Open the Kaspersky Security Center Administration Console.
In the Managed devices folder in the Administration Console tree, open the folder with the name of the administration group for which you want to generate a list of files to be decrypted.
In the workspace, select the Policies tab.
Select the necessary policy.
Open the Properties: <Policy name> window by using one of the following methods:
In the context menu of the policy, select Properties.
Click the Configure policy link located in the right part of the Administration Console workspace.
In the Data Encryption section, select File Level Encryption.
In the right part of the window, select the Decryption tab.
In the Encryption mode drop-down list, select the Default rules item.
On the Decryption tab, click the Add button, and in the drop-down list select one of the following items:
Select the Predefined folders item to add files from folders of local user profiles suggested by Kaspersky experts to a decryption rule.
The Select predefined folders window opens.
Select the Custom folder item to add a manually entered folder path to a decryption rule.
The Add custom folder window opens.
Select the Files by extension item to add file extensions to a decryption rule. Kaspersky Endpoint Security does not encrypt files with the specified extensions on all local drives of the computer.
The Add / edit list of file extensions window opens.
Select the Files by group(s) of extensions item to add groups of file extensions to a decryption rule. Kaspersky Endpoint Security does not encrypt files that have the extensions listed in the groups of extensions on all local drives of computers.
The Select groups of file extensions window opens.
To save your changes, in the Properties: <Policy name> window, click OK.
Apply the policy.
For details on applying a Kaspersky Security Center policy, please refer to the Kaspersky Security Center Help Guide.
If the same file has been added to the encryption rule and the decryption rule, Kaspersky Endpoint Security does not encrypt this file if it is not encrypted, and decrypts the file if it is encrypted.