Encrypting files on local computer drives

Kaspersky Endpoint Security does not encrypt files that are located in OneDrive cloud storage or in other folders that have OneDrive as their name. Kaspersky Endpoint Security also blocks the copying of encrypted files to OneDrive folders if those files are not added to the decryption rule.

To encrypt files on local drives:

  1. Open the Kaspersky Security Center Administration Console.
  2. In the Managed devices folder in the Administration Console tree, open the folder with the name of the administration group to which the relevant client computers belong.
  3. In the workspace, select the Policies tab.
  4. Select the necessary policy and double-click to open the policy properties.
  5. In the policy window, select Data EncryptionFile Level Encryption.
  6. In the Encryption mode drop-down list, select According to rules.
  7. On the Encryption tab, click the Add button, and in the drop-down list select one of the following items:
    1. Select the Predefined folders item to add files from folders of local user profiles suggested by Kaspersky experts to an encryption rule.
      • Documents. Files in the standard Documents folder of the operating system, and its subfolders.
      • Favorites. Files in the standard Favorites folder of the operating system, and its subfolders.
      • Desktop. Files in the standard Desktop folder of the operating system, and its subfolders.
      • Temporary files. Temporary files related to the operation of applications installed on the computer. For example, Microsoft Office applications create temporary files containing backup copies of documents.
      • Outlook files. Files related to the operation of the Outlook mail client: data files (PST), offline data files (OST), offline address book files (OAB), and personal address book files (PAB).
    2. Select the Custom folder item to add a manually entered folder path to an encryption rule.

      When adding a folder path, adhere to the following rules:

      • Use an environment variable (for example, %FOLDER%\UserFolder\). You can use an environment variable only once and only at the beginning of the path.
      • Do not use relative paths. You can use the set \..\ (e.g. C:\Users\..\UserFolder\). The set \..\ denotes the transition to the parent folder.
      • Do not use the * and ? characters.
      • Do not use UNC paths.
      • Use ; or , as a separator character.
    3. Select the Files by extension item to add individual file extensions to an encryption rule. Kaspersky Endpoint Security encrypts files with the specified extensions on all local drives of the computer.
    4. Select the Files by groups of extensions item to add groups of file extensions to an encryption rule (for example, Microsoft Office documents). Kaspersky Endpoint Security encrypts files that have the extensions listed in the groups of extensions on all local drives of the computer.
  8. Save your changes.

As soon as the policy is applied, Kaspersky Endpoint Security encrypts the files that are included in the encryption rule and not included in the decryption rule.

File encryption has the following special features:

Page top