I had a machine with Full Disk Encryption and tried out the Recovery process. The process completed successfully: the disk was fuly decrypted, and Pre-boot authentication was disabled. However, the next steps were somewhat unclear to me. Since the Data Protection policy rule applied to that machine still has FDE enabled, I expected the disk to re-encrypt automatically once the agent updated the policy, but this wasn't the case. I attempted to reinstall the policy with minor adjustments via the Infinity Portal, but FDE remained inactive.
Questions:
- What is the correct procedure to reactivate Full Disk Encryption for this machine?
- Why didn’t the re-encryption process start automatically as anticipated?
By the way, on the Infinity Portal, the deployment status of the FDE capability is: installed, not activated.
![deployment.jpg deployment.jpg](https://community.checkpoint.com/t5/image/serverpage/image-id/28282iCB7B988F3DA76DB9/image-size/large?v=v2&px=999)
On the other hand, the Full Disk Encryption view shows the following statuses to the FDE blades:
![fde view.jpg fde view.jpg](https://community.checkpoint.com/t5/image/serverpage/image-id/28283i0DDF9F9C610F9736/image-size/large?v=v2&px=999)
On the machine, this is the FDE view:
![epsec.png epsec.png](https://community.checkpoint.com/t5/image/serverpage/image-id/28284i040CB2CC0A42E98A/image-size/large?v=v2&px=999)