Prepare Device Encryption

By default, most system drives are prepared for BitLocker. If this is not the case, Sophos Central Device Encryption automatically runs the required Microsoft command line tool BdeHdCfg.exe to prepare the drive.

This means that a separate BitLocker partition is created on the system drive.

During setup of Sophos Central Device Encryption, a message informs the user that a restart is required to prepare the system drive. The user can choose to restart the computer immediately or postpone the operation. Device Encryption can only start when the computer is restarted and the preparation of the system drive has been successful.

The .NET Framework version required by Device Encryption is installed on the endpoints automatically.