Skip to content
Supported migration paths

Uninstall SafeGuard Enterprise on Windows computers

This page describes how to uninstall the SafeGuard Enterprise Windows client.

Before you uninstall SafeGuard Enterprise

On Windows computers with SafeGuard Enterprise BitLocker installed, encrypted volumes remain encrypted when you uninstall the SafeGuard Enterprise client. You're only removing BitLocker management.

We recommend migrating recovery key management to another application before uninstalling the SafeGuard Enterprise Windows client.

See Migrate BitLocker key management.

Allow uninstalling SafeGuard Enterprise

If you assigned a policy to your Windows computers that prevents uninstalling the SafeGuard Enterprise client, you must update the policy.

To update the policy, do as follows:

  1. In SafeGuard Management Center, open your policy of type Specific Machine Settings.
  2. If the Uninstallation allowed policy setting is No, set it to Yes.

    If Uninstallation allowed is already Yes, go to Uninstall SafeGuard Enterprise.

  3. Go to Users and Computers and right-click the domain node containing the Windows computers with a SafeGuard Enterprise client.

  4. Select New > Create new group.
  5. Select the domain node of the new group.
  6. Drag the policy from Available Policies tab to the Policies tab.
  7. To activate the policy, drag the group from the Available Groups list to the Activation area.
  8. On the domain node's Policies tab, set Priority to 1 and turn on No Override.
  9. In the Activation area of the domain node, check that only group members are affected by this policy.
  10. Add all Windows computers to the group.
  11. Open the SafeGuard Enterprise clients on all Windows computers and let them synchronize with SafeGuard Enterprise Server.

Uninstall SafeGuard Enterprise

You need to uninstall Safeguard Enterprise on all your Windows computers. To do this, do as follows:

  1. In Windows settings, go to Apps & features and uninstall all SafeGuard Enterprise components.

    You must uninstall the components in the following order:

    1. The configuration package.
    2. The SafeGuard client.
    3. If applicable: The SafeGuard pre-installation package.
  2. Restart the computer.

  3. Sign in with an account that has local Windows administrator permissions.
  4. A clean-up tool starts automatically, performs post-processing tasks, and restarts the computer again.

    If the clean-up tool doesn't start automatically, start it by double-clicking the following file in Windows Explorer:

    C:\Program Files (x86)\Sophos\SafeGuard Enterprise\SGNCleanUp.exe.