Configuring Media Encryption and Port Protection

Media Encryption & Port Protection protects data stored in the organization by encrypting removable media devices and allowing tight control over computer ports (USB, Bluetooth, and so on). Removable devices are for example: USB storage devices, SD cards, CD/DVD media and external disk drives.

On the client-side, Media Encryption & Port Protection protects sensitive information by encrypting data and requiring authorization for access to storage devices and other input/output devices.

Media Encryption lets users create encrypted storage on removable storage devices that contain business-related data. Encrypted media is displayed as two drives in Windows Explorer. One drive is encrypted for business data. The other drive is not encrypted and can be used for non-business data. Rules can apply different access permissions for business data and non-business data.

Port Protection controls, according to the policy, device access to all available ports including USB and Firewire (a method of transferring information between digital devices, especially audio and video equipment). Policy rules define access rights for each type of removable storage device and the ports that they can connect to. The policy also prevents users from connecting unauthorized devices to computers.

Note:

Media Encryption, Remote Help, and automatic access do not work if you install the scanner after installing Media Encryption. To ensure proper operation, install the required scanner (Microsoft Entra ID or Active Directory) before you install Media Encryption.

Media Encryption & Port Protection functionalities are available in both Windows and macOS clients (for macOS starting at client version E85.30).

Tip:

We recommend to not encrypt non-computer external devices such as: digital cameras, smartphones, MP3 players, and the like. Do not encrypt removable media that can be inserted in or connected to such devices.

For instructions on how to encrypt, see sk166110.

Configuring the Read Action

The Read action defines the default settings for read access to files on storage devices. For each action, you can define different settings for specified device types. The default predefined actions are:

  • Allow encrypted data - Users can read encrypted data from storage devices (typically business-related data).

  • Allow unencrypted data - Users can read unencrypted data from storage devices (typically non business-related data).

You can configure these actions for specific devices.

To configure the Read action

  1. In the Media Encryption tab, go to Exclusions Center.

  2. Click New to create a new exclusion or configure an existing exclusion on the list.

  3. Configure the options as necessary for: Read Encrypted, Read Unencrypted:

    • Read Encrypted

      • Accept - Allow reading only encrypted data from the storage device. Users cannot read unencrypted data from the storage device.

      • According to Policy - According to the default Media Encryption & Port Protection rule.

      • Block - Block all reading from the storage device.

    • Read Unencrypted

      • Accept - Allow reading of unencrypted files from the storage device.

      • According to Policy - According to the default Media Encryption & Port Protection rule

      • Block - Block reading of unencrypted files from the storage device.

Import exclusions

You can import an exported exclusion file in the JSON format.

  1. In the Media Encryption tab, click View Exclusions.
  2. Click Import and select the JSON file.

To export exclusions

  1. In the Media Encryption tab, click View Exclusions.
  2. Select the exclusion from the list.
  3. Click Export.