SafeGuard Enterprise Client: description of ADDLOCAL command line parameters for installation

  • Article ID: 108426
  • Rating:
  • 4 customers rated this article 5.0 out of 6
  • Updated: 02 Feb 2016

This article describes the parameters you can use when the SafeGuard Client installation is done using msiexec and ADDLOCAL.

Known to apply to the following Sophos product(s) and version(s)
SafeGuard Enterprise
SafeGuard Easy Client, all versions.

Operating systems
All supported versions.

What To Do

Functions that are available for installation in the user interface can also be entered using the switch ADDLOCAL for an automated installation which uses parameters. The availability of features differs depending on the used SafeGuard Client version and Operating System.

It is important to note that the majority of Features (second column in the table) are associated with a Feature_Parent (third column in the table) and require this Feature_Parent to be considered during the installation.

Title (based on version 7) Feature Feature_Parent OS Comments 
Client Client XP, Vista, Win7, Win8  
n/a Authentication Client XP removed as of SGN 6.10
Full-disk encryption for internal and external hard disks BaseEncryption
Client XP, Vista, Win7, Win8
BitLocker BitLockerSupport
Vista, Win7, Win8  
BitLocker Challenge/Response BitLockerSupportCR BitLockerSupport Win7UEFI /Win8 UEFI 
64Bit only
available as of SGN 6.10
Cloud Storage CloudStorage
Client XP, Vista, Win7, Win8  
n/a ConfigurationProtection
XP, Vista, Win7
removed as of SGN 6.10
Credential Provider CredentialProvider
Vista, Win7, Win8  
File Encryption FileShare
Client XP, Vista, Win7, Win8  
Volume Based Encryption SectorBasedEncryption
BaseEncryption XP, Vista, Win7  
Data Exchange SecureDataExchange
Client XP, Vista, Win7, Win8

Note (does not apply any longer as of SafeGuard Client version 6.10):

The Features Client and Authentication (or CredentialProvider depending on the OS) must be used by Default.

For Example, if you just want to install the SGN Client with ConfigurationProtection, FileShare and CloudStorage on Windows XP then use:


If you want to install the same on a Windows Vista/ 7 machine then you would need to replace 'Authentication' with 'CredentialProvider'.

For further information, please refer to the SafeGuard Enterprise 6.0 installation guide, page 65.

Additional SGN client parameters

(Knowledgebase article 107781 - SafeGuard Enterprise: Hotkeys and the POA)

During the boot process, various combinations of SHIFT + Fx keys can be used to toggle SGN core functions of the.

Shift F3 = switch USB Legacy support (Off/On)*
Shift F4 = toggle from VESA to VGA graphics mode (Off/On)*
Shift F5 = switch USB support (Off/On)*
Shift F6 = switch from ATA to Int13 (Off/On)* 
Shift F7 = switch USB 2.0 support (Off/On)* 
Shift F9 = switch ACPI/APIC (Off/On)* 

* The bold marked option is the default value.

These toggles can be done during the installation by adding the below mentioned parameters. During an upgrade of the SafeGuard Device Encryption Client these parameters have no effect.

NOATA= (0/1)

Example installation for SGN clients with the following options using Windows 7

Your requirements:

- The functions shown in the GUI should be installed on the client
- The MSI Installer should document the installation process in a single file
- The SGN client configuration should be automatically installed
- USB support should be deactivated in the POA

The following commands are necessary to fulfill the above described requirements

msiexec /i "\\server\sgn\SGNClient_x64.msi" /l*v c:\log\SGNClient.log ADDLOCAL=Client,BaseEncryption,SectorBasedEncryption,CredentialProvider,SecureDataExchange ALTERNATE=1
msiexec /i "\\server\sgn\ClientConfig.msi" /L*v c:\log\ClientConfig.log

If you need more information or guidance, then please contact technical support.

Rate this article

Very poor Excellent