If someone has 2 different computers, both encrypted with DE in the same ePO, is there a risk to running the DE: user query and resetting the User's token or is everything ok??
Generally speaking, any risks should be minimal but of course, I really cannot say that there are no risks for any action related to MDE or not. For example, if the token is in a new/reset state on a system and that system is stolen before the user gets a chance to reboot and get their token set up again, then the person who stole the system may be able to use that to their advantage in gaining access to the system. Of course, there are some best practices that could be utilized to minimize that risk like using a default password that is different than the McAfee default one, ensuring that user assignments on any given system cover only the minimum number of users necessary for that system, not using the option to "do not prompt for default password", etc.
In asking about risks, is there a specific situation that you are concerned about?
User has a computer (log in with pw, no smart card or fob) that will be replaced, the build team is working on the new computer and decide to reset the token in the middle of the process. Will the User's current computer not log in or have any problems arise due to this? Should we alert the user to reboot after the token is reset so they can get the new one?
In this situation, if the token reset has already been completed on the ePO server, then when the current computer syncs up with ePO, it will receive that reset state. Depending upon when it was done and if the system is online and can reach ePO or an agent handler then it may have already received it. Once the reset is received, if they are not aware of the change, they will probably attempt to enter their normal password and get failure messages. Depending upon your policy settings, too many failures could cause their account to be locked.
With that in mind, I would definitely let them know that a reset was issued to their user account.
If you are so inclined, you\they can check the MfeEpe.log to see if the system has received the reset just looking for the key word "reset" associated to their user in recent messages.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA