ALERT: Some images may not load properly within the Knowledge Base Article. If you see a broken image, please right-click and select 'Open image in a new tab'. We apologize for this inconvenience.

Symantec Endpoint Encryption Client, version 11.0.x - System Requirements

book

Article ID: 161130

calendar_today

Updated On:

Products

Endpoint Encryption

Issue/Introduction

This article details the system requirements for the current version of Symantec Endpoint Encryption Client.

Resolution

The article will be updated as additional platforms or other system requirements are tested and added for Symantec Encryption Desktop for Windows.

Updates

Platform \ Functionality Added Added in Release Date Support Added
Mac OS X 10.10.5 (Symantec Endpoint Encryption for FileVault and the Removable Media Encryption Access Utility for Mac) 11.0.1 MP1 Sept 4, 2015
Microsoft Windows 10 11.0.1 MP1 Aug 27, 2015
Mac OS X 10.10.4 (Symantec Endpoint Encryption for FileVault and the Removable Media Encryption Access Utility for Mac) 11.0.1 MP1 Aug 27, 2015


System Requirements for Endpoint Encryption 11.0.0 GA Release

Software requirements for Drive Encryption

Compatible Microsoft Windows operating systems

Operating Systems Compatible Firmware Interfaces
Microsoft Windows 8.1 Enterprise, 64-bit 1 BIOS, UEFI
Microsoft Windows 8.1 Enterprise, 32-bit 1 BIOS
Microsoft Windows 8.1 Pro, 64-bit BIOS, UEFI
Microsoft Windows 8.1 Pro, 32-bit  BIOS
Microsoft Windows 8 Enterprise, 64-bit BIOS, UEFI
Microsoft Windows 8 Enterprise, 32-bit BIOS
Microsoft Windows 8 Pro, 64-bit BIOS, UEFI
Microsoft Windows 8 Pro, 32-bit BIOS
Microsoft Windows 7 Ultimate SP1, 64-bit BIOS, UEFI
Microsoft Windows 7 Ultimate SP1, 32-bit BIOS, UEFI
Microsoft Windows 7 Enterprise SP1, 64-bit BIOS, UEFI
Microsoft Windows 7 Enterprise SP1, 32-bit BIOS, UEFI
Microsoft Windows 7 Professional SP1, 64-bit BIOS, UEFI
Microsoft Windows 7 Professional SP1, 32-bit BIOS, UEFI
Microsoft Windows Server 2012 R2 Datacenter, 64-bit 2 BIOS
Microsoft Windows Server 2012 R2 Standard, 64-bit 2 BIOS
Microsoft Windows Server 2008 R2 Enterprise SP1, 64-bit BIOS
Microsoft Windows Server 2008 R2 Standard SP1, 64-bit BIOS

 

1. Including the November 2014 update, August 2014 update, and Update 1 for Windows 8.1.
2. Including the November 2014 update, August 2014 and R2 update.


Notes

  • These operating systems are supported only with all of the latest hot fixes and security patches from Microsoft.
     
  • For the client software to appear properly on Microsoft Windows Server 2008 R2 and Microsoft Windows Server 2012 R2 when using Symantec Endpoint Encryption 11.0.0, you must install the Aero Desktop theme. You must be an administrator to install the theme. For more information on how to install the Aero Desktop theme, see the Microsoft documentation.
     
  • Starting with Symantec Endpoint Encryption 11.0.1, users are not required to install the Aero Desktop theme on Microsoft Windows Server 2008 R2 or Windows Server 2012 R2.
     
  • Drive Encryption is not compatible with the Microsoft Windows BitLocker Drive Encryption feature. Symantec Endpoint Encryption does not support a system running BitLocker.
     
  • Drive Encryption is compatible with software based encryption of Opal V1 and Opal V2 drives. Drive Encryption will handle these drives as regular non-Opal drives and will not take advantage of their hardware-based encryption capabilities.
     
  • Symantec Endpoint Encryption does not support a client that you have configured for Dual Boot (when Microsoft Windows and Linux are both installed in BIOS mode).
     

Drive Encryption on Microsoft Windows Servers

Drive Encryption is supported on all client versions above as well as the following Windows Server versions:

  • Microsoft Windows Server 2012 R2,Datacenter 64-bit, with update with internal RAID 1 and RAID 5 (UEFI and BIOS boot mode)
  • Microsoft Windows Server 2012 R2,Standard 64-bit, with update with internal RAID 1, (UEFI boot mode only)
  • Microsoft Windows Server 2008 R2 64-bit Standard SP1, with internal RAID 1 and RAID 5, (UEFI and BIOS boot mode)
  • Microsoft Windows Server 2008 R2 64-bit Enterprise SP1, with internal RAID 1, (BIOS boot mode only)
     

Notes:

  • Dynamic disks and software RAID are not supported.
  • These operating systems are supported only with all of the latest hot fixes and security patches from Microsoft.
     

.NET Framework requirements for Drive Encryption

  • Symantec Endpoint Encryption requires you to enable multiple versions of .NET. One version of .NET is required to install the application and one version of .NET is required to use the application.
  • You must make sure that .NET is enabled before you can install the components.
  • The Drive Encryption requires .NET 4.0 and .NET 3.5
     

Supported Virtual Machines

  • VMware ESXi 5.1
  • VMware ESXi 5.5


Citrix and Terminal Services Compatibility

Symantec Endpoint Encryption supports the Management Agent with the following terminal services software:

  • Microsoft Windows Server 2008 Terminal Services R2 (SP1) (Remote Desktop Services) 32-bit and 64-bit
  • Microsoft Windows Server 2012 R2, 32-bit, and 64-bit with update
  • Citrix XenDesktop 7.1
  • Citrix XenApp 6.5 (formerly named Presentation Server and MetaFrame Server)
  • Citrix XenServer 6.1 Hypervisor
  • VMware vSphere 5.5
     

Notes

  • Symantec Endpoint Encryption does not support Drive Encryption in the Citrix and Terminal Services environments.
  • These operating systems are supported only with all of the latest hot fixes and security patches from Microsoft.
     

Tablet Support

Microsoft Surface Pro 3, with external Type or Touch keyboard

The external Type or Touch keyboard is required for preboot authentication on the tablet. The keyboard can be detached once the user authenticates.

Drive Encryption is not compatible with the Microsoft Windows BitLocker Drive Encryption feature. BitLocker is enabled by default.

Note: You must disable BitLocker to use Symantec Endpoint Encryption functionality on tablet computers.

Online Help requirements

To view the online Help, Symantec Endpoint Encryption requires Microsoft Internet Explorer 8, 9, 10, or 11.


Smart card support for preboot authentication

Symantec Endpoint Encryption supports the following for preboot authentication on both BIOS and UEFI systems:

Smart card readers

  • Any generic USB CCID-compatible readers that you connect to a USB port.
     

Personal Identity Verification (PIV) cards

  • G&D SmartCafe Expert 144K DI v3.2
  • G&D SmartCafe Expert 80K DI v3.2
  • Gemalto Cyberflex Access 64K v2c
  • Gemalto ID Prime .NET
  • Gelmalto TOP DL GX4 144K FIPS
  • HID Global Crescendo JCOP 21 version 2.4.1 R2 64K
  • Oberthur ID-One Cosmo v7.0
  • Oberthur CS PIV End Point v1.08 FIPS201 Certified
  • Oberthur ID-One Cosmo 128 v5.5 Dual
     

Symantec Endpoint Encryption requires the following smart card firmware:

  • AMI
  • HPQ
     

Note: If you have issues with any of the cards listed, refer to the following Symantec knowledge base article: http://www.symantec.com/docs/TECH222272
 

System requirements for Symantec Endpoint Encryption for FileVault

You can install Symantec Endpoint Encryption for FileVault on Macintosh computers running the following versions of Mac OS X operating systems:
  • Mac OS X 10.8.1, 10.8.2, 10.8.3, 10.8.4, 10.8.5
  • Mac OS X 10.9, 10.9.1, 10.9.2, 10.9.3, 10.9.4, 10.9.5
  • Mac OS X 10.10, 10.10.1, 10.10.2, 10.10.3

Supported and unsupported disk types for Drive Encryption

The following are the supported and unsupported disk types and file systems for Drive Encryption:

Supported disk types

  • Desktop or laptop disks, including solid-state drives (either partitions or an entire disk)
  • USB flash disks
  • Advanced format drives with 512-byte emulation mode (512e)
  • FAT32, and NTFS formatted disks or partitions
  • Up to ten logical partitions
  • GPTboot disks on Microsoft Windows 8.x and Microsoft Windows Server 2012 (UEFI systems only)
     

The following are the supported Opal v2 compliant eDrives for Drive Encryption:

  • Samsung SSD 840 EVO mSATA
  • Intel SSD Pro 2500
     

Drive Encryption manages these drives and uses the Opal drive's built-in hardware encryption capability when these drives are used with following laptop models:

  • Lenovo ThinkPad W540
  • Lenovo ThinkPad T540p
  • Lenovo ThinkPad X240
     

Note: For unsupported laptops, Drive Encryption is compatible with software-based encryption of Opal V1 and Opal V2 drives. Drive Encryption handles these drives as regular non-Opal drives and does not take advantage of their hardware-based encryption capabilities.

