• Automatic Data Encryption only works for Linux and Windows devices that meet the qualifications described in Linux Encryption Prerequisites and Windows Encryption Prerequisites.
  • Automatic Data Encryption only works for Linux devices that are not mounted. Therefore, you cannot use Automatic Data Encryption to encrypt Linux system devices such as /root, swap, or /home.
  • Automatic Data Encryption for Linux works with partitioned disks only.
  • If you want to encrypt a Windows boot drive, you must install the Entrust Bootloader option with the Policy Agent on that VM. Auto encryption on the boot drive will fail if the Bootloader is not installed. For details, see Windows Boot Drive Encryption.
  • If you change the Automatic Data Encryption Policy for a Cloud VM Set, you can choose whether to propagate the changes to the VMs already registered with the set. If you do so, any changes you made on the individual VMs will be overwritten by the settings in the Cloud VM Set. All customizations on the individual VMs will be lost.
  • If you change the Automatic Data Encryption Policy to include a device that was not included before, Cryptographic Security Platform Vault automatically schedules a task to encrypt the newly- added device.
  • After a device has been encrypted (either manually or through an Automatic Data Encryption Policy), Cryptographic Security Platform Vault will not automatically decrypt it, even if you change the Automatic Data Encryption Policy to exclude that device. Once encrypted, all devices must be decrypted manually.
  • If you try to decrypt a device that is specified as Included in the Automatic Data Encryption Policy, the decryption task will fail. You must first remove the device from the Automatic Data Encryption Policy before you can decrypt it. If you remove the device from the policy at the VM-level, that device can only be decrypted on that VM. If you remove the device from the policy on the Cloud VM Set level and you propagate the changes from the Cloud VM Set to the registered VMs, then you can decrypt that device on any registered VM.