Technical details for ESET Endpoint Encryption and Windows feature updates
Install Windows feature updates while Full Disk Encryption is installed.
Solution
To install Windows Feature updates on a Full Disk Encrypted system, the encryption drivers must be made available to Windows during the update. ESET Endpoint Encryption includes a file SetupConfig.ini stored inside the following directory:
C:\Users\Default\AppData\Local\Microsoft\Windows\WSUS\
If you are using a custom SetupConfig.ini file as part of your update process, ensure it has been fully tested alongside FDE.
The SetupConfig.ini file passes /reflectdrivers to Windows during the update process, which passes the encryption driver to Windows to access the disk correctly during the update. Without this switch, Windows cannot read the disk correctly due to the encryption, and the update process will fail.
After Windows successfully installs an update, the Postoobe switch runs a script. The Postoobe script creates the necessary entries to allow Windows to update correctly again in the future.
The ESET Endpoint Encryption Windows Update utility uses the /ConfigFile switch to point Windows toward the SetupConfig.ini file.
Additional information
Visit the following Microsoft articles: