What are the key advantages of ESET Endpoint Encryption Enterprise Server?
Central console – Manages all ESET Endpoint Encryption clients remotely.
Disk encryption – Deploy and monitor full disk encryption remotely.
Key management – Add or revoke encryption keys without user action.
Password recovery – Unlock users locked out at pre-boot.
Directory integration – Imports users and teams from Active Directory.
Important note – No malware protection, runs outside ESET PROTECT.
Central management console – Controls ESET Endpoint Encryption clients over the internet.
Full disk encryption control – Deploy, monitor and recover FDE including TPM and OPAL.
Encryption key allocation – Issue, change or revoke keys silently, without user action.
Removable media policy – Encrypt USB media or block access to unencrypted devices.
Roles and Active Directory – System Admin, Admin, Help Desk roles plus AD import.
Important – No anti-malware, and it cannot be managed from ESET PROTECT.
ESET Endpoint Encryption Enterprise Server is the management console for ESET Endpoint Encryption clients, installed on a Windows machine in your own network and reaching endpoints through an ESET-hosted proxy, so no inbound firewall openings are required. The product line was formerly sold as DESlock+, and ESET documentation still refers to that predecessor name.
No inbound connections – All client and server traffic leaves the network outbound.
Remote password recovery – Help desk unlocks pre-boot logins without a site visit.
Inherited policy structure – Teams and sub-teams inherit policies, so exceptions stay small.
Multiple organisations – Separate sites or clients managed from one server installation.
Encryption status reports – Export workstation encryption state to PDF or CSV.
Remote device disabling – Block a lost or stolen endpoint from decrypting data.
The deciding factor is not headcount but whether laptops leave the building and whether someone other than the user has to be able to recover them. A company with fifteen field notebooks has the same key custody problem as one with fifteen hundred. Larger organisations run into the console split described below.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | By sector |
| Security questionnaire from large customers | Sometimes | ✓ | ✓ |
| Central key custody and recovery | Optional | ✓ | ✓ |
| This product fits | ✓ | ✓ | Partial |
The Swiss reporting obligation applies to operators of critical infrastructure, not to companies in general, and it took effect on 1 April 2025 under the revised Information Security Act, which requires a significant cyberattack to be reported to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. This console supports two things an operator has to be able to show inside that window: its reporting function records which workstations were encrypted at the time of an incident and exports that state to PDF or CSV, and the encryption keys of a lost or stolen device can be revoked so the device can no longer decrypt data. What it does not do is detect the attack. The server tracks encryption status, not malicious activity, so it generates no alerts and nothing that starts the 24-hour clock; that has to come from endpoint protection, EDR or log monitoring. It also cannot be viewed next to your antivirus estate in ESET PROTECT, so encryption evidence has to be collected from a second console. This text describes a product and is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.
No software product makes an organisation NIS 2 compliant. The directive requires risk management measures across categories including incident handling, business continuity and crisis management, supply chain security, access control, cryptography and encryption, and asset management, together with accountability duties for management bodies. This console addresses the cryptography category directly: it enforces disk and removable media encryption centrally, keeps encryption keys under administrator control rather than on the device, and produces per-device evidence that a laptop was encrypted before it went missing. It contributes nothing to incident handling, business continuity, vulnerability handling or supply chain security, and it has no incident reporting workflow of its own. Organisations that need those categories covered by the same vendor normally combine this console with an ESET PROTECT tier and accept running two separate management interfaces.
Yes, for the encryption and data protection block, and for nothing else. It answers questions on encryption at rest for notebooks and removable media, on algorithm and key length through FIPS 140-2 validated 256-bit AES, on pre-boot authentication, on central key custody and immediate key revocation, on separation of administrative duties through System Admin, Admin, Help Desk and custom roles, and on per-device proof of encryption state, which is the item auditors most often want evidenced rather than asserted. It answers nothing on malware protection, patching, vulnerability management, logging and monitoring, incident response times, multi-factor authentication or backup, because none of those functions exist in this product. It also cannot demonstrate a single pane of glass across security controls, which some questionnaires ask for explicitly. Where a questionnaire fails you on the detection and response items, adding an ESET PROTECT tier from the same vendor is usually the cheaper route than mixing suppliers, and it is worth checking first whether ESET Full Disk Encryption inside ESET PROTECT already covers what you need, because it removes the second console entirely.
The decisive difference is the console. ESET Full Disk Encryption is managed from ESET PROTECT next to your antivirus policies, while ESET Endpoint Encryption requires this separate Enterprise Server. The second difference is scope: ESET Full Disk Encryption encrypts disks and nothing else, whereas ESET Endpoint Encryption adds removable media encryption, file and folder encryption, virtual disks and encrypted archives, and an Outlook plugin for encrypted mail. Licensing differs as well, per user here and per device there. Client editions also matter, because this server can only enable what a user's licence contains, and full disk encryption belongs to the Pro edition.
| Capability | ESET Endpoint Encryption | ESET Full Disk Encryption |
|---|---|---|
| Full disk encryption | ✓ | ✓ |
| Removable media encryption | ✓ | ✕ |
| File and folder encryption | ✓ | ✕ |
| Outlook plugin for encrypted email | ✓ | ✕ |
| Virtual disks and encrypted archives | ✓ | ✕ |
| Management from ESET PROTECT | ✕ | ✓ |
| BIOS systems supported | ✓ | ✕ |
| Licensing model | Per user | Per device |
The client is a Windows application. On macOS this server can switch on and recover Apple's native FileVault for users holding a Pro licence, but removable media, file and folder, virtual disk and Outlook encryption are Windows only, and there is no Linux client. Full disk encryption does not run on ARM-based Windows devices and is not supported on Macs that use Boot Camp to dual-boot. The console itself is an on-premises Windows installation with its own database, so it is a further system you have to patch, back up and include in your own recovery planning, and there is no ESET-hosted alternative console for this product. The limitation that most often causes a follow-up purchase is the missing link to ESET PROTECT: encryption status lives here and threat detection lives elsewhere, so teams that expected one dashboard end up either operating both or switching to ESET Full Disk Encryption.
No, the client also runs standalone, where the user controls their own keys and settings. Without the server there is no central key custody, no remote policy enforcement and no administrator-side password recovery, which is precisely what makes encryption defensible to an auditor.
An administrator issues a recovery from the console and the user regains access without the disk being decrypted or rebuilt. On managed Macs the FileVault recovery key is retrieved from the same console.
No. Both the server and the clients post to an ESET-hosted proxy over outgoing HTTPS, so a notebook in a hotel or home office stays manageable without a VPN and without any port forwarded into your network.
Yes. The server supports single or multiple organisations, and policies and encryption keys cascade down through teams and sub-teams, so one exception does not require a duplicated policy set.
Central console for ESET Endpoint Encryption clients. Deploys full disk encryption and holds the keys. Client licences are bought separately.
ESET Endpoint Encryption Enterprise Server, ESET, ESET Endpoint Encryption, DESlock, endpoint encryption software, encryption management console, full disk encryption, removable media encryption, encryption key management
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies