Enable Silent Enrollment for PGP Encryption Desktop (Symantec Encryption Desktop)
search cancel

Enable Silent Enrollment for PGP Encryption Desktop (Symantec Encryption Desktop)

book

Article ID: 153688

calendar_today

Updated On:

Products

Encryption Management Server

Issue/Introduction

This article details how to enable silent enrollment for Symantec Encryption Desktop application (previously PGP Desktop).
 

Resolution

Silent enrollment reduces the number of screens your users must navigate during enrollment with Symantec Encryption Management Server. Only essential Setup Assistant screens appear during enrollment. Silent enrollment suppresses non-essential screens and uses default settings. Silent Enrollment is supported on both Windows and Mac Operating Systems, but is not supported on Linux clients.

Silent enrollment requires the use of the LDAP Directory Synchronization feature.

To enable Silent enrollment

  1. Login to the Symantec Encryption Management Server (previously PGP Universal Server) admin interface.
  2. If Directory Synchronization is currently not enabled, click Consumers > Directory Synchronization and then click Enable.
  3. On the Directory Synchronization screen, click Settings.
  4. Place a checkmark next to Enroll clients using directory authentication and then click Save.
  5. Enable Silent Enrollment for the users policy by clicking Consumers > Consumer Policy and then selecting the desired policy.
  6. Click Desktop next to PGP Desktop. The PGP Desktop options are displayed.
  7. Scroll down and place a checkmark next to Enable Silent Enrollment.
  8. Download the client installer by selecting Consumers > Groups and then clicking Download Client. The Download PGP Clients screen is displayed.
  9. Select the Client, Platform, Language, and then place a checkmark next to Customize.

    Note: Select the client to use Auto-detect Policy Group (Preset Policy is only used if no LDAP Enrollment is being used).
     
  10. Click Download and specify a location for the installer file.
  11. Upon reboot after installation, the enrollment wizard will be displayed.  Enter the username and password associated to the user.  

Considerations:

 

  • When using Silent Enrollment, only one Keymode should be configured in the policy.  Because the Silent Enrollment wizard eliminates certain portions of the normal enrollment wizard, select only the keymode that is intended on being used.
  • Key Reconstruction can be enabled for Silent Enrollment, however this will add additional windows to the enrollment screen.
  • Enrollment using SKM key mode is completely silent as users are not prompted for key creation. 
  • Enrollment using GKM will use the Windows password as the passphrase of the key.  Although this is done automatically, when the Windows password is changed, the passphrase for the GKM key remains unchanged.
  • Silent Enrollment is not to be confused with Invisible Silent Enrollment.  Invisible Silent Enrollment eliminates the actual enrollment prompt, such that the user would not be prompted to enroll and is done behind the scenes.  For more information on Invisible Silent Enrollment, see article 181069.

 

 

Applies To

Symantec Encryption Management Server 10.5.X

Microsoft Windows Family Operation Systems

Additional Information

153668 - Enroll PGP Encryption Desktop client using Directory Authentication with PGP Encryption Server (Symantec Encryption Management Server)


180181 - Re-enrolling PGP Encryption Desktop for Windows clients (Symantec Encryption Desktop)
181366 - Re-enrolling PGP Encryption Desktop for Linux Clients (Symantec Encryption Desktop)
155714 - Re-enrolling PGP Encryption Desktop for macOS X clients (Symantec Encryption Desktop)

217682 - Enrolling a user on multiple machines with PGP Encryption Desktop with SCKM Keymode (Symantec Encryption Desktop) 

153688 - Enable Silent Enrollment for PGP Encryption Desktop (Symantec Encryption Desktop)
181069 - Configure Invisible Silent Enrollment for PGP Encryption Desktop (Symantec Encryption Desktop Clients)

153437 - Using Email Enrollment for PGP Desktop Clients with the PGP Server (Symantec Encryption Management Server)
153324 - PGP Email Proxy Fails or Next Button Grayed out during Enrollment to PGP Encryption Server (Symantec Encryption Management Server)