Hello Everyone,
I recently implemented Harmony Endpoint in my customer's environment and I noticed strange behavior with BitLocker Encryption.
The laptop we tested the solution on was encrypted with BitLocker prior to installation of Harmony Endpoint Client. Before the installation, we enabled Full Disk Encryption on the relevant Deployment policy, as well as on the relevant Data protection policy.
As expected, Harmony showed the endpoint as encrypted and didn't attempt to encrypt it again. We tried disabling Full Disk Encryption on the Deployment policy, but not on the Data protection policy and Harmony immediately started decrypting the disk. It made no particular sense to us, however, it might be for security reasons, so that the endpoint wouldn't stay encrypted without the ability to decrypt it since Full disk encryption is now disabled on Deployment policy.
Could someone please confirm if this is the reason for the described behavior?
In addition to the aforementioned, the strangest part about this feature was: when we disabled encryption on the Data protection policy and then enabled it on the Deployment policy, we expected the feature to be visible on the Endpoint Client, but the encryption to be turned off, however, as soon as we upgraded the client and installed the policy, Harmony Endpoint started Encrypting the disk.
What could be the reason for this behavior?
Thank you all in advance.