1546 - Using WinPE to do SecureDoc Recovery

Prev Next

Topic: This How-To article addresses the following tools within WinPE to do SecureDoc Recovery:

1.Obtaining and Creating Emergency Disk
2.Export SDSpace
3.Repair MBR/SDSpace/UEFI
4.Analyze and Recover
5.MBR SDSpace Recovery
6.UEFI Recovery
7.Restore Original MBR
8.DAC Unblock all devices               
 
Product version affected: SecureDoc 6.4 and newer, SDRecovery v3.0 and WinPE 6.5 supporting up to Windows 10
 
Environment:
All Windows OS versions
All devices
All SATA and Self-Encrypting OPAL 2 hard drives
 
WinPE tool Download:
Download the latest WinPE iso file https://fileshare.winmagic.com/link/tKkd6zB34mgkalBz4u8T42
If customers have difficulty downloading the iso file, please contact technical support for assistance. Please refer to KB 1540 – How to create a Bootable WinPE USB tool
 
Steps to follow:

1. Obtaining and Creating Emergency Disk

The SES database contains all the information necessary to create recovery media that Users can use if, for some reason, Boot Logon is missing, keys are lost, or other issues are encountered with their encrypted boot disk or any internal or external drives associated with the device.
 
Note1: You must use the same password for SDSpace Recovery at boot logon that was created while creating the emergency disk. Thus, it is strongly recommended to remember this password.
Note2: If a device profile is deleted, emergency disk cannot be created.
 
Additional Reference Material:
 
KB 1039 - How to Create Emergency Disk from a SD Standalone Device
KB 1543 - How to Create Emergency Disk From SES Console
KB 1544 - How to Create Emergency Disk from SESWeb Console
 
Step 1: Generate Emergency Disk for Target device, Save to the root of an external media (E.g. USB Disk)
Note: Emergency Disk is unique for each device.
Graphical user interface, application  Description automatically generated

Once generated, the contents of external media should look similar as the screenshot shown.
Note: It may differ depending on the SecureDoc version.
 
Graphical user interface, application  Description automatically generated

2.Export SDSpace

Step 1: Boot to WinPE.
Step 2: Insert an external media (e.g. USB device).
Step 3: Open SDRecovery from the Emergency Disk folder that was created from SES or SD Client and Click on Export SDSpace.
Note: There is no need to Unlock the Drive prior to selecting Export SDSpace.

Graphical user interface, text, application  Description automatically generated

Step 4: Type in a filename and Save on external media.
 
Graphical user interface, text  Description automatically generated 

3.Repair MBR/SDSpace/UEFI

As from SDRecovery 3.0, new options are available to scan and repair MBR, UEFI and SDSpace depending on the option selected.

Graphical user interface, text, application, email  Description automatically generated



NOTE: The following recovery/restore options will NOT work on Self-Encrypting Drives.
 

SSDRecovery Option

Aim

Pre-Requisite

Analyze and Recover

To scan and fix EFI and MBR Corruptions

  1. WinPE should be created on bootable USB or Disk.
  2. Emergency Disk should be created from SES or SD Client.

MBR and SDSpace Recovery

To restore MBR and SDSpace from Emergency Backup from SES

  1. WinPE should be created on bootable USB or Disk.
  2. Emergency Disk should be created from SES or SD Client.

UEFI Recovery

To fix UEFI boot order

  1. WinPE should be created on bootable USB or Disk.

Restore original MBR

Restores original MBR

  1. Drive should not be encrypted.

 

4.Analyze and Recover

The Analyze and Recover option detects the system problems and repairs it.

  1. Click on the Recover tab.
  2. Click on the Analyzer and Recover option from the dropdown menu. The Emergency disk path window opens.

  Graphical user interface, text, application  Description automatically generated

     3. Navigate to the Emergency Disk folder that you have created from SES or SD Client.

Graphical user interface, text, application, email  Description automatically generated

4. Click Choose. A message “Analyzing Disk 0 Completed successfully”, is displayed. 

Graphical user interface, text, application  Description automatically generated

5. Click OK.

5.MBR SDSpace Recovery

WARNING: Use this option only when MBR or SDSpace is corrupted.

  1. Click on the Recovery tab.
  2. Select MBR SDSpace and Recovery.

Graphical user interface, text, application  Description automatically generated

A prompt, “SecureDoc MBR is not valid. Do you want to recover MBR on Disk 0?” is displayed.

T:\Nagesh\winpe\1.PNG

3. Click Yes if you want to recover MBR; otherwise, Click No if you want to recover only SDSpace and then go to step 5.
 
Graphical user interface, text, application, email  Description automatically generated

4. Click Choose. A confirmation message, “MBR on Disk 0 has been overwritten successfully” is displayed.

Graphical user interface, text, application, chat or text message  Description automatically generated

5. When clicked No to recover the SDSpace only, a prompt “Do you want to recover SDSPACE on Disk 0?” appears.

Graphical user interface, text, application  Description automatically generated

6. Click Yes. A message “SDSPACE on Disk 0 has been overwritten successfully” is displayed.

Graphical user interface, text, application, chat or text message  Description automatically generated 

7. Click OK.

6.UEFI Recovery

Note: This option is enabled for UEFI devices only. Use UEFI-based WinPE bootable disk.

  1. Click on the Recovery tab.
  2. Select UEFI Recovery.



A prompt, “Do you want to recover UEFI boot files?” is displayed.
Graphical user interface, text, application, chat or text message  Description automatically generated


3. Click No. A prompt, “Do you want to recover UEFI Boot Order variable?” is displayed.
Graphical user interface, text, application  Description automatically generated 

3. Click Yes. A confirmation message, “UEFI Boor Order variable has been recovered successfully” is displayed.

A screenshot of a computer  AI-generated content may be incorrect. 

5. Click OKNote: If the device fails to boot, then proceed to perform the next steps.
6. Repeat the steps 1 through 2. A confirmation message, “UEFI Boot Files have been recovered successfully” is displayed.

Graphical user interface, application  Description automatically generated 

7. Click Yes. A confirmation message, “UEFI Boot Files have been recovered successfully”, is displayed.
 
A screenshot of a computer  AI-generated content may be incorrect.

8. Click OK.

7.Restore Original MBR

WARNING: Use this option only when the drive is NOT encrypted.

1. Click on the Recovery tab.
2. Select Restore original MBR.

Graphical user interface, text, application  Description automatically generated
 
3. A prompt, “Do you want to restore original MBR on Disk 0?” is displayed.

Graphical user interface, text, application  Description automatically generated

3. Click Yes.
4. Navigate to the emergency disk folder.

Graphical user interface, text, application, email  Description automatically generated 

5. Click Choose. A message, “Original MBR on Disk 0 has been restored successfully”, is displayed.
 

8.DISABLE DISK ACCESS CONTROL (DAC)

Disk Access Control may be enabled in the profile on the client device.  By default, the administrator, when booting to WinPE, will not have write access to any external media plugged in to the WinPE environment.

A screenshot of a computer  AI-generated content may be incorrect.

  • First Unlock the Encrypted drive with SDRecovery.

A screenshot of a computer  AI-generated content may be incorrect.
 

  • The menu option ‘DAC Unblock’ is no longer greyed-out and is now available. 

Note: Only unlocking with an admin key file will allow the ‘DAC Unblock’ option to be available.

A screenshot of a recovery software  AI-generated content may be incorrect.
 

  • Click on the menu to unblock external media. You can now save data from the WinPE environment to any external media (e.g USB drive) plugged in.

 A screenshot of a computer error  AI-generated content may be incorrect.