See below for the Windows-specific Policy Agent issues in 10.6.1.
- Windows Server 2025 MBR VM installation is unsupported
- VM does not boot after bootloader installation
- KVM bootloader support is unavailable
- Imported disk rekey does not restart automatically
- Bootloader installation error during Windows boot encryption
- MBR to GPT conversion is unsupported
- Shrinking a partition during rekey fails
- VM cloning with an encrypted Active Directory drive is unsupported
- Background encryption requires Vault availability after reboot
- Partition extension leaves unallocated space
- Encrypted disks do not attach after reauthorization or certificate expiry
- Encrypted data drives require the HCLD service
- Bootloader network interface configuration error
- Imported disks can receive conflicting drive letters
- Migrated encrypted disks can receive incorrect drive letters
- Boot volume extension can show an incorrect size in the web GUI
- PendingFileRename can prevent SEP installation
- Early Attach requires a gateway with a static first NIC
- Paging files on encrypted data drives are unsupported
- Encrypted boot partitions and Policy Agent binaries require C:
- Azure instance restarts prevent Early Attach on first boot
- Do not reboot or shut down while a disk is decrypting
Windows Server 2025 MBR VM installation is unsupported
Windows policy agent installation is not allowed in Windows Server 2025 MBR (Legacy BIOS) VMs.
VM does not boot after bootloader installation
If the Windows VM installed with the Entrust policy agent's bootloader does not boot:
- Disable the OS secure boot option and retry.
- Update to the latest Microsoft patch, as this behavior may have been fixed.
KVM bootloader support is unavailable
Windows policy agent does not support bootloaders in the Windows VM created on the KVM hypervisor.
Imported disk rekey does not restart automatically
Importing an encrypted disk with a pending rekey does not automatically restart the rekey. Reboot the system after importing the disk to resume the rekeying process.
Bootloader installation error during Windows boot encryption
If the following error is seen during Windows boot encryption, "Please install the Windows bootloader before encrypting," and the bootloader is already installed, then perform the following steps:
- Verify that the HyTrust Bootloader partition is available on the boot disk (labeled "HTBOOTLDR" or "HTEFIBL").
- Mount the Bootloader partition with the Drive Letter specified at HKLM\Software\HyTrust\bootldr_driveletter in the registry.
- If the HyTrust bootloader partition is not available, install it using the InstallHTBootloader.ps1 script.
MBR to GPT conversion is unsupported
Converting MBR boot disk to GPT using MBR2GPT utility is not supported.
Shrinking a partition during rekey fails
Shrinking an encrypted partition during rekey fails. After rekey completes, extend the file system using the diskpart command and then shrink the partition.
VM cloning with an encrypted Active Directory drive is unsupported
You cannot clone a VM if one of the encrypted data drives on that VM contains a Windows Active Directory (AD) Server and its AD Database.
Background encryption requires Vault availability after reboot
If the system reboots while a drive is being encrypted in the background, the drive becomes inaccessible if the Cryptographic Security Platform Vault is not accessible. Workaround: Reboot the system again after the Cryptographic Security Platform Vault becomes available.
Partition extension leaves unallocated space
If unallocated space exists between two partitions, extending a partition will leave 10MB of unallocated space after the extended partition.
Encrypted disks do not attach after reauthorization or certificate expiry
If a system is rebooted after the grace period has expired, when reauthorization is required, or if the VM certificate has expired, Cryptographic Security Platform Vault does not attach the encrypted data disks. If the Active Directory Database (AD DB) is located on one of the encrypted data disks, the system will not boot.
Workaround for AD DB issue:
- Boot the system into Directory Services Restore Mode (DSRM)
- Take the appropriate corrective action
- Ensure the data disks are correctly attached
- Reboot the system
Workaround for all other cases:
- Take the appropriate corrective action
- Reboot the system or restart any services that failed because disks were not available
- Restart the 'LanManServer' service for File Sharing
Encrypted data drives require the HCLD service
Encrypted data drives will become inaccessible if the Entrust KeyControl Service 'HCLD' is stopped.
Bootloader network interface configuration error
If you see the error message: "HyTrust Bootloader is configured to use a network interface which is different from the one used to connect to the Cryptographic Security Platform Vault server. Please reconfigure HyTrust bootloader network configuration to use the correct network interface. If you do not wish to update the network configuration (not recommended), please use option 'N'."
- Verify the network setting using htblconf.exe or the PowerShell
SetupHTBootloaderNetwork.ps1script. - If you do not want to update the network configuration, or you determine that networking is configured correctly for the bootloader, use the -N option (as suggested) to force encryption in those cases. For example:
hcl encrypt -N C:
Imported disks can receive conflicting drive letters
When importing disks to a Windows VM, Windows may assign a conflicting drive letter to the newly imported partitions. In Windows Disk Manager, reassign the drive letters as needed before using hcl import to incorporate the new drive.
Migrated encrypted disks can receive incorrect drive letters
Migrating an encrypted disk from one VM to another VM may cause incorrect/invalid drive letter assignments. To correct the drive letter assignments:
- Remove current drive letter assignments for all the encrypted data disks.
- Assign drive letters to the encrypted data disks that were already present on the VM. Each drive letter assignment must be the same as what it was before.
- Assign any available drive letter to the migrated encrypted data disk.
Boot volume extension can show an incorrect size in the web GUI
If Cryptographic Security Platform Vault is unreachable when you extend the boot volume using the MoveHTBootloader.ps1 script, the new size of the disk may not be accurately displayed in the Cryptographic Security Platform Vault web GUI. Workaround: Manually update the volume size in the web GUI using the following command.
hcl extend C:.PendingFileRename can prevent SEP installation
A PendingFileRename registry entry is created on HCLD startup with a location for the following file:
hcs\hcld.bootSEP might refuse to install if this registry key is present. See https://support.symantec.com/en_US/article.TECH98292.html
for details.
If hcs\hcld.boot is the only entry in the PendingFileRename registry entry:
- Back up the following entry
Key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\PendingFileRename - Restart SEP installation
- Wait while the installation completes
- Restore the backup before any system restart.
Early Attach requires a gateway with a static first NIC
Early Attach requires the Gateway to be configured if the first network interface has a Static IP address. NIC teaming is not supported.
Paging files on encrypted data drives are unsupported
Windows Policy Agent does not support the paging file on encrypted data drives.
Encrypted boot partitions and Policy Agent binaries require C:
Windows Policy Agent requires the boot partition to be on C: if it is to be encrypted. Also, encryption of a non-C: device that contains the Policy Agent binary is not supported.
Azure instance restarts prevent Early Attach on first boot
Azure replaces the Network Interface and assigns a new MAC address on VM Instance restart. Early Attach cannot set up access to encrypted data disks on the first boot. Workaround: Reboot the guest OS.
Do not reboot or shut down while a disk is decrypting
Do not reboot or shut down while a disk is being decrypted. If the system reboots while a disk is being decrypted, it might not reboot, or the data disk might become inaccessible due to File System corruption.