Symantec Endpoint Encryption v11.0.1 Recovery Procedure from an UnExpected corruption of OS.
Important Note:
Do & Don’ts for Symantec Endpoint Encryption
=> Never format “C” drive or System Boot Drive (Where OS is installed) without performing Decryption for all the drives. If “C” drive or System Boot Drive (OS in installed) is formatted then data is unrecoverable from the remaining drives.
=> Never perform Windows Recovery / Windows Installation/ Third party Recovery without performing Decryption of Disc which will lead to Data Corruption & Unrecoverable.
=> Force Shutdown of System should be avoided which may lead to MBR Corruption.
Case study: Operation System is Corrupted and windows can’t boot normally, we will perform decryption of full disk using WinPE.
Steps to Follow.
1. Boot From WInPE Recovery Media USB.
If you don't know about WinPE recovery media Refer https://support.symantec.com/en_US/article.TECH223783.html
=> Type following command to check disk status.
eedAdminCli --disk 0 --status --au username --ap password
(Please Enter Actual Admin username & Password above)
2. Find Out users of client machine
=> List User: The --list-userscommand lists user information for all registered users.
3. Start eedRecoveryGui.exe From Command Line.
Command: eedRecoveryGui.exe
Click NEXT to decrypt full disk.
Select Disk to Decrypt
You can Chose one of the below method.
Select Client Admin & Enter Administrator UserName and Password, Enter the relevant Information and press Next.
Now It will start decrypting Disk.
Most Important: Be Patient It will take a long time to decrypt whole disk. ( Depends on your Drive size but still minimum 5-6 Hours )
Successful Decryption.
Done.