changing soon. I'm not really looking for troubleshooting, just products. Thanks 
- 
 @Hubtech said: they are currently running vdi and local computers aren't on a domain. Something I'm changing soon. I'm not really looking for troubleshooting, just products. Thanks Ok, my bad. Then yea, several options are out there but I'm far from an expert on the matter of centrally managed encryption. 
- 
 Here's a decent comparison chart: http://en.wikipedia.org/wiki/Comparison_of_disk_encryption_software Depending on which A/V solution you are using, you might want to go with that. Our philosophy here is to not put all our eggs in the same basket, so we use McAfee for encryption and Symantec for A/V. YMMV. 
- 
 I'm using Vipre via GFI Max at this particular client. I've been asking them to add endpoint encryption to their offering. they really listen to their subscribers. just a waiting game though 
- 
 @Hubtech said: I'm using Vipre via GFI Max at this particular client. I've been asking them to add endpoint encryption to their offering. they really listen to their subscribers. just a waiting game though That's pretty cool. Will they be offering centralized management when they do? 
- 
 @scottalanmiller said: @Hubtech said: I'm using Vipre via GFI Max at this particular client. I've been asking them to add endpoint encryption to their offering. they really listen to their subscribers. just a waiting game though That's pretty cool. Will they be offering centralized management when they do? that's the plan. I've been riding them for a little while now asking to be on their beta team:) i'm such a gfiFanboi 
- 
 @Hubtech Using Symantec PGP since before it as Symantec's. Backend is not for the faint of heart. Not inexpensive overall. Central management and policy enforcement was a mandatory component for the clinical users/HIPAA. Has a reasonable wrapper for multiple logins to access the encrypted HDD, can do remote revocation, tracks usage/callbacks, and makes our OCR monitor happy. Have an agreement for data recovery & encryption key exchange if/when that needs to occur. Has a CD boot option to decrypt drives. Works for external HDDs. Policy has high number of options, which we have much limited for manageability. Generally have problems with: - new laptop models,
- new OSes,
- dual boot machines, and
- firmware/BIOS/UEFI updates.
 Some I.T. admins have got it on dual boot machines, but most in the organization make do with VMs for those users. Can take 3-6 months for a PGP update to catchup to the "new" OS or laptops. 
- 
 BeCrypt DiskProtect is worth looking at - used heavily in defence and government (with higher grade approved encryption). 
- 
 @Bud said: Here's a decent comparison chart: http://en.wikipedia.org/wiki/Comparison_of_disk_encryption_software Depending on which A/V solution you are using, you might want to go with that. Our philosophy here is to not put all our eggs in the same basket, so we use McAfee for encryption and Symantec for A/V. YMMV. Always a good move. Of course all us vendors want everyone using every product but come on...we know that diversity in applications keeps you safe. If you need anything w/r/t your SEP, hit me up. 
- 
 Long time follow up here. But for those stumbling on there, VeraCrypt would be an important tool to consider today. 




