Kaspersky Endpoint Security for Windows 11.0.0

Special considerations for file encryption

When using file encryption functionality, keep the following points in mind:

  • The Kaspersky Security Center policy with preset settings for removable drive encryption is formed for a specific group of managed computers. Therefore, the result of applying the Kaspersky Security Center policy configured for encryption / decryption of removable drives depends on the computer to which the removable drive is connected.
  • Kaspersky Endpoint Security does not encrypt / decrypt files with read-only status that are stored on removable drives.
  • Kaspersky Endpoint Security encrypts / decrypts files in predefined folders only for local user profiles of the operating system. Kaspersky Endpoint Security does not encrypt / decrypt files in predefined folders of roaming user profiles, mandatory user profiles, temporary user profiles, and redirected folders. The list of standard folders recommended by Kaspersky for encryption includes the following folders:
    • My Documents
    • Favorites
    • Cookies
    • Desktop
    • Temporary Internet Explorer files
    • Temporary files
    • Outlook files
  • Kaspersky Endpoint Security does not encrypt files whose modification could harm the operating system and installed applications. For example, the following files and folders with all nested folders are on the list of encryption exclusions:
    • %WINDIR%.
    • %PROGRAMFILES%, %PROGRAMFILES(X86)%.
    • Windows registry files.

    The list of encryption exclusions cannot be viewed or edited. While files and folders on the list of encryption exclusions can be added to the encryption list, they will not be encrypted during a file encryption task.

  • The following device types are supported as removable drives:
    • Data media connected via the USB bus
    • hard drives connected via USB and FireWire buses
    • SSD drives connected via USB and FireWire buses