File-based full disk encryption

File-based encryption ensures that all data is encrypted, apart from the boot medium and directory information. With file-based encryption, even optical media such as CD/DVD can be encrypted. Also, data can be exchanged with external computers on which SafeGuard Enterprise is not installed, if policies permit, see SafeGuard Data Exchange.

Note: Boot volumes are never file-based encrypted. They are automatically exempted from file-based encryption, even if a corresponding rule is defined.
Note: Data encrypted using file-based encryption cannot be compressed. Nor can compressed data be file-based encrypted.

To apply file-based encryption to endpoints, create a policy of the type Device Protection and set the Media encryption mode to File-based.