Selecting Decrypt Disk in preboot decrypts an encrypted Full Disk Encryption hard disk, but does not remove
any of the encryption drivers.
![]() |
WARNING
|
To decrypt the Full Disk Encryption device, the user must have sufficient rights to
access the recovery console. To allow all users in a group/policy to access the recovery
console, enable the following policy:
Management Console
|
Menu Path
|
PolicyServer MMC
|
Go to
. |
Control Manager
|
Create or edit a policy, then go to
. |
With an Administrator, Authenticator, or permitted User, perform the following to
decrypt a disk.
Procedure
- Log on to Recovery Console.
Recovery Console opens to the Manage Disk page.
- Do one of the following:
-
Click Decrypt All to decrypt all encrypted drives in the device.
-
Click Summary, select a disk, and click Decrypt to decrypt only the selected disk.
Decryption begins immediately and the Manage Disk page shows the decryption progress. -
- When decryption completes, Full Disk Encryption displays the following options:
-
For system disks, Full Disk Encryption displays Restore Boot Partition or Unlock SED, depending on the disk type.For details, see Restore Boot.
-
For data disks, Full Disk Encryption displays Detach Disk. Click to exclude the disk from being managed by Full Disk Encryption.
-
- Click Exit to reboot the Endpoint Encryption device.
- Log on the Full Disk Encryption preboot.
- Log on to Windows.Verify that all disks selected for decryption are no longer encrypted.