Decrypt a device using a rule

You can decrypt and remove Disk Encryption Manager from multiple devices. Note that when you decrypt devices, you remove all encryption from all drives. If you need to re-enable decryption, you need to run the encryption process again.

Using a rule, SolarWinds N-central automates the decryption and uninstall of Disk Encryption Manager with no user intervention, ensuring all selected devices automatically have a disk encryption solution removed.

You need to create a filter that selects devices based on the criteria you have for deployed disk encryption.

  1. Click Configuration > Monitoring > Rules and click Add.
  2. Enter a Name and Description.
  3. Click the Devices to Target tab and select the filters to add to the Selected Filters box.
  4. Click the Network Device Configuration Options tab, then Security Manager.
  5. Click to deselect the check box for Enable Disk Encryption.
  6. You have the option to Leave the device encrypted or Decrypt all volumes.
  7. Bitlocker is natively part of the device system. If you chose to remove the Disk Encryption Manager from a device and leave the disk encrypted, you will lose the management capabilities. Ensure you collect all recovery keys before choosing this option. You should ALWAYS obtain the recovery key. SolarWinds MSP does not store or backup recovery keys. If something goes wrong with the decryption, and you removed the device from SolarWinds N-central, there is no way to recall the recovery keys or unlock the drive. SolarWinds N-central stores deleted device recovery keys for 90 days.

  8. Note that decryption cannot occur during a maintenance window.

  9. If creating this rule at the Service Organization level, click the Grant Customers & Sites Access tab and select how to propagate the rule to other customers and sites and select the customer/sites from the list.
  10. Click Save.

BitLocker begins the decryption process on the disk drives of selected devices. The user will see a message indicating that the decryption process has started.