Unsupported disk types

  • Any configuration where the system partition is not on the same disk as the boot partition
  • Native mode advanced format drives
  • Dynamic disks
  • SCSI drives and controllers
  • Software RAID disks
  • exFAT formatted disks
  • Resilient File System (ReFS)
     

Software Requirements for Removable Media Encryption

You can install Removable Media Encryption functionality on systems running the following versions of Microsoft Windows operating systems:

  • Microsoft Windows Server 2012 R2 Datacenter (64-bit) with update
  • Microsoft Windows Server 2012 R2 Standard (64-bit) with update
  • Microsoft Windows Server 2008 R2 Enterprise (64-bit, including Service Pack 1)
  • Microsoft Windows Server 2008 R2 Standard (64-bit, including Service Pack 1)
  • Microsoft Windows 8.1 Pro 64-bit, update 1 in BIOS and UEFI mode
  • Microsoft Windows 8.1 Pro 32-bit,, update 1 in BIOS mode
  • Microsoft Windows 8.1 Enterprise 64-bit, update 1 in BIOS and UEFI mode
  • Microsoft Windows 8.1 Enterprise 32-bit,, update 1 in BIOS mode
  • Microsoft Windows 8.1 Enterprise 64-bit in BIOS and UEFI mode
  • Microsoft Windows 8.1 Enterprise 32-bit in BIOS mode
  • Microsoft Windows 8 Pro 64-bit in BIOS and UEFI mode
  • Microsoft Windows 8 Pro 32-bit in BIOS mode
  • Microsoft Windows 8 Enterprise 64-bit in BIOS and UEFI mode
  • Microsoft Windows 8 Enterprise 32-bit in BIOS mode
  • Microsoft Windows 8 Pro 64-bit in BIOS and UEFI mode
  • Microsoft Windows 8 Pro 32-bit in BIOS mode
  • Microsoft Windows 7 (all 32- and 64-bit editions, including Service Pack 1 in BIOS and UEFI mode)

Note: These operating systems are supported only with all of the latest hot fixes and security patches from Microsoft.

Supported virtual servers include:

  • VMware ESXi 5.5
  • VMware ESXi 5.1
  • VMware vSphere 5.5
  • Citrix XenServer 6.1 Hypervisor
     

In addition to the Microsoft Windows operating systems, Removable Media Access Utility is supported on the following platforms:

  • Mac OS X 10.9.10, 64-bit
  • Mac OS X 10.9.5, 64-bit
  • Mac OS X 10.9.4, 64-bit
  • Mac OS X 10.9.3, 64-bit
  • Mac OS X 10.9.2, 64-bit
  • Mac OS X 10.9.1, 64-bit
  • Mac OS X 10.9, 64-bit
  • Mac OS X 10.8.5, 64-bit
     

.NET Framework Requirements

Symantec Endpoint Encryption requires you to enable multiple versions of .NET. One version of .NET is required to install the application and one version of .NET is required to use the application.

You must make sure that .NET is enabled before you can install the components.

The Removable Media Encryption requires .NET 4.0 and .NET 3.5

Online Help requirements

To view the online Help, Symantec Endpoint Encryption requires Microsoft Internet Explorer 8, 9, 10, or 11.

System requirements for Symantec Data Loss Prevention

To integrate Removable Media Encryption with Symantec Data Loss Prevention, the supported versions of Symantec Data Loss Prevention are 11.5.1 and 12.5.x.

Supported and unsupported media for Removable Media Encryption

The following are the supported and unsupported media for Removable Media Encryption:

Supported media

  • USB flash drives
  • USB external hard drives
  • FireWire external hard drives
  • eSATA external hard drives
  • Secure Digital (SD) cards and memory cards
  • CompactFlash cards
  • NTFS drives that are compressed
  • CD-RW and DVD-RW
  • Blu-Ray
     

Unsupported media

  • Music devices and digital cameras
  • Diskettes