Kaspersky Endpoint Security does not encrypt files whose contents are located in OneDrive cloud storage, and blocks the encrypted files from copying to OneDrive cloud storage, if these files are not added to decryption rule.
To encrypt files on local drives:
Open the Kaspersky Security Center Administration Console.
In the Managed devices folder in the Administration Console tree, open the folder with the name of the administration group to which the relevant client computers belong.
In the workspace, select the Policies tab.
Select the necessary policy and double-click to open the policy properties.
In the policy window, select Data Encryption → File Level Encryption.
In the right part of the window, select the Encryption tab.
In the Encryption mode drop-down list, select the Default rules item.
On the Encryption tab, click the Add button, and in the drop-down list select one of the following items:
Select the Predefined folders item to add files from folders of local user profiles suggested by Kaspersky experts to an encryption rule.
Documents. Files in the standard Documents folder of the operating system, and its subfolders.
Favorites. Files in the standard Favorites folder of the operating system, and its subfolders.
Desktop. Files in the standard Desktop folder of the operating system, and its subfolders.
Temporary files. Temporary files related to the operation of applications installed on the computer. For example, Microsoft Office applications create temporary files containing backup copies of documents.
Outlook files. Files related to the operation of the Outlook mail client: data files (PST), offline data files (OST), offline address book files (OAB), and personal address book files (PAB).
Select the Custom folder item to add a manually entered folder path to an encryption rule.
When adding a folder path, adhere to the following rules:
Use an environment variable (for example, %FOLDER%\UserFolder\). You can use an environment variable only once and only at the beginning of the path.
Do not use relative paths. You can use the set \..\ (e.g. C:\Users\..\UserFolder\). The set \..\ denotes the transition to the parent folder.
Do not use the * and ? characters.
Do not use UNC paths.
Use ; or , as a separator character.
Select the Files by extension item to add individual file extensions to an encryption rule. Kaspersky Endpoint Security encrypts files with the specified extensions on all local drives of the computer.
Select the Files by groups of extensions item to add groups of file extensions to an encryption rule (for example, Microsoft Office Documents). Kaspersky Endpoint Security encrypts files that have the extensions listed in the groups of extensions on all local drives of the computer.
Save your changes.
As soon as the policy is applied, Kaspersky Endpoint Security encrypts the files that are included in the encryption rule and not included in the decryption rule.
If the same file has been added to the encryption rule and the decryption rule, Kaspersky Endpoint Security does not encrypt this file if it is not encrypted, and decrypts the file if it is encrypted.
Kaspersky Endpoint Security encrypts unencrypted files if their properties (file path or file extension) meet the encryption rule criteria after modification.
Kaspersky Endpoint Security postpones the encryption of open files until they are closed. When the user creates a new file whose properties meet the encryption rule criteria, Kaspersky Endpoint Security encrypts the file as soon as it is opened.
If you move an encrypted file to another folder on the local drive, the file remains encrypted regardless of whether or not this folder is included in the encryption rule.