See below for the Windows-specific Policy Agent issues in 10.6.1.

Windows Server 2025 MBR VM installation is unsupported

Windows policy agent installation is not allowed in Windows Server 2025 MBR (Legacy BIOS) VMs.

VM does not boot after bootloader installation

If the Windows VM installed with the Entrust policy agent's bootloader does not boot:

  1. Disable the OS secure boot option and retry.
  2. Update to the latest Microsoft patch, as this behavior may have been fixed.

KVM bootloader support is unavailable

Windows policy agent does not support bootloaders in the Windows VM created on the KVM hypervisor.

Imported disk rekey does not restart automatically

Importing an encrypted disk with a pending rekey does not automatically restart the rekey. Reboot the system after importing the disk to resume the rekeying process.

Bootloader installation error during Windows boot encryption

If the following error is seen during Windows boot encryption, "Please install the Windows bootloader before encrypting," and the bootloader is already installed, then perform the following steps:

  1. Verify that the HyTrust Bootloader partition is available on the boot disk (labeled "HTBOOTLDR" or "HTEFIBL").
  2. Mount the Bootloader partition with the Drive Letter specified at HKLM\Software\HyTrust\bootldr_driveletter in the registry.
  3. If the HyTrust bootloader partition is not available, install it using the InstallHTBootloader.ps1 script.

MBR to GPT conversion is unsupported

Converting MBR boot disk to GPT using MBR2GPT utility is not supported.

Shrinking a partition during rekey fails

Shrinking an encrypted partition during rekey fails. After rekey completes, extend the file system using the diskpart command and then shrink the partition.

VM cloning with an encrypted Active Directory drive is unsupported

You cannot clone a VM if one of the encrypted data drives on that VM contains a Windows Active Directory (AD) Server and its AD Database.

Background encryption requires Vault availability after reboot

If the system reboots while a drive is being encrypted in the background, the drive becomes inaccessible if the Cryptographic Security Platform Vault is not accessible. Workaround: Reboot the system again after the Cryptographic Security Platform Vault becomes available.

Partition extension leaves unallocated space

If unallocated space exists between two partitions, extending a partition will leave 10MB of unallocated space after the extended partition.

Encrypted disks do not attach after reauthorization or certificate expiry

If a system is rebooted after the grace period has expired, when reauthorization is required, or if the VM certificate has expired, Cryptographic Security Platform Vault does not attach the encrypted data disks. If the Active Directory Database (AD DB) is located on one of the encrypted data disks, the system will not boot.

Workaround for AD DB issue:

  1. Boot the system into Directory Services Restore Mode (DSRM)
  2. Take the appropriate corrective action
  3. Ensure the data disks are correctly attached
  4. Reboot the system

Workaround for all other cases:

  1. Take the appropriate corrective action
  2. Reboot the system or restart any services that failed because disks were not available
  3. Restart the 'LanManServer' service for File Sharing

Encrypted data drives require the HCLD service

Encrypted data drives will become inaccessible if the Entrust KeyControl Service 'HCLD' is stopped.

Bootloader network interface configuration error

If you see the error message: "HyTrust Bootloader is configured to use a network interface which is different from the one used to connect to the Cryptographic Security Platform Vault server. Please reconfigure HyTrust bootloader network configuration to use the correct network interface. If you do not wish to update the network configuration (not recommended), please use option 'N'."

  1. Verify the network setting using htblconf.exe or the PowerShell SetupHTBootloaderNetwork.ps1 script.
  2. If you do not want to update the network configuration, or you determine that networking is configured correctly for the bootloader, use the -N option (as suggested) to force encryption in those cases. For example: 
    hcl encrypt -N C:

Imported disks can receive conflicting drive letters

When importing disks to a Windows VM, Windows may assign a conflicting drive letter to the newly imported partitions. In Windows Disk Manager, reassign the drive letters as needed before using hcl import to incorporate the new drive.

Migrated encrypted disks can receive incorrect drive letters

Migrating an encrypted disk from one VM to another VM may cause incorrect/invalid drive letter assignments. To correct the drive letter assignments:

  1. Remove current drive letter assignments for all the encrypted data disks.
  2. Assign drive letters to the encrypted data disks that were already present on the VM. Each drive letter assignment must be the same as what it was before.
  3. Assign any available drive letter to the migrated encrypted data disk.

Boot volume extension can show an incorrect size in the web GUI

If Cryptographic Security Platform Vault is unreachable when you extend the boot volume using the MoveHTBootloader.ps1 script, the new size of the disk may not be accurately displayed in the Cryptographic Security Platform Vault web GUI. Workaround: Manually update the volume size in the web GUI using the following command.

hcl extend C:.

PendingFileRename can prevent SEP installation

A PendingFileRename registry entry is created on HCLD startup with a location for the following file:

hcs\hcld.boot

SEP might refuse to install if this registry key is present. See https://support.symantec.com/en_US/article.TECH98292.html for details.

If hcs\hcld.boot is the only entry in the PendingFileRename registry entry:

  1. Back up the following entry 
    Key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\PendingFileRename
  2. Restart SEP installation
  3. Wait while the installation completes
  4. Restore the backup before any system restart.

Early Attach requires a gateway with a static first NIC

Early Attach requires the Gateway to be configured if the first network interface has a Static IP address. NIC teaming is not supported.

Paging files on encrypted data drives are unsupported

Windows Policy Agent does not support the paging file on encrypted data drives.

Encrypted boot partitions and Policy Agent binaries require C:

Windows Policy Agent requires the boot partition to be on C: if it is to be encrypted. Also, encryption of a non-C: device that contains the Policy Agent binary is not supported.

Azure instance restarts prevent Early Attach on first boot

Azure replaces the Network Interface and assigns a new MAC address on VM Instance restart. Early Attach cannot set up access to encrypted data disks on the first boot. Workaround: Reboot the guest OS.

Do not reboot or shut down while a disk is decrypting

Do not reboot or shut down while a disk is being decrypted. If the system reboots while a disk is being decrypted, it might not reboot, or the data disk might become inaccessible due to File System corruption.